The European Commission's Tech Sovereignty Package, unveiled earlier this summer, was framed as a long-term response to structural dependence on American cloud and artificial intelligence infrastructure. But the legislation acquired sudden urgency on 12 June 2026, when the United States government suspended access to Anthropic's most advanced AI models, Mythos and Fable, for all foreign nationals, including European governments and researchers.

A transatlantic rupture years in the making

Since Donald Trump returned to the White House in January 2025, his administration has treated European digital regulation as a trade irritant. The first fines under the Digital Markets Act, levied against Meta and Apple in April 2025, drew a White House statement describing the penalties as "economic extortion." By August, Trump threatened "substantially higher tariffs and export controls on US technologies" against any country imposing digital laws or taxes on American firms.

Meta's chief executive, Mark Zuckerberg, set the corporate tone early, characterising EU rules as censorship and pledging cooperation with the administration. The alignment between Big Tech and the White House left Brussels confronting a coordinated campaign that mixed regulatory pressure with explicit threats to the technology supply chain.

The kill-switch scenario moves from theory to practice

European policymakers had long worried that critical cross-border platforms, used for defence, commerce and information, could be disabled by a "kill-switch" controlled from Washington. Precedents existed. In 2022, Elon Musk restricted Ukrainian military use of Starlink communications. In early 2025, the Trump administration compelled Microsoft to cut off the chief prosecutor of the International Criminal Court from its services. Neither episode involved a formal export control; both demonstrated that corporate compliance with US government demands could sever European access overnight.

What the Tech Sovereignty Package contains

The Commission's response bundles three strands. The Cloud and AI Development Act reserves a portion of sensitive government cloud contracts for European providers and encourages public bodies to adopt open-source components when building AI stacks. Chips Act 2.0 extends semiconductor subsidies with stricter supply-chain conditions. The Open Source Strategy directs funding toward community-maintained alternatives for critical infrastructure. None of the measures is revolutionary, but together they mark a shift: digital dependence is now treated as a security vulnerability, not merely an economic loss.

Anthropic's Mythos and the Glasswing exclusion

Days after the package's announcement, the kill-switch fear materialised. Anthropic had released Mythos, a model that in its first weeks identified more than 10,000 flaws across major operating systems and web browsers. The company established Project Glasswing, a 40-member consortium including Amazon, Google, NVIDIA and CrowdStrike, to manage access and misuse risks. European governments were not invited. The European Commission confirmed only limited contact with Anthropic and no access to Mythos.

In a closed-door briefing to German lawmakers, Claudia Plattner, president of the Bundesamt für Sicherheit in der Informationstechnik, warned that Chinese companies such as Alibaba could soon match Mythos's automated vulnerability-discovery capabilities. If Europeans lacked access to the defensive tool while adversaries developed equivalents, the asymmetry would be dangerous.

Export controls and a rapid reversal

Within days of ENISA, the EU's cybersecurity agency, being added to Glasswing, the US Commerce Department imposed export controls on Mythos and Fable, formally blocking European users. By the end of June, the restrictions were lifted. Anthropic regained permission to serve European customers. But the episode demonstrated that Washington would invoke national-security authority to cut off allies not only over regulatory disputes but over control of dual-use AI capabilities.

Near-term exposure, long-term legislative test

In the immediate term, Europe remains dependent on American cloud hyperscalers and frontier-model providers. No European alternative matches the scale of AWS, Azure or Google Cloud, nor the model performance of Anthropic, OpenAI or Google DeepMind. The Commission's reserved-contract approach will shift only a sliver of workloads. Chips Act 2.0 funding will take years to translate into fabrication capacity. Open-source stacks are maturing but still lack the operational support ecosystems that enterprises and governments require.

Parliament and Council now hold the pen

The package now enters the ordinary legislative procedure. The European Parliament's internal market committee and the Council's digital working party will negotiate amendments over the coming months. Key battles include the definition of "sensitive" contracts eligible for the European cloud set-aside, the scope of open-source mandates, and whether Chips Act 2.0 subsidies carry mandatory domestic-sourcing clauses that could breach WTO commitments. The outcome will determine whether the Tech Sovereignty Package becomes a credible industrial strategy or a symbolic gesture.

People mentioned

  • Claudia Plattner

    President of the Federal Office for Information Security, Bundesamt für Sicherheit in der Informationstechnik

  • Donald Trump

    President of the United States, White House

  • Mark Zuckerberg

    Chief Executive Officer, Meta

Organisations

European Commission · Anthropic · Meta · Microsoft · International Criminal Court · ENISA