Less than a month ago, I published an article on the simplification measures introduced by the “Digital Omnibus on AI” — a package adopted amid intense concern from European digital industry players about the practical challenges of implementing the AI Act and its negative impact on Europe’s capacity to develop AI. I noted that while the text adopted on May 7th sent a positive signal, it would take real political will and commensurate resources to follow through. I concluded with: “The Tech Sovereignty Package will be the next signal. Watch closely.”
That long-awaited package was finally presented by the Commission on June 3, 2026. It brings together four initiatives: a revision of the Chips Act (Chips Act 2.0), the Cloud and AI Development Act (CADA), an open-source software strategy, and a roadmap for the digitalisation of the energy sector.
While this package represents a genuine step forward — the first time Europe has moved from a regulatory logic to something resembling an offensive industrial policy — several dimensions of digital sovereignty remain only partially addressed.
Let us examine what the Tech Sovereignty Package resolves, what it does not, and what still needs to be built.
The Four Pillars of the Package
Chips Act 2.0: A Welcome Paradigm Shift
The original 2023 Chips Act mobilised €52 billion in public and private investment but fell short of its goal of relocating 20% of global semiconductor production to Europe. The continent still accounts for only around 10% of global semiconductor output, and Intel cancelled its planned €30 billion mega-factory in Magdeburg last year — despite €9.9 billion in promised German subsidies.
Subsidising production is not enough when demand is not guaranteed. Chips Act 2.0 therefore pivots toward demand — underwriting purchases and creating guaranteed industrial offtake — alongside faster permitting procedures. This is a meaningful methodological shift.
The text also introduces crisis powers. The Commission would now be able to force chipmakers to prioritise orders for critical products in short supply, override existing contracts, purchase chips centrally on behalf of Member States, and levy fines of up to €300,000 for concealing information about supply chain capacity.
The Cloud and AI Development Act (CADA): A Modular, Legally Enforceable Sovereignty Framework
This is probably the most innovative instrument in the package. The CADA introduces a sovereignty framework called SEAL (Sovereignty Effectiveness Assurance Levels), defining five levels: from SEAL-0 (no sovereignty, exclusive control by non-European third parties) to SEAL-4 (technologies and operations entirely under European control, subject only to EU law, with no critical external dependency).
This framework transforms the concept of “digital sovereignty” into a legally enforceable criterion in public procurement. While it does not formally exclude American companies, they will structurally struggle to attain the higher SEAL levels due to the US Cloud Act, which allows US law enforcement to access data held by American companies regardless of where it is stored.
The CADA also aims to streamline data centre deployment conditions across Europe, support R&D in advanced and sustainable cloud and AI technologies, and integrate data centre energy consumption into European energy planning. This last point is more significant than it appears: the energy constraint will likely be the defining variable in Europe’s computational capacity by 2030.
The Open-Source Strategy: Digital Commons Finally Formalised
The third pillar addresses a domain too often overlooked in analysis: the governance of open-source contributions to software and operating systems. Europe has nearly 25 million developers who generated over 155 million contributions to public projects in a single year. Yet the commercial value of this massive output is overwhelmingly captured by large non-European companies, who “package” open-source code into proprietary products.
The open-source strategy formalises the concept of European “digital commons”, positioning free software as critical public infrastructure for sovereignty, democratic resilience and cybersecurity. This is an important conceptual reframing — though the dedicated resources remain to be specified.
Digitalising the European Energy Sector
Digitalising the European energy sector is the fourth pillar of the package — and more urgent than it may seem. Rising energy prices are weighing on industrial competitiveness and household budgets, while the expansion of digital infrastructure across Europe will drive up electricity demand and require rapid modernisation of production capacity. Without adequate energy capacity, Europe risks applying rules to technologies conceived, developed, hosted and operated elsewhere.
The strategic roadmap for digitalisation and AI in the energy sector addresses both dimensions, explaining how AI and digital technologies can support this transformation. These solutions can ensure the sustainable integration of digital infrastructure into the energy system, while helping to make that system more efficient. Smart meter deployment — essential for giving European consumers greater control over their consumption — is also a stated priority.
Will the Tech Sovereignty Package Reduce the €264 Billion in Annual Digital Spending Flowing to the United States?
Before going further, it is worth stating the figure that gives the full measure of the problem.
According to a study by Asterès for Cigref published in April 2025, 80% of European organisations’ spending on professional software and cloud services goes to American companies — amounting to €264–265 billion per year leaving the European economy. This is comparable to the EU’s annual energy bill (€360 billion in 2024). Nicolas Bouzou, director of Asterès, puts it bluntly: “€140 billion extracted each year from European companies in a position of dependency, and partly removed from our investment capacity: it is almost like a tax that dare not speak its name.”
What these €264 billion represent concretely:
- Approximately 2 million direct, indirect and induced jobs created in the United States through European digital purchases.
- An average annual price increase of +8.7% over the past three years, with a forecast of +12% per year over the next five — with European organisations unable to negotiate: dependency creates captivity.
- At this rate, cumulative outflows could exceed €421 billion by 2035 — a US digital bill larger than the entire EU multiannual budget over the same period.
The Asterès study is strictly limited to cloud and professional software. It excludes hardware, terminals, operating systems, security components, and purchases by households or public administrations. The true scale of European digital dependency is therefore structurally higher.
Asterès modelled three progressive re-appropriation scenarios:
- Scenario 1 (5% redirected immediately): 178,000 additional jobs in Europe, €9 billion in annual added value preserved.
- Scenario 2 (10% redirected by 2030): 321,000 additional jobs.
- Scenario 3 (15% redirected by 2035): 463,000 additional jobs and a productivity gain equivalent to +1.2% of overall EU productivity.
Even a partial reorientation of purchases can create substantial macroeconomic effects — provided that credible European alternatives exist at the required scale.
A Major Step Toward Reclaiming Digital Sovereignty — But With Significant Gaps That Must Be Addressed
The Tech Sovereignty Package concentrates most of its ambition on semiconductors and cloud — two essential upstream layers of the digital value chain. Yet digital sovereignty is a complete stack, encompassing many downstream layers that the Commission’s proposal does not yet fully address.
Terminals: The Most Visible Blind Spot
The question must be asked directly: on what terminal will the European AI catalysed by CADA actually run? On a smartphone assembled in Asia, powered by an ARM processor, running iOS or Android. On a laptop whose essential components — CPU, memory, display — are manufactured outside Europe.
Europe has had no global-scale mobile phone manufacturer since the end of Nokia’s smartphone business, sold to Microsoft in 2013. It has no PC manufacturer with significant global consumer market presence. It is entirely dependent on terminal ecosystems controlled by non-European actors, who set the rules for market access, application distribution and data collection.
A sovereign cloud accessible through a non-sovereign terminal is sovereignty in name only. The package does not address this. It is its first blind spot.
Operating Systems: The Most Structural Layer — Partially Addressed, Insufficiently Funded
Above the hardware sits the most powerful software layer: the operating system. Windows, macOS/iOS, Android, ChromeOS. These four systems control the vast majority of devices used across Europe.
The open-source strategy within the Tech Sovereignty Package does explicitly cite operating systems among its priority domains. It aims to support secure open-source alternatives for public services, position administrations as embedded open-source users and contributors, and integrate sovereignty as a criterion in public digital investment decisions. This is a genuine signal — an official acknowledgement that dependency on non-European proprietary OS is a strategic problem.
But the envelope dedicated to the entire open-source strategy stands at €2 billion over seven years, spread across a very wide perimeter spanning OS, AI, cybersecurity and semiconductors. This will not be enough to close the €264 billion annual dependency gap identified by Asterès. For comparison, Microsoft alone invests more each quarter in Windows development.
National initiatives exist and point in the right direction — Linux deployments in German Länder, open-source software experiments in French ministries — but they remain disconnected from a European industrial strategy backed by commensurate resources. The open-source strategy sets the right diagnosis and the right objectives. It still awaits its funding.
Security and Cryptography: The Trust Layer
Digital sovereignty also depends on the ability to secure data and communications autonomously. This requires hardware security components (TPM, HSM, secure enclaves), controlled cryptographic libraries and encryption standards whose design is transparent.
Europe has real assets here: companies such as Thales, Atos, and cybersecurity players including Airbus CyberSecurity, Sekoia, Tehtris, Pradeo and Harfang Lab. But the ecosystem remains fragmented, underfunded relative to its American and Israeli counterparts, and undervalued in public procurement strategies. Dependence on American solutions (Palo Alto, Cisco, CrowdStrike) remains massive in large European companies and administrations.
The CADA addresses security as a cloud sovereignty criterion. But it does not propose a systemic strategy for cybersecurity as a sovereignty layer in its own right.
Networks and Connectivity: A Layer Already Largely Addressed by Other Instruments
Digital sovereignty also rests on physical networks: the submarine cables carrying 99% of global internet traffic; mobile network equipment (5G, soon 6G); communication satellites and the non-terrestrial networks now converging with terrestrial infrastructure through 5G.
Unlike terminals and operating systems, the network and connectivity layer is where Europe’s legislative and industrial arsenal is most advanced. The Tech Sovereignty Package is not the primary vehicle here, because a dedicated instrument already exists: the Digital Networks Act, presented in January 2026, modernises the entire framework for European digital networks — fibre, standalone 5G, edge, cloud-network integration — and explicitly protects critical infrastructure including submarine cables against sabotage.
On submarine cables specifically, Europe has an industrial asset that is rarely cited: Orange Marine. With 15% of the global fleet of cable-laying ships, over 288,000 kilometres of fibre optic cables laid across every ocean, and two new vessels under construction that will give it the world’s most modern maintenance fleet, Orange Marine is a genuine sovereignty asset — a global top 3-4 player alongside Alcatel Submarine Networks (Nokia). Europe is not starting from scratch on this layer.
The real blind spots remain dependency on submarine amplification and routing equipment — heavily concentrated among American and Asian players — and the growing dominance of US tech giants investing massively in their own proprietary cables, bypassing traditional operators. These are the points requiring strategic vigilance.
AI Models: The Decisive Application Layer — and the Package’s Most Worrying Silence
This is where the Tech Sovereignty Package’s limitations are most salient and most strategically costly.
The package presents itself as the road to an “AI continent”. It funds the underlying infrastructure — chips, cloud, data centres. It does not directly fund what gives that infrastructure its value: AI models themselves. Yet it is models that determine who controls the applicative layer of artificial intelligence. And on this front, the gap is staggering.
The numbers are unambiguous. The United States produced over 50% of significant AI models globally in 2025, against 6% for Europe (Stanford HAI). The four American giants — Google, Microsoft, Amazon, Meta — collectively invested $320 billion in AI infrastructure in 2025, equivalent to 16 times the total envelope the EU has planned for its gigafactories. Three American players alone capture nearly two thirds of the European cloud market: AWS (32%), Azure (24%), Google Cloud (12%). Forrester judges that no European company will fully migrate away from American hyperscalers in 2026 — not for lack of will, but for lack of credible alternatives at the required scale.
Reversing this trend depends on a condition the package does not directly address: the availability of high-quality European-language training data at the scale needed to compete with American and Chinese corpora.
Complementary initiatives do exist outside the package. The Frontier AI Grand Challenge, launched by the EU and EuroHPC in February 2026, funds a competition to develop a sovereign European frontier model leveraging existing supercomputers. The call for proposals for InvestAI gigafactories — approximately €20 billion for four to five 100,000-chip sites — is now expected for July 2026. Measured against the American dynamic, these European resources remain, for now, inadequate.
Building sovereign cloud infrastructure without massively funding the models that will run on it is like building motorways so that others can drive their lorries on them. The Tech Sovereignty Package lays the foundations. Funding European frontier models remains the most urgent missing piece.
Conclusion
Reclaiming digital sovereignty requires addressing the entire technology stack that creates value in this domain. Each layer depends on the others.
The Tech Sovereignty Package is a genuine step forward. It marks a shift in the Commission’s posture — moving resolutely from regulation toward the beginnings of an industrial policy. The Chips Act 2.0 crisis powers, the CADA’s SEAL framework, the formalisation of digital commons through open source — these are real instruments and real levers.
The package needs to be complemented by:
- A European Competitiveness Fund (€234 billion planned for 2028–2034) that must prioritise the digital sector with precise sectoral targets: terminals, OS, security, AI models — to give the Tech Sovereignty Package the means to match its ambition.
- A specific strategy for terminals and operating systems for sensitive public uses. No European state can currently manage a major crisis on infrastructure entirely controlled by third parties.
- An adapted M&A policy to allow European players to consolidate at global scale. Draghi said it. No one has done it yet.
- Deep capital markets to fund the next phase and rival the $285 billion raised in the United States in 2025 alone to finance AI.
The target set by Asterès for 2035 — redirecting 15% of cloud and software purchases toward European players — is ambitious but not utopian. It assumes that the conditions created between 2026 and 2030 have borne fruit: structuring European public demand, consolidated champions, and capital markets capable of financing the necessary scale.
As Vice-President Henna Virkkunen wrote in her op-ed published on June 3, 2026, “in a world where geopolitics and technology are inseparable”, where digital dependencies have become strategic dependencies on a par with energy and defence, Europe cannot afford sovereignty that varies by layer.
Technological sovereignty must guarantee Europe’s control over its critical technologies, infrastructure, data and strategic capabilities. The package presented by the Commission is a very important step in that direction. The expected leap forward still lies ahead.

