EU in Practice

You send an email, save a document, open a school platform, retrieve a patient record or ask an AI assistant to summarise the report you absolutely intended to read yourself. The action takes seconds and feels almost weightless. Yet underneath it sits a technological system of remarkable physical and political complexity: software libraries, operating systems, cloud platforms, data centres, processors, cables, cooling systems, electricity grids, licensing agreements, standards, suppliers and global supply chains. What appears on the screen as a simple click is, underneath, an elaborate choreography of infrastructure.

This is one of the peculiar achievements of modern digital technology. The better it works, the less of it we see. Electricity once arrived with visible power stations and telephones with wires running down the street. Cloud computing managed something more impressive: it persuaded us that industrial-scale computing infrastructure had become meteorological. Our files were suddenly “in the cloud”, as though spreadsheets and medical databases had evaporated gently into the atmosphere rather than being stored inside vast buildings full of machines that require land, water, chips, cooling equipment and a considerable amount of electricity.

That illusion is becoming harder to maintain, and Europe has noticed.

On 3 June 2026, the European Commission presented its European Technological Sovereignty Package, bringing together four major initiatives: Chips Act 2.0, the proposed Cloud and AI Development Act, a new EU Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy. The Commission describes them as interconnected measures stretching across the technology value chain, from semiconductors and infrastructure to software, cloud and artificial intelligence.

At first sight, it looks like the sort of policy bundle that could keep several Brussels conference rooms occupied for years without ever troubling an ordinary laptop user. Semiconductors belong to industrial policy, cloud infrastructure to IT departments, open source to software communities, and electricity grids to energy ministries. Put them together, however, and something much more interesting appears. Europe is beginning to treat the digital world not merely as a market to regulate, but as an infrastructure on which political and economic agency increasingly depends.

The question underneath the package is therefore much larger than whether Europe can produce more chips or host more servers. It is this: how much control must a society retain over the technological systems on which it depends in order to remain capable of making meaningful choices?

Europe Has Become Very Good at Governing Technology. That Is Not the Same as Controlling It.

Over the past decade, the European Union has built perhaps the world’s most ambitious framework for governing the digital economy. The GDPR changed the global language of data protection. The Digital Markets Act challenged the power of technological gatekeepers. The Digital Services Act created new obligations around large online platforms. The AI Act established a risk-based framework for artificial intelligence. The Data Act, Data Governance Act, Cyber Resilience Act and Interoperable Europe Act have added further layers to a regulatory architecture that is now studied well beyond Europe.

This has given the EU considerable regulatory power. Companies wishing to operate in the European market must often adapt to European rules, and the size of that market means those rules can influence practices elsewhere. For years, this phenomenon has been described through the “Brussels effect”: Europe may not dominate every technology, but it can exert influence by setting the conditions under which technology enters its market.

The Technological Sovereignty Package suggests that Brussels increasingly understands the limit of that model. Rules can determine what a cloud provider is permitted to do, but rules alone do not create an alternative cloud provider. Regulation can require data portability, but it cannot automatically give a hospital the technical capacity to migrate thousands of systems. Europe can regulate advanced AI while still depending heavily on computing infrastructure and processors supplied by companies headquartered elsewhere. It can create sophisticated rights around digital systems while lacking sufficient alternatives if the owners of those systems change their commercial or geopolitical calculations.

There is, in other words, a difference between being sovereign over the rules and being sovereign enough to act.

The Commission now defines technological sovereignty partly as Europe’s ability to develop and control key technologies, data and infrastructure while reducing excessive reliance on non-EU providers. That concern also appears to have considerable public support. In the 2026 Digital Decade survey, 85% of Europeans supported investment in EU-developed digital infrastructure and 82% favoured reducing dependence on non-EU suppliers.

This does not mean that Europe has suddenly discovered protectionism or decided that every useful technology should acquire twelve stars and a .eu domain. The more serious question is about capacity. A political community may remain deeply interconnected with the rest of the world while ensuring that critical dependencies do not become points of paralysis.

That distinction matters because dependence is not necessarily weakness. The modern economy is constructed from dependencies. Weakness appears when dependence becomes asymmetric, opaque and difficult to reverse.

Perhaps Sovereignty Is Really About Optionality

There is a useful idea from finance that rarely appears in debates about digital sovereignty: option value. An option is valuable even when you do not intend to use it, because it preserves the ability to respond if circumstances change. The possibility of leaving a supplier, switching technology, sourcing a component elsewhere or operating a system differently has value long before anybody actually wants to exercise it.

That may be one of the most useful ways to think about Europe’s technological sovereignty.

Imagine a municipality whose entire administrative infrastructure runs through one vendor. The arrangement may work perfectly well. The supplier may be reliable, the price acceptable and the software familiar. For years, there may be no reason to change anything. Gradually, however, databases, document systems, authentication tools, workflows, staff practices and specialist knowledge become organised around that ecosystem. The cost of leaving rises certainly and invisibly.

Then something changes. Prices increase. A product is discontinued. Licensing conditions become less favourable. An acquisition changes the supplier’s strategy. A service becomes subject to legal obligations in another jurisdiction. A cybersecurity concern emerges. Suddenly, the theoretical possibility of moving elsewhere has to confront the practical reality of doing so.

At that point, sovereignty is no longer an abstract discussion about where a server happens to be located. It becomes brutally operational. Can the organisation retrieve its data in usable formats? Can competing services interpret those formats? Are open standards available? Are staff capable of managing the migration? Can another supplier take over without rebuilding the entire system? Does the organisation even know which dependencies exist beneath the applications its employees use every day?

The proposed Cloud and AI Development Act reflects this more sophisticated understanding. It introduces an EU-wide framework for assessing different degrees of cloud and AI sovereignty, considering not merely physical location but issues such as control, independence from third-country influence, software-supply-chain transparency and resilience. The Commission also links technological sovereignty to procurement, interoperability and open-source alternatives.

That is important because European location is not automatically European control. Moving a server from Virginia to Frankfurt may improve some things enormously, but it does not by itself resolve every dependency embedded in the ownership, software, contractual structure or supply chain surrounding that server.

A credible exit can therefore be as important as domestic ownership. Indeed, one of the best indicators of power in a relationship is often whether either party can realistically walk away.

The Stack Is the Strategy

The four components of the Commission’s package make much more sense when we stop looking at them horizontally as separate policy initiatives and instead look vertically at the technological stack.

Start with an ordinary cloud application. The application depends on software. The software runs on cloud infrastructure. The infrastructure lives inside data centres. Those data centres contain servers and specialised computing equipment. Those machines depend on semiconductors. Their operation depends on electricity, cooling systems, network infrastructure and physical resources. Artificial intelligence intensifies several of these dependencies simultaneously because advanced models require enormous quantities of computing power.

Once seen this way, Europe’s package becomes less mysterious. Chips Act 2.0 addresses one layer. The Cloud and AI Development Act addresses another. The Open Source Strategy reaches into the software layer, while the energy roadmap confronts the physical system supporting the entire structure.

The Commission itself describes the initiatives as mutually reinforcing across the value chain. That matters because technological sovereignty is only as resilient as the relationships between these layers. Owning a data centre is of limited strategic value if it cannot obtain the advanced chips it requires. Producing chips is insufficient if Europe lacks competitive cloud infrastructure capable of using them. Building AI computing capacity becomes meaningless without access to electricity. Open-source software cannot provide meaningful alternatives if nobody has the expertise or resources to maintain it.

The digital economy therefore begins to resemble older forms of infrastructure more than we sometimes admit. In the nineteenth and twentieth centuries, governments understood perfectly well that railways, ports, telegraph lines, energy networks and industrial capacity were not simply commercial assets. They shaped what a country could move, produce, communicate and defend. Infrastructure created possibilities and dependencies simultaneously.

The cloud did not abolish that political economy. It merely gave it better branding.

Chips: Europe Does Not Need to Make Everything, but It Cannot Afford to Know Nothing

Semiconductors provide perhaps the clearest example of the difference between independence and resilience. Chips sit inside almost every strategic sector modern Europe cares about: telecommunications, vehicles, medical equipment, industrial machinery, defence systems, energy infrastructure, cloud computing and artificial intelligence.

Yet Europe’s share of the global semiconductor market remains around 9%, well below its Digital Decade ambition of reaching 20% by 2030. The first European Chips Act, adopted in 2023, nevertheless helped mobilise more than €52 billion in public and private investment and is estimated by the Commission to have created around 46,000 direct and indirect jobs. Chips Act 2.0 now seeks to strengthen both advanced and mainstream semiconductor capacity, support design capabilities, increase European demand and reduce vulnerabilities in critical supply chains.

The obvious temptation is to translate semiconductor sovereignty into a simple numerical objective: Europe should produce a larger percentage of the world’s chips. But semiconductor production is one of the most internationally fragmented industrial systems humans have ever created. Chip architecture, design software, lithography equipment, specialist chemicals, fabrication, memory, packaging and testing are concentrated in different companies and regions. Some parts of the chain are extraordinarily difficult to reproduce.

Technological sovereignty therefore cannot sensibly mean reconstructing the entire semiconductor ecosystem behind a European border. The more useful question is where the absence of European capacity would become strategically dangerous. Europe needs enough capability to understand the technology, shape its development, maintain leverage in international supply chains and prevent the disappearance of alternatives in areas essential to its economy and public infrastructure.

This is the first place where slogans fail. “Made in Europe” sounds reassuring. A resilient semiconductor strategy is much less photogenic: it requires knowledge of supply-chain bottlenecks, investment horizons, specialised skills, energy requirements, customer demand and the awkward reality that genuine resilience often depends on carefully managed international interdependence rather than self-sufficiency.

The Cloud Is Becoming Ordinary Infrastructure

The cloud layer is already much closer to ordinary European life. In 2025, 52.7% of EU enterprises purchased cloud-computing services, up from just 17.8% in 2014. Among companies using paid cloud services, 85% used them for email, around 72% for office software and another 72% for file storage. For large businesses, overall cloud adoption had reached 85%.

Those numbers are revealing because they show how quickly cloud infrastructure has moved from technological novelty to organisational plumbing. Email, document storage, databases, accounting, customer management and increasingly AI functionality now depend on systems that many organisations neither own nor meaningfully understand.

This is not inherently a problem. Cloud services offer enormous advantages. A small company no longer needs to build its own data centre to access sophisticated computing infrastructure. Universities can scale research workloads. Public bodies can improve services without maintaining every component internally. Startups can acquire computing resources that once belonged only to large corporations.

The sovereignty question emerges because cloud markets also exhibit strong concentration and because switching away from complex ecosystems can become progressively harder. The Commission’s August 2026 study supporting CADA identifies both limited and geographically concentrated European computing capacity and continuing dependence on non-European cloud and AI suppliers as significant challenges. It also highlights lock-in practices, third-country laws with extraterritorial effects, constraints around energy and water, and the difficulty of expanding data-centre infrastructure.

CADA responds with an ambitious physical objective: the EU wants to at least triple its data-centre capacity within five to seven years, while simplifying permitting and improving access to land, energy, water and finance.

That sentence is worth pausing over. Discussions about digital sovereignty often sound as though they belong entirely to software policy. Yet Europe cannot become more capable in AI and cloud without deciding where large industrial facilities will be built, how they will connect to electricity networks, what resources they will consume and who will finance them.

Eventually, every cloud touches the ground.

AI Has Rediscovered the Electricity Grid

Artificial intelligence has made the physicality of digital infrastructure impossible to ignore. The International Energy Agency estimates that global data-centre electricity consumption reached around 485 terawatt-hours in 2025 and could approach 950 TWh by 2030, roughly doubling in five years. Consumption by AI-focused data centres is expected to grow considerably faster.

The numbers become stranger at machine scale. The IEA estimates that by 2027, a single advanced server rack could require peak power comparable to 65 households. Between 2020 and 2025, the power density of AI servers increased eleven-fold.

Europe is already feeling this transition. Data centres currently account for around 2.5% of EU electricity consumption, while installed capacity is expected to rise from roughly 12 GW in 2025 to around 28 GW by 2030. The Commission warns that data-centre demand is geographically concentrated and that individual new facilities can require connections comparable to major industrial sites.

This creates one of the more interesting paradoxes in Europe’s technology strategy. Artificial intelligence is being promoted partly because it may help optimise electricity networks, forecast demand, integrate renewable energy and improve industrial efficiency. At the same time, the infrastructure required to run AI is placing additional demands on those same electricity systems.

AI may help manage the grid. The grid must first survive the AI.

That circular relationship explains why a Strategic Roadmap for Digitalisation and AI in Energy belongs inside a technological-sovereignty package. It also tells us something important about the future of digital policy. The boundary between industrial policy, technology policy and energy policy is disappearing. Europe cannot plan an AI economy without simultaneously planning transmission capacity, electricity generation, transformers, cooling, land use and grid connections.

The same transition occurred during earlier industrial revolutions. Factories changed the demand for coal and transport. Electrification reorganised cities and industry. Motorisation required roads, oil infrastructure and new forms of urban planning. Artificial intelligence may appear on our screens as software, but its expansion increasingly resembles a heavy-industrial transition occurring behind a user interface.

This Is Why Open Source Has Suddenly Become Strategic

Among the four initiatives, the EU Open Source Strategy may initially seem like the odd one out. Chips and data centres are obviously strategic assets. Open-source software still carries a cultural association with programmers, collaborative communities and repositories whose names most citizens will never encounter.

Yet open source already sits beneath an extraordinary amount of the digital economy. Web servers, operating systems, programming languages, cryptographic libraries, databases, networking technologies, cloud infrastructure and development tools depend extensively on openly developed components. Much of the apparently proprietary digital world is built on foundations that are not proprietary at all.

Europe has known for some time that this has economic significance. A Commission study published in 2021 estimated that EU companies invested roughly €1 billion in open-source software in 2018, producing an economic impact estimated between €65 billion and €95 billion. The same study modelled that a 10% increase in contributions to open-source software could generate between 0.4% and 0.6% additional EU GDP annually under its assumptions, alongside more than 600 additional ICT startups.

Those figures are older than the current package and should not be treated as a real-time valuation of Europe’s open-source economy. Their importance lies elsewhere: they show that open source was already economically substantial long before European policy began discussing it primarily through the language of sovereignty.

The strategic attraction is straightforward. Open code can be inspected. It can often be adapted. Multiple companies can provide services around it. Standards and interfaces can be more transparent. Knowledge does not necessarily disappear when one vendor withdraws a product. In principle, open-source ecosystems can make technological systems more contestable.

And contestability is closely related to the optionality we encountered earlier.

If five companies can maintain, host or extend a technology, the relationship between customer and supplier looks very different from a system in which only the original vendor possesses the knowledge and legal authority required to operate it. Open source therefore matters not because it makes Europe technologically pure, but because it can preserve the possibility of alternatives.

This is an important distinction. Some of the world’s most successful open-source projects are profoundly global. Their contributors, users and maintainers cross political borders constantly. Open source is not inherently European, and attempting to turn it into a form of digital nationalism would miss much of its value.

What open source can provide is distributed technological agency.

The Maintenance Problem Nobody Puts on the Poster

There is, however, an uncomfortable problem hiding inside the enthusiasm for open alternatives. Access to code is not the same thing as the capacity to sustain it.

Software has to be maintained. Security vulnerabilities have to be repaired. Dependencies need to be monitored. Documentation must be written. New hardware and operating systems have to be supported. Someone needs to answer questions from users who have somehow managed to configure the system in a way nobody believed technically possible.

The entire modern digital economy contains critical components maintained by relatively small communities. This creates a peculiar mismatch between social dependence and economic visibility. Infrastructure can be essential while the people maintaining it remain poorly funded because the infrastructure is most valuable precisely when nobody notices it.

There is a parallel here with bridges, drainage systems and electricity networks. Maintenance rarely produces political excitement. Opening a new bridge attracts cameras; inspecting the bolts for twenty years does not. Yet infrastructure usually fails because societies neglect maintenance, not because they forgot how to cut ribbons.

Open-source infrastructure faces the same problem. Europe’s new strategy recognises this more clearly than previous approaches, proposing measures around long-term sustainability, security, public-sector competence and maintenance.

This may prove more consequential than encouraging public administrations simply to “use open source”. Without skilled people, institutional knowledge and sustainable funding, open code can become another form of dependency. Europe could theoretically replace reliance on a multinational software company with reliance on a small group of chronically overworked maintainers and then declare the exercise a victory for sovereignty.

The real objective has to be deeper: Europe must become capable not merely of accessing important technologies, but of understanding, maintaining and developing them.

That is a much more demanding form of sovereignty.

The Invisible Power of Procurement

If open source provides potential alternatives, public procurement may determine whether those alternatives ever become strong enough to matter.

This sounds considerably less exciting than semiconductors or artificial intelligence, which is probably why it deserves more attention.

Most of the time, digital lock-in doesn’t show up through a dramatic geopolitical decision. More often it accumulates through years of perfectly rational procurement choices. A ministry buys the software its employees already know. A municipality renews the contract because migrating would be expensive. A school chooses the platform used by neighbouring schools. Additional systems are then integrated around that original decision. Staff are trained. Data accumulates. Contractors specialise. Five years later, switching is technically possible but organisationally terrifying.

Economists call this path dependence: early choices influence the range of choices that remain practical later. Technology markets are particularly susceptible because standards, skills, data formats and network effects can amplify the consequences of apparently small decisions.

This is where digital sovereignty becomes less about heroic European inventions and more about procurement clauses nobody will ever frame on a wall.

Does the contract require usable data export? Are open standards supported? Are interfaces documented? Can another provider assume operation of the system? Does the organisation retain access to necessary technical knowledge? How are switching costs assessed? Is the cheapest offer today still the cheapest offer once ten years of dependency are included?

The new European initiatives increasingly recognise procurement as an industrial-policy tool. CADA proposes common procurement mechanisms for public administrations, while the Open Source Strategy specifically addresses procurement guidance and public-sector adoption.

This is important because markets do not produce alternatives merely because policymakers wish alternatives existed. European providers need customers, scale and predictable demand. Open-source ecosystems need organisations willing to procure services around them. Smaller technological actors need interoperability rules that prevent incumbents from turning existing market share into permanent architecture.

A sovereign technology policy therefore has to care about buying boring things well.

Sovereignty Is Not Autarky

None of this means Europe should attempt to build a sealed digital economy.

Technological autarky would be both unrealistic and undesirable. Modern semiconductor production relies on international specialisation. Scientific research depends on global exchange. Open-source communities are international by design. European companies benefit enormously from technologies developed elsewhere, just as companies elsewhere benefit from European research, equipment, standards and markets.

The problem is not foreign technology. The problem is unavoidable dependency without adequate counterweight.

There is a crucial difference between interdependence and helplessness. In an interdependent system, participants need one another and possess enough alternatives, expertise or bargaining power to prevent one relationship from becoming absolute. In a helpless system, one side discovers that the other can change the conditions while it has nowhere meaningful to go.

This is why technological sovereignty should not be measured simply by counting European companies or calculating the percentage of infrastructure physically located on European soil. A genuinely sovereign system could include non-European suppliers while remaining resilient because standards are open, services are substitutable, skills are distributed, procurement preserves competition and critical capabilities exist inside Europe.

Conversely, a system filled with European flags could remain remarkably fragile if it depends on a handful of irreplaceable suppliers.

The deeper goal is not independence from everyone. It is freedom of action within interdependence.

The Most Interesting Test Is Whether Europe Can Say No

Seen in this light, the European Technological Sovereignty Package is not really four initiatives. It is an attempt to construct a more complete theory of digital power.

Chips matter because computing requires physical components. Cloud matters because digital economies increasingly rent rather than own computing infrastructure. AI matters because access to computation is becoming an economic capability in its own right. Energy matters because computation ultimately depends on electricity. Open source matters because knowledge, inspectability and substitutability influence who can control and maintain the systems connecting all the other layers.

The package will therefore deserve to be judged by more than the amount of investment it mobilises or the number of data centres Europe builds. Those indicators matter, but the more revealing tests will be practical.

Can a European public administration change a critical supplier without years of disruption? Can European companies obtain advanced computing capacity on conditions that preserve meaningful choice? Can hospitals and schools understand where their most sensitive digital dependencies sit? Can European firms participate in strategic layers of the semiconductor value chain strongly enough to preserve bargaining power? Can governments identify and sustain the open-source components embedded in critical systems? Can the electricity system accommodate rapidly growing digital infrastructure without transferring its costs and vulnerabilities elsewhere?

Ultimately, can Europe say no when saying yes is no longer in its interest?

That may be the most useful definition of sovereignty in the entire debate.

A choice is meaningful only if declining one option does not make participation in modern society impossible.

Looking Under the Floorboards

This brings us back to the question we have been exploring in The Code Beneath the Floorboards.

For a small organisation selecting software, the immediate questions tend to be practical. Does the platform work? How much does it cost? Will staff understand it? Does it integrate with existing systems? Those are sensible questions, but they are questions about the present.

The more consequential questions concern the future. What happens if the supplier changes? Can the data move? Who understands the technology? Can another provider maintain it? Are there alternatives? What disappears if the organisation stops paying? Which dependencies have been created by today’s convenience?

Europe is now asking exactly the same questions at extraordinary scale.

That is why the 3 June package matters beyond Brussels. It suggests that digital sovereignty is beginning to mature from a political slogan into a discussion about architecture, capabilities and choices. The interesting part is not whether Europe can manufacture every chip, host every service or produce a European equivalent of every successful technology elsewhere. It cannot, and it should not try.

The more credible ambition is to ensure that Europe retains enough knowledge, infrastructure, supplier diversity, open technology, industrial capacity and interoperability that dependency does not quietly become powerlessness.

This is a less dramatic vision of sovereignty than technological independence. It is also much harder to achieve. It requires investment, but also maintenance. Competition, but also standards. Open software, but also people capable of sustaining it. European infrastructure, but also global partnerships. Regulation, but also industrial capacity. And perhaps most importantly, it requires institutions to think about exit before they urgently need one.

The next time you save a file to the cloud, nothing geopolitical will appear to happen. The document will disappear behind a familiar icon, the interface will reassure you that everything has been saved, and most of the technological stack underneath will remain invisible.

But that stack increasingly determines who can build, who can compete, who can change direction and who has to accept the conditions offered by somebody else.

Digital sovereignty begins when we stop admiring the interface and start asking what lies underneath it.

Europe does not need to own every floorboard. But it does need to understand what the house is standing on, which parts it can repair, and whether the doors still open from the inside.

Want more posts like this? Subscribe to REDefine Weekly Newsletter.