Approach

Finding the right balance

A growing environmental footprint from your digital estate is also a growing risk surface. AI is accelerating the phenomenon. The underlying question is: where does the benefit-risk optimum lie?

Risk mapping

Three digital risks
Only one genuinely addressed

Known — partially addressed

Cyber risk

Cybersecurity sits at the heart of the concerns of large companies and of most mid-caps. The attack surface widens as hardware and digital solutions multiply. A compromise at a supplier can trigger chain reactions, which makes control of the supply chain a major operational resilience issue.

Examples of impact:

Ransomware propagation: an infection of the information system can spread from suppliers to connected clients, forcing digital operations to be halted.

Data leakage: the risk of criminal data leaks is compounded by the institutional risk of data access under US extraterritorial legislation.

Cloud Act DORA
Pressing — rarely mapped

Energy-climate risk

The best-documented systemic threat to digital infrastructure over the 2030-2050 horizon — and the least anticipated in continuity plans. Geolocating the physical sites of your digital value chain, combined with an assessment of your suppliers' maturity, becomes indispensable.

Examples of disruption scenarios:

Supply chain disruption: semiconductors (90% in Taiwan and South Korea¹) and RAM.

Energy shock: geopolitical tensions, over-consumption driven by AI.

Damage to infrastructure: extreme climate events over the short to medium term.

TCFD CSRD/ESRS IPCC OCARA©
Emerging — absent from agendas

Economic & geopolitical dependency

The cost of proprietary solutions is rising fast, driven by energy prices and AI investment. At the same time, the extraterritorial reach of US law is strengthening, rendering European protections ineffective. Your strategic autonomy is at risk.

Examples of impact:

VMware/Broadcom: price increases of 300% to 1,500%².

MS Office: price increases of up to 25% to absorb the cost of AI investment³.

Cloud Act: data hosted with US operators, even in Europe, can be compelled by US authorities.

Data Act AI Act DRI Open Source
AI — the amplifying factor

Artificial intelligence multiplies impacts and deepens dependencies

AI is not one more digital issue among others. It is the systemic amplifier of all of them. Alongside a vague promise of productivity gains come amplified environmental impacts and reinforced strategic dependencies.

Deploying AI — in a market largely dominated by the United States — without discernment risks locking in the core of business operations and know-how by delegating them to a third party. It is an unprecedented final layer of dependency, on top of hardware and software dependencies.

"We have entered the era of the 'sovereignty paradox'. The more states and companies invest in building their own AI, the more they reinforce their structural dependency on a handful of foreign suppliers for chips (GPUs), cloud and foundation models. AI is no longer merely a technology, it is a 'geopolitical supply chain' comparable to energy, structured around a few critical bottlenecks."

Digital New Deal — Damien Kopp, AI: the global economy of dependencies, February 2026

Dependency layers reinforced by AI

1 — Infrastructure layer

GPUs, servers, clouds (IaaS) — logistical dependency and exposure to extraterritorial legislation.

2 — IT software layer

Operating systems, middleware, DevOps: a largely US stack, now beginning to embed AI features.

3 — Business software layer

Business tools embedding AI features under data-use terms that are often opaque.

4 — The enterprise's cognitive layer

Delegation of business know-how — and even of judgement — to AI agents external to the company's culture.

As organisations delegate a growing share of their critical skills to AI, a new liability forms: cognitive debt. Invisible on the balance sheet yet decisive for their autonomy, it reflects the widening gap between the knowledge they need to survive and the knowledge they still command. Behind the promised efficiency, a risk takes hold: losing the ability to understand and steer what constitutes their very substance. Nullans and Chenu — Décideurs Magazine — January 2026

The coming environmental footprint of AI

"10% of the payroll captured by AI by 2027" — Arthur Mensch, French National Assembly commission of inquiry into digital dependencies, May 2026. And how many additional carbon emissions on your balance sheet? That would represent up to one additional tonne of CO2e per employee per year. Adapting models, choosing locations and, above all, adopting a measured deployment can bring this impact down to an acceptable level.

2 x France
AI could add twice France's annual emissions by 2030
The Shift Project, AI Data Compute, 2025
20%
of the growth in global electricity consumption would be AI-related by 2030
International Energy Agency, 2024
1 tCO2e/FTE
if 10% of the payroll is devoted to AI
LUTECIUM calculation
Rationale

Digital sufficiency funds resilience

Reducing environmental impacts and strengthening operational resilience are not two separate projects. They are two coherent projects sharing common levers. And the savings released by digital sufficiency help fund the work that improves resilience.

The sufficiency dividend

38% of the functions that embark on environmentally responsible digital programmes do so for financial reasons¹. At EDF, for example, the gain was estimated at €23m per year in IT savings².

These savings directly fund resilience investments: redundancy, relocation, supplier changes, development of back-up solutions.

"Technological de-escalation consists in identifying everything in our information system or digital strategy that amounts to imported 'surplus' or 'non-essential', and reducing it, so as to make the ecosystem lighter and more modular, and therefore easier to migrate when the time comes."

GreenIT, Responsible digital technology and sovereignty, 2026

Three simultaneous effects

① Reduced footprint

Fewer servers, fewer tools, less data — the carbon footprint of the information system falls mechanically.

② Reduced risk surface

Fewer suppliers, fewer dependencies, fewer points of failure — systemic fragility recedes.

③ Budget released

The sufficiency dividend funds resilience investments, in part or in full.

Return on the approach

(Losses avoided × probability) + sufficiency savings
− cost of redundancy and of migrations/simplifications

The frameworks

Standards and regulations:
treat them as supports, not burdens

The available regulatory and methodological frameworks were built to structure precisely this kind of work. Using them as levers accelerates the transformation.

Regulatory framework

CSRD / ESRS

The sustainability reporting obligation forces organisations to map their real risks and impacts — exactly what a sustainable and resilient digital strategy has to do. It structures the dialogue between general management, sustainability, risk teams and the IT department.

DORA (financial sector, in force since January 2025)

Mapping of supplier dependencies, tested continuity plans, mandatory contractual reversibility clauses. Its approach — identify your dependencies and demonstrate your capacity to absorb them — is a model that applies well beyond the financial sector and beyond cyber issues.

AI Act (first deployment August 2026)

Formalisation of governance and traceability for AI solutions — between proprietary SaaS and open-weight models. The IT department regains control of its operational risks while avoiding technological lock-in with its suppliers.

Market standards

Bilan Carbone© & GHG Protocol & LCA

Reference methods for measuring the full carbon footprint of the information system and for assessing other environmental indicators. Essential to define and steer impact reduction pathways.

TOGAF©

Enterprise architecture (TOGAF©) structures the mapping of business capabilities, the identification of critical components and the transformation of the information system, all in a shared language.

Digital Resilience Index (IRN)

Launched in 2026 and still maturing, this instrument assesses digital dependencies across eight dimensions (strategic, legal, data and AI, operational, supply chain, technological, security, environmental) and guides priorities for action.

The point is not compliance. It is control. These frameworks are accelerators: they structure the work, create a shared language between general management and operational teams, and make it possible to demonstrate progress credibly.

See how LUTECIUM puts these frameworks to work →

Is your organisation ready
for a constrained world?

A first conversation to see how this approach speaks to what is on your desk right now.

Get in touch