Europe has spent the last decade regulating the digital economy. Now it is trying to build the foundations needed to compete in it.
That is the real significance of the EU Tech Sovereignty Package. It is not just another Brussels policy file, nor simply a defensive reaction to the dominance of American and Chinese technology providers. It marks a deeper shift: Europe is moving from regulating digital power to trying to own, operate, govern and sustain more of the infrastructure behind it.
The European Commission presented the package on 3 June 2026 as a set of measures intended to strengthen Europe’s capacity in semiconductors, artificial intelligence, cloud and open source. The package includes two legislative proposals — the Chips Act 2.0 and the Cloud and AI Development Act — together with the EU Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy.
That structure matters. The package is not a single law. It is a coordinated attempt to address the whole digital stack: compute, chips, cloud, AI, open software, energy and public-sector demand.
In other words, sovereignty is no longer being treated as a legal slogan. It is becoming an architectural question.
What “tech sovereignty” really means
The Importance of the EU Tech Sovereignty Package
The European Commission defines tech sovereignty as Europe’s ability to act independently in the digital world by developing and controlling key technologies, data and infrastructure, while reducing reliance on non-EU providers.
That definition is important because it moves the conversation beyond a simplistic idea of data residency.
For years, many organisations reduced sovereignty to one question: where is the data stored? But modern digital dependency is more complex. Data location matters, but it is only one layer. The more difficult questions are:
Can Europe control the infrastructure?
Can public administrations switch providers without operational trauma?
Can sensitive workloads be governed under European legal and security expectations?
Can critical software be maintained sustainably?
Can AI systems be trained, deployed and audited without relying entirely on external platforms?
Can the energy system support the compute demand that AI sovereignty requires?
This is why the Tech Sovereignty Package is relevant far beyond policymakers. It matters to CIOs, CTOs, public-sector leaders, regulated industries, cloud providers, software vendors, infrastructure operators and anyone designing platforms that need to remain resilient under geopolitical pressure.
The four pillars of the package
At a practical level, the package rests on four major pillars.
1. Cloud and AI Development Act
The Cloud and AI Development Act, or CADA, is designed to increase Europe’s cloud and AI infrastructure capacity. According to the Commission, the proposal aims to at least triple the EU’s data centre capacity within the next five to seven years and fully meet the needs of EU businesses and public administrations by 2035. It also seeks to simplify data-centre deployment while linking expansion to sustainability and innovation criteria.
This is the hard-infrastructure side of sovereignty.
Europe cannot become an “AI continent” without compute. But compute is not abstract. It requires land, electricity, cooling, permitting, chips, networking, operational skills and capital. CADA recognises that AI strategy is meaningless if Europe does not have enough cloud and data-centre capacity to train, host and operate AI systems at scale.
The critical point is that CADA is not only about building more data centres. It is about shaping the conditions under which cloud capacity becomes strategically trustworthy for public administrations and highly critical use cases. The Commission explicitly links CADA with a proposed EU-wide cloud policy for public administrations and public procurement.
That means procurement will become a central sovereignty instrument.
2. Chips Act 2.0
The second pillar is the Chips Act 2.0. Its role is to strengthen Europe’s semiconductor ecosystem by supporting research, design, manufacturing capacity and supply-chain resilience.
This is essential because no sovereign AI or cloud strategy can exist without semiconductor capacity. AI depends on specialised chips. Cloud infrastructure depends on reliable supply chains. Defence, automotive, energy, healthcare and public services all depend on compute hardware that can be trusted, sourced and maintained.
The first European Chips Act was already a recognition that semiconductors are geopolitical infrastructure. Chips Act 2.0 pushes that logic further: without hardware sovereignty, software sovereignty remains fragile.
3. EU Open Source Strategy
The open-source pillar is perhaps the most interesting, because it changes the political status of open source.
For years, open source was often treated as a cost-saving tool, a developer preference or a licensing issue. The new strategy places it much closer to the centre of Europe’s sovereignty agenda. The Commission’s package explicitly includes the EU Open Source Strategy as one of its core components.
This reframes open source as digital commons: shared infrastructure that supports innovation, interoperability, transparency, cybersecurity and democratic resilience.
That is a subtle but important shift. If open source is strategic infrastructure, then it cannot be left to exhausted volunteer maintainers while large commercial actors extract most of the value. Europe’s challenge is to support open ecosystems without turning them into slow, over-regulated bureaucratic assets.
The Cyber Resilience Act already reflects part of this tension. It recognises “open-source software stewards” and subjects them to specific obligations, including cybersecurity policies, vulnerability handling and cooperation with market surveillance authorities.
This is the line Europe must walk carefully: secure the commons, but do not suffocate the communities that maintain them.
4. Strategic Roadmap for Digitalisation and AI in Energy
The fourth pillar is energy. This is where the package becomes brutally concrete.
AI sovereignty consumes electricity. Cloud sovereignty consumes electricity. Data-centre expansion consumes electricity. The Commission’s roadmap for digitalisation and AI in energy addresses both sides of the equation: the growing energy demand of digital infrastructure and the use of AI to support a cleaner, more secure and more competitive EU energy system.
This is one of the package’s central tensions.
Europe wants more AI capacity, more data centres and more sovereign infrastructure. At the same time, it wants climate-neutral, highly efficient digital infrastructure. The Commission’s cloud policy already points toward energy efficiency, innovative cooling, power management and integration of data centres into the broader energy system.
So the sovereignty question becomes: can Europe scale compute without breaking its energy model?
That is not a technical footnote. It may become the decisive constraint.
Why this package matters now
The package comes at a moment when Europe’s digital dependencies have become impossible to ignore.
The Commission states that Europe remains heavily dependent on suppliers outside the EU for core digital technologies, while demand for computing capacity is rising sharply with the spread of AI.
This is the strategic context. AI is accelerating the concentration of power around those who control cloud platforms, chips, foundation models, developer ecosystems, data pipelines and security infrastructure. If Europe remains only a regulatory power while others control the underlying stack, its autonomy will be limited.
This does not mean Europe can or should isolate itself. The better concept is open strategic autonomy: remaining globally connected while reducing dangerous dependencies in critical areas.
That distinction matters. Sovereignty is not autarky. It is not about building a digital wall around Europe. It is about ensuring that European governments, companies and citizens are not structurally forced into dependencies they cannot govern, audit, exit or replace.
The hidden shift: from compliance to architecture
The most important implication of the Tech Sovereignty Package is that sovereignty will increasingly become a design principle.
For enterprise and public-sector leaders, this means the conversation has to move beyond legal compliance checklists. The new questions are architectural:
Where are the operational control planes?
Who can access privileged administration layers?
How are encryption keys governed?
What happens if a supplier becomes unavailable, sanctioned, compromised or politically constrained?
Can workloads move?
Can data be exported in usable form?
Can AI models be audited?
Can software dependencies be traced and patched?
Can critical services continue under stress?
This is where sovereignty becomes measurable.
A sovereign architecture is not simply one hosted in Europe. It is one where control, evidence, resilience and exit options are designed into the platform from the beginning.
What it means for public procurement
Public procurement may become one of the strongest levers of the package.
The Commission is already linking cloud sovereignty with public-administration policy and procurement. That matters because public-sector demand can shape markets. If European institutions and Member States require stronger sovereignty criteria, cloud and software providers will have to adapt.
But this is also where the package will face its hardest execution challenge.
Procurement teams will need to distinguish between marketing sovereignty and operational sovereignty. A “sovereign cloud” label is not enough. Buyers will need evidence around ownership, jurisdiction, support model, operational control, cybersecurity posture, subcontractors, encryption, portability, resilience and exit strategy.
The winners will not simply be providers with European branding. They will be providers that can prove sovereign outcomes.
Open source: Europe’s opportunity and risk
The open-source dimension could become Europe’s most distinctive advantage.
Europe may not currently dominate hyperscale cloud or AI chips, but it has deep engineering communities, strong public-sector institutions, advanced research networks and a tradition of interoperability. Open source fits naturally into this model.
However, open source only supports sovereignty if it is sustainable.
There is a difference between using open source and investing in the ecosystems that make it reliable. If public administrations adopt open-source technologies without funding maintenance, security, documentation and support, they simply move dependency from vendors to underfunded communities.
The strategic opportunity is to create a European model where open technologies are treated as infrastructure: maintained, secured, governed and integrated into procurement.
That is a much more mature vision than “use open source because it is cheaper.”
The central dilemma: autonomy needs capital
The Tech Sovereignty Package is ambitious. But ambition is not enough.
Europe’s real constraint is not only regulation. It is capital, execution speed, energy cost, skills availability and market fragmentation. The Commission’s broader competitiveness agenda builds on the Draghi report and the Competitiveness Compass, which identify three major necessities for Europe: closing the innovation gap, decarbonising the economy and reducing dependencies.
Those three goals are perfectly aligned on paper. In practice, they often collide.
More AI requires more compute.
More compute requires more energy.
More infrastructure requires more capital.
More sovereignty criteria may restrict supplier choice.
More regulation can increase trust, but also slow deployment.
More open source can reduce lock-in, but only if it is properly funded.
This is the real policy test: can Europe turn sovereignty into industrial capacity, not just into compliance language?
What organisations should do now
For CIOs, CTOs, public-sector leaders and regulated industries, the Tech Sovereignty Package should trigger immediate preparation.
The first step is to map critical digital dependencies across the full stack: cloud, data platforms, AI services, software supply chains, cybersecurity tools, identity systems, observability, APIs, operational control planes and support models.
The second step is to classify workloads by sovereignty sensitivity. Not every workload needs the same level of control. A citizen-services platform, an energy-grid AI model, a defence analytics system and a public website do not carry the same risk profile.
The third step is to design for portability and evidence. Organisations should be able to prove where data is, who can access it, how it is protected, how services recover, and how they can exit a provider if required.
The fourth step is to take open source seriously. That means not only adopting it, but understanding its governance, maintainers, security model, commercial support options and long-term viability.
Finally, organisations should align sovereignty planning with existing European frameworks such as the AI Act, NIS2, the Cyber Resilience Act, data protection rules and sector-specific regulations. Sovereignty will not replace these obligations. It will increasingly connect them.
The real meaning of the package
The EU Tech Sovereignty Package is not a declaration of independence from global technology. That would be unrealistic.
It is better understood as Europe’s attempt to rebalance the digital equation.
For too long, Europe has been strong in rights, rules and regulation, but weaker in platforms, infrastructure and scale. The package recognises that this imbalance is no longer sustainable in an AI-driven economy.
The next phase of digital power will belong to those who control compute, data, chips, software ecosystems, energy integration and trusted operations. Europe’s challenge is to build enough capacity in those layers while preserving the openness, democratic accountability and legal protections that define its model.
That is why the Tech Sovereignty Package matters.
It is not just about technology. It is about whether Europe can convert its values into infrastructure — and its infrastructure into strategic power.