Europe’s Tech Sovereignty Moment: from Digital Dependence to Strategic Capacity

The European Commission’s new Communication on European Tech Sovereignty marks a significant shift in the EU’s digital policy agenda. The message is clear: Europe can no longer rely primarily on regulation, resilience, and risk mitigation. It must now build, control, and scale the technologies that underpin its economy, security, and democratic life.

The Communication starts from a stark diagnosis. The EU remains heavily dependent on non-European providers for digital products, services, infrastructure, and intellectual property. In areas such as semiconductors, cloud computing, AI infrastructure, data centres, and software ecosystems, these dependencies are no longer merely economic. They have become strategic vulnerabilities, especially in a geopolitical environment where supply chains, export controls, data access, and digital infrastructure can be weaponised.

The Commission defines technological sovereignty as Europe’s ability to develop and control critical technologies, infrastructure, services, data, and digital ecosystems, while reducing excessive dependencies and maintaining openness to global cooperation. Sovereignty, in this sense, does not mean protectionism or technological isolation. It means having credible European capabilities, diversified supply chains, and effective control over sensitive infrastructures and data.

The package rests on four major initiatives.

First, a Chips Act 2.0 is designed to strengthen Europe’s semiconductor ecosystem, including advanced chip production, supply-chain resilience, and demand for EU-designed and EU-made chips. The Commission recognises that Europe’s current share of global semiconductor production remains limited and that chips are essential for AI, automotive, energy, defence, healthcare, and industrial systems.

Second, the Cloud and AI Development Act aims to increase Europe’s cloud and AI infrastructure capacity. It seeks to reduce reliance on non-EU hyperscalers, support sovereign cloud solutions, and introduce sovereignty assurance levels for cloud computing services. Public authorities and EU entities would assess sovereignty risks and determine which level of assurance is necessary for specific use cases.

Third, the Communication includes an EU Open Source Strategy. This is one of the most politically interesting parts of the package. The Commission treats open source not merely as a technical model, but as a strategic instrument for sovereignty. Open source can reduce vendor lock-in, improve auditability, support cybersecurity, and foster European digital ecosystems. The strategy proposes support for open source building blocks, public-sector adoption, open source stewardship, maintenance funding, skills development, and stronger links between open source communities and standard-setting processes.

Fourth, the package includes a Strategic Roadmap for Digitalisation and AI in the energy sector, together with measures on data-centre sustainability. This reflects a central tension in Europe’s digital future: AI, cloud infrastructure, and data centres require vast amounts of energy. Technological sovereignty therefore depends not only on chips and software, but also on clean, affordable, and resilient energy systems.

The Commission’s approach is explicitly “ecosystem-based.” It combines supply-side measures, demand-side tools, strategic projects, skills, funding, public procurement, regulatory simplification, and international partnerships. This is important because Europe’s digital dependency problem cannot be solved through isolated interventions. Building a European technology stack requires coordination across hardware, infrastructure, software, cloud, AI, data, standards, and skills.

The open source dimension deserves particular attention. The Commission notes that Europe has a strong community of open source contributors and successful companies, but that the ecosystem often lacks long-term funding, procurement access, maintenance structures, and market visibility. The strategy therefore seeks to make the public sector an anchor customer for open source solutions, promote the “public money, public code” principle, and support open digital assets for administrations.

The broader political significance is that the EU is moving from a primarily regulatory identity toward a more industrial and infrastructural understanding of digital power. The Digital Services Act, Digital Markets Act, AI Act, Data Act, Cyber Resilience Act, and Digital Identity framework remain central. But the Commission now recognises that rules alone are insufficient if Europe lacks the technological base needed to implement, enforce, and benefit from them.

The challenge will be implementation. The investment needs are enormous: semiconductors, AI infrastructure, data centres, open source maintenance, clean energy, and digital skills all require sustained financing. The Commission therefore points to the future European Competitiveness Fund, stronger capital markets, public-private investment mechanisms, and possible new equity capacity for strategic technologies.

The Communication’s underlying argument is persuasive: Europe must remain open, but it cannot remain structurally dependent. It must cooperate globally, but from a position of technological capacity rather than vulnerability. It must regulate digital markets, but also build competitive alternatives. And it must defend European values not only through law, but through infrastructures, standards, code, and industrial capability.

In this sense, the technological sovereignty package is not just another digital policy initiative. It is an attempt to redefine Europe’s place in the global technology order. Its success will depend on whether the EU and its Member States can move quickly from strategic language to operational capacity.


Leave a Reply