Policy analysis · July 2026 · Briefing reference
The European Technological Sovereignty Package
On 3 June 2026 the Commission proposed four linked instruments under one Communication. The package does not mandate buying European. It does something subtler: it writes down, in four graduated tiers, what control over a digital service actually means — and then wires that definition into public procurement.
1In brief
Summary of the package
The central bet. It is a demand-side instrument dressed as industrial policy: Europe's purchasing power is asked to summon a supply base that its capital markets have not. Whether the bet pays depends on a negotiation that runs to the end of 2027 — and on a budget being decided in a different room. The scenario analysis concludes the most probable outcome is a hardened text alongside an unchanged market: maximal legal ambition and maximal derogation at the same time.
- Four components, two of them binding. The Cloud and AI Development Act (CADA, COM(2026) 502) and the Chips Act 2.0 are proposed regulations. The EU Open Source Strategy and the Strategic Roadmap for Digitalisation and AI in Energy (COM(2026) 501) are non-binding strategies. All four sit under a Communication on European Tech Sovereignty.
- The premise is a dependency figure. The EU relies on non-EU suppliers for more than 80% of key digital products, services, infrastructure and intellectual property. In cloud, three US providers hold over 70% of the European market while EU providers have fallen to roughly 15%, down from about 29% in 2017.
- The conceptual move is from ownership to assurance. CADA's four-level sovereignty framework does not ask who owns a provider as a first question. It asks whether a foreign legal instrument can reach into the service — for data, or to interrupt it. Sovereignty is defined as freedom from foreign compulsion, and graded.
- The mechanism is procurement, not prohibition. Public bodies conduct a sovereignty risk assessment and match workloads to tiers. No US provider is banned. The Commission's own estimate: roughly 70% of public contracts at Level 1, 20% at Level 2, under 10% at Level 3, about 1% at Level 4.
- There is no Buy European mandate. Considered and dropped, principally to avoid provoking US trade retaliation. France pushed for European preference; Germany for a more open construction. What survives is an "EU added value" criterion and an open-source-first procurement principle that is encouraged rather than required.
- Chips Act 2.0 changes strategy, not just scale. The 2023 Act was supply-side: subsidise fabs. It mobilised over €52 billion but left EU market share stuck at 8–10%, and the 20%-by-2030 target is not going to be met. The new Act pivots to demand — demand accelerators, procurement weighted to EU added value, and the domestic pull created by CADA's data centre build-out.
- Two instruments carry real coercive power and have attracted little attention. Chips Act 2.0 would let the Commission compel priority-rated orders over existing commercial contracts during a declared supply crisis. CADA contains a delegated-act power to extend sovereignty risk assessment obligations to private companies in certain critical sectors.
- No money has been attached. The Commission named no semiconductor envelope, explicitly because the 2028–34 Multiannual Financial Framework is still under negotiation. That fight — over the European Competitiveness Fund and its digital line — will determine more than the legislative texts will.
- Nine days after publication, the argument was made for the Commission. On 12 June 2026 a US export control directive forced Anthropic to disable its two most capable models for every non-US national worldwide, including its own foreign-national staff. Access was restored on 1 July after the controls were lifted. It is the clearest available demonstration that the kill-switch risk is not hypothetical and does not require a hostile actor.
- Nothing binds before 2028. Interinstitutional planning targets concluding Chips Act 2.0 in Q2 2027 and CADA in Q4 2027. The CADA rapporteur in the Parliament's IMCO committee is Reinier van Lanschot (Greens/EFA, Netherlands).
2Why now
The road to 3 June
The package is the delivery arm of a diagnosis that has been forming in Brussels for two years, accelerated by a series of events that turned an abstract dependency into a felt vulnerability.
2.1 The policy chain
The intellectual origin is Mario Draghi's 2024 report on European competitiveness, which documented Europe's failure to build a significant technology sector and reframed the problem from consumer protection to industrial capability. The Competitiveness Compass (January 2025) turned that into a Commission programme. The AI Continent Action Plan (April 2025) set out five workstreams — compute, data, skills, adoption and simplification — and the Apply AI Strategy followed as its sectoral deliverable. CADA was conceived inside that plan and placed under Executive Vice-President Henna Virkkunen's tech sovereignty portfolio.
Two things then happened outside the Commission that hardened the politics. In November 2025, France and Germany convened a Summit on European Digital Sovereignty and launched a joint taskforce to produce a common definition of a European digital service, together with sovereignty indicators for cloud, AI and cybersecurity. This mattered because Germany, the Netherlands and Denmark had for years blocked French-style industrial policy at EU level; their conversion removed the principal veto. In September 2025 the twenty-seven Member States signed a Semicon Coalition declaration calling for a reinforced Chips Act 2.0.
Separately, the Commission's own IT directorate published a Cloud Sovereignty Framework and, in April 2026, awarded up to €180 million in cloud contracts largely to European providers — the first procurement in EU history to apply explicit sovereignty criteria. That created a live precedent, and a live controversy, before the legislation was even tabled.
2.2 The two risk theories
The Commission's explanatory memorandum names two distinct legal risks, and it is worth keeping them separate because they have different remedies.
Extraterritorial access
The US CLOUD Act (2018) permits US law enforcement to compel a US-controlled provider to produce data regardless of where it is stored. EU objections date to the statute's enactment; negotiations toward a consensual mechanism have been intermittent since 2019 and have stalled. The EU already has two blunt countermeasures — the 1996 blocking statute and Article 32 of the Data Act — neither of which has proved effective in practice.
Service interruption — the "kill switch"
Newer and more visceral. In February 2025, US sanctions against International Criminal Court officials cut those officials off from payment networks and consumer platforms. The episode became emblematic in Europe of the willingness to weaponise dependency. It is the specific scenario Virkkunen has said the framework exists to foreclose.
3The architecture
Four instruments, one theory
| Component | Instrument | What it principally does |
|---|---|---|
| Cloud and AI Development Act COM(2026) 502 |
Proposed Regulation, Art. 114 TFEU | Defines cloud and AI sovereignty in four assurance levels; ties them to public procurement; triples data centre capacity; accelerates permitting |
| Chips Act 2.0 | Proposed Regulation, repealing Reg. (EU) 2023/1781 | Shifts semiconductor policy from supply subsidy to demand creation; adds crisis powers; supports an EU advanced foundry |
| EU Open Source Strategy | Communication / strategy | Full-lifecycle support for open source as an exit and anti-lock-in layer; maintenance and stewardship instruments |
| Strategic Roadmap for Digitalisation and AI in Energy COM(2026) 501 |
Roadmap | Reconciles AI as a tool for grid management with AI as a load on the grid; tripartite agreements; grid connection transparency |
3.1 The through-line
Read together, the four instruments describe a single theory. Europe cannot out-invest the United States or China at the frontier this decade, and it has stopped pretending otherwise. What it does have is a large, coordinated, publicly funded demand base and the legal capacity to set conditions on it. So the package converts regulatory competence into industrial leverage: it specifies what a trustworthy digital service is, applies that specification to public purchasing, and lets the resulting demand signal do the work that direct subsidy did not do in Chips Act 1.0.
This is a genuine departure. Previous European sovereignty efforts — Gaia-X most notably — were voluntary architectures with no purchasing teeth, and they failed accordingly. CADA is a regulation with a certification scheme attached to a procurement duty. Whether that is sufficient is contestable; that it is categorically different is not.
3.2 What is not in the package
- No Buy European mandate. Nothing on the model of the US Buy American Act. The exclusionary effect, where it exists, arrives indirectly through the top two assurance levels.
- No funding envelope. Neither legislative proposal carries a number. Both defer to the 2028–34 budget negotiation.
- No frontier model programme. Nothing in the package attempts to fund a European frontier lab. The Open Source Strategy is explicitly about ecosystem health and exit rights, not capability parity.
- No mandatory open source adoption. Earlier drafts were reportedly stronger; what survives is encouragement and procurement guidance.
4The centrepiece
The Cloud and AI Development Act
CADA is the centre of gravity of the package and the piece with the sharpest transatlantic consequences. It is organised in three pillars — research and innovation, capacity, and autonomy — of which the third is where the novelty lies.
4.1 Pillar one: research, development and innovation
CADA would support next-generation cloud and AI technologies through a set of "grand challenges" covering frontier AI, industrial AI, physical AI, AI agents, European data centre and cloud stack technologies, and AI in the public sector. It also requires Member States to adopt national cloud and AI strategies and establishes Experience and Acceleration Centres to drive adoption in strategic industrial and public sectors.
This is the least discussed and arguably the highest-return part of the Act. Europe's largest measurable gap is not model capability but diffusion: adoption among small and medium enterprises, public sector procurement competence, and integration skills. Instruments aimed at adoption are unglamorous and cheap relative to fabs and gigafactories.
4.2 Pillar two: capacity
- Tripling data centre capacity within five to seven years. Roughly 12 GW installed today; commentary puts the implied trajectory at 32–60 GW and capital expenditure near €300 billion by the mid-2030s.
- Data centre acceleration zones with a maximum twelve-month permitting procedure.
- Improved access to energy, land, water and financing, coordinated with the energy roadmap.
Note the tension embedded here. Acceleration zones lower the cost of building data centres in Europe for whoever is building them — and the entities currently able to deploy tens of billions of euros of capacity are, overwhelmingly, the US hyperscalers. Absent a preference mechanism, the capacity pillar may reinforce precisely the market structure the autonomy pillar is designed to loosen.
4.3 Pillar three: autonomy — the four assurance levels
Article 16 establishes a single EU-wide framework determining the degree of sovereignty required for cloud procurement by Member State and EU authorities, with primary application to bodies responsible for public order, national and internal security, border management, defence, justice and law enforcement. Providers are audited and recognised by Member States. Requirements are set out in an annex.
4.4 The two derogations, and why Article 30 matters most
Article 30 — the general derogation. A contracting authority may exceptionally turn to a provider not meeting the required assurance level where no adequate, reasonable or comparable alternative service exists. This is the pressure valve, and it is where the framework will be won or lost. The precedent is instructive: in 2023 France's data protection authority and its courts concluded that only Microsoft possessed the technical and operational capability to run the national Health Data Hub. France has since moved to a domestic provider — but the underlying dynamic is unchanged. If "no reasonable alternative" becomes the routine finding rather than the exception, CADA reduces to a labelling exercise with audit costs.
Article 18 — associated third countries. A derogation from Level 3 for providers from countries meeting three conditions: an EU adequacy decision under the GDPR; no requirement to grant governmental access to non-personal data protected under Article 32 of the Data Act; and no power to compel degradation or interruption of service, including through sanctions. The United States holds adequacy under the Data Privacy Framework. It plainly fails the third condition. The provision therefore reads as a diplomatic gesture that cannot presently be cashed — deliberately so, in the view of several commentators.
4.5 Other provisions worth knowing
- A common EU-level procurement framework allowing public administrations to pool purchasing power — the single most underrated instrument in the Act, because scale is precisely what European providers lack.
- An "EU added value" criterion rewarding contributions to EU-based innovation, supply chain resilience and hardware.
- Open-source-first procurement principle, encouraged rather than mandated.
- A delegated-act power permitting the Commission to extend sovereignty risk assessment obligations to private companies in designated critical sectors. This is the sleeper provision: it would take the framework out of public procurement and into the private economy without a fresh legislative act.
4.6 The critique
From the hyperscaler side
CCIA Europe has characterised the scheme as discriminatory and unworkable, and — pointedly, given that enforcement sits with Member States — as producing fragmented discrimination twenty-seven different ways. International industry associations from the US, Canada, Japan and Australia wrote jointly to Member State governments ahead of the 8 June Telecom Council asking for revision consistent with non-discrimination, proportionality and openness. Affected providers have raised concerns with the US Commerce Department, which has begun quiet engagement with European counterparts.
From the European cloud side
CISPE, representing European infrastructure providers, welcomed the strength of Levels 3 and 4 but attacked Levels 1 and 2 as incoherent, arguing that labelling them "sovereign" institutionalises sovereignty washing precisely because US hyperscalers can meet them. The April 2026 €180 million award crystallised this: one winning bid was built on a joint venture running on US cloud technology under French defence-sector control, which CISPE called an own goal.
From the competition-economics side
Origin-based criteria at Levels 3 and 4 function as market restrictions rather than technical safeguards; they will raise costs for European public services; and restricting access to frontier compute and model APIs harms European users more than it harms American vendors — because the capability gap between frontier systems and the next best alternative is widening, not narrowing.
From the critical-scholarship side
The package attempts to serve competitiveness, sustainability and sovereignty simultaneously and cannot serve all three; and by accepting an infrastructure-and-scale framing of the problem, the Commission has already conceded the terms set by the incumbent vendors — sovereignty pursued through the same build-out logic that created the dependency.
The structural objection
Enforcement is delegated to Member States, which creates forum shopping: a provider that cannot satisfy a demanding national regulator may find a permissive one. Harmonisation by regulation, fragmentation by implementation, is a familiar European pattern.
5Semiconductors
The Chips Act 2.0
5.1 What the first Act did and did not do
The 2023 Chips Act was Europe's first coordinated response to semiconductor supply vulnerability. On the Commission's own accounting it helped mobilise more than €52 billion in public and private investment and roughly 46,000 direct and indirect jobs, and it strengthened research capacity. It did not move market share. The EU's global share has sat at approximately 8–10% since the 1990s, and the headline target of doubling the share of cutting-edge semiconductors to 20% by 2030 has been publicly doubted by the European Court of Auditors and effectively conceded by Commission officials — who point out, fairly, that the global market roughly doubled underneath them, so holding share was itself an achievement.
The diagnosis behind the revision is that Chips Act 1.0 subsidised supply into a market where European demand for advanced chips was thin. Fabs without customers do not become ecosystems.
5.2 The four objectives
Improving investment conditions
- Research, innovation and skills across the ecosystem; continuation of the Chips for Europe Initiative as "Chips for Europe Initiative 2.0".
- Permitting within a maximum of twelve months.
- "Grand Challenges" for chips of key EU importance, explicitly including AI chips.
- Strategic Partnerships on Semiconductors with international partners.
Stimulating demand — the genuinely new pillar
- Demand Accelerators aligning new semiconductor products with the requirements of user industries and shortening time to market.
- Public procurement in critical areas weighted toward EU added value in growth, jobs and skills located in the Union.
- Expanded innovation procurement aimed at European startups and scale-ups.
- Explicit synergy with CADA: data centres, cloud providers and AI gigafactories as the domestic customer base that Chips Act 1.0 lacked.
Reinforcing supply
- State aid for First-of-a-Kind projects across the whole value chain, from raw materials through to packaging.
- Strategic Projects designation unlocking EU funding and co-investment with Member States and industry — described by Commission officials as several billion euros each, blending EU, national, industrial and probably private equity capital.
- A Semiconductor Regions of Excellence label to attract regional investment.
- Signalled priority for a European open foundry for state-of-the-art chips, including AI chips and 3D packaging, at 3 nanometres and below.
Resilience and crisis preparedness
- A business-to-business Semiconductor Supply Chain Platform.
- Guidance on risk assessment for repeatedly exposed sectors.
- A crisis stage with intelligence-sharing and, critically, the power to compel priority-rated orders — obliging manufacturers in the Union to prioritise crisis-critical orders over existing commercial commitments. Joint procurement and demand aggregation mechanisms are modelled on the pandemic-era vaccine scheme.
5.3 The critique
Industry support for the direction is broad and the reservations are almost entirely about money. DIGITALEUROPE has called for €200 billion mobilised by 2035 and a dedicated EU semiconductor budget line of at least €20 billion within the European Competitiveness Fund, plus approval times under seven months. ESIA has pressed for a ten-year strategy with a dedicated budget and continuation and expansion of the Chips Joint Undertaking. Independent estimates put the public and private investment required for meaningful leading-edge capacity around €120 billion.
Against that, the Commission has stated plainly that money will be scarcer in Chips Act 2.0 than in its predecessor and that investment must therefore be more targeted. Industry association leaders have made the obvious retort in public: Europe cannot regulate its way into semiconductor capability.
A second critique concerns the crisis powers. Priority-rated orders that override private contracts are without real precedent in EU industrial law. They were among the most contested provisions in the 2022–23 negotiation of the first Act and will be again — particularly from Member States hosting the manufacturers whose contracts would be overridden.
6The commons
The EU Open Source Strategy
6.1 The diagnosis
The strategy starts from a value-capture problem rather than a technology problem. European public and private organisations spend on the order of $300 billion a year predominantly on non-EU proprietary software and services, creating lock-in that can be weaponised. Meanwhile the European open source ecosystem produces substantial value that is captured outside Europe, and suffers from thin long-term funding, difficulty scaling from innovation to industrial deployment, fragmented visibility and limited access to public procurement.
6.2 Structure — four objectives
- Open source for tech sovereignty. Scaling the Open Internet Stack catalogue; supporting open alternatives to proprietary solutions in cloud, workplace tools, secure email and decentralised social media, with Member States and the Digital Commons EDIC; open source in the European Digital Identity Wallet, the European Business Wallet and age verification; prioritised funding in semiconductors, operating systems, cloud, AI, cybersecurity and future internet architectures.
- A vibrant ecosystem. Accelerators, legal and licensing support and procurement access for startups; a stewardship toolkit and support for EU-based steward organisations holding strategic assets; an Open Source Maintenance Instrument, critical dependency mapping and mirroring capability; skills investment.
- Open source in public administration. Procurement guidelines for open standards and fair assessment of open source bids; strengthening the Commission's Open Source Programme Office and the public sector OSPO network; common security baselines for Commission repositories; openness and sovereignty-by-design embedded in digital investment decisions.
- Standards and international outreach. Promoting EU open source solutions abroad; uptake of EU-grown tools in partner countries; integrating open source communities into standardisation, including via revision of the Standardisation Regulation.
6.3 What it can and cannot do
It will not produce a European frontier model, and does not claim to. The realistic picture as of mid-2026: OpenEuroLLM, funded at roughly €37 million under Digital Europe, has been compute-constrained and its models are not expected at frontier scale; the EUROPA project targets delivery in late 2027 to 2028; Mistral is the credible European commercial lab but its frontier models are not fully open-weight. The gap is not talent or data curation — Europe is competitive on both — it is compute.
Two uncomfortable observations follow. First, open weights are not sovereignty if you cannot afford to serve them; the constraint is inference capacity, not licence terms. Second, the strongest permissively licensed open-weight models available to European deployers today are substantially Chinese. Adopting them is dependency substitution, not dependency elimination — and the provenance questions that apply to American models apply to Chinese ones with different valence but equal force.
What it does deliver is exit. The honest value proposition of open source in this package is switching capability, auditability, and an anti-lock-in layer in the domains where the capability gap is small — workplace productivity, collaboration, identity, public administration tooling. That is a real and worthwhile objective, and it is achievable at the scale of funding contemplated. It is simply not the objective the word "sovereignty" implies to most listeners.
7The physical constraint
The Strategic Roadmap for Digitalisation and AI in Energy
The least discussed component and, on a ten-year view, possibly the most binding constraint on everything else in the package.
7.1 Two goals in tension
The roadmap, adopted as COM(2026) 501 and led by Energy Commissioner Dan Jørgensen, pursues two objectives that pull against each other, and it is more candid about this than most Commission documents.
AI for energy
Accelerating digital and AI solutions in electricity grid optimisation, energy efficiency in buildings and industry, and demand-side flexibility — including European sovereign AI solutions for critical energy infrastructure. The flagship here is AI.grids, a community of practice launched at the signature event to develop pan-European AI foundation models for grid management and planning, built on Horizon Europe testing and experimentation facilities.
Energy for AI
Integrating data centre load into the energy system without destabilising it. The International Energy Agency estimates data centres will account for more than 20% of electricity demand growth in advanced economies by 2030, with EU installed data centre capacity projected to grow from approximately 12 GW in 2025 to around 28 GW by 2030 — before accounting for CADA's ambition to triple capacity.
7.2 Mechanisms
- Voluntary tripartite agreements between public authorities, data centre operators and energy parties covering grid integration, clean energy supply, flexibility and energy performance. Fourteen European industry associations signed a declaration of intent at adoption, with six companies signing a supporting declaration; the model agreement is due in the second half of 2026.
- Grid connection transparency with a use-it-or-lose-it principle, to stop speculative queue reservation — a quietly important measure, since phantom connection requests are currently distorting grid planning across several Member States.
- Better use of power purchase agreements and additional clean generation; waste heat recovery; market-based flexibility instruments; flexible connection agreements; optimal siting.
- A framework for cross-border energy data exchange: assessment in 2026, development from 2027.
- Horizon Europe 2026–27 allocations of roughly €100 million for advanced smart grids, €75 million for AI energy applications and a further €190 million for digital solutions in renewables, smart buildings and efficiency, against roughly €1 billion committed to energy systems, grids and storage across the programme.
7.3 The critique
The core instrument is voluntary, and the Commission has already signalled it is considering a dedicated binding instrument — which tells you what it expects. The funding numbers are modest against an estimated grid investment requirement exceeding €1.2 trillion between 2024 and 2040, of which the larger share is distribution rather than transmission. And the structural fact underneath everything is that European electricity is more expensive than American or Chinese electricity, which is precisely the input cost that determines where compute capacity gets built. A roadmap cannot fix that.
One further point worth registering: putting AI foundation models into grid management is a critical-infrastructure decision with its own sovereignty logic. A stakeholder submission to the consultation put it bluntly — having lost the language-model contest, Europe risks permanent dependence on foreign models operating its energy infrastructure. AI.grids is the answer to that concern, and it is at present a community of practice rather than a capability.
8The unwritten chapter
Money
Neither legislative proposal carries a financial envelope. This is not an oversight; the Commission has said explicitly that the semiconductor allocation awaits the outcome of the 2028–34 Multiannual Financial Framework negotiation. The relevant numbers currently in play:
| Instrument | Scale and status |
|---|---|
| MFF 2028–34 | Commission proposal of close to €2 trillion, against roughly €1.2 trillion in the current period. Under negotiation. |
| European Competitiveness Fund | Proposed at roughly €409–450 billion, consolidating fragmented instruments, with an explicit European preference orientation and an intended mobilisation above €1 trillion including private capital. The digital line sits at around €51.5 billion; Parliament's draft report has floated specific envelopes for technology infrastructure and digital leadership. |
| InvestAI | €200 billion mobilisation target announced at the Paris AI Action Summit, including a €50 billion top-up and a dedicated €20 billion facility for four to five AI gigafactories. |
| AI Gigafactories | Roughly 100,000 advanced accelerators each. An informal expression-of-interest call produced 77 proposals across 16 Member States and 60 sites; the formal EuroHPC call was expected in summer 2026. Financing assumes roughly 65–70% private capital, with EIB advisory and co-investment. |
| Industry asks | DIGITALEUROPE: €200 billion mobilised by 2035 and €20 billion ring-fenced for semiconductors within the Competitiveness Fund. Independent estimates: ~€120 billion for meaningful leading-edge capacity; ~€2 billion over seven years for the open source strategy. |
The honest summary is that the package's ambition and its funding are being decided in two different rooms on two different timetables, and the room that matters is the budget room. A tripled data centre estate, a 3-nanometre European foundry and a maintained open source commons are capital questions wearing regulatory clothing.
9Who wants what
Politics
9.1 Member States
The decisive political fact is that the traditional northern European bloc — Germany, the Netherlands, Denmark — which spent years blocking French-style digital industrial policy, has largely converted. The November 2025 Franco-German Summit on European Digital Sovereignty and the subsequent Council declaration formalised that shift.
On 17 June 2026, France and Germany published a joint paper defining digital sovereignty as the capability and capacity to develop, provide, use, adapt and control digital technologies, including hardware, independently and securely, with final decision-making authority over one's own processes. The paper sets out six dimensions across three categories — foundational dimensions including the capability to implement and enforce, economic capabilities, and technical and systemic capabilities — and is explicitly intended to feed the CADA negotiation. Crucially, it does not exclude non-European vendors: it states a preference for EU-headquartered providers and emphasises a strategic public procurement toolbox, but permits providers from trusted international partner states under risk-based conditions. Paris simultaneously announced a €13 billion fund for French and European technology companies.
Residual divergence: France continues to favour explicit European preference and reserved procurement shares; Germany prefers a more inclusive, risk-based construction. That axis will define the Council negotiation on Levels 2 and 3.
9.2 Parliament
CADA sits with the Internal Market and Consumer Protection committee (IMCO), with Reinier van Lanschot (Greens/EFA, Netherlands) as rapporteur, appointed early July 2026 and publicly targeting conclusion of trilogues by end-2027. Interinstitutional planning under the "One Europe, One Market" roadmap indicates Chips Act 2.0 concluding in Q2 2027 and CADA in Q4 2027. Both texts are open to substantial amendment; the Buy European question in particular is likely to return through Parliament rather than through the Council.
9.3 Industry
| Actor | Position |
|---|---|
| CISPE European cloud infrastructure providers | Supports Levels 3 and 4; attacks Levels 1 and 2 as sovereignty washing. Has campaigned for reserved procurement shares, avoidance of mega-frameworks that lock out local providers, and prioritisation of European supply chains in publicly funded cloud and AI. |
| CCIA Europe and international associations | Discriminatory, unworkable, fragmenting. Formal joint intervention with US, Canadian, Japanese and Australian counterparts ahead of the June Telecom Council. |
| DIGITALEUROPE | Supportive of the demand-side pivot in chips; focused on budget, speed and pooling of EU, national and private funding. |
| ESIA semiconductor industry | Wants a ten-year strategy with a dedicated budget line, expansion of the Chips Joint Undertaking, and coverage of the full value chain. Publicly sceptical that regulation substitutes for capital. |
| European cloud aspirants | OVHcloud has put a number on it: roughly 15% of European public-sector procurement would need to be reserved for European providers for them to reach competitive scale. |
10Washington
The transatlantic dimension
10.1 What Washington has and has not done
Notably, there has been no trade retaliation. The US Trade Representative tracks DMA and DSA enforcement against American companies in the annual National Trade Estimate Report — including substantial fines against Meta, Apple and X — but has not acted. The US Ambassador to the EU has criticised both laws repeatedly. The immediate pressure on CADA is running through industry associations to Member States, and through quiet Commerce Department engagement, rather than through tariffs.
There is also a structural resemblance worth noting: the tiered assurance model is not unlike FedRAMP, the US government's own framework for authorising cloud providers in sensitive federal contexts. The salient difference is that foreign companies can reach FedRAMP's highest tier, whereas CADA's Levels 3 and 4 are constructed such that US providers largely cannot. That asymmetry is the strongest US-side argument and it is not easily answered.
10.2 The awkward simultaneity
In the same period as the sovereignty package, the EU moved in the opposite direction on hardware. Under the EU–US trade framework, the bloc pledged to purchase at least $40 billion of American AI chips for computing centres — aspirational memorandum language with no binding allocation mechanism, no named buyer and no timetable. And on 25 June 2026, following a Council mandate process in which France initially resisted, the Commission signed the US-led Pax Silica declaration on behalf of the EU, alongside Germany, Greece and the Netherlands, bringing the initiative to 24 signatories. Sweden, Finland and Norway had already joined. The Commission secured guarantees that the declaration is non-binding, does not touch EU regulatory autonomy or internal decision-making, and is complementary to rather than a replacement for the G7 workstreams.
The obvious reading is incoherence. A better reading is stratification: Europe has decided that input dependence on allied silicon is more tolerable than control dependence on foreign jurisdiction. Chips can be stockpiled, sourced from multiple partners and, in extremis, substituted at a performance penalty. A legal instrument that reaches into a running service cannot be hedged against at all. On that reading the package and Pax Silica are consistent: sovereignty at the control layer, managed interdependence at the input layer.
Two caveats on that reading. It assumes allied chip supply is not itself weaponisable, which recent US export control practice does not obviously support. And it was arrived at, in the EU's case, through a Council process that attracted very little public debate for a structural alignment of that magnitude.
11Part II · Process
The process from here
11.1 The formal machinery
Both CADA and Chips Act 2.0 are proposed regulations under the ordinary legislative procedure (Art. 294 TFEU): qualified majority in Council, simple majority in Parliament, trilogue to reconcile the two mandates.
Council. CADA goes to the working party covering telecommunications and information society; Chips Act 2.0 to competitiveness and growth, where the first Chips Act sat. Files then rise through Coreper I to a General Approach adopted at a Telecom or COMPET Council.
Parliament. CADA is led by the Internal Market committee (IMCO) under rapporteur Reinier van Lanschot; Chips Act 2.0 goes to Industry, Research and Energy (ITRE), which led the first Act. A competence dispute is likely: cloud and AI infrastructure is classic industry-committee territory, and ITRE can be expected to contest IMCO's lead on CADA, most plausibly resolved through an associated-committee arrangement. The Civil Liberties committee (LIBE) has a claim on the data-access provisions and International Trade (INTA) on trade compatibility.
11.2 The presidency sequence, and why it matters more than usual
Opens working-party discussion on both files. Stated priorities: competitiveness, simplification, security. Also the European base of every hyperscaler affected by CADA, and a co-signatory of the 2022 non-paper opposing sovereignty requirements in the EUCS certification scheme.
Security-forward, digitally advanced, without comparable hyperscaler exposure. The likely window for a Council General Approach on Chips Act 2.0, possibly on CADA.
The trilogue presidency; the Q4 2027 target for CADA falls squarely in its term. Also a 2022 non-paper signatory.
Presidencies behave as honest brokers by convention, and Ireland will. But agenda-setting, sequencing and authorship of the compromise texts are real forms of power, and it is a genuine feature of this file's political economy — not a conspiracy — that the opening and closing presidencies are both structurally exposed to the transatlantic downside, while the least exposed of the three sits in the middle.
11.3 Four phases
- Phase 1 — Positioning (now to roughly Q2 2027). Shadow rapporteurs are appointed; draft reports are published; amendments are tabled. On a file this contested the amendment count will plausibly run to the high hundreds or beyond. In parallel, Council working parties produce successive presidency compromise texts. Most of the substance is decided here, before anything is formally voted.
- Phase 2 — Mandates (2027). Council General Approach; Parliament committee vote and plenary negotiating mandate. Chips Act 2.0 will move faster than CADA — it is less transatlantically explosive and enjoys broader Member State buy-in via the Semicon Coalition.
- Phase 3 — Trilogues (2027, possibly running into 2028). Technical then political trilogues on four-column documents; provisional agreement; Coreper endorsement; committee and plenary votes; Council adoption; publication in the Official Journal.
- Phase 4 — Implementation (2028–2030). Entry into force plus staggered application — realistically eighteen to twenty-four months for the sovereignty framework — followed by the delegated and implementing acts that give the annex criteria and certification methodology operational content. On any plausible calendar, the first real Level 3 procurement under CADA is a 2029–2030 event.
12Discipline
Five process observations that discipline any forecast
-
EUCS is the base rate, and it is not encouraging
The EU Cloud Services certification scheme (EUCS) has been in development for over five years. Sovereignty requirements — foreign-law immunity, EU headquarters, EU ownership — were inserted at the Commission's request, fought over at length, and stripped under industry and Member State pressure. In July 2022, seven Member States — Denmark, Estonia, Greece, Ireland, the Netherlands, Poland and Sweden — co-signed a non-paper opposing them. ENISA's scheme has still not been adopted by implementing act.
CADA is best understood as the attempt to achieve by primary legislation what certification could not achieve by technical delegation. That is a genuine strategic upgrade — the political decision is now taken openly by co-legislators rather than routed through an agency — but it also means more veto points, a public negotiation, and Washington watching. The median historical EU outcome on precisely this question is delay and dilution, and a scenario set that does not give substantial weight to that outcome is advocacy rather than analysis. Several of the 2022 non-paper signatories have since shifted position; the disposition has changed, but the structural exposure has not.
-
The MFF is the critical path, and it runs on a different decision rule
The legislative substance can be agreed by qualified majority while the money is decided by unanimity plus parliamentary consent, on a slower clock. It is entirely possible to adopt Chips Act 2.0 in 2027 with its funding line still unresolved. That decoupling is a driver in its own right, not a detail.
-
The real fight will migrate downward
The assurance criteria sit in an annex; the certification methodology will come by secondary legislation. A text can be won in trilogue and lost in comitology. The single most predictive procedural tell on the file is whether Parliament secures delegated acts (which it can veto) rather than implementing acts (which it cannot) for the assurance criteria.
-
There is a legal-basis vulnerability
CADA rests on Article 114 TFEU, the internal-market harmonisation basis. Provisions bearing on national security run into Article 4(2) TEU, under which national security remains the sole responsibility of each Member State. This is both a real constraint and a tactical instrument for those who want the framework weakened; Council Legal Service opinions reshape files quietly and decisively, and one on this question would be a leading indicator.
-
The simplification counter-current is real
The Digital Omnibus is running in parallel under an explicitly deregulatory mandate, and the Irish presidency has named simplification among its priorities. A Commission simultaneously cutting administrative burden and adding a certification-plus-procurement regime is in tension with itself, and CADA's compliance load is the natural target for that tension.
13Method
Scenario architecture: drivers, markers and axes
13.1 Events versus drivers: the treatment of export-control shocks
An obvious construction for a scenario set on this file would be to reserve one scenario for a repeat of the June 2026 export-control episode — a second sudden withdrawal of a frontier capability from European users. That construction is tempting and should be resisted, for three reasons.
First, such an episode is an event, not a driver. The underlying uncertainty is whether the United States continues to demonstrate willingness to exercise unilateral control over the technology stack — through export controls, sanctions reach, blocked acquisitions or trade linkage. A single episode is a symptom of that disposition, not the disposition itself. Second, assigning the shock to one scenario makes that scenario "the bad one" and flattens the remaining three into a common baseline. Third, and most importantly, the same event does not produce the same effect across worlds. In a Europe with money and supply, a second episode hardens provisions and accelerates procurement. In a Europe without them, it produces harder law and more derogation simultaneously — the legislature legislates harder precisely because buyers cannot purchase what does not exist. Identical shock, opposite operational consequence. That asymmetry is the most analytically useful thing the event can reveal, and confining it to one scenario conceals it.
There are also three reasons a second episode might not push in the direction the first one did:
- Diminishing political returns. The June episode converted the marginal sceptics; the constituency for hard sovereignty is already assembled. A second episode adds less political energy and more economic pain — and the pain argument runs the other way.
- Coupled retaliation. If a second action arrives bundled with explicit linkage — soften the framework or lose chip access — it splits the Council along exposure lines rather than uniting it. Ireland, the Nordics and central European Member States carry materially different risk profiles from France.
- Substitution direction. If a second episode drove European deployers toward Chinese open-weight models at scale, the security establishment's threat model would reorient from Washington toward Beijing, and the coalition behind Levels 3 and 4 — jurisdiction-neutral in text, US-aimed in politics — would have to be rebuilt on different terms.
Export-control episodes are therefore treated as markers — observable events that indicate which world is materialising and accelerate its internal logic — rather than as an axis. They occur in both high-pressure scenarios, with divergent consequences.
13.2 The two axes
Axis 1 — External coercion salience
Does the environment keep supplying demonstrations that dependency is dangerous — export controls, sanctions reach, service interruption, blocked acquisitions, trade linkage? Or does it stabilise: Pax Silica institutionalises, a CLOUD Act arrangement revives, the trade détente holds?
Axis 2 — European delivery capacity
Does Europe convert consensus into money, supply and procurement discipline — a funded MFF digital and semiconductor line, gigafactories built, European providers scaling, national buyers actually buying? Or does the effort remain declaratory: the MFF squeezed by defence and enlargement, providers sub-scale, procurement continuing to favour incumbents?
14The situation board
Four scenarios to Q4 2027
Select a quadrant. The matrix below carries through to the provision-landing table and the indicator board.
15The landing zone
Where the key provisions land
Fourteen provisions, four worlds. Use the scenario tabs to highlight a column, or expand a provision to compare all four outcomes side by side.
16What to watch
Early indicators
Observable in the next six to twelve months, and discriminating between the scenarios. The value of an indicator lies in pointing toward one world and away from another; indicators consistent with everything are decoration.
17Judgement
Relative likelihood
Scenario practice ordinarily counsels against attaching probabilities, since the purpose of the exercise is to widen the aperture rather than to forecast. That discipline is right for strategic use and unhelpful for a reader who must decide what to prepare for. Offered explicitly as judgement rather than estimate:
One observation deserves emphasis. Scenarios A and B — the two worlds toward which most participants in the debate are currently arguing — differ almost entirely in a variable that will not be settled in this negotiation at all. The package's fate is being decided in the budget room, and the parties fighting hardest over the legislative text are not in it.
AAnnex
Measuring success
The package will be judged on announcements unless better metrics are proposed. A defensible set, chosen because each is observable and each is hard to game:
- Share of public contracts actually awarded at Level 2 or above to EU-controlled providers. Contracts signed, not spend announced.
- Frequency and grounds of Article 30 derogations, published. The single best health indicator for the whole framework.
- Count of providers certified at Levels 3 and 4, and their revenue growth. A supply-side measure — a framework with no qualifying suppliers is a wish.
- Measured workload exit time. How long it actually takes a public body to move a live workload between providers. Sovereignty that cannot be executed is not sovereignty; the discipline of periodic exit drills, on the model of bank resolution planning, would make the capability real.
- Permitting outturn against the twelve-month statutory maximum, and gigawatts connected versus gigawatts queued under the use-it-or-lose-it principle.
- Funded maintainer-hours on mapped critical open source dependencies. The only number that distinguishes open source as a resilience strategy from open source as a licensing preference.
- For semiconductors: not market share. European share of irreplaceable inputs — lithography, metrology, materials, packaging — and whether Demand Accelerators generate signed offtake agreements rather than memoranda.
BAnnex
Timeline and key dates
CAnnex