Germany and France have published a joint paper on digital sovereignty, dated 17 June 2026. It is only six pages long, but it does something useful: it gives the term digital sovereignty a set of testable criteria.
Europe has spent years talking about sovereignty in broad terms. The Franco-German paper asks a narrower question: when a government, company or public institution buys digital technology, what would make that technology more or less sovereign?
The paper does not pretend this is easy. It says digital sovereignty should be risk-based, modular and scalable. It avoids protectionism and isolation. It leaves defence and national security outside its scope. It creates no direct budget obligation and does not impose conditions on private procurement.
The document is cautious by design. That is useful for consensus. It is also the problem.
Germany and France are not proposing a simple "buy European at any cost" doctrine. They are proposing criteria that could feed into the EU Tech Sovereignty Package, including the Cloud and AI Development Act. If those criteria survive the legislative process, they could start shaping procurement, cloud architecture, sensitive-data handling and public-sector technology choices.
The paper's value is the checklist. Its weakness is that it stops there. It does not yet create the kind of aggressive investment push now visible in other regions.
The definition is broader than cloud

The core definition is worth reading carefully. Digital sovereignty is described as the capability and capacity to develop, provide, use, adapt and control digital technologies, including hardware, in an independent, self-determined and secure manner.
Data location is only one part of it.
It includes hardware, software, data handling, AI, semiconductors, cloud, quantum, robotics, cybersecurity, standards, supply chains, skills and control over operational processes. The paper says critical dependencies exist across the entire stack, from IT infrastructure and semiconductors to software, data and AI.
This maps better to how dependency actually works.
Europe's dependency problem is scattered across the stack: hyperscale cloud, chips, operating systems, cybersecurity tools, AI models, productivity platforms, data infrastructure, technical standards, venture capital depth, and the ability to scale startups into global companies.
One datapoint stands out: in Europe's digital industrial ecosystem, most companies have fewer than 250 employees, based on the European Commission/JRC SME report cited in the paper. That captures one of Europe's structural problems. Europe has plenty of innovation. It has too few digital companies with global scale.
The six criteria matter most

The paper defines six dimensions of digital sovereignty.
The first is the capability to implement and enforce. This is about whether Europe can apply its own legal and security conditions in practice. The criteria include EU-law compliance, transparency of ownership and subcontractor chains, disclosure of dependencies on third countries, restriction of sovereignty-critical extraterritorial data access, and the ability to investigate cybercrime and state-backed attacks.
The cloud debate often gets stuck here: legal jurisdiction and operational control do not always sit in the same place as the data center.
The second is the capability to design, deploy and use technologies. This includes scientific ecosystems for AI, microelectronics, robotics, data, quantum and cybersecurity; industrial demand for key technologies; research transfer; startup scaling; open source, open hardware and interoperability; and participation in standardisation.
Europe often underestimates this layer. Regulation can define the rules. It cannot replace the people, companies and institutions that build, operate, buy and improve the technology.
The third is economic value creation. The paper looks at where value is generated: R&D, engineering, skilled employment, operational control and contribution to the European technology ecosystem. It also explicitly allows partial value creation in trusted partner countries. That keeps the framework open enough to be economically realistic.
The fourth is protection of data. The paper calls on the European Commission to define the highest protection standards for the most sensitive data, including safeguards against cybersecurity risks and the effects of non-EU extraterritorial legislation. It also mentions mandatory privacy-enhancing technologies.
Sensitive data policy is now also industrial policy.
The fifth is substitutability and interoperability. The paper asks for modular architecture, open standards, open interfaces, software bills of materials, migration paths, exit concepts and multi-vendor strategies. In plain English: do not build systems that cannot be changed later.
For me, this is the most practical part of the paper. Lock-in rarely arrives as a crisis. It arrives as a procurement decision that cannot be reversed without years of cost and disruption.
The sixth is infrastructure resilience. The paper calls for sovereign data centers, AI, quantum and cloud computing infrastructure, interchangeable hardware and software stacks, diversified supply chains, secure and sustainable energy, high-performance networks and access to critical space resources.

This links directly to the SoftBank France data-center story. Digital sovereignty now has a power, land, data-center and network dimension. The debate has moved well beyond data location and cloud labels.
The paper is careful, maybe too careful
The paper is politically careful. It is non-binding. It excludes defence and national security. It does not force public spending. It does not impose rules on private procurement. It stresses trade obligations, trusted partners and cost efficiency.
That makes it weaker than a real industrial plan. It also makes the document harder to dismiss as protectionism.
The gap is not definition. The gap is action.
The paper does not unlock capital. It does not create major public procurement demand. It does not accelerate data-center buildout, AI infrastructure, semiconductor capacity, cloud scale or startup growth. It gives Europe a framework for assessing sovereignty, but it does not yet give European providers the demand, reference customers or balance-sheet confidence needed to scale.
The paper does not argue for closing Europe off. Its more useful move is to make dependency measurable. Who owns the provider? Which subcontractors matter? Where is R&D located? Can the customer exit? Are open interfaces available? Can sensitive data be protected from extraterritorial access? Can Europe still operate if one supplier, jurisdiction or supply chain becomes unavailable?
These questions belong in procurement files, architecture reviews and risk discussions.
For enterprise leaders, digital sovereignty is becoming a procurement and architecture discipline. It will affect cloud strategy, AI deployment, data classification, supplier concentration, cybersecurity, exit planning and board-level risk.
For policymakers, a definition is useful only if it changes incentives. Europe needs procurement demand for sovereign solutions, faster scaling paths for startups, deeper capital markets, serious public-sector reference customers, and infrastructure policy that connects cloud, AI, energy, semiconductors and networks.
Without that, sovereignty stays a vocabulary exercise. Other regions are moving with capital, infrastructure, industrial policy and large anchor customers. Europe cannot answer that with criteria alone.
The executive takeaway
The Franco-German paper stops short of a sovereignty plan. It offers criteria. Criteria still matter because they shape what governments and large buyers start asking for. They shape tenders. They influence compliance teams. They tell suppliers what the next market standard may look like.
If Europe uses this framework well, sovereignty becomes less abstract: fewer lock-ins, clearer exit paths, more transparent supply chains, stronger data protection, more European value creation, and better infrastructure resilience.
If Europe uses it badly, it becomes another vocabulary layer on top of slow procurement and fragmented national initiatives.
My read: this paper is strongest where it is most practical. It connects sovereignty to ownership, enforceability, interoperability, data protection, value creation and infrastructure. It avoids the fantasy of full autarky. It accepts trusted partners. It treats sovereignty as a risk-based capability, not as a flag on a server.
But the next test is not another definition. It is demand.
Without procurement demand, budgets, infrastructure, reference customers and scale, European providers will stay small. Without scale, the dependency problem stays exactly where it is.
Bottom line: good start. Now Europe needs action.

