Skip to content

Europe

Independent · Brussels & Berlin

Technology · Digital regulation

EU pushes unified cloud and AI sovereignty framework as executives weigh cost of independence

The European Commission's proposed Cloud and AI Development Act aims to create a single assessment framework across the bloc, while surveys show most executives accept higher costs to reduce dependence on US and Chinese technology providers.

By , Technology Editor

Published

7 min read

The European Commission's proposal for a Cloud and AI Development Act, tabled on 3 June 2026, marks the most ambitious attempt yet to translate the continent's digital sovereignty rhetoric into a single, enforceable framework. The legislation would establish four assurance levels for cloud and AI services, graded by data location, independence from non-EU jurisdictions, European ownership and control over the software supply chain. A joint roadmap from the Commission, Parliament and Council sets the fourth quarter of 2027 as the target for agreement. Until then, the bloc's enterprises navigate a thickening thicket of overlapping rules, GDPR, the Data Act, the Digital Markets Act, the Digital Services Act, the Data Governance Act and the AI Act, each touching on sovereignty from a different angle.

From Snowden leaks to strategic autonomy

The term digital sovereignty entered European policy discourse after the 2013 Edward Snowden revelations exposed the reach of US intelligence into commercial cloud infrastructure. What began as a data protection concern has mutated into a broader strategic autonomy agenda. The World Economic Forum noted in 2025 that the United States avoids the language of sovereignty altogether, China pursues a state-led model, while Europe frames the concept around individual rights and regulatory control. That framing has produced the world's most comprehensive regulatory stack, but it has also left organisations struggling to operationalise compliance across borders and vendors.

Geopolitics has accelerated the shift. Export controls, sanctions and the threat of economic coercion have turned dependence on foreign-controlled infrastructure into a board-level risk. The European Commission itself notes that digital sovereignty helps organisations reduce single-country and single-provider dependencies while retaining control over where data and workloads move. Futurum's Q4 2025 CIO Insight Survey found 54 percent of organisations are actively reevaluating where workloads run, a figure that suggests the conversation has moved from strategy slides to procurement decisions.

Four pillars and a moving target

IBM's taxonomy breaks digital sovereignty into four components. Operational sovereignty concerns control over how environments are run, governance, compliance, resilience and visibility built into the system. The EU's own 2025 definition describes it as the practical ability of European actors to run, support and evolve technology independently of foreign control. Data sovereignty covers control over data at rest, in use and in motion, extending beyond mere residency to encompass encryption keys, access logs and audit evidence. Technology sovereignty addresses the full stack, advocating open, modular architecture to avoid vendor lock-in. AI sovereignty, the newest pillar, demands governed execution of models and inference within defined boundaries.

These pillars are not static. The EU's 2025 European Data Union Strategy explicitly links sovereignty to openness: "Sovereignty requires openness to trusted partners, including exchange of data across borders, but on terms that are fair, secure, and consistent with EU values and interests." That formulation attempts to square the circle of autonomy and interdependence. It also reflects a pragmatic shift from the earlier, geography-obsessed notion of data localisation toward a control-based model where location is necessary but insufficient.

The vendor lock-in battleground

Technology sovereignty is where the commercial fight is sharpest. The EU's 2023 Data Act requires contracts to include the right to switch providers and port data to on-premises infrastructure. The Digital Markets Act demands interoperability, data access and portability from designated gatekeepers, predominantly US firms such as Apple and Google. A January 2026 European Parliament resolution called for digital infrastructure built on common and open standards that promote interoperability and interconnection.

Open-source advocates argue this does not go far enough. Amandine Le Pape, co-founder and chief operating officer of Element, wrote in February 2026: "Genuine digital sovereignty goes far beyond a European government buying European software. It means a government not having to rely on a specific vendor, European or otherwise." The distinction matters. A European proprietary stack still creates single-vendor dependency; open standards and portable workloads are the only architecture that lets an organisation exit without great disruption. The Business Software Alliance and analysts at Gartner have both highlighted portability as the litmus test for genuine sovereignty.

AI sovereignty: the existential layer

AI has intensified every pressure. Scaling AI means more systems, more models, more data, and exponentially harder governance. The EU AI Act, the Data Governance Act, the DMA and the DSA all touch on AI, creating a compliance surface that few organisations can map confidently. NIST's AI Risk Management Framework and the OECD's AI Principles both stress transparency and control over AI components as prerequisites for trustworthy deployment.

The executive mood is stark. A McKinsey survey of 300 leaders found 71 percent place sovereign AI in the category of either "existential concern" or "strategic imperative." Yet The Economist, writing in 2026, called fully independent sovereign AI a "pipe dream" given that only the United States and China dominate the foundational model layer. Its assessment: governments must decide which parts of the stack to recreate domestically and which dependencies are worth living with. IBM's own Institute for Business Value proposes a model of "selective AI sovereignty", accepting vendor lock-in for less strategic functions such as transcription while insisting on multi-vendor control for core capabilities. Its research found 72 percent of executives would accept a 20 percent cost increase to maintain multiple AI vendors if it improved strategic freedom.

Security as the enforcement mechanism

Regulation is not the only driver. ENISA's 2025 Threat Landscape reported that supply chain risks constitute 10.6 percent of attacks, confirming that adversaries actively exploit third-party dependencies. For chief information security officers, digital sovereignty translates into controlling administrative access, encryption keys, monitoring and recovery across a fragmented estate. The NIST 2024 Cybersecurity Framework embeds many of these concepts. Boards increasingly demand proof of resilience and business continuity, not just compliance certificates. That shift moves sovereignty from a legal checkbox to an operational requirement.

What the CADA proposal actually changes

The Cloud and AI Development Act would not replace existing regulations but overlay a unified sovereignty assessment. Its four assurance levels would give procurers, public and private, a common language to evaluate cloud and AI services. The criteria are deliberate: data location, non-EU independence, EU ownership, and software supply chain control. Together they answer the question that current rules leave ambiguous: how sovereign is this service, really? The proposal remains a draft. The Q4 2027 target assumes the usual trilogue negotiations between Commission, Parliament and Council. Industry lobbying on the definition of "EU ownership" and the treatment of US-owned but EU-operated infrastructure will be intense.

Sources

  1. IBM

    ibm.com · 2026-08-14

People mentioned

  • Arvind Krishna

    Chief executive officer, IBM

  • Amandine Le Pape

    Co-founder and chief operating officer, Element

Organisations

European Commission · European Parliament · European Council · IBM · Element · ENISA

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.