Policy analysis · Third edition · 30 July 2026
The European Technological Sovereignty Package
On 3 June 2026 the Commission proposed four linked instruments under one Communication. The package does not mandate buying European. It does something subtler: it writes down, in four graduated tiers, what control over a digital service actually means — and then wires that definition into public procurement.
1In brief
Summary of the package
The central bet. It is a demand-side instrument dressed as industrial policy: Europe's purchasing power is asked to summon a supply base that its capital markets have not. Whether the bet pays depends on a negotiation that runs to the end of 2027 — and on a budget being decided in a different room. The scenario analysis concludes the most probable outcome is a hardened text alongside an unchanged market: maximal legal ambition and maximal derogation at the same time. Claims are labelled throughout by provenance: proposal text, Commission estimate, external estimate, or this paper's own assessment.
- Four components, including two proposed regulations. The Cloud and AI Development Act (CADA, COM(2026) 502) and the Chips Act 2.0 (COM(2026) 504) would become directly applicable only if adopted by Parliament and Council; as Commission proposals they have no binding effect yet. The EU Open Source Strategy and the Strategic Roadmap for Digitalisation and AI in Energy (COM(2026) 501) are non-binding strategies. All four sit under a Communication on European Tech Sovereignty.
- The premise is a dependency figure. The EU relies on non-EU suppliers for more than 80% of key digital products, services, infrastructure and intellectual property Commission — a Commission-defined basket with no published denominator. In cloud specifically, three US providers hold over 70% of the European market while EU providers have fallen to roughly 15%, down from about 29% in 2017.
- The conceptual move is from ownership to assurance. CADA's four-level sovereignty framework does not ask who owns a provider as a first question. It asks whether a foreign legal instrument can reach into the service — for data, or to interrupt it. Sovereignty is defined as freedom from foreign compulsion, and graded.
- The mechanism is procurement, not prohibition. Public bodies conduct a sovereignty risk assessment and match workloads to tiers. No US provider is banned. The Commission's impact-assessment estimate — drawn from a very small consultation sample — is that roughly 70% of public contracts sit at Level 1, 20% at Level 2, under 10% at Level 3 and about 1% at Level 4.
- There is no Buy European mandate. Considered and dropped, principally to avoid provoking US trade retaliation. France pushed for European preference; Germany for a more open construction. What survives is an "EU added value" criterion and an open-source-first procurement principle that is encouraged rather than required.
- Chips Act 2.0 changes strategy, not just scale. The 2023 Act was supply-side: subsidise fabs. It mobilised over €52 billion, but Europe's share of global semiconductor sales — roughly a fifth in the 1990s — is now around a tenth, and the Court of Auditors projects about 11.7% by 2030 against the 20% political objective External. The new Act pivots to demand — demand accelerators, procurement weighted to EU added value, and the domestic pull created by CADA's data centre build-out.
- Two instruments carry real coercive power and have attracted little attention. Chips Act 2.0 would broaden a crisis mechanism introduced in the 2023 Act under which the Commission can compel priority-rated orders over existing commercial contracts — subject to crisis activation, last-resort status and proportionality tests. CADA contains a delegated-act power to extend sovereignty risk assessment obligations to private companies in certain critical sectors.
- No industrial money has been attached. Both proposals carry modest implementation appropriations in their legislative financial statements, but the Commission named no investment envelope, explicitly because the 2028–34 Multiannual Financial Framework is still under negotiation. That fight — over the European Competitiveness Fund and its digital line — will determine more than the legislative texts will.
- Nine days after publication, the argument was made for the Commission. On 12 June 2026 US export controls — described by the company as a US government requirement — led Anthropic to restrict access to its two most capable models for foreign nationals worldwide, including its own foreign-national staff. Fable was restored globally on 1 July; Mythos initially returned only to selected US organisations. It is the clearest available demonstration that the kill-switch risk is not hypothetical and does not require a hostile actor.
- Nothing binds for some time. Interinstitutional planning targets — targets, not deadlines Assessment — foresee concluding Chips Act 2.0 in Q2 2027 and CADA in Q4 2027; under the proposal, CADA would apply one year after entry into force. The CADA rapporteur in the Parliament's IMCO committee is Reinier van Lanschot (Greens/EFA, Netherlands).
2Why now
The road to 3 June
The package is the delivery arm of a diagnosis that has been forming in Brussels for two years, accelerated by a series of events that turned an abstract dependency into a felt vulnerability.
2.1 The policy chain
The intellectual origin is Mario Draghi's 2024 report on European competitiveness, which documented Europe's failure to build a significant technology sector and reframed the problem from consumer protection to industrial capability. The Competitiveness Compass (January 2025) turned that into a Commission programme. The AI Continent Action Plan (April 2025) set out five workstreams — compute, data, skills, adoption and simplification — and the Apply AI Strategy followed as its sectoral deliverable. CADA was conceived inside that plan and placed under Executive Vice-President Henna Virkkunen's tech sovereignty portfolio.
Two things then happened outside the Commission that hardened the politics. In November 2025, France and Germany convened a Summit on European Digital Sovereignty and launched a joint taskforce to produce a common definition of a European digital service, together with sovereignty indicators for cloud, AI and cybersecurity. This mattered because Germany, the Netherlands and Denmark had for years blocked French-style industrial policy at EU level; their conversion removed the principal veto. In September 2025 the twenty-seven Member States signed a Semicon Coalition declaration calling for a reinforced Chips Act 2.0.
Separately, the Commission's own IT directorate published a Cloud Sovereignty Framework and, in April 2026, conducted its first sovereign-cloud framework procurement — up to €180 million over six years, awarded largely to European providers — presented as a benchmark for applying explicit sovereignty criteria. That created a live precedent, and a live controversy, before the legislation was even tabled.
2.2 The two risk theories
The Commission's explanatory memorandum names two distinct legal risks, and it is worth keeping them separate because they have different remedies.
Extraterritorial access
The US CLOUD Act (2018) permits US law enforcement to compel a US-controlled provider to produce data regardless of where it is stored. EU objections date to the statute's enactment; negotiations toward a consensual mechanism have been intermittent since 2019 and have stalled. The EU already has two blunt countermeasures — the 1996 blocking statute and Article 32 of the Data Act. The blocking statute has a poor record on the Commission's own evaluation; Article 32 is too new to have one. Neither has yet shown it can reliably neutralise conflicting third-country access obligations of the kind CADA contemplates.
Service interruption — the "kill switch"
Newer and more visceral. In February 2025, US sanctions against International Criminal Court officials cut those officials off from payment networks and consumer platforms. The episode became emblematic in Europe of the willingness to weaponise dependency. It is the specific scenario Virkkunen has said the framework exists to foreclose.
3The architecture
Four instruments, one theory
| Component | Instrument | What it principally does |
|---|---|---|
| Cloud and AI Development Act COM(2026) 502 |
Proposed Regulation, Arts. 114 and 173(3) TFEU | Defines four assurance levels for cloud-computing services, including AI delivered remotely as a service; ties them to public procurement; targets a tripling of data centre capacity; accelerates permitting |
| Chips Act 2.0 | Proposed Regulation, repealing Reg. (EU) 2023/1781 | Shifts semiconductor policy from supply subsidy to demand creation; adds crisis powers; supports an EU advanced foundry |
| EU Open Source Strategy | Communication / strategy | Full-lifecycle support for open source as an exit and anti-lock-in layer; maintenance and stewardship instruments |
| Strategic Roadmap for Digitalisation and AI in Energy COM(2026) 501 |
Roadmap | Reconciles AI as a tool for grid management with AI as a load on the grid; tripartite agreements; grid connection transparency |
3.1 The through-line
Read together, the four instruments describe a single theory. Europe cannot out-invest the United States or China at the frontier this decade, and it has stopped pretending otherwise. What it does have is a large, coordinated, publicly funded demand base and the legal capacity to set conditions on it. So the package converts regulatory competence into industrial leverage: it specifies what a trustworthy digital service is, applies that specification to public purchasing, and lets the resulting demand signal do the work that direct subsidy did not do in Chips Act 1.0.
This is a genuine departure. Previous European sovereignty efforts — Gaia-X most notably — were voluntary architectures with no purchasing teeth, and they failed accordingly. CADA is a regulation with a recognition-and-audit scheme attached to a procurement duty. Whether that is sufficient is contestable; that it is categorically different is not.
3.2 What is not in the package
- No Buy European mandate. Nothing on the model of the US Buy American Act. The exclusionary effect, where it exists, arrives indirectly through the top two assurance levels.
- No industrial funding envelope. Both proposals carry only implementation-scale appropriations in their legislative financial statements; neither names an investment envelope. Both defer that to the 2028–34 budget negotiation.
- No frontier model programme. Nothing in the package attempts to fund a European frontier lab. The Open Source Strategy is explicitly about ecosystem health and exit rights, not capability parity.
- No mandatory open source adoption. Earlier drafts were reportedly stronger; what survives is encouragement and procurement guidance.
4The centrepiece
The Cloud and AI Development Act
CADA is the centre of gravity of the package and the piece with the sharpest transatlantic consequences. It is organised in three pillars — research and innovation, capacity, and autonomy — of which the third is where the novelty lies.
4.1 Pillar one: research, development and innovation
CADA would support next-generation cloud and AI technologies through a set of "grand challenges" covering frontier AI, industrial AI, physical AI, AI agents, European data centre and cloud stack technologies, and AI in the public sector. It also requires Member States to adopt national cloud and AI strategies and establishes Experience and Acceleration Centres to drive adoption in strategic industrial and public sectors.
This is the least discussed and arguably the highest-return part of the Act. Europe's largest measurable gap is not model capability but diffusion: adoption among small and medium enterprises, public sector procurement competence, and integration skills. Instruments aimed at adoption are unglamorous and cheap relative to fabs and gigafactories.
4.2 Pillar two: capacity
- Tripling data centre capacity within five to seven years. Roughly 12 GW installed today; commentary puts the implied trajectory at 32–60 GW and capital expenditure near €300 billion by the mid-2030s External.
- Data centre acceleration zones with a maximum twelve-month permitting procedure.
- Improved access to energy, land, water and financing, coordinated with the energy roadmap.
Note the tension embedded here. Acceleration zones lower the cost of building data centres in Europe for whoever is building them — and the entities currently able to deploy tens of billions of euros of capacity are, overwhelmingly, the US hyperscalers. Absent a preference mechanism, the capacity pillar may reinforce precisely the market structure the autonomy pillar is designed to loosen.
4.3 Pillar three: autonomy — the four assurance levels
Article 16 establishes a single EU-wide framework determining the degree of sovereignty required for cloud procurement by Member State and EU authorities, with primary application to bodies responsible for public order, national and internal security, border management, defence, justice and law enforcement. Providers are recognised on the basis of their own statements and, at the higher levels, independent audits, with recognition by Member States; requirements are set out in an annex Proposal. The levels classify cloud-computing services — including services through which AI functionality is delivered remotely — and expressly not AI systems or models as such. A frontier model consumed through an API is in scope as a service; the model itself is not.
4.4 The two derogations, and why Article 30 matters most
Article 30 — the general derogation. The article provides three alternative grounds on which a contracting authority may turn to a provider not meeting the required assurance level: no adequate alternative service is available; a comparable procurement procedure has failed; or compliance would impose disproportionate cost Proposal. (The lettering of the third ground appears to contain a drafting error, but it stands as a separate condition.) The cost ground deserves particular attention: availability can be established, but disproportionality is always arguable, which makes it the widest of the three valves. Nothing in the proposal requires derogation decisions to be published; any transparency duty would have to be inserted by the co-legislators. This is the pressure valve, and it is where the framework will be won or lost. The precedent is instructive: France's Health Data Hub was to leave Microsoft from 2020 onward, yet in March 2026 the Conseil d'État upheld the CNIL authorisation under which Microsoft Ireland continues to host the relevant health data. The flagship European case for replacing incumbent hyperscale infrastructure has, six years on, not yet managed it. If "no reasonable alternative" — or "disproportionate cost" — becomes the routine finding rather than the exception, CADA reduces to a labelling exercise with audit costs.
Article 18 — associated third countries. A derogation from Level 3 for providers from countries designated against six cumulative criteria Proposal: adequacy of data protection; the reach of third-country authorities into non-personal data; continuity of service and exposure to coercive measures, including sanctions; restrictions affecting access to state-of-the-art technology; market openness; and reciprocal access to public procurement. The first three are security tests; the last three belong to the trade-reciprocity family of the International Procurement Instrument. The United States holds adequacy under the Data Privacy Framework and most plainly fails the continuity condition — the power to compel degradation or interruption of service is precisely what June demonstrated. Six cumulative criteria make designation harder still, which reinforces the reading of the provision as a diplomatic gesture that cannot presently be cashed — deliberately so, in the view of several commentators.
4.5 Other provisions worth knowing
- A common EU-level procurement framework allowing public administrations to pool purchasing power — the single most underrated instrument in the Act, because scale is precisely what European providers lack.
- An "EU added value" criterion rewarding contributions to EU-based innovation, supply chain resilience and hardware.
- An obligation on Member States to encourage the use and reuse of open-source cloud solutions (Article 41), taking account of functionality, security and cost — an encouragement duty, not a procurement preference.
- A delegated-act power permitting the Commission to extend sovereignty risk assessment obligations to private companies in designated critical sectors. This is the sleeper provision: it would take the framework out of public procurement and into the private economy without a fresh legislative act.
4.6 The critique
From the hyperscaler side
CCIA Europe has characterised the scheme as discriminatory and unworkable, and — pointedly, given that enforcement sits with Member States — as producing fragmented discrimination twenty-seven different ways. International industry associations from the US, Canada, Japan and Australia wrote jointly to Member State governments ahead of the 8 June Telecom Council asking for revision consistent with non-discrimination, proportionality and openness. Affected providers have raised concerns with the US Commerce Department, which is reported to have begun quiet engagement with European counterparts.
From the European cloud side
CISPE, representing European infrastructure providers, welcomed the strength of Levels 3 and 4 but attacked Levels 1 and 2 as incoherent, arguing that labelling them "sovereign" institutionalises sovereignty washing precisely because US hyperscalers can meet them. The April 2026 €180 million award crystallised this: one winning bid was built on a joint venture running on US cloud technology under French defence-sector control, which CISPE called an own goal.
From the competition-economics side
Origin-based criteria at Levels 3 and 4 function as market restrictions rather than technical safeguards; they will raise costs for European public services; and restricting access to frontier compute and model APIs harms European users more than it harms American vendors — because the capability gap between frontier systems and the next best alternative is widening, not narrowing.
From the critical-scholarship side
The package attempts to serve competitiveness, sustainability and sovereignty simultaneously and cannot serve all three; and by accepting an infrastructure-and-scale framing of the problem, the Commission has already conceded the terms set by the incumbent vendors — sovereignty pursued through the same build-out logic that created the dependency.
The structural objection
Enforcement is delegated to Member States, which creates forum shopping: a provider that cannot satisfy a demanding national regulator may find a permissive one. Harmonisation by regulation, fragmentation by implementation, is a familiar European pattern.
5Semiconductors
The Chips Act 2.0
5.1 What the first Act did and did not do
The 2023 Chips Act was Europe's first coordinated response to semiconductor supply vulnerability. On the Commission's own accounting it helped mobilise more than €52 billion in public and private investment and roughly 46,000 direct and indirect jobs, and it strengthened research capacity. It did not reverse the long decline. Measured consistently by share of global semiconductor sales — the metric used throughout this paper — Europe stood at roughly a fifth of the market in the 1990s and is now around a tenth External. The European Court of Auditors projects approximately 11.7% by 2030 against the 20% political objective, and Commission officials have effectively conceded the target — noting, fairly, that the global market roughly doubled underneath them, so holding recent share was itself an achievement.
The diagnosis behind the revision is that Chips Act 1.0 subsidised supply into a market where European demand for advanced chips was thin. Fabs without customers do not become ecosystems.
5.2 The four objectives
Improving investment conditions
- Research, innovation and skills across the ecosystem; continuation of the Chips for Europe Initiative as "Chips for Europe Initiative 2.0".
- Accelerated procedures for designated European semiconductor technology initiatives and strategic projects, including a twelve-month permitting objective — a special framework, not a general deadline for all facilities.
- "Grand Challenges" for chips of key EU importance, explicitly including AI chips.
- Strategic Partnerships on Semiconductors with international partners.
Stimulating demand — the genuinely new pillar
- Demand Accelerators aligning new semiconductor products with the requirements of user industries and shortening time to market.
- In specified critical and highly critical sectors, public buyers may include resilience, security-of-supply, sustainability and other non-price requirements in semiconductor procurement — an option for covered sectors, not a universal weighting rule.
- Expanded innovation procurement aimed at European startups and scale-ups.
- Explicit synergy with CADA: data centres, cloud providers and AI gigafactories as the domestic customer base that Chips Act 1.0 lacked.
Reinforcing supply
- State aid for First-of-a-Kind projects across the whole value chain, from raw materials through to packaging.
- Strategic Projects designation unlocking EU funding and co-investment with Member States and industry — described by Commission officials as several billion euros each, blending EU, national, industrial and probably private equity capital.
- A Semiconductor Regions of Excellence label to attract regional investment.
- Signalled priority for a European open foundry for state-of-the-art manufacturing and advanced packaging, including AI chips. The proposal fixes no node; the 2–3-nanometre class commonly cited is an industry reading, not the legal text External.
Resilience and crisis preparedness
- A business-to-business Semiconductor Supply Chain Platform.
- Guidance on risk assessment for repeatedly exposed sectors.
- A crisis stage with intelligence-sharing and a revised priority-rated order mechanism — introduced in the 2023 Act, broadened and restructured here — obliging manufacturers in the Union to prioritise crisis-critical orders over existing commercial commitments, subject to crisis activation, last-resort status and necessity and proportionality tests. Joint procurement and demand aggregation mechanisms are modelled on the pandemic-era vaccine scheme.
5.3 The critique
Industry support for the direction is broad and the reservations are almost entirely about money. DIGITALEUROPE has called for €200 billion mobilised by 2035 and a dedicated EU semiconductor budget line of at least €20 billion within the European Competitiveness Fund, plus approval times under seven months. ESIA has pressed for a ten-year strategy with a dedicated budget and continuation and expansion of the Chips Joint Undertaking. Independent estimates put the public and private investment required for meaningful leading-edge capacity around €120 billion.
Against that, the Commission has stated plainly that money will be scarcer in Chips Act 2.0 than in its predecessor and that investment must therefore be more targeted. Industry association leaders have made the obvious retort in public: Europe cannot regulate its way into semiconductor capability.
A second critique concerns the crisis powers. The priority-order mechanism was among the most contested provisions in the 2022–23 negotiation of the first Act, and its broadened successor will be contested again — particularly from Member States hosting the manufacturers whose contracts would be overridden.
6The commons
The EU Open Source Strategy
6.1 The diagnosis
The strategy starts from a value-capture problem rather than a technology problem. European public and private organisations spend on the order of $300 billion a year predominantly on non-EU proprietary software and services, creating lock-in that can be weaponised. Meanwhile the European open source ecosystem produces substantial value that is captured outside Europe, and suffers from thin long-term funding, difficulty scaling from innovation to industrial deployment, fragmented visibility and limited access to public procurement.
6.2 Structure — four objectives
- Open source for tech sovereignty. Scaling the Open Internet Stack catalogue; supporting open alternatives to proprietary solutions in cloud, workplace tools, secure email and decentralised social media, with Member States and the Digital Commons EDIC; open source in the European Digital Identity Wallet, the European Business Wallet and age verification; prioritised funding in semiconductors, operating systems, cloud, AI, cybersecurity and future internet architectures.
- A vibrant ecosystem. Accelerators, legal and licensing support and procurement access for startups; a stewardship toolkit and support for EU-based steward organisations holding strategic assets; an Open Source Maintenance Instrument, critical dependency mapping and mirroring capability; skills investment.
- Open source in public administration. Procurement guidelines for open standards and fair assessment of open source bids; strengthening the Commission's Open Source Programme Office and the public sector OSPO network; common security baselines for Commission repositories; openness and sovereignty-by-design embedded in digital investment decisions.
- Standards and international outreach. Promoting EU open source solutions abroad; uptake of EU-grown tools in partner countries; integrating open source communities into standardisation, including via revision of the Standardisation Regulation.
6.3 What it can and cannot do
It will not produce a European frontier model, and does not claim to. The picture as of 27 July 2026 — the assessments in this subsection are time-stamped to that date and rest on project documents and public reporting: OpenEuroLLM, funded at roughly €37 million under Digital Europe, has been compute-constrained and its models are not expected at frontier scale; the EUROPA project targets delivery in late 2027 to 2028; Mistral is the credible European commercial lab but its frontier models are not fully open-weight. The gap is not talent or data curation — Europe is competitive on both — it is compute.
Two uncomfortable observations follow. First, open weights are not sovereignty if you cannot afford to serve them; the constraint is inference capacity, not licence terms. Second, the strongest permissively licensed open-weight models available to European deployers today are substantially Chinese. Adopting them is dependency substitution, not dependency elimination — and the provenance questions that apply to American models apply to Chinese ones with different valence but equal force.
What it does deliver is exit. The honest value proposition of open source in this package is switching capability, auditability, and an anti-lock-in layer in the domains where the capability gap is small — workplace productivity, collaboration, identity, public administration tooling. That is a real and worthwhile objective, and it is achievable at the scale of funding contemplated. It is simply not the objective the word "sovereignty" implies to most listeners.
7The physical constraint
The Strategic Roadmap for Digitalisation and AI in Energy
The least discussed component and, on a ten-year view, possibly the most binding constraint on everything else in the package.
7.1 Two goals in tension
The roadmap, adopted as COM(2026) 501 and led by Energy Commissioner Dan Jørgensen, pursues two objectives that pull against each other, and it is more candid about this than most Commission documents.
AI for energy
Accelerating digital and AI solutions in electricity grid optimisation, energy efficiency in buildings and industry, and demand-side flexibility — including European sovereign AI solutions for critical energy infrastructure. The flagship here is AI.grids, a community of practice launched at the signature event to develop pan-European AI foundation models for grid management and planning, built on Horizon Europe testing and experimentation facilities.
Energy for AI
Integrating data centre load into the energy system without destabilising it. The International Energy Agency estimates data centres will account for more than 20% of electricity demand growth in advanced economies by 2030, with EU installed data centre capacity projected to grow from approximately 12 GW in 2025 to around 28 GW by 2030 External — before accounting for CADA's ambition to triple capacity.
7.2 Mechanisms
- Voluntary tripartite agreements between public authorities, data centre operators and energy parties covering grid integration, clean energy supply, flexibility and energy performance. Fourteen European industry associations signed a declaration of intent at adoption, with six companies signing a supporting declaration; the model agreement is due in the second half of 2026.
- Grid connection transparency with a use-it-or-lose-it principle, to stop speculative queue reservation — a quietly important measure, since phantom connection requests are currently distorting grid planning across several Member States.
- Better use of power purchase agreements and additional clean generation; waste heat recovery; market-based flexibility instruments; flexible connection agreements; optimal siting.
- A framework for cross-border energy data exchange: assessment in 2026, development from 2027.
- Horizon Europe 2026–27 allocations of roughly €100 million for advanced smart grids, €75 million for AI energy applications and a further €190 million for digital solutions in renewables, smart buildings and efficiency, against roughly €1 billion committed to energy systems, grids and storage across the programme.
7.3 The critique
The core instrument is voluntary, and the Commission has already signalled it is considering a dedicated binding instrument — which tells you what it expects. The funding numbers are modest against externally estimated grid investment requirements exceeding €1.2 trillion between 2024 and 2040 External, of which the larger share is distribution rather than transmission. And the structural fact underneath everything is that European electricity is more expensive than American or Chinese electricity, which is precisely the input cost that determines where compute capacity gets built. A roadmap cannot fix that.
One further point worth registering: putting AI foundation models into grid management is a critical-infrastructure decision with its own sovereignty logic. A stakeholder submission to the consultation put it bluntly — having lost the language-model contest, Europe risks permanent dependence on foreign models operating its energy infrastructure. AI.grids is the answer to that concern, and it is at present a community of practice rather than a capability.
8The unwritten chapter
Money
Neither proposal carries an industrial financing envelope commensurate with its ambitions. Both do carry legislative financial statements — implementation budgets, not investment: for CADA, roughly €54.3 million in operational and €25.2 million in administrative appropriations over 2028–34; for Chips Act 2.0, about €90 million in total Proposal. The absence of an investment envelope is not an oversight; the Commission has said explicitly that the semiconductor allocation awaits the outcome of the 2028–34 Multiannual Financial Framework negotiation. The relevant numbers currently in play:
| Instrument | Scale and status |
|---|---|
| MFF 2028–34 | Commission proposal of close to €2 trillion, against roughly €1.2 trillion in the current period. Under negotiation. |
| European Competitiveness Fund | Approximately €409 billion proposed for competitiveness — about €451 billion when Horizon Europe research funding is included — consolidating fragmented instruments, with an explicit European preference orientation and an intended mobilisation above €1 trillion including private capital Commission. The digital line sits at around €51.5 billion; Parliament's draft report has floated specific envelopes for technology infrastructure and digital leadership. |
| InvestAI | €200 billion mobilisation target announced at the Paris AI Action Summit, including a €50 billion top-up and a dedicated €20 billion facility for four to five AI gigafactories. |
| AI Gigafactories | Roughly 100,000 advanced accelerators each. An informal expression-of-interest call produced 77 proposals across 16 Member States and 60 sites; the formal EuroHPC call was expected in summer 2026. Financing assumes roughly 65–70% private capital, with EIB advisory and co-investment. |
| Industry asks | DIGITALEUROPE: €200 billion mobilised by 2035 and €20 billion ring-fenced for semiconductors within the Competitiveness Fund. Independent estimates: ~€120 billion for meaningful leading-edge capacity; ~€2 billion over seven years for the open source strategy. |
The honest summary is that the package's ambition and its funding are being decided in two different rooms on two different timetables, and the room that matters is the budget room. A tripled data centre estate, a 3-nanometre European foundry and a maintained open source commons are capital questions wearing regulatory clothing.
9Who wants what
Politics
9.1 Member States
Assessment The decisive political fact — an assessment resting on the dated record rather than any formal renunciation — is that the traditional northern European bloc of Germany, the Netherlands and Denmark, which spent years blocking French-style digital industrial policy at EU level, has largely shifted. The November 2025 Franco-German Summit on European Digital Sovereignty, the subsequent Council declaration and the June 2026 joint paper are the evidence for that reading.
On 17 June 2026, France and Germany published a joint paper defining digital sovereignty as the capability and capacity to develop, provide, use, adapt and control digital technologies, including hardware, independently and securely, with final decision-making authority over one's own processes. The paper sets out six dimensions across three categories — foundational dimensions including the capability to implement and enforce, economic capabilities, and technical and systemic capabilities — and is explicitly intended to feed the CADA negotiation. Crucially, it does not exclude non-European vendors: it states a preference for EU-headquartered providers and emphasises a strategic public procurement toolbox, but permits providers from trusted international partner states under risk-based conditions. Paris simultaneously announced a €13 billion fund for French and European technology companies.
Residual divergence: France continues to favour explicit European preference and reserved procurement shares; Germany prefers a more inclusive, risk-based construction. That axis will define the Council negotiation on Levels 2 and 3.
9.2 Parliament
CADA sits with the Internal Market and Consumer Protection committee (IMCO), with Reinier van Lanschot (Greens/EFA, Netherlands) as rapporteur, appointed early July 2026 and publicly targeting conclusion of trilogues by end-2027. Interinstitutional planning under the "One Europe, One Market" roadmap indicates Chips Act 2.0 concluding in Q2 2027 and CADA in Q4 2027. Both texts are open to substantial amendment; the Buy European question in particular is likely to return through Parliament rather than through the Council.
9.3 Industry
| Actor | Position |
|---|---|
| CISPE European cloud infrastructure providers | Supports Levels 3 and 4; attacks Levels 1 and 2 as sovereignty washing. Has campaigned for reserved procurement shares, avoidance of mega-frameworks that lock out local providers, and prioritisation of European supply chains in publicly funded cloud and AI. |
| CCIA Europe and international associations | Discriminatory, unworkable, fragmenting. Formal joint intervention with US, Canadian, Japanese and Australian counterparts ahead of the June Telecom Council. |
| DIGITALEUROPE | Supportive of the demand-side pivot in chips; focused on budget, speed and pooling of EU, national and private funding. |
| ESIA semiconductor industry | Wants a ten-year strategy with a dedicated budget line, expansion of the Chips Joint Undertaking, and coverage of the full value chain. Publicly sceptical that regulation substitutes for capital. |
| European cloud aspirants | OVHcloud has put a number on it: roughly 15% of European public-sector procurement would need to be reserved for European providers for them to reach competitive scale. |
10Washington
The transatlantic dimension
10.1 What Washington has and has not done
Notably, no CADA-specific US retaliatory measure had been publicly announced as of 27 July 2026. The US Trade Representative tracks DMA and DSA enforcement against American companies in the annual National Trade Estimate Report — including substantial fines against Meta, Apple and X — but has not acted. The US Ambassador to the EU has criticised both laws repeatedly. The immediate pressure on CADA is running through industry associations to Member States, and through reported Commerce Department engagement, rather than through tariffs.
There is also a structural resemblance worth noting: the tiered assurance model is not unlike FedRAMP, the US government's own framework for authorising cloud providers in sensitive federal contexts. The salient difference is that foreign companies can reach FedRAMP's highest tier, whereas CADA's Levels 3 and 4 are constructed such that US providers largely cannot. That asymmetry is the strongest US-side argument and it is not easily answered.
10.2 The awkward simultaneity
In the same period as the sovereignty package, the EU moved in the opposite direction on hardware. Under the EU–US trade framework, the bloc pledged to purchase at least $40 billion of American AI chips for computing centres — aspirational memorandum language with no binding allocation mechanism, no named buyer and no timetable. And on 25 June 2026, following a Council mandate process in which France initially resisted, the Commission signed the US-led Pax Silica declaration on behalf of the EU, alongside Germany, Greece and the Netherlands, bringing the initiative to 24 signatories. Sweden, Finland and Norway had already joined. The Commission secured guarantees that the declaration is non-binding, does not touch EU regulatory autonomy or internal decision-making, and is complementary to rather than a replacement for the G7 workstreams.
The obvious reading is incoherence. A better reading is stratification: Europe has decided that input dependence on allied silicon is more tolerable than control dependence on foreign jurisdiction. Chips can be stockpiled, sourced from multiple partners and, in extremis, substituted at a performance penalty. A legal instrument that reaches into a running service cannot be hedged against at all. On that reading the package and Pax Silica are consistent: sovereignty at the control layer, managed interdependence at the input layer.
Two caveats on that reading. It assumes allied chip supply is not itself weaponisable, which recent US export control practice does not obviously support. And it was arrived at, in the EU's case, through a Council process that attracted very little public debate for a structural alignment of that magnitude.
11Part II · Process
The process from here
11.1 The formal machinery
Both CADA and Chips Act 2.0 are proposed regulations under the ordinary legislative procedure (Art. 294 TFEU): qualified majority in Council, simple majority in Parliament, trilogue to reconcile the two mandates.
Council. CADA goes to the working party covering telecommunications and information society; Chips Act 2.0 to competitiveness and growth, where the first Chips Act sat. Files then rise through Coreper I to a General Approach adopted at a Telecom or COMPET Council.
Parliament. CADA is led by the Internal Market committee (IMCO) under rapporteur Reinier van Lanschot; Chips Act 2.0 goes to Industry, Research and Energy (ITRE), which led the first Act. A competence dispute is likely: cloud and AI infrastructure is classic industry-committee territory, and ITRE can be expected to contest IMCO's lead on CADA, most plausibly resolved through an associated-committee arrangement. The Civil Liberties committee (LIBE) has a claim on the data-access provisions and International Trade (INTA) on trade compatibility.
11.2 The presidency sequence, and why it matters more than usual
Opens working-party discussion on both files. Stated priorities: competitiveness, simplification, security. Also the European base of every hyperscaler affected by CADA, and a co-signatory of the 2022 non-paper opposing sovereignty requirements in the EUCS certification scheme.
Security-forward, digitally advanced, without comparable hyperscaler exposure. The likely window for a Council General Approach on Chips Act 2.0, possibly on CADA.
The trilogue presidency; the Q4 2027 target for CADA falls squarely in its term. Also a 2022 non-paper signatory.
Presidencies behave as honest brokers by convention, and Ireland will. But agenda-setting, sequencing and authorship of the compromise texts are real forms of power, and it is a genuine feature of this file's political economy — not a conspiracy — that the opening and closing presidencies are both structurally exposed to the transatlantic downside, while the least exposed of the three sits in the middle.
11.3 Four phases
- Phase 1 — Positioning (now to roughly Q2 2027). Shadow rapporteurs are appointed; draft reports are published; amendments are tabled. On a file this contested the amendment count will plausibly run to the high hundreds or beyond. In parallel, Council working parties produce successive presidency compromise texts. Most of the substance is decided here, before anything is formally voted.
- Phase 2 — Mandates (2027). Council General Approach; Parliament committee vote and plenary negotiating mandate. Chips Act 2.0 will move faster than CADA — it is less transatlantically explosive and enjoys broader Member State buy-in via the Semicon Coalition.
- Phase 3 — Trilogues (2027, possibly running into 2028). Technical then political trilogues on four-column documents; provisional agreement; Coreper endorsement; committee and plenary votes; Council adoption; publication in the Official Journal.
- Phase 4 — Implementation (2028–2030). Under the proposal, CADA enters into force twenty days after publication in the Official Journal and applies one year later Proposal; recognition arrangements and secondary rulemaking extend the practical runway well beyond that. On any plausible calendar, the first genuine Level 3 procurement under CADA is a 2029–2030 event — an implementation forecast, not a statutory date Assessment.
12Discipline
Five process observations that discipline any forecast
-
EUCS is the base rate, and it is not encouraging
The EU Cloud Services certification scheme (EUCS) has been in development for over five years. Sovereignty requirements — foreign-law immunity, EU headquarters, EU ownership — were inserted at the Commission's request, fought over at length, and stripped under industry and Member State pressure. In July 2022, seven Member States — Denmark, Estonia, Greece, Ireland, the Netherlands, Poland and Sweden — co-signed a non-paper opposing them. ENISA's scheme has still not been adopted by implementing act.
CADA is best understood as the attempt to achieve by primary legislation what certification could not achieve by technical delegation. That is a genuine strategic upgrade — the political decision is now taken openly by co-legislators rather than routed through an agency — but it also means more veto points, a public negotiation, and Washington watching. The median historical EU outcome on precisely this question is delay and dilution, and a scenario set that does not give substantial weight to that outcome is advocacy rather than analysis. Several of the 2022 non-paper signatories have since shifted position; the disposition has changed, but the structural exposure has not.
-
The MFF is the critical path, and it runs on a different decision rule
The legislative substance can be agreed by qualified majority while the money is decided by unanimity plus parliamentary consent, on a slower clock. It is entirely possible to adopt Chips Act 2.0 in 2027 with its funding line still unresolved. That decoupling is a driver in its own right, not a detail.
-
The real fight will migrate downward
The assurance criteria sit in an annex, and the operative detail follows by several distinct routes: delegated acts to modify the assurance-level annexes; implementing acts on practical recognition arrangements; and implementing decisions on associated third countries and on the assurance level assigned to particular use cases Proposal. A text can be won in trilogue and lost in this machinery. The most predictive procedural tell on the file is whether the annex powers remain delegated acts (which Parliament can veto) rather than migrating toward implementing acts (which it cannot).
-
There is a legal-basis vulnerability
CADA rests on Articles 114 and 173(3) TFEU — internal-market harmonisation plus industrial competitiveness. Provisions bearing on national security run into Article 4(2) TEU, under which national security remains the sole responsibility of each Member State. This is both a real constraint and a tactical instrument for those who want the framework weakened; Council Legal Service opinions reshape files quietly and decisively, and one on this question would be a leading indicator.
-
The simplification counter-current is real
The Digital Omnibus is running in parallel under an explicitly deregulatory mandate, and the Irish presidency has named simplification among its priorities. A Commission simultaneously cutting administrative burden and adding a certification-plus-procurement regime is in tension with itself, and CADA's compliance load is the natural target for that tension.
13Method
Scenario architecture: drivers, markers and axes
13.1 Events versus drivers: the treatment of export-control shocks
An obvious construction for a scenario set on this file would be to reserve one scenario for a repeat of the June 2026 export-control episode — a second sudden withdrawal of a frontier capability from European users. That construction is tempting and should be resisted, for three reasons.
First, such an episode is an event, not a driver. The underlying uncertainty is whether the United States continues to demonstrate willingness to exercise unilateral control over the technology stack — through export controls, sanctions reach, blocked acquisitions or trade linkage. A single episode is a symptom of that disposition, not the disposition itself. Second, assigning the shock to one scenario makes that scenario "the bad one" and flattens the remaining three into a common baseline. Third, and most importantly, the same event does not produce the same effect across worlds. In a Europe with money and supply, a second episode hardens provisions and accelerates procurement. In a Europe without them, it produces harder law and more derogation simultaneously — the legislature legislates harder precisely because buyers cannot purchase what does not exist. Identical shock, opposite operational consequence. That asymmetry is the most analytically useful thing the event can reveal, and confining it to one scenario conceals it.
There are also three reasons a second episode might not push in the direction the first one did:
- Diminishing political returns. The June episode converted the marginal sceptics; the constituency for hard sovereignty is already assembled. A second episode adds less political energy and more economic pain — and the pain argument runs the other way.
- Coupled retaliation. If a second action arrives bundled with explicit linkage — soften the framework or lose chip access — it splits the Council along exposure lines rather than uniting it. Ireland, the Nordics and central European Member States carry materially different risk profiles from France.
- Substitution direction. If a second episode drove European deployers toward Chinese open-weight models at scale, the security establishment's threat model would reorient from Washington toward Beijing, and the coalition behind Levels 3 and 4 — jurisdiction-neutral in text, US-aimed in politics — would have to be rebuilt on different terms.
Export-control episodes are therefore treated as markers — observable events that indicate which world is materialising and accelerate its internal logic — rather than as an axis. They occur in both high-pressure scenarios, with divergent consequences.
13.2 The two axes
Axis 1 — External coercion salience
Does the environment keep supplying demonstrations that dependency is dangerous — export controls, sanctions reach, service interruption, blocked acquisitions, trade linkage? Or does it stabilise: Pax Silica institutionalises, a CLOUD Act arrangement revives, the trade détente holds?
Axis 2 — European delivery capacity
Does Europe convert consensus into money, supply and procurement discipline — a funded MFF digital and semiconductor line, gigafactories built, European providers scaling, national buyers actually buying? Or does the effort remain declaratory: the MFF squeezed by defence and enlargement, providers sub-scale, procurement continuing to favour incumbents?
14The situation board
Four scenarios to Q4 2027
Select a quadrant. The matrix below carries through to the provision-landing table and the indicator board.
15The landing zone
Where the key provisions land
Fourteen provisions, four worlds — judgements of tendency under each scenario's stated conditions, Assessment throughout. "Recognised" is used in the CADA sense defined in the glossary. Use the scenario tabs to highlight a column, or expand a provision to compare all four outcomes side by side.
16What to watch
Early indicators
Observable in the next six to twelve months, and discriminating between the scenarios. The value of an indicator lies in pointing toward one world and away from another; indicators consistent with everything are decoration.
17Judgement
Relative likelihood
Scenario practice ordinarily counsels against attaching probabilities, since the purpose of the exercise is to widen the aperture rather than to forecast. That discipline is right for strategic use and unhelpful for a reader who must decide what to prepare for. Offered explicitly as judgement rather than estimate:
One observation deserves emphasis. Scenarios A and B — the two worlds toward which most participants in the debate are currently arguing — differ almost entirely in a variable that will not be settled in this negotiation at all. The package's fate is being decided in the budget room, and the parties fighting hardest over the legislative text are not in it.
18Conflicts of law
What the package collides with
The package's central mechanism is a set of criteria about what third-country law can and cannot do to a service. That makes conflict with third-country law not an incidental risk but the operating premise of the instrument. It also adds a recognition regime, an assessment duty and a procurement criterion to a body of Union law that already contains several of each.
What follows maps both: the collisions with the law of third countries and with international trade law, and the collisions inside Union law. Each entry names the instrument, states the collision, and states what resolution would require. Three severity marks are used, and they are the mapping's own: Structural no drafting fix resolves it, a policy choice is required; Resolvable a fix exists but has not been made; Watch contingent on an external event or a parallel file. Fourteen of the forty-three entries carry — no mark, because the mapping records the collision without taking a view on its gravity.
18.1 The conflicts explorer
Forty-three instruments across fourteen thematic groupings. Filter by severity, by body of law or by jurisdiction; expand any entry for the collision and what resolution requires. Selecting a severity excludes the unmarked entries, since they carry no mark to match.
18.2 Four conflicts that resist tabulation
Other third countries
Adequacy holders are the natural pool of Article 18 candidates: Japan, Korea, Israel, Switzerland, and Brazil, which received a mutual adequacy decision in January 2026. The instructive point is that several will pass the three security criteria and fail on the three trade criteria — market openness and reciprocal procurement access — because their procurement markets are not open to Union suppliers on equivalent terms. An instrument written to manage security risk would then exclude countries that pose no security risk, on grounds that have nothing to do with security. That inversion is the clearest evidence that two different policies have been placed in one article.
The missing lawful channel
The package asserts a right of refusal without offering an alternative route. The Second Additional Protocol to the Budapest Convention (2022) on enhanced co-operation and disclosure of electronic evidence is the multilateral answer to the problem the CLOUD Act solved unilaterally, and ratification remains incomplete. Mutual legal assistance channels remain slow, which is the practical justification the United States gives for acting alone.
A sovereignty framework that hardens refusal while the lawful channel stays congested increases the incentive for unilateral action rather than reducing it. Progress on the Protocol and on a § 2523 executive agreement would do more for the package's stated objective than Levels 3 and 4 combined, and would cost the Union nothing it is not already committed to.
Contract, property and private international law
The Chips Act crisis mechanism — priority-rated orders obliging Union manufacturers to prioritise crisis-critical orders over existing commercial commitments — engages Charter Article 16 (freedom to conduct a business) and Article 17 (property), and is subject to necessity and proportionality review. The mechanism dates to the 2023 Act and has never been triggered; the broadened version raises the stakes.
The under-examined dimension is private international law. A Union manufacturer ordered to deprioritise a customer's order will frequently be breaching a contract governed by non-EU law, with jurisdiction in a non-EU forum. Union law would compel the breach; it would not excuse it before a New York or English court. The Rome I regime governs the law applicable to the contract, not the enforceability of a foreign public-law command against it, and foreign courts are not obliged to treat an EU regulation as an excuse. The 2023 Act did not solve this; the revision should, through express provision for compensation and, ideally, coordination with partner jurisdictions on mutual recognition of crisis measures.
Internal sequencing and the simplification agenda
- Level 4 depends on EUCS High, which does not exist and may not.
- Level 3 demand depends on Level 3 supply, which depends on capacity the Chips Act is meant to build with money that has not been allocated.
- Exit rights arrive before the framework that should have incorporated them. Data Act switching applies from January 2027; CADA assurance from roughly 2029.
- Three successive compliance waves on one estate. The AI Omnibus defers AI Act high-risk obligations while CADA adds new obligations to the same systems.
- CADA's referents are moving during CADA's negotiation. The Digital Omnibus is amending the GDPR, the Data Act, NIS2 and the ePrivacy Directive while CADA cross-refers to them.
- Simplification against addition. One Commission agenda is removing administrative burden; this package adds a recognition regime, an assessment duty and a procurement criterion. Both are being negotiated in the same institutions in the same period, and the Irish presidency has named simplification among its priorities.
Source
Legal mapping, July 2026: Conflicts of Law in the European Technological Sovereignty Package — position as at 27 July 2026. Parts I and II are reproduced here in full; the ranked shortlist follows as section 19.
19Before adoption
The shortlist of ten
Ten conflicts ranked by how far they determine whether the package works at all, rather than by legal elegance. Assessment
AAnnex
Measuring success
The package will be judged on announcements unless better metrics are proposed. A defensible set, chosen because each is observable and each is hard to game:
- Share of public contracts actually awarded at Level 2 or above to EU-controlled providers. Contracts signed, not spend announced.
- Frequency and grounds of Article 30 derogations, published — publication itself being a reform, since the proposal does not require it. The single best health indicator for the whole framework.
- Count of providers recognised at Levels 3 and 4, and their revenue growth. A supply-side measure — a framework with no qualifying suppliers is a wish.
- Measured workload exit time. How long it actually takes a public body to move a live workload between providers. Sovereignty that cannot be executed is not sovereignty; the discipline of periodic exit drills, on the model of bank resolution planning, would make the capability real.
- Permitting outturn against the twelve-month statutory maximum, and gigawatts connected versus gigawatts queued under the use-it-or-lose-it principle.
- Funded maintainer-hours on mapped critical open source dependencies. The only number that distinguishes open source as a resilience strategy from open source as a licensing preference.
- For semiconductors: not market share. European share of irreplaceable inputs — lithography, metrology, materials, packaging — and whether Demand Accelerators generate signed offtake agreements rather than memoranda.
BAnnex
Timeline and key dates
CAnnex