Article

By

Darren Smith

Europe's Digital Declaration of Independence — What the Tech Sovereignty Package Means for Business

Brussels has unveiled the most ambitious overhaul of European technology policy in a generation. Here is what the Tech Sovereignty Package means for your business.

European Union flags flying outside parliament building

Europe has never forgotten that dependency on foreign critical infrastructure is a strategic vulnerability. When oil-producing nations demonstrated they could weaponise supply chains in 1973, the response was decades of attempts at diversification, strategic reserves, and eventually investment in alternatives. The next dependency Europe must break is not oil. It is digital.

On 3 June 2026, Brussels unveiled the most ambitious overhaul of European technology policy in a generation. The European Technological Sovereignty Package — comprising the Cloud and AI Development Act (CADA), the Chips Act 2.0, an EU Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy — is not a regulatory adjustment. It is a structural declaration of intent: Europe intends to own its digital infrastructure, or at least control it well enough that no external power can hold it hostage.

For business leaders across the UK and Europe, the question is how this matters, how quickly the landscape will shift, and whether your organisation is positioned to adapt.

The Dependency Problem

The numbers are stark. Europe currently relies on non-European suppliers for over 80 per cent of its digital products and services. Cloud infrastructure is dominated by three American hyperscalers. Advanced semiconductor manufacturing is concentrated in Taiwan and South Korea. The AI models reshaping every industry are trained on American platforms, using American chips, hosted on American-owned data centres — even when those data centres sit on European soil.

This is not a theoretical risk. The Draghi Report on European Competitiveness, published in September 2024, framed it as an existential threat to European autonomy. When hospitals run on foreign cloud platforms, when energy grids depend on foreign AI systems, when government services are underpinned by foreign-controlled infrastructure, the leverage extends far beyond commerce. It becomes a matter of strategic vulnerability.

The Tech Sovereignty Package is Brussels’ answer — not with tariffs or trade barriers, but with a comprehensive industrial strategy designed to build European capacity from the silicon up.

What the Package Actually Contains

Think of the Package as four interlocking investments, each addressing a different layer of the technology stack.

At the foundation sits the Chips Act 2.0. The original Chips Act, enacted in 2023, mobilised over €52 billion in public and private investment and created an estimated 46,000 jobs. But it focused primarily on supply — building manufacturing capacity. The revised Act shifts the balance to demand. It introduces ‘Demand Accelerators’ connecting European chip producers with industrial buyers, accelerates permitting to a maximum of 12 months, and targets €120 billion in investment by 2035. The semiconductor market is expected to reach €1.37 trillion by 2030, with AI-related components driving roughly 70 per cent of that growth. Europe’s ambition is not to compete with TSMC or Samsung on volume, but to become indispensable in specific segments — automotive, industrial, and AI-optimised chips — where European demand can sustain European production.

The centrepiece is the Cloud and AI Development Act (CADA). This is where the political ambition becomes most concrete. CADA aims to triple the EU’s data centre capacity within five to seven years — an infrastructure build-out comparable in scale to Europe’s post-war energy programme. But it is not merely about capacity. CADA introduces a four-tier sovereignty assurance framework for cloud services, ranging from basic data residency (Level 1) to full EU ownership and control with no third-country interference (Level 4). Public authorities handling sensitive data will be required to assess the sovereignty risk of their cloud providers — a mechanism modelled on France’s SecNumCloud regime, now extended across the Union.

Alongside these two legislative proposals sit the EU Open Source Strategy, promoting the adoption of open-source solutions across cloud computing and AI, and the Strategic Roadmap for Digitalisation and AI in Energy, which outlines how AI can be integrated into Europe’s energy grids to enhance efficiency and sustainability.

The legislative proposals must clear the European Parliament and the Council before becoming law, with a target agreement window of Q4 2027. But the direction is unambiguous.

How the Sovereignty Framework Works in Practice

The four-tier assurance system deserves particular attention, because it will shape procurement decisions across the European public sector for years to come.

At Level 1, providers must demonstrate data residency within the EU. Level 2 adds supply-chain independence from third countries — ensuring that critical components and subprocessors are not subject to foreign jurisdiction. Level 3 requires EU-domiciled ownership and control. Level 4 — the most stringent — demands complete supply-chain transparency with no third-country interference whatsoever. This is the baseline for defence sector workloads.

Member States will conduct risk assessments to determine the appropriate assurance level for cloud providers serving critical public functions. The Commission retains the power to identify third countries whose providers may be subject to audit against the framework. For businesses selling to the European public sector — or to regulated industries such as banking, healthcare, and energy — these assurance levels will become a defining feature of the competitive landscape.

What This Means for UK Businesses

The implications for British companies are layered. The UK is no longer an EU member state, but it remains deeply integrated into European digital supply chains. Any UK firm providing cloud services, AI solutions, or digital infrastructure to EU-based clients will need to understand the sovereignty framework — and potentially restructure operations to meet its requirements.

For UK-based technology companies, there are both challenges and opportunities. The compliance burden is real. But the infrastructure build-out — tripling data centre capacity across the EU — represents one of the largest digital investment programmes in a generation. Companies positioned to support that expansion, whether through hardware, software, consulting, or integration services, will find significant demand.

The broader shift is towards what the Commission describes as ‘ecosystem sovereignty’ — not isolation, but the creation of a European layer of control and oversight atop the global technology stack. For business leaders, this means that the default assumption of open, vendor-neutral digital infrastructure is giving way to a more fragmented, jurisdiction-aware landscape. The question is not whether to engage with it, but how to do so strategically.

The Philosophical Shift

What makes the Tech Sovereignty Package significant is not its regulatory ambition — Brussels has never lacked for that. It is the underlying recognition that digital infrastructure is no longer a utility. It is a strategic asset.

For decades, the cloud was treated as plumbing — invisible, interchangeable, and fundamentally neutral. The assumption was that a data centre in Dublin was functionally identical to one in Virginia. CADA dismantles this assumption. It asserts that the legal jurisdiction, ownership structure, and supply-chain dependencies of cloud infrastructure matter — not just for compliance, but for national security and economic resilience.

This is the same shift that occurred in energy policy after 1973, when oil-producing nations demonstrated that critical infrastructure could be weaponised. Europe spent the subsequent decades building strategic reserves, diversifying supply, and investing in alternatives. The Tech Sovereignty Package applies the same logic to digital infrastructure. The dependency is acknowledged. The response is underway.

For business leaders, the lesson is that technology strategy can no longer be separated from geopolitical strategy. The platforms you choose, the infrastructure you depend on, the supply chains you maintain — these are no longer purely commercial decisions. They are strategic choices with regulatory, legal, and geopolitical dimensions.

The Question You Should Be Asking

The legislative process will take time. The infrastructure build-out will take longer. But the direction is set, and the organisations that begin positioning now — understanding the sovereignty framework, evaluating their infrastructure dependencies, and aligning their European strategy — will be the ones that capture the advantage when the new landscape takes shape. The question is no longer whether Europe will pursue digital sovereignty. It is whether your business will be part of building it, or scrambling to adapt to it.