Skip to main content

© European Union, 2026

On 3 June 2026, the European Commission adopted the Technological Sovereignty Package — a suite of four interlinked measures to reduce the EU’s structural dependence on non-EU providers across the digital technology stack. The package follows three postponements since March 2026, driven partly by US pressure over perceived protectionism.

The package comprises: The Chips Act 2.0 and the Cloud and AI Development Act (CADA), both Regulations requiring Parliament and Council agreement; the EU Open Source Strategy; and the Strategic Roadmap for Digitalisation and AI in Energy. Together, they aim to build what the Commission calls a full ‘European technology stack’ — from silicon to cloud to software to energy infrastructure.

By Eda Aygen, Partner at SoWhatCommunications Powered by Square Circle

The revised Chips Act moves beyond production alone to support both supply and demand. Europe still produces less than 10% of global chips and depends heavily on the US and Asia for advanced technologies, particularly those used in AI. The main initiative is to build a large, advanced semiconductor plant in Europe capable of producing cutting-edge chips, with pilot production expected around 2030–2033. Public procurement and large-scale innovation programmes will stimulate demand for EU-made chips, while expanded supply chain monitoring and crisis planning will improve resilience against future disruptions. Overall, the goal is to produce more advanced chips in Europe, reduce dependence on foreign suppliers, and strengthen resilience to future disruptions.

Non-European hyperscalers hold over 70% of the EU cloud market, while European providers’ share has fallen from 29% in 2017 to 15% in 2022 and stagnated since. CADA seeks to reposition Europe as a sovereign hub for cloud and AI. At its core is a four-tier cloud sovereignty assurance framework, with levels determined by: control over the service and software supply chain; governance of AI inference data; location of infrastructure and key personnel; and cybersecurity compliance. Public authorities must conduct sovereignty risk assessments for each use case, supported by Commission guidance.

CADA also creates Data Centre Acceleration Zones — designated areas with streamlined permitting and reliable energy access — aiming to triple EU data centre capacity within five to seven years, backed by an estimated €200 billion in predominantly private investment by 2035. A Cloud and AI Leadership Initiative drives research in energy-efficient computing, frontier AI and industrial AI. Public procurement is reformed through EU-added-value non-price award criteria, and anti-sovereignty-washing provisions make misleading sovereign cloud claims legally actionable.

Today, the EU spends around €264 billion every year, mostly on proprietary (closed) IT solutions from large, mainly US-based companies. The Open-Source Strategy aims to reduce this dependence by building strong European alternatives based on open-source technologies across the whole digital stack.

The plan is to significantly increase the use of European open-source tools, with a target of 30 million active users by 2030, particularly for collaboration and workplace software. To make this happen, the EU will:

  • create a new funding tool (the Open-Source Maintenance Instrument) to support and secure critical open-source projects over time,
  • update public procurement rules to encourage public authorities to prefer open-source solutions where possible (“open-source-first”),
  • launch a catalogue of trusted European open-source tools (the Open Internet Stack) to make solutions easier to find and use,
  • and support companies through business accelerators to help open-source projects grow and scale.

The strategy focuses especially on key technologies where Europe wants to reduce dependencies, such as:

  • AI models and tools,
  • operating systems,
  • cloud software,
  • and cybersecurity solutions.

Overall, around €2 billion will be invested over seven years.

Data centres in Europe are growing very fast. By 2030, their total capacity is expected to more than double, which will put a lot of pressure on electricity grids and climate goals. The EU’s roadmap aims to manage this growth so that digital development supports (rather than harms) the energy transition.

The plan is built around three main pillars and will start quickly, with some actions already planned from 2026.

  • The first pillar focuses on making sure energy systems can support AI and data centres. The idea is to improve cooperation between data centre operators, energy companies, and public authorities. A model agreement will be introduced to help them work together on issues such as connecting to the grid, using clean energy, recovering waste heat, and being flexible with energy use. At the same time, the EU will introduce a rating system to measure how sustainable data centres are, and later develop minimum performance standards.
  • The second pillar looks at how AI can improve the energy system itself. The EU plans to speed up the rollout of smart meters and make electricity grids “smarter”. It will also invest in developing AI tools that help manage electricity networks more efficiently—for example by predicting demand or avoiding congestion. Early versions of these tools are expected by 2027.
  • The third pillar focuses on data. Today, energy data is often fragmented and difficult to use across borders. The EU wants to create a simpler system that allows data to be shared more easily between countries. This will help companies provide smart energy services and allow AI models to be trained on better and larger datasets.

This package will affect a wide range of companies — essentially any business that uses cloud services, works with digital infrastructure, relies on electronic components, operates energy systems, or sells to public authorities in the EU.

Across all sectors, five major changes are likely.

  1. Companies will increasingly need to carry out “sovereignty risk assessments”. This means checking whether the cloud services they use meet EU requirements on security, control and data location. In practice, this becomes a new compliance step, similar to existing financial or IT outsourcing rules, but applied much more broadly across industries.
  2. Public procurement rules are changing. When governments buy digital services, they will look not only at price, but also at how “European” and secure the solution is. At the same time, there will be a push to favour open-source solutions. This means that companies offering non-EU or fully proprietary products may find it harder to win public contracts, and will need to rethink their positioning.
  3. There will be more focus on supply chain transparency. Companies will need to provide clearer information about where their hardware and software come from, especially if they are used in critical systems. This is particularly important for sectors like infrastructure, defence, energy, and telecoms.
  4. Sustainability requirements will increase. Data centres and digital infrastructure will be measured against EU environmental standards. Over time, this will not only affect operators but also the companies using these services, which may face new expectations around energy efficiency and carbon footprint.
  5. Open source becomes more important. It will move from being just one option to becoming the preferred (and sometimes expected) approach, especially in public sector projects. Companies relying only on proprietary technologies may face growing disadvantages in procurement and potential reputational risks.

In simple terms, the direction is clear: more control, more transparency, more sustainability — and a stronger preference for European and open digital solutions.

This package is as much about global politics as it is about technology. Three forces drive it: Technology has become a geopolitical tool, particularly in US-China rivalry; the EU remains heavily dependent on non-European providers for most of its digital infrastructure; and the rapid rise of AI means that decisions made now will shape market control for the next decade.

The package has already created transatlantic tensions, having been delayed three times following US concerns over its cloud sovereignty provisions. The Commission has nonetheless been clear: Europe must ensure no single provider can effectively switch off its critical systems.

Within the EU, France and Germany strongly support the ambition, while Ireland and Luxembourg — which host many US tech companies and data centres — are more cautious. This matters particularly because Ireland takes over the Council Presidency in July 2026. Central and Eastern European countries are less focused on cloud sovereignty but broadly supportive of the semiconductor measures, given their automotive sector exposure.

The Technological Sovereignty Package should be understood as the starting point of a multi-year strategic reorientation of the European technology landscape, rather than a set of measures with immediate, fixed outcomes. The most consequential elements will be determined downstream—through the positions taken by the European Parliament, the red lines that emerge in Council from the Member States, and, critically, in the technical detail of implementing acts and procurement frameworks.

For businesses, the implication is that the window for influence remains open but is narrowing quickly. This is particularly true around how concepts such as “sovereignty”, “trusted providers” and “EU-added value” are ultimately defined and operationalised. These definitions will shape market access conditions for the next decade—especially for cloud, AI, cybersecurity, and infrastructure-related activities.

At a strategic level, the key question is not only how the package affects compliance or market positioning in the short term, but how companies are perceived within this emerging policy narrative. The EU is actively distinguishing between actors it sees as enabling its technological sovereignty and those it views as creating structural dependencies. That framing will increasingly inform procurement decisions, regulatory expectations, and political engagement.

In that context, early and sustained engagement—both at EU and Member State level—will be important to ensure that your capabilities, contributions, and value proposition are clearly understood and reflected in the evolving legislative and implementation framework.

  • June–July 2026: The European Parliament starts work on both laws and appoints lead MEPs. It will be important to see who they are and what their political views are.
  • 1 July 2026: Ireland takes over leadership of the Council. Its priorities will strongly influence how quickly discussions move forward.
  • Second half of 2026: The Commission begins rolling out the first concrete measures (e.g. data centre rules, guidance on sovereignty, smart meter proposal). This is an early moment where companies may start seeing real requirements and can still influence details.
  • Early 2027: The Parliament and Member States each agree on their positions. This is a key stage where major issues will be negotiated, especially on cloud sovereignty and chips policy.
  • Mid-2027: The EU publishes its semiconductor crisis plan.
  • Second half of 2027: Final negotiations between Parliament and Member States begin. At this stage, it becomes much harder to make major changes.
  • 2027–2028: The laws are likely to be adopted. After that, detailed rules will follow, and concrete obligations for companies will start to apply.

If you’re interested to have more information on this field of expertise, don’t hesitate to contact Eda Aygen, partner at SoWhatCommunications powered by Square Circle.

Contact us:   info@sowhatcoms.com

More information: www.sowhatcoms.comwww.squarecircle.be