Karakun AGKarakun AGKarakun AGKarakun AG
  • Services
  • Products
  • Projects
  • About us
  • News
  • Jobs
  • EN
    • DE
    • EN
  • Services
  • Products
  • Projects
  • About us
  • News
  • Jobs
  • EN
    • DE
    • EN
28. September 2026

From AI Prototype to Software

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Generative AI makes it easier than ever to build applications. An idea can become a prototype within a short time – complete with a user interface, database and perhaps even a login. This allows business teams in particular to create solutions for problems that central IT may not have the time or resources to address.

But once other people start using an application, real company data is involved or business processes depend on it, a working prototype is no longer enough. The experiment has become software that needs to operate reliably.


When Experiments Go Live

Enabling business teams to build their own applications creates new opportunities. They often have the deepest understanding of their processes, requirements and everyday challenges. Generative AI and vibe coding lower the technical barriers and make it possible to test ideas quickly.

The transition to production software, however, is rarely clear-cut. A personal productivity tool can quickly become something an entire team relies on. At that point, familiar software engineering questions arise: Who can access which data? Who is responsible for maintenance and updates? And who takes care of operations?

A professional-looking interface does not answer these questions. Security, data protection and maintainability remain essential – regardless of whether the code was written by developers or generated with the help of AI.

The role of AI itself also matters. An application developed with AI is not necessarily an AI system. If the application uses an AI model at runtime or sends company data to an external AI service, additional requirements around governance, data protection and potentially regulation come into play.

Enable Innovation with Clear Guardrails

The answer is hardly to prevent experimentation or subject every small productivity tool to an extensive approval process. Instead, companies need a pragmatic path from experimentation to regular operations.

This includes approved tools, clear rules for handling company data and criteria for determining when an application requires professional review. As an application becomes more important, clear ownership of security, maintenance and operations needs to be established as well.

Conclusion

Generative AI can turn valuable process knowledge into working solutions much faster. But it does not make professional software development obsolete. Instead, the role of software engineering is evolving: helping turn successful experiments into secure, maintainable applications that can be operated reliably over the long term.

When business teams and software engineers manage this transition together, a quick prototype can become a dependable tool.

This article is based on the September edition of our “Schlicht und einfach” column in Inside IT. The original article  was written by Markus Schlichting, CEO of Karakun, and has been edited for publication on our website.

Want to turn a prototype into a secure and maintainable software solution? We support you with professional software engineering – from architecture to operations.

Contact us!

Logo der Digitale Woche Dortmund, bestehend vor einem grauen Hintergrund. Rechts am Bildrand zu sehen ist das U vom berühmten Gebäude in Dortmund.
24. September 2026

Digitale Woche Dortmund 2026

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Digitale Woche Dortmund brings together companies, experts and anyone interested in digitalisation and technology to share knowledge and experiences. In 2026, Karakun once again actively contributed to the event with several talks and the Hackergarten Dortmund.

Recordings of our talks are now available online. Here you can find the videos and presentation slides covering the EU AI Act, the Cyber Resilience Act (CRA), Software Bills of Materials (SBOM), modern OCR, antifragile software and browser security.

Cyber Resilience Act: What Developers Need to Know

The Cyber Resilience Act (CRA) introduces new requirements for digital products placed on the EU market with direct implications for software development. But what does the regulation mean for developers in practice?

Ixchel Ruiz and Markus Schlichting explain what the CRA requires from software teams and what this means for software development and dependency management. Software Bills of Materials (SBOM) and the software supply chain play an important role. Using practical examples, they cover challenges such as transitive dependencies and shaded JARs as well as tools including CycloneDX and Dependency-Track.

Download presentation

EU AI Act: Compliance Without Metrics – How Does That Work?

The EU AI Act requires certain AI systems to demonstrate compliance with regulatory requirements. But how can compliance be assessed when the quality of a non-deterministic system cannot be captured by a single metric?

Mike Mannion shows how statistical methods and probabilistic testing can be used to systematically evaluate the performance of non-deterministic AI systems. The talk explores predefined criteria, robust baselines and well-founded decision rules – and how they can provide traceable evidence of an AI system’s quality.

download presentation (German)
Download handout (German)

Modern OCR in Resource-Constrained Environments

Optical Character Recognition (OCR) is an important building block for automating the processing of scanned documents. But how can high recognition quality and robust results be achieved when computing power and other resources are limited?

Drawing on real-world applications, Olmo Barberis shows how OCR solutions have evolved from traditional approaches using dictionaries and rule-based post-processing to modern pipelines based on open-source frameworks, vision models and LLMs. Using concrete examples, he compares different approaches and explores the engineering trade-offs between efficiency, reliability and maintainability.

Download Presentation

Unbreakable by Design: The Secret Tech of Antifragile Software

Failures and disruptions cannot be completely avoided in complex software systems. Antifragile systems go a step beyond resilience: they use failures, variability and unexpected events to evolve and become more robust over time.

Iryna Dohndorf explores the technical principles behind antifragile software. The talk covers approaches including fault tolerance and fault handling, automated software repair, fault injection in production and Test-Driven Development (TDD) – and examines how antifragility can be incorporated into software development and architecture from the outset.

Download Presentation

What Your Browser Reveals About You

Browsers reveal a surprising amount of information when we visit a website – often more than users realise. This can allow websites to recognise visitors even without a login. And some measures intended to protect privacy can inadvertently make identification even easier.

François Martin shows what information different browsers expose to websites and how these differences affect the ability to recognise individual users. He also explores what users can do to protect themselves – and where the limits of these measures lie.

Download Presentation (German)

3. July 2026

Regulation as an Opportunity

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

With the Cyber Resilience Act (CRA), NIS2, DORA and the AI Act, far-reaching regulatory requirements for software development will come into force by 2027. Companies that already embrace security, quality and modern engineering practices can turn these obligations into a competitive advantage.


Good Engineering Practices Pay Off

The new regulations require, among other things:

  • CRA: Software Bills of Materials (SBOMs), vulnerability management and security updates.
  • NIS2 and DORA: Incident reporting obligations and documented risk management.
  • AI Act: Technical documentation, data quality measures and human oversight, depending on the risk category.

These requirements are no longer limited to large enterprises or regulated industries. Through supply chains and international business relationships, they increasingly affect software companies in Switzerland and beyond.

For organisations that already integrate quality, security and maintainability into their development processes, the new regulations are less about starting from scratch and more about demonstrating existing engineering excellence. Compliance is becoming a mark of quality rather than just another cost factor.

Companies that adopt Security by Design create many of the required artefacts during the development process itself. CI/CD pipelines, automated testing and Software Bills of Materials (SBOMs) make documentation a natural outcome of modern software engineering instead of an afterthought.

Learn more in our article “Thinking Security Strategically”.

Act Now Instead of Catching Up Later

DORA already applies, the main obligations of the CRA will take effect by the end of 2027, and the AI Act is being introduced in stages. Organisations that evolve their engineering practices today will not only be better prepared for compliance but also strengthen their long-term competitiveness.

This article is based on the June edition of our column “Schlicht und einfach” published in the Swiss IT Magazine Inside IT. The original article by Markus Schlichting, CEO of Karakun, has been editorially revised and expanded with practical insights for the Karakun website

Regulation starts with good software engineering. Let’s discuss how Security by Design and modern engineering practices can be integrated into your development processes.

Talk to us

FAQ

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements sold in the EU. It covers areas such as vulnerability management, security updates and Software Bills of Materials (SBOMs). The main obligations apply from the end of 2027.

Does the CRA also affect Swiss companies?

Yes. Swiss companies that sell products in the EU or develop software for customers subject to EU regulation may also need to comply. Regulatory requirements increasingly flow through supply chains and procurement processes.

What is a Software Bill of Materials (SBOM)?

A Software Bill of Materials (SBOM) lists the software components and dependencies used in an application. It improves transparency, simplifies vulnerability management and plays an important role in meeting CRA requirements.

Why is Security by Design important for regulatory compliance?

Security by Design integrates security requirements into architecture, development and operations from the beginning. As a result, many compliance-related artefacts—such as documentation, traceability and security evidence—are created as part of the engineering process.

Are CRA, NIS2, DORA and the AI Act only relevant for large enterprises?

No. Small and medium-sized software companies can also be affected, particularly when they supply regulated industries or operate in international markets. Preparing early helps reduce effort and creates a competitive advantage.


Logo des Java Forum Stuttgart 2026, einer der wichtigsten Java-Konferenzen im deutschsprachigen Raum.
5. June 2026

Karakun at Java Forum Stuttgart 2026

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

With the Cyber Resilience Act (CRA), NIS2 and DORA, Java teams are facing new requirements for transparency, security and control over their software supply chains. At Java Forum Stuttgart 2026, Java Champion Ixchel Ruiz and Karakun CEO Markus Schlichting will explain the role Software Bills of Materials (SBOMs) will play in the future and what development teams should start preparing today to meet regulatory requirements by 2027.

Java Forum Stuttgart (JFS) will take place on 9 July 2026 at the Kultur- & Kongresszentrum Liederhalle in Stuttgart, Germany. For many years, it has been one of the leading Java events in the German-speaking region. With multiple parallel tracks, a comprehensive expo area and a strong community presence, the conference brings together developers, architects, DevOps professionals and technology companies.

CRA, NIS2 and DORA: What Java-Teams Need to Know

In their joint session “CRA, NIS2, DORA: What Senior Java Engineers Must Deliver Before 2027”, Ixchel Ruiz and Markus Schlichting will explore the technical and organisational challenges that new European regulations are creating for software manufacturers.

By December 2027, the Cyber Resilience Act will require many organisations to provide Software Bills of Materials (SBOMs) for their software products. For Java applications, this presents a particular challenge: complex dependency trees, transitive dependencies, BOM-managed versions, container images and runtime components all need to be documented and managed in a transparent and traceable way.

The session will provide practical guidance on the information an SBOM should capture in a Java ecosystem and explain why CRA, NIS2 and DORA increasingly view software supply chains as a critical element of modern cybersecurity. SBOMs are becoming an important mechanism for demonstrating control over open-source dependencies and improving transparency across complex software ecosystems.

About the Speakers

Ixchel Ruiz has been developing software applications and tools since 2000. As a member of the JCP Executive Committee, Java Champion, Oracle ACE Pro, Testcontainers Community Champion and open-source advocate, she is widely recognised as one of the leading voices in the international Java community.

Markus Schlichting is CEO of Karakun and brings more than 20 years of experience in software engineering and the successful delivery of complex software projects. His areas of expertise include software architecture, documentation, automation and the establishment of sustainable development processes and toolchains.

Together, Ixchel Ruiz and Markus Schlichting combine deep Java expertise with extensive experience in software architecture, open source, security and modern software supply chains — topics that are becoming increasingly important in the context of CRA, NIS2, DORA and SBOMs.

Meet us in Stuttgart

Karakun will also be present in the expo area throughout Java Forum Stuttgart 2026. Our team looks forward to discussing software development, software architecture, Java technologies, cybersecurity, digital sovereignty and modern software supply chains with attendees.

Visitors are also invited to participate in our community survey and learn more about the projects and initiatives we are currently working on.

And of course, we will once again be bringing Karakun stickers and authentic Basler Läckerli, the traditional Swiss gingerbread speciality from Basel.

We Look Forward to Meeting You

The requirements introduced by CRA, NIS2, DORA and SBOMs will have a significant impact on Java teams in the years ahead. Java Forum Stuttgart provides an excellent opportunity to explore the technical, organisational and regulatory implications at an early stage.

If you would like to learn how Software Bills of Materials can be integrated into existing development and operational processes, or what CRA, NIS2 and DORA mean for your organisation in practice, speak with Ixchel Ruiz, Markus Schlichting or our team during the event.

Karakun supports organisations in building secure and sustainable software solutions — from software architecture and open-source governance to security by design, software supply chain management, compliance and digital sovereignty.

We look forward to engaging discussions and meeting the Java community in Stuttgart.


Nachhaltige Softwareentwicklung mit KI: bewusster Einsatz von künstlicher Intelligenz in der Programmierung
24. April 2026

Software Development with AI

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Artificial intelligence has quickly become part of modern software development—often faster than it has been fully thought through. But more AI doesn’t automatically mean better software. Building sustainable systems today starts with a simple question: Where does AI actually add value – and where doesn’t it?


AI has quickly become the default

In many projects, AI is now used by default — whether for writing code, generating documentation, or producing content. What starts as a productivity boost often turns into standard practice, without much reflection on its actual value.

That’s where the real challenge lies: not every task needs AI – and not every use of AI makes sense.

Sustainability starts with conscious decisions

Using AI has real implications — both technically and organizationally. Behind every AI-powered feature are resource-intensive infrastructures, rising costs, and increased system complexity.

At the same time, a familiar pattern is emerging: content is generated, refined, and condensed again — often without delivering real value.

Architecture over hype

Integrating AI into a system is always an architectural decision. Using large models typically introduces dependencies — on cloud providers, proprietary technologies, or specific platforms.

These dependencies affect not only how systems are built, but also how flexible they remain over time. Sustainable software development therefore means actively managing these trade-offs, rather than focusing only on short-term gains.

Conclusion

Artificial intelligence is a powerful tool but not an end in itself.

Sustainable software is built where technology is applied deliberately and decisions are made consciously. Sometimes, that also means choosing not to use AI where it doesn’t provide real value.

This article is based on the April edition of our column “Schlicht und einfach” in the Swiss IT Magazine Inside IT. The original text was written by Markus Schlichting, CEO of Karakun, who regularly explores fundamental technology topics and their real-world implications in this column.

If you’re looking to integrate AI into your software architecture in a sustainable and meaningful way, we’d be happy to support you — from concept to implementation.

Talk to us

FAQ

What does sustainable software development mean in the context of AI?

Sustainable software development means using AI deliberately and responsibly. It focuses not only on functionality, but also on resource consumption, system complexity, and long-term maintainability.

When does it make sense to use AI in software projects?

AI is particularly useful for handling large volumes of data or automating repetitive tasks. For simple or well-structured problems, its use is often unnecessary.

What risks come with using AI in software systems?

Common risks include dependencies on cloud providers and proprietary models, as well as increased system complexity. These factors can limit flexibility and long-term control.

Why can AI lead to higher resource consumption?

AI applications rely on powerful data centers that require significant energy and cooling. Large models in particular consume substantially more resources than traditional software solutions.

How can AI be integrated into software in a sustainable way?

By using it selectively, choosing smaller or specialized models where possible, and designing architectures that minimize dependencies while maintaining transparency around cost and resource usage.


17. April 2026

Karakun supports SwissText 2026

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

We are pleased to support SwissText 2026 as Silver Sponsor. Organized by the SwissNLP association, the conference is the key meeting point for Natural Language Processing (NLP) in Switzerland.

This year’s edition will take place on June 10, 2026, at the University of Zurich’s Oerlikon campus, bringing together experts from academia and industry.

For Karakun, a Swiss provider of software and AI solutions, SwissText is an ideal platform to stay close to current developments in NLP and text analytics and to exchange ideas with the community on real-world use cases and challenges.

With our sponsorship, we underline our commitment to not only applying AI and language technologies, but actively shaping them.

Meet us at SwissText 2026 and join the conversation on NLP, text analytics and real-world use cases – including topics related to our HIBU Platform for semantic search and text analytics.

Get in touch with us

26. March 2026

Karakun at JCON EUROPE 2026

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

From April 21 to 23, 2026, Karakun will be attending JCON EUROPE 2026 as a sponsor at the Cinedom in Cologne.

JCON is one of Europe’s established conferences for Java, software engineering, and modern development practices, bringing together developers from a wide range of backgrounds.

Meet us at the booth

At our booth, we’ll share insights into how we work and the kinds of projects we’re involved in. Most of all, we’re looking forward to connecting with the community.

We’ll also be exploring current topics such as artificial intelligence and the Cyber Resilience Act. As part of this, we’ll be conducting short interviews with visitors to gather perspectives from day-to-day development work.

And yes, there will also be the usual extras: stickers, a Karakun-branded Spitzgugge filled with Basel treats – and, most importantly, good conversations.

Talk: Accessibility as part of building better software

Our colleague Tamari Gogebashvili will give a talk on Thursday, April 23, from 12:55 to 13:15 (Cinema 6):

“From a Workshop to a Wake-Up Call: My Journey into Accessibility”

In her talk, she shares how her perspective on software development evolved through accessibility – from a compliance-driven topic to an integral part of building robust, high-quality software.

Using practical examples, she covers topics such as semantic HTML, ARIA, keyboard navigation, and automated accessibility testing, showing how small decisions in code can have a significant impact.

Visiting JCON? Come say hello

If you’re attending JCON EUROPE 2026 in Cologne, feel free to stop by our booth – we’d love to chat.

More information about the conference: https://2026.europe.jcon.one/ 


prostep_news
18. March 2026

Agentic AI needs semantics

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Agentic AI is widely seen as the next evolution of industrial digitalization. In the future, systems are expected to autonomously select data, parameterize models, and orchestrate analysis processes.

In practice, however, a key challenge quickly becomes apparent: without semantically structured data, AI systems lack the context needed to reliably interpret engineering information.

These are exactly the questions discussed at the prostep ivip Symposium 2026, taking place on April 14/15 in Frankfurt. Karakun will be present with both an exhibition booth and a technical presentation.

Semantics as the foundation of intelligent engineering systems

In the development of complex mechatronic systems, vast amounts of data are generated from simulations, modeling activities, and testing. To make this data usable in automated processes, simple storage is not enough. What is needed is a semantic description of system functions and their relationships.

This is where the FDX data standard from prostep ivip comes into play. It provides an open, tool-independent way to describe the functional behavior of components and systems in a semantically precise manner. As such, it forms a key foundation for automated engineering processes and future agentic AI workflows.

Why agentic AI remains blind without semantics

At the prostep ivip Symposium, Mike Mannion (Karakun) and an industry partner from the automotive sector will demonstrate how semantic data models enable the next level of engineering automation.

No Semantics, No Intelligence: Why Agentic AI Remains Blind Without FDX

📅 April 14, 2026
🕒 14:55 Uhr
📍 Auditorium 3

The presentation provides an overview of the current state of automation in engineering and shows how machine learning and agentic AI can further enhance data quality, data selection, and analysis processes.

EXOKNOX: Data management for engineering functional data

At the Karakun booth (Booth 06), we will also present our data management solution EXOKNOX.

Functional data defines the purpose and behavior of each component within a vehicle or other mechatronic products. It serves as a foundation across many stages of product development – from design to validation and verification.

The quality of this data is therefore a key factor in determining the quality of the final product. At the same time, its accessibility and ease of use are critical levers for improving the efficiency of the entire development process.

EXOKNOX was built by engineers for engineers – from practical experience for future challenges.

The solution makes functional data easily accessible, traceable, and centrally available – independent of specific technologies or vendors. This enables a consistent, data-driven development process that also integrates development partners efficiently.

At the same time, EXOKNOX provides an essential foundation for AI-driven product development.

Meet us in Frankfurt

Would you like to learn more about FDX, semantic data models, or AI-driven engineering processes? Visit us at the prostep ivip Symposium 2026 in Frankfurt. Or schedule a meeting with us in advance.

Get in Touch with us


Visualization of a structured information core with radiating digital elements – symbolic image for hybrid AI search and controlled information processing.
13. February 2026

AI Search Beyond the Black Box

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

In many organisations, knowledge workers spend a significant portion of their time gathering information: searching across repositories, comparing document versions, identifying relevant passages. This is more than inefficient. It ties up valuable capacity and turns knowledge work into repetitive retrieval tasks.

AI-powered search solutions promise faster answers. And speed matters. But in enterprise environments, speed alone is not enough. The real questions are different:

  • Which sources were considered?
  • Is the information scope clearly defined?
  • Are data protection requirements and digital sovereignty ensured?
  • Can the solution be integrated into existing systems?

To address these challenges, our HIBU platform follows a hybrid AI search principle.

The approach is based on a simple but crucial sequence: first define the relevant information space through structured search, filtering, or selected document scopes. Only within this controlled context do various AI methods support analysis and insight generation.

The result is not a black box, but transparent and governed information processing aligned with enterprise architecture.

Especially in regulated or security-sensitive environments, this balance between efficiency and control is critical. AI becomes part of the information architecture — not an isolated experiment.

For organisations that want to explore AI potential in a structured way, we also offer an AI Discovery Session as a pragmatic entry point into concrete use cases and strategic options.

Interested in how hybrid AI search with HIBU can create value in your system landscape?

Let's start the conversation


Security by Design
10. December 2025

Thinking Security Strategically

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Security delivers the greatest impact when it is embedded early in the planning and design of digital systems. Security by Design reduces risks, avoids costly last-minute fixes and improves an organisation’s cyber resilience. Approaches like Shift Left and DevSecOps help identify vulnerabilities early, automate checks and build sustainable security into development processes. Organisations that treat security as a strategic priority create more stable, trustworthy and durable digital products.


Security by Design: Embedding Security Where It Matters Most

Cybersecurity fails rarely because of missing tools, but because security is addressed too late. Security by Design ensures that risks are considered from the very beginning, forming the foundation for robust and trustworthy digital systems.

Organisations that postpone security decisions until shortly before go-live face unnecessary risks, higher costs and avoidable operational disruptions. Early, strategic integration of security prevents exactly that.

Why Security Must Start Early

Digital products and platforms are becoming increasingly complex, and weaknesses in the foundation are difficult or impossible to fix later. Security by Design means:

  • identifying risks during planning
  • building security directly into the architecture
  • considering security as a first-class requirement

Studies consistently show that issues discovered late in the lifecycle are exponentially more expensive to fix than those addressed early. Treating security as an architectural concern reduces long-term costs and strengthens resilience.

Shift Left & DevSecOps: Practical Ways to Build Secure Software

Many modern organisations rely on Shift Left and DevSecOps to operationalise Security by Design. These approaches integrate security into processes and teams rather than treating it as a separate discipline.

Key practices include:

  • automated security tests in CI/CD pipelines
  • versioned, auditable policies (“Security as Code”)
  • continuous monitoring and clear feedback loops
  • shared responsibility across engineering, security and operations

The result: fewer vulnerabilities, more stable systems and faster release cycles.

Regulatory Requirements and Strategic Benefits

With the GDPR and the revised Swiss Data Protection Act, Security by Design is not merely best practice — it is a legal requirement. rganisations must implement appropriate technical and organisational measures from the design phase onward, including data minimisation, encryption and clear access controls.

Those who apply these principles consistently benefit twice: they meet regulatory expectations while strengthening the security and reliability of their digital landscape.

Conclusion

Security by Design is not an additional effort, but an investment in quality, resilience and trust. Organisations that consider security early develop faster, more reliably and more economically.

This article is based on the December edition of our column “Schlicht und einfach” in the Swiss IT Magazin Inside IT. The original text was written by Markus Schlichting, CEO of Karakun, who regularly explores fundamental technology topics and their real-world implications in this column.

If you want to think about security strategically and embed it sustainably into your development processes, Karakun is here to support you. Let’s talk.

Kontaktieren Sie uns!

FAQ

What is Security by Design?

A development approach in which security considerations are integrated from the earliest stages of planning, architecture and implementation.

 

Why is late-stage security insufficient?

Issues discovered near go-live are harder to fix, more expensive and often lead to operational delays or vulnerabilities in production.

 

How does DevSecOps support Security by Design?

DevSecOps integrates security into development and operations workflows, supported by automation, shared responsibility and continuous feedback.

 

Is Security by Design legally required?

Yes. GDPR and Swiss revDSG require organisations to implement appropriate security measures from the design phase onward.

 

What is the business impact?

Lower costs, fewer incidents, stronger resilience and higher trust in digital products.

 


Lugano AI Week 2025
19. November 2025

Lugano AI Week 2025

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

From 1 to 5 December 2025, Asilo Ciani in Lugano will host the second edition of Lugano AI Week – a public event organised by Lugano Living Lab that brings together more than 50 experts to explore the opportunities and impacts of artificial intelligence across creativity, health, work and business.

Karakun: Sponsoring and Talk

Karakun is participating as a Silver Sponsor and will be present throughout On 4 December (12:40–13:00), our experts Sandro Pedrazzini and Olmo Barberis will deliver the talk: From Search to Insight: from research to interaction with content.

Using real-world examples from customer projects, they will demonstrate how modern retrieval pipelines, semantic search and interactive user interfaces help organisations interpret complex information and transform it into actionable knowledge.

An event for everyone interested in understanding and shaping AI

Lugano AI Week offers an accessible way to explore how AI is used today – and how future developments can be shaped. Workshops, talks and open-house sessions at local companies and research institutions provide hands-on insights into current technologies and practical use cases.

Visit us at our booth – or join our talk on 4 December. We look forward to meeting you in Lugano!


FAQ

What is Lugano AI Week?

Lugano AI Week is a free, multi-day event with talks, workshops and open-door sessions offering insights into the local AI ecosystem.

Who organises the event?

The event is organised by Lugano Living Lab, the City of Lugano’s urban innovation laboratory.

Where does the event take place?

At Asilo Ciani, located in central Lugano.

What will Karakun present on site?

We will showcase practical AI solutions, including semantic search, retrieval pipelines and interaction layers for navigating complex information spaces.

Is participation free of charge?

Yes, general participation is free. Workshops require prior registration.


Close-up of a stylised globe with illuminated circuit-board lines and data points, representing global digital connectivity and technological dependencies.
17. November 2025

Understanding Digital Sovereignty

  • Posted By : Dirk Kress/
  • 0 comments /
  • Under : Nicht kategorisiert

Digital dependencies are becoming a strategic risk for many organisations. Political conflicts, foreign legislation and proprietary technologies can affect the availability of critical systems or expose data to jurisdictions outside one’s control. The US CLOUD Act, for example, grants US authorities access to data held by American providers – regardless of where the data is stored. For organisations, this can mean loss of control and reduced operational readiness when it matters most.

As a result, digital sovereignty is gaining relevance – not as a buzzword, but as a prerequisite for long-term resilience.

What Digital Sovereignty Really Means

Digital sovereignty refers to the ability to make independent, informed decisions about one’s own data, systems and technologies at any time. It is not about isolation but about choice and control: external services can be used, provided the organisation maintains transparency, portability and the ability to switch if needed.

Dependencies often emerge gradually: through proprietary interfaces, low workload portability or reliance on specific legal frameworks. If a provider changes its APIs, faces geopolitical issues or withdraws services, core business processes can be affected. The Swiss Federal Audit Office therefore warns that cloud dependencies may endanger the availability of data and applications.

Sovereignty Washing: Local Labels Are Not Enough

With rising demand for “sovereign” solutions, more providers are adopting labels that signal independence. However, data centres located in Europe, data trustees or local partnerships do not automatically ensure true digital sovereignty.

Germany’s Centre for Digital Sovereignty (ZenDiS) warns against “sovereignty washing”: solutions that appear compliant with sovereignty requirements but still depend on proprietary technologies, lack portability or remain subject to foreign jurisdictions.

True digital sovereignty requires:

  • Open interfaces and standards
  • Verifiable vendor portability without operational risk
  • Full control over data and encryption keys
  • Transparency through inspectable code

A European label may support trust – but it cannot replace these fundamentals.

Open Source as the Foundation of Independence

Open source is a cornerstone of digital sovereignty. Transparent code and open standards prevent lock-in, improve interoperability and enable independent security assessments.
Public-sector examples illustrate this shift:

  • Schleswig-Holstein is gradually migrating parts of its administration to open-source solutions and multi-vendor models.
  • In Switzerland, the renewal of the EMBAG strengthens the preference for open technologies.
  • The network “Souveräne Digitale Schweiz” brings together stakeholders committed to strengthening digital independence.

Modern open-source ecosystems are driven by professional service providers with clear support models. Organisations gain transparency, influence over future development and long-term technological control.

Five Steps Towards Digital Sovereignty

Strengthening digital sovereignty does not require radical changes. Even incremental measures can have a significant impact:

  1. Analyse dependencies
    Identify critical systems and the providers, technologies and jurisdictions on which they rely.
  2. Use open standards
    Avoid proprietary formats; choose interoperable interfaces and portable data structures.
  3. Establish a multi-vendor strategy
    Reduce risk by distributing workloads instead of concentrating everything in a single cloud.
  4. Ensure data control
    Encrypt sensitive data and manage encryption keys internally.
  5. Test exit scenarios
    Assess regularly how services could be replaced or migrated if they became unavailable.

 

Conclusion

Digital sovereignty is not a political concept but a business imperative. It strengthens resilience and enables organisations to respond flexibly to change – especially in times of geopolitical uncertainty and dynamic technology markets.

Understanding dependencies, adopting open technologies and preparing alternatives helps secure technological independence and long-term organisational viability.

This article is based on the September edition of our column “Schlicht und einfach” in the Swiss IT magazine Inside IT. The original text was written by Markus Schlichting, CEO of Karakun, who regularly explores fundamental technology topics and their real-world implications in this column.

If you would like to understand how to identify dependencies, build sovereign architectures or implement open-source strategies effectively, we are happy to support you. We help organisations design sustainable and independent digital solutions.

Contact us!

FAQ

What is Digital Sovereignty?

Digital sovereignty means maintaining full control over your data, systems and technology choices at all times – without being dependent on a single vendor or external political framework.

Why is digital sovereignty important for organisations?

Because dependencies can cause loss of control, operational disruptions and legal risks. A sovereign IT architecture ensures resilience and flexibility.

How can organisations strengthen digital sovereignty?

By adopting open standards, using multi-vendor strategies, managing encryption keys internally and regularly testing exit scenarios.

What is “sovereignty washing”?

Solutions marketed as “sovereign” that fail to meet key criteria such as interoperability, switchability, transparency or customer control over data and keys.

Why is open source essential for digital sovereignty?

Open source prevents vendor lock-in, increases transparency, improves security and allows independent auditing. It is a foundational element of sovereign digital infrastructures.


1234Next ›Last »
Recent Posts
  • From AI Prototype to Software
  • Digitale Woche Dortmund 2026
  • Regulation as an Opportunity
  • Karakun at Java Forum Stuttgart 2026
  • Software Development with AI
Archives
  • Developer Hub
  • Jobs
  • Contact
  • Legal notice
  • Privacy statement
  • Terms and conditions
  • Code of Conduct


© Karakun AG, 2026. Alle Rechte vorbehalten.


Swiss Made SoftwareSwiss ICTSwissNLPLT-InnovateEclipse Foundationprostep ivipASAM e.V.OpenMDM