Subscribe on LinkedIn

From Buzzword to Blueprint? The EU Tech Sovereignty Package Has Landed

A year ago, we argued that digital sovereignty was Europe’s favourite empty buzzword: elastic enough for everyone to project their fears onto, specific enough to satisfy no one. Yesterday, the European Commission adopted a package that tries, with notable seriousness, to prove that argument wrong.

The Tech Sovereignty Package was postponed three times since March 2026. Those delays were themselves informative: reporting suggested that language around preferential treatment for European providers was carefully managed to avoid triggering a transatlantic confrontation. The substance survived the editing. The slogans were trimmed. 

What finally landed is, in parts, striking in its candour. The Communication opens by acknowledging that the EU remains structurally reliant on non-EU providers for over 80% of its digital products, services, infrastructure and intellectual property. That is not the usual register of Brussels policy documents. It reads less like a strategy paper and more like a diagnosis.

What the Package Actually Contains

Four initiatives form the core of the package:

The Commission frames these as an integrated European technology stack, running from chip design to cloud infrastructure to software and AI.

The Cloud and AI Development Act (CADA) is the centre of gravity. It sets an explicit target of tripling EU data-centre capacity within five to seven years, reaching the needed capacity by 2035. More consequentially, it introduces four levels of cloud sovereignty assurance, tiered by criteria including control over the service and software supply chain, processing of AI inference data, infrastructure location, and cybersecurity posture. Member States will be required to conduct sovereignty risk assessments to determine which government workloads require which tier. The total investment picture is substantial: the adopted Communication estimates EUR 200 billion for data-centre capacity by 2036, a further EUR 100 billion for cloud and AI leadership initiatives, including AI Factories and Gigafactories, and EUR 120 billion for the semiconductor ecosystem by 2035.

The Chips Act 2.0 works both sides of the market, addressing the supply-side lesson of its predecessor: investment without demand-side coordination produces limited results. Through ‘Demand Accelerators’, it links EU-designed chip suppliers with users via offtake agreements and deploys public innovation procurement to stimulate uptake. The CADA grand challenge on cloud and AI autonomy is explicitly linked to the development of EU-designed processors and accelerators, closing the loop between cloud infrastructure policy and the semiconductor agenda.

AI Gigafactories sit at the apex of this architecture. Each facility will operate at industrial scale, providing compute time for EU developers of advanced AI solutions. The adopted Communication is direct about what this requires: strategic data and proprietary models must remain under exclusive EU oversight, the entire data lifecycle must be governed by European standards, and the infrastructure must be immune to foreign interference. The ambition is for these facilities to evolve from compute infrastructure into trusted environments for high-value AI innovation built in Europe and under European law.

Worth noting alongside the industrial instruments is what the final text declares as a fourth pillar of technological sovereignty: lead the standard setting for key strategic technologies. A leaked draft gestured at this; the adopted text names it explicitly. We return to the significance of that below.

Open Source as Industrial Strategy

The Open Source Strategy is arguably the most structurally significant for how Europe thinks about building a domestic AI ecosystem. But it’s a non-binding communication. 

The Commission’s starting diagnosis is blunt: the EU currently spends approximately 264 billion euros annually, mostly on US proprietary IT products and services. This creates vendor lock-in, constrains control over critical digital infrastructure, and extracts public value into foreign corporate structures. The counter-proposal is not merely to fund more open source projects. It is to use the public sector’s scale as a structural lever.

The open source-first principle in public procurement for cloud and AI software, combined with a public money, public code expectation, is a deliberate demand-side intervention. Software purchased with public funds should be available for reuse. Procurement frameworks that have historically been designed around proprietary vendor characteristics, and that tolerate vendor lock-in, are to be revised. CADA and the Open Source Strategy together aim to make the public sector an anchor customer: a source of stable, predictable demand that gives EU-grown open source providers a route to scale that does not require winning against hyperscalers on price alone.

The Commission also names the governance problem directly. Open source steward organisations, the foundations that maintain critical digital infrastructure, are currently dominated by US and Chinese big-tech funding. The strategy proposes a stewardship toolkit for EU-based foundations, a European Digital Public Infrastructure Steward Organisation, and an Open Source Maintenance Instrument providing sustained financial support, including the capacity to fork projects where necessary. This last point matters: the ability to fork is a form of technical sovereignty that money alone cannot buy once dependency is established.

Practically, the strategy targets areas where open source development could displace proprietary dependencies: operating systems across compute, mobile and IoT; cloud stack infrastructure; AI foundational models and agentic frameworks; software development tooling; and cybersecurity frameworks for compliance with the Cyber Resilience Act. It also aims for 30 million active users by 2030 for open source collaboration and productivity tools, which is the demand volume required to make the European open source ecosystem commercially viable at scale.

Europe has the developer base to support this. The final Communication confirms that the EU is home to over 3 million open source contributors, and names EU-based companies with industrial-grade capabilities as proof that the ecosystem can produce global-quality output. Odoo, cited as an example, reached a valuation of 5 billion euros with over 13 million users. Mistral AI, which we have discussed previously, is named as a sovereign alternative to closed-source systems. 

The Commission also establishes what it is already doing, not just what it intends. The annexes catalogue a substantial body of existing investment: the Next Generation Internet initiative, which mobilised approximately 190 million euros through Horizon and funded over 1,700 grassroots projects; the openEuroLLM project, co-investing 20 million euros toward fully open European foundation models covering all 24 official EU languages; ELLIOT, a 25 million euro multimodal AI project whose models, datasets and pipelines will be fully open source; and the DVPS initiative, a 29 million euro consortium developing open foundation models with immediate applications in cardiology, earth observation and inclusive language technology. code.europa.eu, the Commission’s own open source platform, counted over 4,500 registered users and 1,280 repositories as of May 2026. We are not starting from a blank slate. This is about an existing investment base being given strategic direction for the first time.

Buy European Without Saying It

There is no Buy European clause in the package. The adopted text repeatedly insists that technological sovereignty is grounded in openness, partnership and fair competition, and does not mean isolation, protectionism or tech decoupling. This framing is legally sensible and politically necessary.

But the architecture points in one direction. Sovereignty risk assessments will push sensitive government workloads toward high-sovereignty assurance level solutions, which are structurally easier to provide from within the EU or from operators willing to place infrastructure and governance entirely under EU law. The emphasis on immunity from foreign interference and full EU jurisdictional control creates a de facto filter against third-country corporate structures subject to US cloud laws or Chinese state-access requirements.

The strategy is architecturally honest even where it is diplomatically circumspect. The repeated delays and the reported role of US trade concerns in managing the language only reinforce how real the external pressure was and how deliberately the Commission navigated it. What remains as policy direction is a de facto “Buy European by design” approach: sovereignty levels, risk-based criteria, and procurement principles that structurally favour EU-law-compliant offerings without requiring an explicit geographic mandate.

The Problem the Package Cannot See From Inside

The package is coherent on its own terms. The contradiction lies in what surrounds it.

The AI Gigafactories initiative is premised on European developers having the infrastructure to build the next generation of AI models. But building AI models requires access to large, diverse training datasets. As we have argued previously, the Text and Data Mining (TDM) framework under Articles 3 and 4 of the Copyright in the Digital Single Market (CDSM) Directive is the legal floor that makes that access possible. Tighten that floor, or reverse the burden of proof as the French senate’s IA et creation bill proposed, and the compute infrastructure the package is spending billions to build has no meaningful data to run on. You cannot build Europe’s AI industrial base while simultaneously legislating away its access to training data.

The adopted Communication does acknowledge this tension, obliquely. It notes that the Digital Omnibus has proposed targeted amendments to the GDPR to bring legal certainty on lawful personal data used for training AI in Europe. That is a welcome signal. But the GDPR amendment covers personal data; it does not resolve the broader TDM framework question, which concerns the conditions under which AI developers can mine text and data across the open web, regardless of whether that data is personal. The two problems are related but not identical, and one sentence in a horizontal communication is not a substitute for legislative coherence across the copyright and AI agendas.

The JURI Committee’s January 2026 own-initiative report on copyright and generative AI illustrates the same tension from the legislative side. That report proposed full transparency requirements on training data, a rebuttable presumption of use, and extended press publisher rights over AI training. Each of those instruments would impose compliance costs on exactly the companies the AI Gigafactories and CADA are designed to support. European AI SMEs would face legal friction that their US and Asian competitors, operating under fair use or Japan’s non-enjoyment framework, do not. The Commission funds the silos; the Parliament makes it a crime to mill the grain.

The Commission’s machine-readable opt-out workshop process, which convened on 2 June, the day before the package was adopted, compounds the problem. That process, running under Measure 1.3(1)(b) of the GPAI Code of Practice, is attempting to produce a Commission-published list of approved opt-out mechanisms tied to AI Act compliance. The consultation drew 153 respondents, approximately 60% of whom were rightsholders and 7% of whom were AI developers. A compliance framework built on those proportions does not represent the ecosystem the Tech Sovereignty Package is trying to build. And a Commission-published list of specific mechanisms, tied to legal obligations, functions as a de facto standard regardless of what the covering note calls it.

That last observation connects directly to a new formulation in the EC’s final position. One of the four pillars of technological sovereignty is now stated explicitly as leading the standard setting for key strategic technologies. That is a legitimate ambition in semiconductors, cloud protocols and AI infrastructure. It is a different matter when applied to the machine-readable expression of copyright opt-out rights, where the Commission is simultaneously legislator, enforcer, co-drafter of the GPAI Code of Practice, and now prospective standard-setter. A November 2025 CERRE paper on EU digital competitiveness identified exactly this accumulation of roles as a structural problem. The package confirms the pattern rather than resolving it.

EU-specific, fragmented, and technically immature compliance requirements on AI training do not strengthen European digital sovereignty. They create a compliance island that raises the barrier to entry for European developers and produces no commensurate benefit for rights holders. The package names sovereignty-washing, superficial compliance with the form of sovereign requirements without the substance, as a risk to be prohibited. The same logic applies to the adjacent policy environment: piling EU-specific compliance requirements onto AI training while investing billions in AI infrastructure is a form of structural self-contradiction.

Where This Differs From Previous Attempts

The EU has produced digital sovereignty rhetoric before. Gaia-X was announced with similar ambition and delivered considerably less. The difference here is the coupling of political language with concrete industrial policy instruments: Data Centre Acceleration Zones, Semiconductor Regions of Excellence, the AI Gigafactories initiative, and a European Competitiveness Fund with a dedicated Digital Leadership Window.

The cloud sovereignty tiering is also operationally new. Previous EU cloud policy was largely principles-based. Classification frameworks that procurement officials and security teams can actually work with are a different order of instrument. They convert political preference into contractual criteria.

The Brussels Effect, Europe’s demonstrated capacity to export regulatory standards and make them global norms, is real. But as Bruegel’s Guntram Wolff put it and as we previously analysed, referees do not win games. Regulation is not a substitute for technological capacity. The question this package raises is whether the EU can move from referee to player quickly enough to matter, or whether the sovereignty tiers and procurement rules will simply reshape what it costs to serve the European market without shifting where the underlying technology is built.

There is also a sequencing problem. The package is candid about the equity gap: the EU accounts for only 5% of global venture capital raised, compared to 52% in the US and 40% in China. Scale dynamics in AI infrastructure create tipping points: once a limited number of platforms reach sufficient scale, cost advantages and ecosystem effects become self-reinforcing. The package acknowledges that Europe still has a window of opportunity in compute and cloud infrastructure, but that the window is narrowing as investment decisions and long-term contracts are being locked in. Data-centre capacity targets for 2035 and semiconductor pilot production targets for 2030 to 2033 are the tools available. The geopolitical dependencies are immediate.

A Direction, Not Yet a Fact

Our earlier post argued that as long as digital sovereignty remained a slogan instead of a strategy, Europe would continue mistaking the theatre of autonomy for the practice of power. The EU’s proposed package is, at minimum, an attempt at a strategy. It names the dependency. It prices the investment. It builds instruments that go beyond the declarative.

But a strategy cannot function in isolation from the policy environment it inhabits. The Commission is investing in the infrastructure of an AI-capable Europe at the same time as other parts of its institutional apparatus are creating legal conditions that make building AI in Europe harder, not easier. The open source-first principle and the AI Gigafactories initiative point in one direction. The European Parliament’s JURI Committee copyright trajectory, and the Commission’s opt-out mechanism process and its accumulation of de facto standard-setter authority point in another.

The package proves that the Commission understands the gap between regulatory power and technological capacity, and is trying to close it. Whether the tools are equal to the scale of the problem depends on implementation, investment discipline, and whether the Commission can hold its own internal contradictions together long enough to let the strategy take effect. The direction is set. The institutional coherence required to follow it is the harder question.

Written by Caroline De Cock, LL.M., Head of Research