Overview
The core discussion covers DNS Belgium's decision, matured over 10 years of annual risk assessments, to leave AWS and find a fully European alternative for its registry systems, driven by geopolitical risk and its exemplary role as manager of Belgium's critical .be infrastructure. Tuyteleers explains vendor lock-in, the 'too big to regulate' power concentration among a handful of cloud players, the compliance burden disadvantaging European providers, and the loss of the internet's original decentralized, redundant design. He urges companies to at least prepare technically for potential migrations and to reinvest ICT spending in European technology to restore innovation capacity.
Talks about
- Geopolitics
- Defense tech
- Digital Sovereignty
Insights & ideas
The through-line
Everything here circles one argument: sovereignty is a question of power concentration, not of technical quality. Kristof Tuyteleers does not claim American hyperscalers run bad infrastructure. He claims that six to ten companies now control an internet that was designed to be decentralised and hyper-redundant, and that we connected everything to it, from electricity meters to cars, exactly while that concentration was happening [1][2]. The consequence he keeps returning to: "Als alles aan het internet hangt en we hebben eigenlijk bijna geen controle meer over dat internet zelf, over die snelweg, die datasnelweg. Ja, hoe soeverein zijn we dan nog?" [1][2].
The shift he describes is gradual rather than dramatic. DNS Belgium re-evaluated its AWS dependency every year for more than a decade, and there was no single tipping point [1][2]. Geopolitical risk crept upward, and the inconsistency of preaching local digital identity while running on US infrastructure became untenable, so the decision to migrate to a European provider was finally taken last year [1][2]. The obligation he draws from being critical infrastructure is stated bluntly: "Wij zijn een kritische component in het internet in België. Dus wij vinden het gewoon onze verdomde plicht om ervoor te zorgen dat we klaar zijn" [1][2].
On differentiating risk function by function
The migration story is not a blanket rejection of cloud. DNS Belgium never put its core DNS "address book" function in the cloud at all, always self-hosting it, and used cloud only for its registrar or "notary" function, a deliberate risk assessment made separately per function [1][2]. What changed is that the notary side is now judged too risky as well, partly because of the role-model responsibility that comes with operating critical infrastructure [2]. The underlying scepticism is compressed into a line he says he uses constantly: "Ik zeg altijd de cloud, dat is een heel duur woord voor het is iemand anders computer" [1][2].
On "too big to regulate"
His central political claim is that scale eventually outruns law. "Ik noem dat too big to regulate. Op het moment dat bedrijven zo groot worden dat wetgeving er minder toe doet" [2]. The mechanism is capital: Big Tech war chests are large enough to buy not only startups but mid-size companies pre-emptively, before they ever become competition, which produces a power imbalance regulation cannot correct [1][2]. He is candid that this leaves his own organisation exposed. DNS Belgium admits it has no ready answer to what happens if the European provider it chooses is later acquired by an American player, an outcome those war chests make entirely feasible [1][2].
Regulation also misfires in his account. EU privacy legislation aimed partly at the advertising market ended up strengthening Google's position in online advertising [1][2]. And the compliance burden works as a market distortion in the wrong direction: European providers face higher costs to demonstrate regulatory compliance than foreign competitors selling into Europe, which makes matching American cost-efficiency harder still [1][2].
On lock-in that runs through the classroom
Vendor lock-in, in his framing, is self-reinforcing well beyond convenience. As more companies outsource to hyperscalers, schools train graduates to work only with that American cloud technology rather than with open standards, so the dependency becomes structural rather than contractual [1][2]. The pipeline of skills reproduces the concentration that created it.
On sham redundancy
He rejects the idea that cloud delivers resilience. "Er is helemaal geen redundantie niet meer. Het is een soort schijnredundantie" [1]. The evidence is that a single cloud outage can take down 60% of a country's websites [2]. He treats this as a betrayal of the internet's design intent: "Het internet is niet in die geest gemaakt. Dus wij willen ook niet in die vaak trappen die ervoor zorgt dat die redonantie eigenlijk opgeven is" [2]. Notably, he considers the concentration itself a bigger risk than the scenario people usually reach for, a hostile state cutting off internet access [1].
On buying European as an innovation policy
The strongest commercial argument he makes for European providers is where the money ends up. "Het is massief veel geld dat wij in ICT stoppen, dat we dat alsjeblieft terug in Europese technologie investeren zodanig dat wij terug innovatief worden" [1]. He pairs this with a claim about capacity: "Wij zijn toch altijd een innovatief continent geweest. Maar voor innovatie is er geld nodig" [2]. Redirecting ICT spending to local companies gives them room to reinvest, whereas budgets that leak to the US weaken local ICT, and he draws the explicit parallel with advertising budgets flowing to US social platforms and hollowing out local media [1][2].
On being ready without being reckless
His practical advice is deliberately moderate. Companies do not need to migrate immediately, but they should be technically ready: containerise workloads, know what a migration would actually require, and hold a step-by-step plan so that leaving Microsoft or Amazon is possible when it becomes necessary [1][2]. It should be treated as a planned project rather than an emergency. For operators of critical infrastructure, though, readiness is not optional but a "verdomde plicht" [1][2].
On SMEs building on rented ground
The same logic scales down. Small businesses and startups should not build their entire presence on Instagram or Facebook, because profiles get blocked in ways that are hard to appeal or even to understand, leaving the owner without recourse [1][2]. An own website under an own domain is the resilience layer. "Leg al je eieren niet in dat ene mandje" [1][2].
Takeaways
- Assess cloud risk per function, not per organisation: DNS Belgium always self-hosted its core DNS "address book" and used cloud only for the registrar or notary function, then judged even that too risky [1][2].
- Treat migration readiness as a standing project: containerise, know what a move would take, and hold a step-by-step plan, even if you do not migrate now [1][2].
- The concentration of the internet into six to ten companies is a bigger risk than a hostile state cutting off access; a single cloud outage taking out 60% of a country's websites is "schijnredundantie", not resilience [1][2].
- Lock-in is reproduced by education: graduates trained only on American cloud technology rather than open standards deepen the dependency structurally [1][2].
- EU rules can work against European providers, who pay more to prove compliance than foreign competitors selling into Europe, and privacy rules aimed at the ad market ended up strengthening Google [1][2].
- Buying European is an innovation argument as much as a sovereignty one: ICT money spent locally gets reinvested locally, the way ad budgets leaking to US platforms weaken local media [1][2].
- Big Tech war chests make pre-emptive acquisition of startups and mid-size firms routine, which is why he calls it "too big to regulate" and why he has no answer if his European provider is bought by an American player [1][2].
- SMEs should own a website and domain rather than depend on Instagram or Facebook, where profile blocks come without explanation or recourse [1][2].
Related profiles
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.