A growing environmental footprint from your digital estate is also a growing risk surface. AI is accelerating the phenomenon. The underlying question is: where does the benefit-risk optimum lie?
Cybersecurity sits at the heart of the concerns of large companies and of most mid-caps. The attack surface widens as hardware and digital solutions multiply. A compromise at a supplier can trigger chain reactions, which makes control of the supply chain a major operational resilience issue.
Examples of impact:
Ransomware propagation: an infection of the information system can spread from suppliers to connected clients, forcing digital operations to be halted.
Data leakage: the risk of criminal data leaks is compounded by the institutional risk of data access under US extraterritorial legislation.
The best-documented systemic threat to digital infrastructure over the 2030-2050 horizon — and the least anticipated in continuity plans. Geolocating the physical sites of your digital value chain, combined with an assessment of your suppliers' maturity, becomes indispensable.
Examples of disruption scenarios:
Supply chain disruption: semiconductors (90% in Taiwan and South Korea¹) and RAM.
Energy shock: geopolitical tensions, over-consumption driven by AI.
Damage to infrastructure: extreme climate events over the short to medium term.
The cost of proprietary solutions is rising fast, driven by energy prices and AI investment. At the same time, the extraterritorial reach of US law is strengthening, rendering European protections ineffective. Your strategic autonomy is at risk.
Examples of impact:
VMware/Broadcom: price increases of 300% to 1,500%².
MS Office: price increases of up to 25% to absorb the cost of AI investment³.
Cloud Act: data hosted with US operators, even in Europe, can be compelled by US authorities.
AI is not one more digital issue among others. It is the systemic amplifier of all of them. Alongside a vague promise of productivity gains come amplified environmental impacts and reinforced strategic dependencies.
Deploying AI — in a market largely dominated by the United States — without discernment risks locking in the core of business operations and know-how by delegating them to a third party. It is an unprecedented final layer of dependency, on top of hardware and software dependencies.
"We have entered the era of the 'sovereignty paradox'. The more states and companies invest in building their own AI, the more they reinforce their structural dependency on a handful of foreign suppliers for chips (GPUs), cloud and foundation models. AI is no longer merely a technology, it is a 'geopolitical supply chain' comparable to energy, structured around a few critical bottlenecks."
Digital New Deal — Damien Kopp, AI: the global economy of dependencies, February 20261 — Infrastructure layer
GPUs, servers, clouds (IaaS) — logistical dependency and exposure to extraterritorial legislation.
2 — IT software layer
Operating systems, middleware, DevOps: a largely US stack, now beginning to embed AI features.
3 — Business software layer
Business tools embedding AI features under data-use terms that are often opaque.
4 — The enterprise's cognitive layer
Delegation of business know-how — and even of judgement — to AI agents external to the company's culture.
As organisations delegate a growing share of their critical skills to AI, a new liability forms: cognitive debt. Invisible on the balance sheet yet decisive for their autonomy, it reflects the widening gap between the knowledge they need to survive and the knowledge they still command. Behind the promised efficiency, a risk takes hold: losing the ability to understand and steer what constitutes their very substance. Nullans and Chenu — Décideurs Magazine — January 2026
Reducing environmental impacts and strengthening operational resilience are not two separate projects. They are two coherent projects sharing common levers. And the savings released by digital sufficiency help fund the work that improves resilience.
38% of the functions that embark on environmentally responsible digital programmes do so for financial reasons¹. At EDF, for example, the gain was estimated at €23m per year in IT savings².
These savings directly fund resilience investments: redundancy, relocation, supplier changes, development of back-up solutions.
"Technological de-escalation consists in identifying everything in our information system or digital strategy that amounts to imported 'surplus' or 'non-essential', and reducing it, so as to make the ecosystem lighter and more modular, and therefore easier to migrate when the time comes."
GreenIT, Responsible digital technology and sovereignty, 2026① Reduced footprint
Fewer servers, fewer tools, less data — the carbon footprint of the information system falls mechanically.
② Reduced risk surface
Fewer suppliers, fewer dependencies, fewer points of failure — systemic fragility recedes.
③ Budget released
The sufficiency dividend funds resilience investments, in part or in full.
Return on the approach
(Losses avoided × probability) + sufficiency savings
− cost of redundancy and of migrations/simplifications
The available regulatory and methodological frameworks were built to structure precisely this kind of work. Using them as levers accelerates the transformation.
CSRD / ESRS
The sustainability reporting obligation forces organisations to map their real risks and impacts — exactly what a sustainable and resilient digital strategy has to do. It structures the dialogue between general management, sustainability, risk teams and the IT department.
DORA (financial sector, in force since January 2025)
Mapping of supplier dependencies, tested continuity plans, mandatory contractual reversibility clauses. Its approach — identify your dependencies and demonstrate your capacity to absorb them — is a model that applies well beyond the financial sector and beyond cyber issues.
AI Act (first deployment August 2026)
Formalisation of governance and traceability for AI solutions — between proprietary SaaS and open-weight models. The IT department regains control of its operational risks while avoiding technological lock-in with its suppliers.
Bilan Carbone© & GHG Protocol & LCA
Reference methods for measuring the full carbon footprint of the information system and for assessing other environmental indicators. Essential to define and steer impact reduction pathways.
TOGAF©
Enterprise architecture (TOGAF©) structures the mapping of business capabilities, the identification of critical components and the transformation of the information system, all in a shared language.
Digital Resilience Index (IRN)
Launched in 2026 and still maturing, this instrument assesses digital dependencies across eight dimensions (strategic, legal, data and AI, operational, supply chain, technological, security, environmental) and guides priorities for action.
The point is not compliance. It is control. These frameworks are accelerators: they structure the work, create a shared language between general management and operational teams, and make it possible to demonstrate progress credibly.
A first conversation to see how this approach speaks to what is on your desk right now.
Get in touch