Category: Digital Sovereignty

  • Europe’s tech sovereignty: building capacity where it matters

    Europe’s tech sovereignty: building capacity where it matters

    In brief

    Europe has an opportunity to build much stronger positions in cloud, AI and semiconductors. The European Commission's new technology sovereignty package points in that direction. It seeks to speed up permits, aggregate demand and apply different sovereignty standards to different levels of risk.

    The next step is execution. Funding, energy supply and measures of success still need sharper definition. My read: Europe should increase investment and engagement where it already has industrial strength, while keeping global partnerships open. That combination creates more choice and resilience.

    What the Commission has proposed

    On 3 June 2026, the European Commission presented four measures:

    • the Chips Act 2.0
    • the Cloud and AI Development Act, or CADA
    • the EU Open Source Strategy
    • a roadmap for digitalisation and AI in the energy sector

    The Chips Act 2.0 and CADA are proposals, not final law.

    Commission President Ursula von der Leyen framed the case clearly:

    "We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable and our services secure."

    That is the right starting point. Europe can create more options for critical services by expanding local capacity and working with a broader set of trusted partners.

    Chips Act 2.0: more speed, no firm funding plan

    Silicon wafer transitioning into a series of advanced semiconductor packages
    The Chips Act 2.0 aims to turn European research and industrial demand into scalable semiconductor capacity.

    The proposal aims to make Europe a more attractive place to design, produce and buy semiconductors. It includes:

    • a maximum approval period of 12 months for strategic projects
    • "Grand Challenges" for technologies such as AI chips
    • stronger links between chipmakers and European buyers
    • more joint procurement
    • a business-to-business platform for supply-chain monitoring

    The Commission says the first Chips Act mobilised more than €52 billion and created about 46,000 direct and indirect jobs.

    It expects the global semiconductor market to reach €1.37 trillion by 2030. AI-related components could account for about 70% of that growth.

    Those numbers show the scale of the opportunity. Europe now needs to convert policy into commercially viable capacity.

    The European Court of Auditors warned in 2025:

    "The Chips Act is very unlikely to be enough to reach the very ambitious Digital Decade target."

    The EU wants a 20% share of the global semiconductor value chain by 2030. The Commission's own forecast pointed to 11.7%, according to the auditors. That gap is a reason to focus investment more clearly, not to lower the ambition. The Commission controls only about 10% of the announced public funding, so success will depend on coordinated action by member states, companies and the EU.

    CADA: tripling Europe’s computing capacity

    Data centre module protected by four clean nested architectural layers
    CADA proposes four sovereignty levels so protection can match the risk of each workload.

    CADA aims to at least triple EU data-centre capacity within five to seven years. It also addresses access to energy, land, water and capital.

    The Commission proposes four sovereignty levels. They range from EU-based data processing to full control of the software supply chain.

    I think this tiered approach is sensible. A public website does not need the same protection as health records or a national power grid.

    The opportunity is to make European capability more competitive without making origin the only criterion. Non-European providers can remain part of the mix when infrastructure, encryption, interfaces and exit terms meet the required standard.

    Open source: turning shared technology into European scale

    Modular digital products supported by an open framework and a maintenance tool
    Open source creates strategic value when Europe funds maintenance, governance and commercial scale.

    The Open Source Strategy covers development, deployment and long-term maintenance. It proposes procurement guidance, business support and a maintenance instrument for critical components.

    Open source can give public administrations and companies more control, better interoperability and lower switching barriers. Europe should capture more commercial value by helping maintainers and companies scale products in cloud, AI, cybersecurity and operating systems.

    The test will be professional execution. Critical open-source software still needs accountable owners, security updates and reliable funding.

    Energy and AI: building both sides of the equation

    Data centre connected to wind, solar and electricity-grid infrastructure across Europe
    Europe can combine data-centre growth with grid intelligence, renewable energy and industrial automation.

    The energy roadmap connects digital ambition with physical infrastructure. It covers grid optimisation, energy efficiency, demand flexibility and data-centre integration.

    Data centres currently use about 2.5% of EU electricity. In Ireland, their share exceeds 20%. The Commission is therefore developing tripartite agreements between data-centre operators, energy companies and public authorities. It has also launched AI.grids, a pan-European AI model for electricity networks.

    This is where Europe can combine two strengths: industrial automation and energy-system engineering. The Commission estimates that digitalising energy could create €71 billion in annual consumer savings and more than €300 billion in wider system benefits.

    Where the package creates momentum

    • The Commission creates a reason to invest. It says more than 80% of important digital products, services, infrastructure and intellectual property currently come from outside the EU. That leaves significant room for European suppliers and partnerships to grow.
    • Some targets are measurable. A 12-month permit period and a tripling of computing capacity can be tracked.
    • Demand receives more attention. Joint procurement and early customers could help European start-ups scale.
    • Open source is treated as infrastructure. That can improve control and make switching providers easier.

    Where execution needs to improve

    • Funding needs to become more specific. Announced investment is not the same as an available EU budget.
    • Europe needs to measure commercial outcomes alongside programmes and funding commitments.
    • Member states should concentrate capital in the strongest industrial clusters instead of competing for identical projects.
    • Energy policy must advance with digital policy. Chip plants and data centres need power, grids, cooling and water.
    • Europe should pursue strategic capacity with global partners rather than full autonomy. The European Court of Auditors says complete autonomy is impossible in semiconductors.

    Andreas’s view

    My read on this: the package is a useful foundation for a more confident European technology strategy.

    Europe is right to connect chips, cloud, AI, open source and energy. It is also right to distinguish between ordinary and critical workloads. The next move is to turn that framework into investment, capacity and competitive products. Funding, ownership and success metrics need to become more precise.

    I would add operational measures to the 20% chip-market target: capacity for critical chip classes, the cost of changing cloud providers and the share of critical systems with a tested exit plan.

    Europe should dial up investment where it has an edge: semiconductor equipment, power electronics, industrial software and specialised chips. Public procurement can create early demand for competitive European products based on security, portability and total cost.

    The real test is whether European companies gain more choice, scale and freedom to operate under pressure. A stronger European technology base can deliver that without closing the door to global innovation.

    What I would watch over the next 90 days

    For leadership teams, five questions can turn this policy direction into a growth and resilience agenda:

    1. Do we know our critical dependencies across cloud, AI, chips and software?
    2. Does every critical system have a workable switch or contingency plan?
    3. Are data and applications classified by actual risk?
    4. Do contracts provide portability, data access and transparent exit costs?
    5. Are procurement, technology and risk teams making these decisions together?

    Technology sovereignty is the capacity to create, choose and keep operating when conditions change.

    Sources

    1. European Commission: Strengthening Europe’s Tech Sovereignty, 23 June 2026
    2. European Commission: Tech sovereignty package, 3 June 2026
    3. European Commission: Cloud and AI Development Act, 3 June 2026
    4. European Commission: Chips Act 2.0, 3 June 2026
    5. European Commission: EU Open Source Strategy
    6. European Commission: Strategic roadmap for digitalisation and AI in energy, 3 June 2026
    7. European Court of Auditors: Special Report 12/2025, The EU’s strategy for microchips
    8. Mario Draghi: The future of European competitiveness, September 2024
    9. European Commission: AI Continent Action Plan
  • Germany and France put digital sovereignty into operational terms

    Germany and France put digital sovereignty into operational terms

    Germany and France have published a joint paper on digital sovereignty, dated 17 June 2026. It is only six pages long, but it does something useful: it gives the term digital sovereignty a set of testable criteria.

    Europe has spent years talking about sovereignty in broad terms. The Franco-German paper asks a narrower question: when a government, company or public institution buys digital technology, what would make that technology more or less sovereign?

    The paper does not pretend this is easy. It says digital sovereignty should be risk-based, modular and scalable. It avoids protectionism and isolation. It leaves defence and national security outside its scope. It creates no direct budget obligation and does not impose conditions on private procurement.

    The document is cautious by design. That is useful for consensus. It is also the problem.

    Germany and France are not proposing a simple "buy European at any cost" doctrine. They are proposing criteria that could feed into the EU Tech Sovereignty Package, including the Cloud and AI Development Act. If those criteria survive the legislative process, they could start shaping procurement, cloud architecture, sensitive-data handling and public-sector technology choices.

    The paper's value is the checklist. Its weakness is that it stops there. It does not yet create the kind of aggressive investment push now visible in other regions.

    The definition is broader than cloud

    Minimal stacked blocks representing chip, network, server, cloud and AI layers
    Digital sovereignty has to be assessed across the stack, from chips and networks to cloud platforms and AI.

    The core definition is worth reading carefully. Digital sovereignty is described as the capability and capacity to develop, provide, use, adapt and control digital technologies, including hardware, in an independent, self-determined and secure manner.

    Data location is only one part of it.

    It includes hardware, software, data handling, AI, semiconductors, cloud, quantum, robotics, cybersecurity, standards, supply chains, skills and control over operational processes. The paper says critical dependencies exist across the entire stack, from IT infrastructure and semiconductors to software, data and AI.

    This maps better to how dependency actually works.

    Europe's dependency problem is scattered across the stack: hyperscale cloud, chips, operating systems, cybersecurity tools, AI models, productivity platforms, data infrastructure, technical standards, venture capital depth, and the ability to scale startups into global companies.

    One datapoint stands out: in Europe's digital industrial ecosystem, most companies have fewer than 250 employees, based on the European Commission/JRC SME report cited in the paper. That captures one of Europe's structural problems. Europe has plenty of innovation. It has too few digital companies with global scale.

    The six criteria matter most

    Minimal procurement checklist beside a cloud architecture cube and pencil
    The six criteria can be used in procurement, supplier reviews, architecture decisions and exit planning.

    The paper defines six dimensions of digital sovereignty.

    The first is the capability to implement and enforce. This is about whether Europe can apply its own legal and security conditions in practice. The criteria include EU-law compliance, transparency of ownership and subcontractor chains, disclosure of dependencies on third countries, restriction of sovereignty-critical extraterritorial data access, and the ability to investigate cybercrime and state-backed attacks.

    The cloud debate often gets stuck here: legal jurisdiction and operational control do not always sit in the same place as the data center.

    The second is the capability to design, deploy and use technologies. This includes scientific ecosystems for AI, microelectronics, robotics, data, quantum and cybersecurity; industrial demand for key technologies; research transfer; startup scaling; open source, open hardware and interoperability; and participation in standardisation.

    Europe often underestimates this layer. Regulation can define the rules. It cannot replace the people, companies and institutions that build, operate, buy and improve the technology.

    The third is economic value creation. The paper looks at where value is generated: R&D, engineering, skilled employment, operational control and contribution to the European technology ecosystem. It also explicitly allows partial value creation in trusted partner countries. That keeps the framework open enough to be economically realistic.

    The fourth is protection of data. The paper calls on the European Commission to define the highest protection standards for the most sensitive data, including safeguards against cybersecurity risks and the effects of non-EU extraterritorial legislation. It also mentions mandatory privacy-enhancing technologies.

    Sensitive data policy is now also industrial policy.

    The fifth is substitutability and interoperability. The paper asks for modular architecture, open standards, open interfaces, software bills of materials, migration paths, exit concepts and multi-vendor strategies. In plain English: do not build systems that cannot be changed later.

    For me, this is the most practical part of the paper. Lock-in rarely arrives as a crisis. It arrives as a procurement decision that cannot be reversed without years of cost and disruption.

    The sixth is infrastructure resilience. The paper calls for sovereign data centers, AI, quantum and cloud computing infrastructure, interchangeable hardware and software stacks, diversified supply chains, secure and sustainable energy, high-performance networks and access to critical space resources.

    Minimal data center model connected to power grid, cloud and network nodes
    Digital sovereignty depends on the physical layer too: data centers, energy supply, networks and resilience.

    This links directly to the SoftBank France data-center story. Digital sovereignty now has a power, land, data-center and network dimension. The debate has moved well beyond data location and cloud labels.

    The paper is careful, maybe too careful

    The paper is politically careful. It is non-binding. It excludes defence and national security. It does not force public spending. It does not impose rules on private procurement. It stresses trade obligations, trusted partners and cost efficiency.

    That makes it weaker than a real industrial plan. It also makes the document harder to dismiss as protectionism.

    The gap is not definition. The gap is action.

    The paper does not unlock capital. It does not create major public procurement demand. It does not accelerate data-center buildout, AI infrastructure, semiconductor capacity, cloud scale or startup growth. It gives Europe a framework for assessing sovereignty, but it does not yet give European providers the demand, reference customers or balance-sheet confidence needed to scale.

    The paper does not argue for closing Europe off. Its more useful move is to make dependency measurable. Who owns the provider? Which subcontractors matter? Where is R&D located? Can the customer exit? Are open interfaces available? Can sensitive data be protected from extraterritorial access? Can Europe still operate if one supplier, jurisdiction or supply chain becomes unavailable?

    These questions belong in procurement files, architecture reviews and risk discussions.

    For enterprise leaders, digital sovereignty is becoming a procurement and architecture discipline. It will affect cloud strategy, AI deployment, data classification, supplier concentration, cybersecurity, exit planning and board-level risk.

    For policymakers, a definition is useful only if it changes incentives. Europe needs procurement demand for sovereign solutions, faster scaling paths for startups, deeper capital markets, serious public-sector reference customers, and infrastructure policy that connects cloud, AI, energy, semiconductors and networks.

    Without that, sovereignty stays a vocabulary exercise. Other regions are moving with capital, infrastructure, industrial policy and large anchor customers. Europe cannot answer that with criteria alone.

    The executive takeaway

    The Franco-German paper stops short of a sovereignty plan. It offers criteria. Criteria still matter because they shape what governments and large buyers start asking for. They shape tenders. They influence compliance teams. They tell suppliers what the next market standard may look like.

    If Europe uses this framework well, sovereignty becomes less abstract: fewer lock-ins, clearer exit paths, more transparent supply chains, stronger data protection, more European value creation, and better infrastructure resilience.

    If Europe uses it badly, it becomes another vocabulary layer on top of slow procurement and fragmented national initiatives.

    My read: this paper is strongest where it is most practical. It connects sovereignty to ownership, enforceability, interoperability, data protection, value creation and infrastructure. It avoids the fantasy of full autarky. It accepts trusted partners. It treats sovereignty as a risk-based capability, not as a flag on a server.

    But the next test is not another definition. It is demand.

    Without procurement demand, budgets, infrastructure, reference customers and scale, European providers will stay small. Without scale, the dependency problem stays exactly where it is.

    Bottom line: good start. Now Europe needs action.

    Sources and further reading