
By Fredrik Lindstrom · ~35 minute read · September 2026
From Dependency to Resilience — A Practitioner’s Roadmap to 2035
Why eighteen months of incidents made the case operational — and what it actually takes to build a sovereign European technology stack across the next decade.
In February 2026, U.S. Customs and Border Protection issued an administrative summons to Google. The summons demanded six months of location data, account history, and activity logs for a Google account belonging to a Canadian citizen. The Canadian had not entered the United States in more than ten years. He owed no duties. He had imported nothing. His only connection to American jurisdiction was that his email provider was headquartered in Mountain View.
The legal instrument was the Tariff Act of 1930 — Section 1509 — originally written to compel testimony in customs disputes about the value of imported goods. No grand jury. No judge. An administrative form, signed by a CBP officer, citing a 1930 statute, served on a 2026 cloud platform, demanding records about a person who has nothing to do with American commerce. Google’s options: comply, sue, or wait to be sued.
This is not a hypothetical. The lawsuit was filed in U.S. District Court on May 4, 2026 by the ACLU (American Civil Liberties Union, 2026; CBC News, 2026). The plaintiff is identified only as “John Doe.” His Google records are now the subject of contested litigation in a foreign court, under a foreign legal instrument, because his vendor was American. WIRED’s reporting (Newman, 2026) traces the underlying mechanism — the customs summons — to roughly 170,000 issuances between 2016 and mid-2022. The DHS Inspector General’s own 2017 review found that one in five of the summonses it audited violated CBP’s own policies (DHS Office of Inspector General, 2017).
If you are a European board director, a senior IT leader, a procurement officer, or an investor, this case is not about one Canadian. It is about the operational mechanism by which any non-American user of any American cloud, model, or platform has standing legal exposure to American executive process. That mechanism has been theoretical for years. It is now exhibited.
This article makes two arguments. First, that European technology sovereignty has stopped being a policy debate and started being an operational requirement, with a specific evidence pile-up over the past eighteen months. Second, that there is a practitioner’s roadmap to a sovereign European technology stack by 2035, and the work to deliver it must begin now or the window closes.
I have spent twenty-five years building and scaling cybersecurity and technology services into European governments and enterprises for American companies. The dependency architecture I describe below is one I helped build. The roadmap I propose is one I would actually run.
Part 1: The eighteen-month pile-up
Sovereignty has been a theoretical concern in European tech policy for at least a decade. The Schrems II ruling in July 2020 (Court of Justice of the European Union, 2020) established that EU data transferred to the United States lacked adequate protection because of the structure of American surveillance law. The Schrems II ruling was foundational. It did not change what most enterprises actually did. The transfers continued. The Standard Contractual Clauses got longer. The Transfer Impact Assessments got filed. Most organizations interpreted Schrems II the way most organizations interpret most regulatory rulings: as a paperwork exercise.
What changed the conversation is a sequence of incidents over roughly eighteen months. Each one moved sovereignty from a theoretical concern to an operational fact. Considered in isolation, any one of them could be dismissed. Considered together, the pattern is unmistakable.

Figure 1: The eighteen-month pile-up. Each event reinforced the next.
February 2025 — the ICC email suspension. Microsoft cut off the Outlook account of Karim Khan, the chief prosecutor of the International Criminal Court, in connection with a U.S. executive order sanctioning ICC officials (Xinhua, 2025; The Register, 2026a). Microsoft’s public position has been consistent and unhelpful: the company says it never suspended services to the ICC. But Khan’s email stopped working. He moved to Proton Mail. The Dutch government, which hosts the ICC, opened urgent reviews of its digital exposure. The European Parliament filed a formal question (European Parliament, 2025). The mechanism on display: a U.S. executive order, applied to a U.S. company, blocking communications for an international institution operating on European soil. Gartner’s analysts now estimate that European sovereign cloud investment will more than triple between 2025 and 2027, and they cite the ICC incident as a primary catalyst (The Register, 2026a).
June 10, 2025 — the Carniaux moment. Anton Carniaux, Microsoft France’s Director of Public and Legal Affairs, testified under oath before a French Senate procurement inquiry (Sénat français, 2025). He was asked whether he could guarantee that French citizens’ data stored in Microsoft’s cloud would never be transferred to U.S. authorities without French authorization. His answer:
« Non, je ne peux pas le garantir. »
— Anton Carniaux, Microsoft France, under oath, French Senate, June 10, 2025
No, I cannot guarantee that. This was not a leaked memo or a hostile framing. It was Microsoft’s own French executive, on the record, under oath, in the French Senate. The CLOUD Act applies whether Microsoft wants it to or not.
September 2025 — Latombe. The European General Court dismissed French parliamentarian Philippe Latombe’s challenge to the EU-US Data Privacy Framework (General Court of the European Union, 2025; WilmerHale, 2025). The EU-US Data Privacy Framework survives, for now. But the court’s analysis was limited to the framework as it stood under the Biden administration. The Trump administration’s removal of independent agency heads at the Privacy and Civil Liberties Oversight Board after the Latombe ruling has not yet been litigated. Latombe’s appeal was filed at the Court of Justice of the European Union on October 31, 2025. Max Schrems, who has driven this litigation cycle for fifteen years, has publicly argued that the EU-US Data Privacy Framework’s foundations have weakened materially since the General Court’s review (IAPP, 2025).
November 2025 — the Berlin Summit. Twenty-three EU ministers and over one thousand attendees gathered at EUREF Campus in Berlin for the first formal Summit on European Digital Sovereignty, co-hosted by Emmanuel Macron and Friedrich Merz (Élysée, 2025). The participants signed a Declaration for European Digital Sovereignty. Private investment commitments of more than €12 billion were announced. A joint Franco-German task force on digital sovereignty was established. The European Commission’s executive vice-president for technology sovereignty, Henna Virkkunen, would put it most plainly to reporters in Lille the following March: “We are really living in a world where that kind of very strong dependencies … can be also weaponized against us” (Agence France-Presse, 2026).
January 27, 2026 — France’s Visio mandate. The French government issued a directive requiring all 2.5 million civil servants to migrate from Microsoft Teams, Zoom, Webex, and Google Meet to a sovereign platform (Euronews, 2026). The replacement is Visio, built on the open-source Jitsi framework, hosted on the SecNumCloud-qualified Outscale cloud. Minister for the Civil Service David Amiel’s framing was unequivocal: France cannot risk having scientific exchanges, sensitive data, and strategic innovations exposed to non-European actors. Migration completes by 2027. Estimated savings: roughly one million euros annually per 100,000 users (Euronews, 2026). The savings are real. The signal is bigger. The world’s seventh-largest economy has decided that platform sovereignty is operational policy, not aspirational.
December 2025 — Schleswig-Holstein crosses the line. The German state of Schleswig-Holstein announced that nearly 80 percent of its administrative workstations have migrated from Microsoft Office to LibreOffice (Land Schleswig-Holstein, 2025). Forty-four thousand employee inboxes have moved off Microsoft Exchange to open-source mail. SharePoint has been replaced with Nextcloud. Annual license savings projected for 2026: €15 million. One-time migration cost: €9 million. Payback period: under one year (Land Schleswig-Holstein, 2025). Other German states, Austria’s federal military, Italy’s Ministry of Defence, and Denmark’s Ministry of Digital Affairs are now publicly migrating along similar paths.
May 4, 2026 — the Canadian. And then the case that opened this article.
June 12, 2026 — the model layer. On a Friday evening, the U.S. Commerce Department issued an export-control directive barring all foreign nationals, inside the United States as well as outside it, from accessing Anthropic’s two most capable AI models, Fable 5 and Mythos 5, released days earlier. Anthropic could not verify nationality inside shared cloud infrastructure, so it disabled both models for every customer worldwide — simultaneously across its own platform, AWS Bedrock, Google Cloud, and Microsoft Foundry (Anthropic, 2026; The Register, 2026b). European enterprises that had built against those models on Thursday had no access on Friday. No contract was breached. No European law was violated. No European institution was consulted.
The reaction was immediate and it crossed political families that agree on almost nothing. Thomas Regnier, the European Commission’s spokesperson on technology sovereignty, said the episode was a further illustration of why Europe needs to strengthen its technological sovereignty, and pointed to the EU AI Act, the Cyber Resilience Act, and the NIS2 Directive as the instruments for managing exactly this class of risk on European terms (Meyer, 2026a). The Commission also stated that contingency measures of this kind should not be discriminatory against partners (The Register, 2026b). Gabriel Attal, the Renaissance presidential candidate, compared the shutdown to a blockade of the Strait of Hormuz. Jordan Bardella of the National Rally called it a reminder that AI is already a question of national sovereignty. On June 28, Austria’s State Secretary Alexander Pröll wrote to Commission executive vice-president Henna Virkkunen urging member states to explore hosting Anthropic inside the European Union, citing the U.S. restrictions as the direct cause (Meyer, 2026b).
The controls came off as abruptly as they went on. The U.S. Commerce Department lifted them on June 30 and access was restored on July 1 (Anthropic, 2026). Nineteen days.
Two weeks into that window, the same mechanism appeared at a second laboratory in a different legal form. On June 26, OpenAI confirmed that its new GPT-5.6 family would launch only to a small group of partners approved by the administration, with access cleared customer by customer (TechCrunch, 2026b). OpenAI’s own statement was unusually direct: it did not believe this kind of government access process should become the long-term default. The legal footing was a June 2 executive order asking developers of advanced models to submit them for voluntary federal review thirty days before release, which also bars mandatory licensing or preclearance (CNN Business, 2026). The restrictions were lifted on July 8, and the models became generally available the following day (Axios, 2026). The White House disputes that it granted approval at all, on the grounds that no approval was required.
There is a serious counter-argument here and it deserves to be stated plainly. Both interventions were cybersecurity measures aimed at models with unusual capability in vulnerability discovery, not instruments aimed at Europe. The IAPP’s analysis argues directly that reading the Anthropic episode as a kill switch pointed at Europe misreads what happened (International Association of Privacy Professionals, 2026). That is probably right about intent. It is beside the point for anyone doing dependency planning. The question a board has to answer is not whether a foreign government intends to disrupt its operations. It is whether a foreign government can, how fast, and whether anything the organization owns changes the answer. For nineteen days in June, nothing did. Not the contract. Not the data residency. Not the European data centre the workload was running in.
Each of these events strengthened the next. The ICC suspension generated parliamentary questions. The parliamentary questions exposed Carniaux. Carniaux’s testimony under oath made SecNumCloud the only credible procurement standard for sensitive French government data. SecNumCloud made France’s Visio mandate operationally feasible. The Visio mandate, the Schleswig-Holstein migration, and the Berlin Summit moved sovereignty from a Brussels white paper to a continent-wide political project. The Canadian case shows that this is not a paranoid European preoccupation. The mechanism on display is real, expanding, and now affects users with no connection to the United States at all. And the June sequence closed the loop. The mechanism reached the layer Europe had adopted fastest and can substitute least — twice in one month, at two different laboratories, under two different legal instruments. The European Technological Sovereignty Package had been announced days before the U.S. Commerce export-control directive landed. That directive made the case for the package better than the package did.
The case is operational. The next question is what to do about it.
Part 2: The dependency architecture
European technology dependency is not monolithic. From inside, it operates across five distinct layers, each with its own risk profile, transition timeline, and viable alternatives. From years of building these dependencies for the American side of the table, the architecture looks like this.

Figure 2: The five-layer European technology dependency architecture.
Infrastructure layer (cloud and compute). Amazon, Google, and Microsoft control roughly 70 percent of European cloud infrastructure services revenue, with European players holding about 15 percent (Synergy Research Group, 2025). The European cloud market reached €61 billion in 2024 and is projected to exceed €75 billion in 2025, growing at 24 percent year-over-year (Synergy Research Group, 2025). European alternatives exist — OVHcloud crossed €1 billion in revenue in fiscal 2025 and holds SecNumCloud 3.2 qualification (OVHcloud, 2025); Outscale, Scaleway, T-Systems, and STACKIT each occupy meaningful positions — but the scale gap, the tooling ecosystem gap, and the AI-compute gap remain large. Realistic transition timeline for critical workloads: five to ten years.
Platform layer (productivity and collaboration). Microsoft 365, Google Workspace, Zoom, and Slack are embedded in the daily operations of nearly every EU institution and enterprise. France’s January 2026 mandate is the first major test of platform-layer sovereignty at scale. Schleswig-Holstein’s LibreOffice migration is the first major test of office-suite displacement at scale. Both are succeeding. Both are early. The most replaceable of the five layers, but with the most embedded muscle memory.
Security layer (cybersecurity and identity). American vendors dominate endpoint protection, threat intelligence, identity management, and incident response. This is, in my professional judgment, the most sensitive of the five dependencies. It means American companies have observability into European security posture and incident telemetry — by design, because that is what the products do. The European alternatives are there — Stormshield, ESET, F-Secure, WithSecure — but the gap in scale and breadth remains significant.
Intelligence layer (AI and data). The newest and fastest-growing dependency. European organizations are adopting U.S.-built AI models, APIs, and data analytics platforms at scale. Roughly 70 percent of foundational AI models in production today originate in the United States (Draghi, 2024). The EU AI Act provides a regulatory framework, and its timeline moved in July 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on July 24 and entered into force on July 27, six days before the EU AI Act’s original high-risk deadline. Obligations for stand-alone high-risk systems under Annex III now apply from December 2, 2027, and for AI embedded in regulated products under Annex I from August 2, 2028 (Regulation (EU) 2026/1744). What did not move matters as much as what did. The Article 4 AI literacy duty has applied since February 2025. The general-purpose AI obligations have applied since August 2025. The Article 50 transparency duties applied from August 2, 2026, with only the watermarking requirement in Article 50(2) deferred to December 2, 2026 for systems already on the market. The relief is real for the heaviest compliance regime and narrow everywhere else. Anyone describing the EU AI Act as delayed, or as fully operational, is describing a document they have not read. But absent sovereign AI infrastructure at scale, enforcement of any of it still depends on foreign compliance — and June demonstrated that access to the models themselves depends on a foreign executive. Mistral AI is the most credible European frontier-model effort, with a €11.7 billion valuation post the September 2025 Series C, ASML as anchor investor, and contracts with the French Ministry of Armed Forces, the German federal government, HSBC, and the Singapore Defence Ministry (Mistral AI, 2025; Sacra, 2026). The Cohere acquisition of Aleph Alpha in April 2026 — at a combined entity valuation of $20 billion, with Schwarz Group’s STACKIT cloud anchoring infrastructure — created the second European pole (TechCrunch, 2026a). The intelligence layer is moving fastest. It is also where the loss of control accelerates fastest if Europe does not act.
Hardware layer (silicon, networking, compute infrastructure). This is the fifth layer, and it sits beneath all the others. It is the layer that policy debates routinely overlook, the layer where European dependency is most acute, and the layer where the consequences of inaction take the longest to reverse.
Consider the picture today. In enterprise networking — the gear that runs every cloud, every datacentre, and every corporate WAN in Europe — Cisco holds nearly 40 percent of the global wireless LAN market and remains a top-three vendor in core routing (Dell’Oro Group, 2025). The HPE acquisition of Juniper closed in mid-2025 at $14 billion, consolidating American share rather than reducing it. Huawei and ZTE are being phased out of EU 5G networks under member-state security mandates, leaving a structural gap that European vendors do not currently fill. There is no European Cisco. There is no European Juniper. T-Systems’ Open Telekom Cloud — one of the flagship sovereign offerings — runs publicly disclosed Huawei networking hardware underneath. That is what the dependency looks like at the wiring layer.
In compute silicon, the picture is starker. NVIDIA dominates AI training and inference globally, and its Spectrum-X bundle vaulted it past Cisco and Arista in datacentre Ethernet revenue in 2025 (Dell’Oro Group, 2025). AMD and Intel hold the rest of the data centre CPU and GPU market. ARM is British-headquartered but Japanese-owned, with most production capacity in Taiwan. Mistral’s €722 million March 2026 debt round is being deployed almost entirely on NVIDIA GB300 GPUs at Bruyères-le-Châtel, because the alternative does not exist at production scale (CNBC, 2026).
There are bright spots worth naming. ASML’s monopoly on EUV lithography means every advanced semiconductor in the world depends on Dutch equipment — a real strategic asset. NXP and Infineon are world-class in automotive and industrial chips. SiPearl’s Arm-based Rhea processor for European supercomputing raised €130 million in late 2025. The DARE project — Digital Autonomy with RISC-V in Europe — was launched in March 2025 with €240 million across thirty-eight partners in thirteen countries, building three open-source chiplets: a vector accelerator led by Openchip in Barcelona, an AI processing unit led by Axelera AI in the Netherlands, and a general-purpose processor led by Codasip in Munich (DARE, 2025; EuroHPC Joint Undertaking, 2025). EuroHPC has co-funded all of this. These are foundations. They are not yet at production scale.
Axelera AI deserves more than a line in that list, because it is this article’s argument compressed into one company. The Eindhoven firm raised $250 million in February 2026, taking its total past $450 million, the largest any European AI chip company has raised, and it holds up to €61.6 million of DARE funding for Titania, its inference chiplet, which is not due until 2027 (Axelera AI, 2025a; SiliconANGLE, 2026). Its Europa processor was announced in October 2025 for first-half-2026 shipment, a date Axelera has not since confirmed it met (Axelera AI, 2025b). That is real European silicon, aimed at generative AI, from a company that can fund itself. The money arrived ahead of the parts.
On the specification it still loses on memory bandwidth to the cheapest American part a buyer can get today, and it runs Axelera’s own toolchain rather than the American stacks every open-weight model ships against on release day. Then there is where it is going. EuroHPC signed the build contract for IT4LIA, Italy’s AI factory, in April 2026: NVIDIA Grace processors, NVIDIA Blackwell accelerators, NVIDIA Quantum-X800 networking, and a dedicated inference partition carrying Axelera’s accelerators alongside SiPearl’s European CPUs (EuroHPC Joint Undertaking, 2026). The sovereign AI factory is an NVIDIA machine with a European wing.
That is the hardware layer’s actual shape. European capability exists. What it buys, bought this way, is a sovereignty checkbox and a second dependency to govern.
The European Court of Auditors stated plainly in April 2025 that the EU Chips Act’s headline target of 20 percent of global semiconductor market share by 2030 is unreachable. Current trajectory delivers roughly 11.7 percent (European Court of Auditors, 2025). The Court’s framing is a warning, not a death sentence — but only if Europe responds by re-scoping the target rather than retreating from it. Hardware sovereignty is the slowest of the five layers to change, and it is where strategic decisions made now produce results in seven to ten years, not eighteen months. That makes it the layer most likely to be deferred and the layer most expensive to defer.
| Layer | Where Europe stands | Realistic transition | European alternatives in production |
|---|---|---|---|
| Intelligence AI and data | Roughly 70% of foundational models in production are US-built. Access itself proved revocable in June 2026. | Fastest-moving layer, in both directions | Mistral AI, Cohere–Aleph Alpha |
| Security cybersecurity and identity | The most sensitive of the five. US vendors see European security posture and incident telemetry by design. | Cannot wait for 2030 | Stormshield, ESET, F-Secure, WithSecure |
| Platform productivity and collaboration | Embedded in the daily operations of nearly every EU institution. | Migrating now, 2026–2028 | LibreOffice, Nextcloud, Visio, Tchap, Olvid |
| Infrastructure cloud and compute | Hyperscalers hold roughly 70% of European cloud revenue; European providers about 15%. | Five to ten years | OVHcloud, Outscale, Scaleway, STACKIT, T-Systems |
| Hardware silicon and networking | The most acute dependency. No European Cisco, no European Juniper. | Seven to ten years | ASML, NXP, Infineon, SiPearl, DARE, Nokia, Ericsson |
The critical insight: these five layers are interdependent, and hardware is the foundation. Cloud sovereignty cannot be achieved without addressing the security tools that monitor those clouds, the AI models that optimize those workloads, the collaboration platforms through which decisions about all of the above are made, and the silicon and networking that runs everything underneath. Bertelsmann Stiftung’s EuroStack analysis puts total European import dependency for digital technologies and infrastructure above 80 percent (Bertelsmann Stiftung, 2025). Bitkom’s January 2025 survey of 603 German companies found that 53 percent of those importing digital technology could not last more than twelve months without it (Bitkom, 2025). Ninety-five percent want Germany to become more independent of the United States. That is not a number that survives many more incidents like the ones above.
The procurement-lock-in dimension is what makes this hard. Once an organization migrates to a hyperscaler, the technical, organizational, and contractual switching costs are enormous. Five to ten year dependency windows are common. The status quo is therefore not stable equilibrium — it is accumulated debt. And like all debt, the longer it sits, the more expensive it becomes to refinance.
Part 3: The roadmap to 2035
A practitioner’s framework prioritizes risk reduction over ideological decoupling. The goal is resilience, not separation. It is to ensure that no single external actor can unilaterally disrupt critical European digital services. With that frame, three phases — short, medium, and long term — produce defensible sovereignty by 2035.

Figure 3: The three-phase roadmap. Each phase builds on the last.
Short term — before 2028: eliminate the kill switches
The short-term focus is exclusively on dependencies where a unilateral U.S. action could cause immediate disruption to critical European services. Not all dependencies. The dangerous ones. Five concrete priorities.
Mandate sovereign hosting for all classified and sensitive government data. France’s SREN law (Loi n° 2024-449, 2024) and SecNumCloud framework (ANSSI, 2024) provide a working template. Germany’s BSI C5 Type 2 certification, made mandatory for German healthcare from July 2025, is the parallel template (Bundesamt für Sicherheit in der Informationstechnik, 2025). The EU Cybersecurity Scheme (EUCS) should adopt SecNumCloud-equivalent requirements at the highest tier and make them binding for all member-state critical infrastructure operators by end of 2027.
Require contractual continuity guarantees from non-European cloud providers. Service continuity must be guaranteed regardless of geopolitical disputes, backed by escrowed source code, data portability mechanisms, and binding clauses. Microsoft’s April 2025 commitment to add such clauses to European government contracts is a starting point (Microsoft, 2025). It needs to be enforced as a procurement minimum, not as a vendor courtesy. The same requirement now has to extend to AI model providers. A continuity clause that covers cloud tenancy but says nothing about model access does not cover what happened in June.
Establish a sovereign readiness assessment for critical infrastructure operators. Every member state should map all single-vendor dependencies in critical infrastructure — energy, water, transport, financial market infrastructure, public health — and score them by disruption risk. This is a six- to nine-month exercise per sector. The output is not a glossy report. It is a list of specific contracts that need to be renegotiated, replaced, or escrowed within twenty-four months.
Accelerate platform-layer alternatives across all member-state governments. France’s Visio rollout completes in 2027. Schleswig-Holstein crosses 100 percent in 2026. By 2028, every EU member state should have a documented migration path away from Microsoft Teams, Zoom, and Webex for civil-service collaboration. Bavaria’s late-2025 decision to renew with Microsoft is exactly the wrong direction. The Commission should make non-sovereign collaboration platforms ineligible for EU co-funded programs by 2028.
Stand up a European cybersecurity services consortium. Threat intelligence, incident response, and managed security services at scale, run by European-controlled providers, available to public-sector and critical-infrastructure customers. This is the most sensitive dependency layer. It cannot wait until 2030.
The short-term phase is not about building new technology. It is about closing the gaps that already exist between credible European alternatives and the procurement decisions that ignore them. It is operational. Eighteen-month execution windows.
Medium term — by 2030: build strategic alternatives
The medium-term focus is investment in European-controlled alternatives at the layers where current options lack scale, with a focus on interoperability rather than isolation. Four priorities.
Fund European cloud infrastructure for sensitive and sovereign workloads at scale. The Bertelsmann Stiftung EuroStack analysis estimates €300 billion of investment is needed across ten years, with €10 billion as a seed for the European Technology Fund and EuroStack Challenge demonstrators (Bertelsmann Stiftung, 2025). That order of magnitude is correct. The structure of the investment matters more than the headline number. It must include direct equity in scale-stage European cloud providers, procurement guarantees that give them demand certainty, and a deliberate consolidation strategy that produces three to five European cloud champions of meaningful scale rather than thirty subscale providers.
Support European AI champions with dedicated compute infrastructure and procurement preferences. Mistral and the combined Cohere–Aleph Alpha entity are the two credible poles. Each needs dedicated sovereign compute capacity at the scale of the U.S. hyperscalers’ AI infrastructure, not nominal access. The French government’s June 2025 launch of Mistral Compute, with eighteen thousand NVIDIA Grace Blackwell Superchips at Bruyères-le-Châtel, is the right model (Mistral AI, 2025). By 2030, Europe should have at least 200 megawatts of sovereign AI compute distributed across France, Germany, the Nordics, and Iberia — and EU public-sector procurement should preference European-controlled AI providers for sensitive workloads by default.
Establish EU-wide procurement standards that require multi-vendor strategies and contractual data portability. Single-vendor lock-in for any public-sector technology contract above a defined threshold should require an explicit risk acceptance signed at ministerial level. Multi-vendor architectures, data portability mandates, and exit-cost transparency should be standard contract clauses in all EU public-sector technology procurement by 2028 and binding by 2030.
Operationalize the European cybersecurity services consortium. What was stood up in the short-term phase should reach competitive scale by 2030 — comparable threat intelligence, comparable incident response capacity, comparable managed security services to the dominant American providers, with European data control and European legal jurisdiction by design.
Long term — by 2035: structural resilience
The long-term horizon shifts from dependency reduction to structural autonomy. Five priorities, with hardware now treated at the depth it deserves.
Re-scope and execute Chips Act 2.0 around sovereign-relevant capability, not aggregate market share. The European Court of Auditors stated plainly in April 2025 that the headline 20 percent global market share target by 2030 is unreachable; current trajectory delivers roughly 11.7 percent (European Court of Auditors, 2025). The right response is to stop optimizing for the wrong metric. The strategic question is not whether Europe captures 20 percent of the world’s commodity chip volume. It is whether Europe can produce, at sovereign scale, the silicon required to run its defense systems, its critical infrastructure, its AI workloads, and its strategic enterprise applications. That is a smaller, more achievable, more important target. Chips Act 2.0 — currently in consultation — should be sized to deliver at least two European foundries operating advanced-node capacity for strategic applications by 2032, with the Semicon Coalition’s September 2025 declaration as the political mandate to move it forward. The €69 billion in investment catalysed by the original Chips Act through October 2025 is a real foundation (SEMI Europe, 2025). The next phase needs to be deployed with sharper strategic targeting.
Build credible RISC-V production capacity for defense and government workloads. The DARE project’s three chiplets — Openchip’s vector accelerator, Axelera AI’s processing unit, Codasip’s general-purpose processor — should reach production-grade silicon by 2030 and meaningful European deployment by 2032. SiPearl’s Rhea processor and successor designs should be in production deployment across the EuroHPC supercomputing fleet by 2030. By 2035, every new defense computing platform procured by an EU member state should have a credible RISC-V or European Arm-based option in its evaluation matrix — and procurement preferences should make that option the default for sensitive workloads. RISC-V matters more than the equivalent ARM bet for one specific reason: it is open-source and not controlled by any non-European entity. Strategic autonomy is structural, not contractual. RISC-V is structural autonomy in silicon.
Stand up a European networking hardware program. This is the most overlooked priority in current EU industrial policy and arguably the most urgent. There is no European Cisco. There is no European Juniper. The HPE-Juniper consolidation in mid-2025 deepened the dependency rather than addressing it. Building a European networking champion from scratch is a fifteen-year project. Europe does not have fifteen years. The realistic path is some combination of consolidation among existing European specialists — Nokia, Ericsson, and the surviving European telecom equipment vendors — backed by Sovereign Technology Fund equity and underwritten by binding procurement preferences for critical infrastructure. By 2030, every European telecom operator and critical-infrastructure operator should have a credible European networking option in its core procurement decisions. By 2035, that option should hold majority share of EU public-sector networking spend. Without this, the cloud-sovereignty work above runs on Chinese or American wires regardless of whose datacentre tenancy it sits in.
Build cross-border European digital infrastructure that enables member states to operate critical services independently of any single external provider. Federated cloud architectures across member states. Cross-border emergency continuity for critical public-sector workloads. Sovereign DNS, sovereign certificate authorities, sovereign identity infrastructure. None of these are exotic. All require sustained ten-year political will to execute.
Establish a permanent EU digital sovereignty assessment capability. Continuous monitoring of dependency exposure, scoring of new procurement decisions against sovereignty criteria, and binding advisory authority on technology contracts above defined thresholds. Not a regulator. An assessor. Modelled on the European Court of Auditors but for digital exposure.
Build a European technology talent pipeline. University programs, professional certification frameworks, cross-border skills mobility, and tax incentives for European technology professionals to relocate within the union. The talent gap is invisible in most policy frameworks because it is not on a balance sheet, but it is the most binding constraint on every other priority — and it is most acute in semiconductors, where Europe trains world-class engineers and then loses them to American and Asian fabs.
By 2035, the test of success is not whether Europe has fully replaced American technology. The test is whether a unilateral American executive action can disrupt European critical services. If the answer is no, the work was correct.
Part 4: Precedent — what Europe has already proven it can build
A standard objection to the roadmap is that Europe cannot execute multi-decade industrial strategy at scale. The objection is empirically wrong.
The EU has built and operates three flagship sovereign space programmes that follow exactly the template the rest of the stack needs. Galileo, the EU’s satellite navigation system, was planned starting in 2003, became operational in 2016, and reached full deployment by 2020 (European Space Agency, n.d.-b). The constellation runs on 28 operational satellites, cost roughly €10 billion across two decades, and is now the world’s most accurate civilian satnav system — used in every smartphone shipped in Europe (European Space Agency, n.d.-b). Copernicus has operated since 2014 and is now the largest civil Earth observation programme on the planet, with a downstream ecosystem of SMEs, applications, and services that the rest of the stack has yet to produce (European Space Agency, n.d.-a). IRIS² — Infrastructure for Resilience, Interconnectivity and Security by Satellite — moved from concept to contract on December 16, 2024, when the European Commission, the European Space Agency, and the SpaceRISE consortium (led by SES, Eutelsat, and Hispasat) signed a €10.6 billion, 12-year concession (European Commission, 2024b; European Space Agency, 2024; Foust, 2024). The constellation will deploy 290 satellites across low Earth orbit and medium Earth orbit, with services beginning in 2030 (Foust, 2024). Public funding contributes €6 billion (EU) plus €550 million (ESA); the consortium contributes more than €4 billion (European Space Agency, 2024). The EU is the anchor customer. Ten percent of ESA contract value is mandated to SMEs (European Commission, 2024b).
The EU Space Act, proposed by the Commission on June 25, 2025 and currently in negotiation by the European Parliament and the Council under the ordinary legislative procedure (European Commission, 2025b; European Parliament, 2025a), locks in the regulatory layer. It replaces the current patchwork of 13 national regimes with a single EU-wide framework — binding rules on safety, cybersecurity, resilience, and sustainability that apply to any operator providing services in the Union, with application from January 1, 2030 (European Commission, 2025b; White & Case, 2026). The legal basis is Article 114 TFEU — the same single-market article that grounds the General Data Protection Regulation and the EU AI Act (European Parliament, 2025a).
The pattern across these four programmes is identical to what the rest of the stack needs. Long-term horizons. Public anchor demand. Public-private partnership financing with majority public contribution. Mandated European industrial participation. SME carve-outs. A dedicated regulatory framework that makes the strategic asset durable. The template is not theoretical. It is operationally proven, with more than €30 billion already deployed and infrastructure already in orbit or under construction (European Space Agency, 2024; European Commission, 2024b).
But the precedent argument cuts deeper than “Europe can execute.” It also reveals why the rest of the stack is urgent in a way that even sophisticated readers miss. A sovereign satellite constellation that runs on American cloud for its ground operations, American GPUs for its threat-detection AI, American networking gear for its data centres, and American cybersecurity tooling for its incident response is not sovereign. It is a sovereign satellite layer floating on a dependent stack. The same is true of Galileo’s ground-segment infrastructure, of Copernicus’ data processing pipelines, of the IRIS² command-and-control architecture currently in design phase.
There is no version of sovereignty in which the space layer succeeds and the rest of the stack fails. The €30 billion already invested in sovereign space programmes is, at the current architectural posture, only as sovereign as the foundation it runs on. The Sovereign Tech Stack is not a parallel project to the Space Programme. It is the foundation that determines whether the Space Programme delivers the outcome it was funded to deliver.
The right way to read IRIS² and the EU Space Act, then, is not as proof that the rest of the stack work is achievable. It is as proof that the rest of the stack work is non-negotiable. The investments are already made. The sovereignty premium is already being paid. Completing the stack is what converts that premium into the actual outcome it was supposed to buy.
Part 5: Acceleration — capital, M&A, grants, procurement
The roadmap above describes what to build and when. The harder question is how to fund it and how to execute it at the necessary speed. Six interlocking acceleration mechanisms make the timeline achievable.
A European Sovereign Technology Fund. A dedicated, large-scale investment vehicle with the mandate to make direct equity investments, acquire strategic assets, and provide patient capital for European technology companies in sovereignty-critical sectors. Not another R&D grant program. An industrial strategy fund. The scope should explicitly include the hardware layer that policy debates routinely overlook — networking and routing equipment, server and compute infrastructure, storage systems, telecom access hardware. European enterprises and governments depend overwhelmingly on American (Cisco, Juniper, Arista, HPE) and Chinese (Huawei, ZTE) vendors for this layer. The hardware sovereignty gap is as significant as the cloud gap, and arguably more dangerous because hardware supply chains are harder to diversify quickly than software platforms. The model exists. IRIS² is the Sovereign Technology Fund operating at the space layer — public anchor customer, public-private partnership financing, binding industrial participation, multi-decade horizon. The remaining work is generalizing the template to the cloud, AI, security, hardware, and networking layers underneath.
EU-funded strategic M&A defense. This is the lesson the Aleph Alpha story should teach. When a European AI champion is acquired by a non-European entity — even a friendly Canadian one — sovereignty thins. The combined Cohere–Aleph Alpha entity is 90 percent owned by Cohere shareholders, headquartered in Toronto, with German governance through the STACKIT cloud arrangement. That is a defensible outcome. It is not a sovereign one. The Sovereign Technology Fund should have explicit authority to co-invest in strategic M&A involving European technology champions to keep majority European control, and to acquire strategic assets when foreign acquirers would otherwise capture them. Pre-emption capital, deployed quickly.
Capital Markets Union acceleration through the Savings and Investments Union. Europe’s capital markets remain fragmented along national lines. A Finnish pension fund investing in a Portuguese cloud infrastructure company faces regulatory friction, tax complexity, and legal uncertainty that does not exist when investing in a U.S.-listed hyperscaler. This is a structural subsidy for American technology. The European Commission’s March 2025 Savings and Investments Union strategy is the right vehicle (European Commission, 2025c) but needs to move faster on three specific instruments — harmonized fund structures for sovereignty-classified technology companies, mutual recognition of cross-border due diligence for technology investment, and a simplified prospectus regime for European technology companies seeking capital across member states. The €10 trillion in European household savings currently sitting in low-yield bank deposits is the resource (European Commission, 2025c). Channeling even a small percentage of it into European sovereign technology is what closes the gap with the Bertelsmann €300 billion estimate. The precedent already exists at the sector level: the EU Space Act creates exactly this kind of single market for space services — replacing 13 fragmented national regimes with one EU-wide investment and authorisation framework grounded in Article 114 TFEU (European Commission, 2025b; European Parliament, 2025a). The space sector now has the harmonised cross-border investment environment the rest of the technology stack lacks. Generalising that pattern to cloud, AI, semiconductors, and cybersecurity is what an actual Savings and Investments Union for sovereign technology means in practice.
Citizen tax incentives for strategic autonomy investment. Institutional capital alone will not close the funding gap. The model already exists nationally: France’s PEA provides tax-advantaged investment in European equities, with €114 billion in PEA outstanding at end of 2024 across 7.2 million plans (Banque de France, 2025). Germany’s Riester and Rürup provide retirement-savings vehicles with tax incentives (Investment & Pensions Europe, 2025). The UK’s EIS offers 30 percent income tax relief for qualifying investments (HM Revenue & Customs, 2024). None of these are pan-European. The proposal: an EU Strategic Autonomy Investment Label, granted to companies and funds meeting defined criteria for contributing to European digital sovereignty — European cloud providers, cybersecurity vendors, semiconductor manufacturers, networking hardware producers, AI model developers, open-source infrastructure projects. Citizens investing in labeled companies receive harmonized tax benefits across all member states: reduced capital gains tax on holdings of three-plus years, income tax credits for direct investment, tax-free reinvestment of gains into other labeled companies. This is not protectionism. It is strategic capital allocation, and the United States already does the equivalent through its venture capital ecosystem, defense procurement preferences, and CHIPS Act subsidies.
Innovation grants targeted at execution gaps, not headline technology. The InvestAI initiative’s €200 billion commitment (European Commission, 2025a), the EU AI Factories program with seven sites and €750 million plus member-state matching (European Commission, 2024a), the DARE RISC-V project at €240 million (DARE, 2025), the EuroHPC Joint Undertaking — the grant infrastructure exists. The execution problem is that grant funding currently flows substantially to projects that ultimately deepen U.S. hyperscaler dependency. Cloud allocations on AWS or Azure that are paid for with EU grants are not sovereign infrastructure. They are sovereignty laundering. By 2027, EU innovation funding should be conditional on infrastructure-tier sovereignty: grants above defined thresholds should require execution on European-controlled infrastructure unless an explicit sovereignty waiver is approved.
Procurement preferences anchored on certified sovereignty. Public-sector procurement is the single largest demand lever Europe has. SecNumCloud, BSI C5 Type 2, and the upcoming EUCS at the highest tier provide certified definitions of sovereignty-grade infrastructure. EU public sector procurement should preference these certifications by default for sensitive workloads, with explicit sovereignty waivers required for any contracted exception. The U.S. uses defense procurement preferences as an industrial policy instrument continuously and effectively. The European equivalent — call it a Buy European Act or a strategic sovereignty preference framework — is the industrial policy lever that does not require new tax revenue, only political will.
These six mechanisms are interdependent. The Sovereign Technology Fund provides direction and capital. The Savings and Investments Union provides scale. M&A defense capital protects strategic assets in market events. Citizen tax incentives provide democratic legitimacy and additional capital. Innovation grants direct flow to sovereignty-aligned execution. Procurement preferences create demand certainty that justifies the supply-side investment. Without all six, Europe risks building sovereign technology that no one funds, or funding mechanisms with no strategic direction. Together, they create a self-reinforcing ecosystem: public investment de-risks the market, institutional capital provides growth, citizen investment provides capital and political mandate, and procurement provides demand.
Part 6: What this is not
This framework explicitly rejects two extreme positions.
It is not a call for autarky. Complete technological isolation from the United States would be economically devastating and strategically unnecessary. The American technology ecosystem has produced extraordinary capability, and many of those products will remain best-in-class for years. The goal is resilience, not separation — ensuring that no single external actor can unilaterally disrupt European digital services. Productive transatlantic technology partnerships are valuable and should continue. Single points of strategic failure should not.
It is not a defense of the status quo. The current level of dependency represents a genuine strategic vulnerability. The argument that “American technology is the best available” may be true today, but it does not address the question of what happens when access to that technology becomes conditional on geopolitical compliance. The eighteen-month pile-up demonstrates that this question is no longer hypothetical.
The right framing is not decoupling. It is diversification with strategic autonomy — maintaining productive transatlantic technology partnerships while ensuring Europe can never be held hostage by them.
There is also a credibility risk worth naming directly. Microsoft’s Sovereign Cloud, AWS’s European Sovereign Cloud, and parallel Google initiatives are now in market with credible-sounding governance frameworks. Microsoft’s Bleu joint venture with Capgemini and Orange, Delos Cloud with SAP, and AWS’s dedicated European parent company with EU-citizen management each offer real architectural improvements. They also each retain the core CLOUD Act exposure. Carniaux’s testimony settled that question. National Partner Cloud arrangements with a U.S. parent are an improvement over standard hyperscaler tenancy. They are not equivalent to SecNumCloud-qualified infrastructure under European legal control. Calling them “sovereign cloud” is a marketing decision. Treating them as equivalent in procurement is sovereignty theater.
The verdict
The case for European technology sovereignty has stopped being theoretical. The Canadian whose Google records were demanded under a 1930 customs statute is not the only exhibit. The Microsoft France executive who could not guarantee sovereignty under oath is the strongest one. The nineteen days in June when the two most capable AI models available to European enterprises went dark by order of a government no European elects is the fastest one. The pattern across eighteen months is consistent: where there is a single point of strategic failure in a dependency on American infrastructure, that point will eventually be exercised. Sometimes by accident, sometimes by policy, sometimes by executive order — but exercised.
The roadmap to 2035 is achievable. The standards exist — NIST AI Risk Management Framework, ISO 42001, the EU AI Act, SecNumCloud, BSI C5, the upcoming EUCS. The capital exists — €10 trillion in European household savings, the €200 billion InvestAI commitment, the €300 billion EuroStack estimate, member-state defense and digital budgets. The technology exists — Mistral and the combined Cohere–Aleph Alpha entity at the AI layer; OVHcloud, Outscale, STACKIT, T-Systems at the cloud layer; Nextcloud, LibreOffice, Tchap, Olvid at the platform layer; the DARE project’s RISC-V chiplets at the hardware layer. None of these are aspirational. All are in production at meaningful scale, somewhere.
What does not exist yet is the connective tissue. The Sovereign Technology Fund. The pan-European tax incentive. The procurement preference framework. The M&A defense capital. The Savings and Investments Union at sufficient depth. The political will to make sovereignty a procurement default rather than a Brussels declaration.
The next eighteen months are decisive. Each new procurement decision either accumulates more strategic debt or begins to refinance it. Each new architectural pattern either entrenches dependency or starts to dismantle it. The boards that act early will be the ones whose minutes look defensible if a question lands two years from now about what they knew and when. The boards that wait will not be the ones surprised by the answer — they will be the ones who supplied it.
Europe does not need to win every layer. It needs to eliminate the single points of strategic failure. That is the difference between sovereignty as a slogan and sovereignty as an outcome.
Fredrik Lindström is a Swedish national and senior technology executive currently based in the United States. He has spent twenty-five years building and scaling global technology services organizations for American cybersecurity and IT companies, most recently as Head of Global Services Sales. He holds ISACA AAISM, CISSP, CISM, CISA, PMP, ITIL, AWS, and Azure certifications, and many more. He is the creator of Promise & Risk of AI and publisher of The Governance Memo*.*
Email: fredrik@fredriklindstrom.info
LinkedIn: linkedin.com/in/fredriklindstrom
Web: fredriklindstrom.info · promiseandrisk.ai
References
Agence France-Presse. (2026, March 31). EU digital chief warns of ‘weaponized’ reliance on foreign tech. Courthouse News Service. https://courthousenews.com/eu-digital-chief-warns-of-weaponized-reliance-on-foreign-tech/
American Civil Liberties Union. (2026, May 4). Canadian Trump critic sues to stop Google from sharing personal information with Department of Homeland Security [Press release]. https://www.aclu.org/press-releases/canadian-trump-critic-sues-to-stop-google-from-sharing-personal-information-with-department-of-homeland-security
ANSSI. (2024). SecNumCloud 3.2: Référentiel d’exigences applicables aux prestataires de services d’informatique en nuage. Agence nationale de la sécurité des systèmes d’information. https://cyber.gouv.fr/sites/default/files/document/secnumcloud-referentiel-exigences-v3.2.pdf
Anthropic. (2026, July 1). An update on Fable 5 and Mythos 5 availability. Anthropic. https://www.anthropic.com/news/fable-mythos-access
Axelera AI. (2025a, March 6). Axelera AI secures up to €61.6 million grant to develop scalable AI chiplet for high-performance computing [Press release]. https://axelera.ai/news/axelera-ai-secures-up-to-61-million-grant-to-develop-scalable-ai-chiplet-for-high-performance-computing
Axelera AI. (2025b, October 21). Axelera announces Europa AIPU, setting new industry benchmark for AI accelerator performance, power efficiency and affordability [Press release]. https://axelera.ai/news/axelera-announces-europa-aipu-setting-new-industry-benchmark-for-ai-accelerator-performance-power-efficiency-and-affordability
Axios. (2026, July 8). Trump administration lifts restrictions on OpenAI’s GPT-5.6. Axios. https://www.axios.com/2026/07/08/openai-gpt-trump-ban-lifted
Banque de France. (2025, June 5). Plan d’épargne en actions — Statistiques 2024. Banque de France. https://www.banque-france.fr/fr/statistiques/epargne/plan-depargne-en-actions-2024
Bertelsmann Stiftung. (2025, February 13). EuroStack — A European alternative for digital sovereignty (F. Bria, P. Timmers, & F. Gernone, Eds.). https://www.bertelsmann-stiftung.de/en/our-projects/reframetech-algorithmen-fuers-gemeinwohl/project-news/eurostack-a-european-alternative-for-digital-sovereignty
Bitkom. (2025, January 15). Deutschlands digitale Abhängigkeit steigt [Press release]. Bitkom e.V. https://www.bitkom.org/Presse/Presseinformation/Deutschlands-digitale-Abhaengigkeit-steigt
Bundesamt für Sicherheit in der Informationstechnik. (2025). Cloud Computing Compliance Criteria Catalogue (C5). BSI. https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html
CBC News. (2026, May 6). Canadian sues U.S. Homeland Security, which allegedly sought his Google data after critical social media posts. CBC News. https://www.cbc.ca/news/world/us-dhs-aclu-lawsuit-canadian-john-doe-9.7187851
CNBC. (2026, March 30). Mistral secures $830 million in debt financing to fund AI data center. CNBC. https://www.cnbc.com/2026/03/30/mistral-ai-paris-data-center-cluster-debt-financing.html
CNN Business. (2026, June 25). White House asks OpenAI to limit its next model release. CNN. https://www.cnn.com/2026/06/25/tech/openai-limit-release-white-house
Court of Justice of the European Union. (2020, July 16). Data Protection Commissioner v. Facebook Ireland Ltd. and Maximillian Schrems (Case C-311/18). ECLI:EU:C:2020:559. https://curia.europa.eu/juris/liste.jsf?num=C-311/18
DARE. (2025, March 6). Europe takes a major step towards digital autonomy in HPC and AI with the launch of DARE SGA1 project [Press release]. Digital Autonomy with RISC-V in Europe. https://dare-riscv.eu/wp-content/uploads/2025/03/DARE-press-release-final-EN.pdf
Dell’Oro Group. (2025, November). Worldwide router and Ethernet switch market report. Dell’Oro Group. https://www.delloro.com/news/
DHS Office of Inspector General. (2017, November 16). Management alert — CBP’s use of examination and summons authority under 19 U.S.C. § 1509 (OIG-18-18). U.S. Department of Homeland Security. https://www.oig.dhs.gov/sites/default/files/assets/Mga/2017/oig-18-18-nov17.pdf
Draghi, M. (2024, September 9). The future of European competitiveness: A competitiveness strategy for Europe. European Commission. https://commission.europa.eu/document/97e481fd-2dc3-412d-be4c-f152a8232961_en
Élysée. (2025, November 18). Sommet pour la souveraineté numérique européenne [Press release]. Présidence de la République française. https://www.elysee.fr/en/emmanuel-macron/2025/11/18/summit-on-european-digital-sovereignty-delivers-landmark-commitments-for-a-more-competitive-and-sovereign-europe
EuroHPC Joint Undertaking. (2025, March 6). Advancing European sovereignty in HPC with RISC-V — the DARE project. European High Performance Computing Joint Undertaking. https://eurohpc-ju.europa.eu/advancing-european-sovereignty-hpc-risc-v-2025-03-06_en
EuroHPC Joint Undertaking. (2026, April 22). EuroHPC JU signs contract to boost AI capabilities with IT4LIA AI Factory [Press release]. https://www.eurohpc-ju.europa.eu/eurohpc-ju-signs-contract-boost-ai-capabilities-it4lia-ai-factory-2026-04-22_en
Euronews. (2026, January 27). France to ditch US platforms Microsoft Teams, Zoom for ‘sovereign platform’ citing security concerns. Euronews. https://www.euronews.com/next/2026/01/27/france-to-ditch-us-platforms-microsoft-teams-zoom-for-sovereign-platform-amid-security-con
European Commission. (2024a, December 10). Commission selects first seven AI Factories to drive Europe’s leadership in AI [Press release]. https://digital-strategy.ec.europa.eu/en/news/commission-selects-first-seven-ai-factories-drive-europes-leadership-ai
European Commission. (2024b, December 16). Commission takes next step to deploy the IRIS² secure satellite system [Press release]. https://defence-industry-space.ec.europa.eu/commission-takes-next-step-deploy-iris2-secure-satellite-system-2024-12-16_en
European Commission. (2025a, February 11). EU launches InvestAI initiative to mobilise €200 billion of investment in artificial intelligence [Press release]. https://ec.europa.eu/commission/presscorner/detail/en/ip_25_467
European Commission. (2025b, June 25). Proposal for a Regulation of the European Parliament and of the Council on the safety, resilience and sustainability of space activities in the Union (COM(2025) 335 final). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0335
European Commission. (2025c, March 19). Savings and Investments Union: A strategy to foster citizens’ wealth and economic competitiveness in the EU [Communication COM(2025) 124 final]. https://finance.ec.europa.eu/publications/savings-and-investments-union-strategy-enhance-financial-opportunities-eu-citizens-and-businesses_en
European Court of Auditors. (2025, April 28). Special Report 12/2025: The EU’s strategy for microchips — Reasonable progress in its implementation but the Chips Act is very unlikely to be sufficient to reach the overly ambitious Digital Decade target. ECA. https://www.eca.europa.eu/en/publications/SR-2025-12
European Parliament. (2025a, September 22). EU space act [EU Legislation in Progress briefing PE 775.922]. European Parliamentary Research Service. https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/775922/EPRS_BRI(2025)775922_EN.pdf
European Parliament. (2025b, May 15). Parliamentary question P-002270/2025: The effect of the sanctions imposed by the United States on the functioning of the ICC. https://www.europarl.europa.eu/doceo/document/P-10-2025-002270_EN.html
European Space Agency. (n.d.-a). Copernicus. ESA. https://www.esa.int/Applications/Observing_the_Earth/Copernicus
European Space Agency. (n.d.-b). Galileo: Europe’s Global Navigation Satellite System. ESA. https://www.esa.int/Applications/Satellite_navigation/Galileo
European Space Agency. (2024, December 16). ESA to support the development of EU’s secure communication satellites system [Press release]. https://www.esa.int/About_Us/Corporate_news/ESA_to_support_the_development_of_EU_s_secure_communication_satellites_system
Foust, J. (2024, December 16). Europe signs contracts for IRIS² constellation. SpaceNews. https://spacenews.com/europe-signs-contracts-for-iris%C2%B2-constellation/
General Court of the European Union. (2025, September 3). Latombe v. Commission (Case T-553/23). https://curia.europa.eu/juris/liste.jsf?num=T-553/23
HM Revenue & Customs. (2024). Enterprise Investment Scheme, Seed Enterprise Investment Scheme and Social Investment Tax Relief statistics. HM Government. https://www.gov.uk/government/statistics/enterprise-investment-scheme-seed-enterprise-investment-scheme-and-social-investment-tax-relief-may-2024/enterprise-investment-scheme-seed-enterprise-investment-scheme-and-social-investment-tax-relief-statistics-2024
International Association of Privacy Professionals. (2025, October). Schrems addresses emerging questions around EU-US Data Privacy Framework. IAPP. https://iapp.org/news/a/schrems-addresses-emerging-questions-around-eu-us-data-privacy-framework
International Association of Privacy Professionals. (2026, June 16). The Anthropic episode: Probably a security challenge in need of governance, certainly not Europe’s kill switch. IAPP. https://iapp.org/news/a/the-anthropic-episode-probably-a-security-challenge-in-need-of-governance-certainly-not-europe-s-kill-switch
Investment & Pensions Europe. (2025, April). Germany sees private pensions decline while parties’ reform plans diverge. IPE. https://www.ipe.com/news/germany-sees-private-pensions-decline-while-parties-reform-plans-diverge/10128898.article
Land Schleswig-Holstein. (2025, December 4). LibreOffice ersetzt Microsoft: Schon fast 80 Prozent der Arbeitsplätze auf quelloffene Office-Lösung umgestellt [Press release]. https://www.schleswig-holstein.de/DE/landesregierung/ministerien-behoerden/I/Presse/PI/2025/cds/251204_cds_open-source
Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et à réguler l’espace numérique (SREN). (2024). Journal Officiel de la République Française. https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000049563368
Meyer, D. (2026a, June 15). US Anthropic export controls sparks sharp EU reaction. Information Security Media Group. https://www.bankinfosecurity.com/us-anthropic-export-controls-sparks-sharp-eu-reaction-a-31972
Meyer, D. (2026b, June 29). Austria urges Anthropic to move to EU to avoid US controls. Information Security Media Group. https://www.bankinfosecurity.com/austria-urges-anthropic-to-move-to-eu-to-avoid-us-controls-a-32106
Microsoft. (2025, April 30). Microsoft’s European digital commitments. Microsoft On the Issues. https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/
Mistral AI. (2025, September 9). Mistral AI raises 1.7B€ to accelerate technological progress with AI [Press release]. https://mistral.ai/news/mistral-ai-raises-1-7-b-to-accelerate-technological-progress-with-ai
Newman, L. H. (2026, May 4). DHS demanded Google surrender data on Canadian’s activity, location over anti-ICE posts. WIRED. https://www.wired.com/story/dhs-demanded-google-surrender-data-on-canadians-activity-location-over-anti-ice-posts/
OVHcloud. (2025, March 31). OVHcloud announces the SecNumCloud 3.2 qualification of its Bare Metal Pod cloud platform [Press release]. https://corporate.ovhcloud.com/en/newsroom/news/secnumcloud-qualification-bare-metal-pod/
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). (2024). Official Journal of the European Union, L 168/1. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal of the European Union, L, 24 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj
Sacra. (2026). Mistral AI revenue, funding & news. Sacra. https://sacra.com/c/mistral/
SEMI Europe. (2025, November). European Chips Act investment tracker. SEMI Europe. https://www.semi.org/
Sénat français. (2025, June 10). Audition de M. Anton Carniaux, directeur des affaires publiques et juridiques, et de M. Pierre Lagarde, directeur technique du secteur public, de Microsoft France [Commission d’enquête sur les coûts et les modalités effectifs de la commande publique]. Sénat de la République française. https://www.senat.fr/actualite/commande-publique-audition-de-microsoft-5344.html
SiliconANGLE. (2026, February 24). Edge AI chip startup Axelera AI raises $250M+ funding round. SiliconANGLE. https://siliconangle.com/2026/02/24/edge-ai-chip-startup-axelera-ai-raises-250m-funding-round/
Synergy Research Group. (2025, July 24). European cloud providers’ local market share now holds steady at 15%. Synergy Research Group. https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15
TechCrunch. (2026a, April 24). Cohere acquires, merges with Germany-based startup to create a “transatlantic AI powerhouse”. TechCrunch. https://techcrunch.com/2026/04/24/cohere-acquires-merges-with-german-based-startup-to-create-a-transatlantic-ai-powerhouse/
TechCrunch. (2026b, June 26). OpenAI limits GPT-5.6 rollout after government request, says restrictions shouldn’t be the norm. TechCrunch. https://techcrunch.com/2026/06/26/openai-limits-gpt-5-6-rollout-after-government-request-says-restrictions-shouldnt-be-the-norm/
The Register. (2026a, February 18). Microsoft throws spox under the bus in ICC email flap. The Register. https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/
The Register. (2026b, June 15). US clampdown on Anthropic models sends EU sovereignty surge into overdrive. The Register. https://www.theregister.com/ai-and-ml/2026/06/15/us-clampdown-on-anthropic-models-sends-eu-sovereignty-surge-into-overdrive/5255487
WilmerHale. (2025, December 1). European Court of Justice to review challenge to EU-U.S. Data Privacy Framework. WilmerHale Privacy and Cybersecurity Law Blog. https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework
White & Case LLP. (2026, March 26). Regulating space: A closer look at the proposed EU Space Act. White & Case Insights. https://www.whitecase.com/insight-our-thinking/regulating-space-closer-look-proposed-eu-space-act
Xinhua. (2025, May 21). Microsoft email block of ICC prosecutor fuels Dutch alarm over U.S. tech dependence. Xinhua News Agency. https://english.news.cn/