Europe’s Sovereignty Stack: CADA, Compute, and the Limits of Autarky
Executive Summary
This issue brief examines the European Commission’s proposed Cloud and AI Development Act (CADA). The Act pursues a legitimate goal: reducing Europe’s dependence on foreign cloud and artificial-intelligence infrastructure. The proposal also has important strengths. It is formally risk-based, focused on public-sector procurement, and paired with a permitting fast-track for data-center construction.
But CADA’s highest assurance levels risk confusing sovereignty with insulation from non-EU law, ownership, and supply chains. That insulation is not realistically available for the cloud and AI services Europe most needs. Advanced chips, frontier AI models, critical software, financing, and energy infrastructure remain deeply embedded in allied and global supply chains.
CADA’s top tiers should therefore require stronger security, not a narrower focus on nationality. Ownership and citizenship tests should give way to technical and organizational safeguards: customer-held encryption keys, zero-retention architectures, data-in-use protections, personnel screening and clearance, migration plans, anti-tamper controls, and multi-cloud portability.
The proposal should also distinguish adversaries from allies. The relevant question is not whether a provider is non-EU, but whether its home state is likely to weaponize it against Europe and whether the provider can meaningfully resist. Article 18 should be retargeted accordingly.
Finally, Europe cannot procure or certify its way to frontier capability. The durable path to sovereignty is to build leverage: more compute capacity located in Europe, governed by European law, and deployed at sufficient scale that dependence with allies becomes mutual. That requires grid-connection reform, deeper capital markets, a workable pan-EU corporate form, and better tax treatment for employee equity.
I. Introduction
The European Commission has proposed the Cloud and AI Development Act (CADA), the legislative centerpiece of its European Technological Sovereignty Package, alongside a Chips Act 2.0. CADA seeks to create demand for EU-native cloud services, while Chips Act 2.0 aims to increase Europe’s supply of domestically produced semiconductors.
Together, these measures seek to reduce Europe’s dependence on foreign technology. That is a legitimate and important objective. But CADA’s highest assurance levels—its most demanding tiers for cloud services used in sensitive public-sector contexts—risk confusing sovereignty with insulation from the outside world. For the cloud and artificial-intelligence (AI) services that matter most, such insulation is not realistically available.
CADA begins from a risk-based premise. Its requirements apply formally to the public sector, and its Buy European procurement preference is ancillary by design. But the act also creates incentives to push more workloads toward the highest assurance levels. The Commission estimates that only about 10% of public-sector use cases would require those levels. In practice, that share may grow, and the pressure may spill over into private markets.
The stakes are significant because, at the highest levels, CADA treats sovereignty as freedom from third-country control, foreign legal compulsion, and operational dependence. In effect, it asks cloud providers to demonstrate that non-EU governments and non-EU supply chains cannot affect their services. No provider of major cloud or AI workloads can credibly make that promise.
The problem is not limited to where a provider is incorporated or who owns it. For many high-value workloads, the relevant risks turn on leverage: who controls essential chips, software, AI models, facilities, power, financing, and legal chokepoints. Even a fully EU-based company may face foreign legal process, as OVH did in Canada, or may be exposed to foreign mandates because it depends on foreign hardware, software, or other critical inputs.
Those dependencies are especially important for AI clouds—cloud infrastructure used to train, host, or run AI models. The EU package partly acknowledges the semiconductor problem, but its proposed solution would arrive only in the 2030s. It does far less to confront the gap between U.S.-based frontier AI laboratories and everyone else. Frontier AI models are the most capable systems at the leading edge of development. Today, the leading labs are mostly American, and they invest at a scale and speed that European competitors have not matched.
The EU strategy therefore appears to rest on a contested premise: that building more compute capacity in Europe will allow EU-developed AI models to reach the frontier. Compute capacity—the data centers, advanced chips, and electricity needed to train and run AI systems—is necessary. But it is not sufficient. The package offers little reason to believe Europe will match future frontier AI capabilities, rather than continue to lag behind a frontier that is moving quickly and backed by much larger investment elsewhere.
The responsible course is not technological autarky. The Commission itself acknowledges that Europe cannot isolate itself from global technology markets. Dependence is inevitable. The policy objective should be to make that dependence more secure, more diversified, and more mutual, especially with allied democracies.
The risks became concrete on June 12, when a U.S. export-control directive forced Anthropic, a leading American AI lab, to cut every non-U.S. user—including allied users—off from its two state-of-the-art models overnight.[1] No ownership rule, Level 4 certificate, or EU-citizen staffing requirement would have preserved that access. The decisive layer was not cloud procurement. It was control over the best AI models, a layer upstream of CADA’s main regulatory tools.
The lesson is not that Europe can build its own frontier models on any timeline relevant to current policy. It likely cannot. Europe’s more durable source of leverage lies in building the infrastructure on which frontier AI depends: data centers and power, located in Europe, governed by European law, and deployed at sufficient scale that foreign partners would incur real costs by cutting Europe off. In other words, Europe should seek to make technological dependence mutual rather than mistake ownership labels for sovereignty.
Country-of-origin rules do have a legitimate role, but the relevant distinction is between adversaries and allies, not between EU and non-EU providers as such. The key question is whether a provider’s home government is likely to weaponize that provider against Europe, and whether the provider would meaningfully resist.
That distinction matters. A European or American firm ordered to act against an ally may be expected to resist, litigate, appeal, and delay. A firm answerable to a nondemocratic adversary government is less likely to have those options. CADA should therefore sort providers along the ally/adversary line, not the EU/non-EU line.
Once a non-EU jurisdiction is recognized as an ally, CADA should focus on technical and organizational safeguards that reduce concrete risks to confidentiality and availability. These include encryption, customer-held keys, access controls, personnel screening, service-continuity planning, portability, and other measures that make data harder to access and services harder to disrupt. Those safeguards should apply equally to EU-native firms and allied foreign providers.
The package’s “build” agenda also remains incomplete. Its headline 12-month permitting clock excludes the steps that most often constrain data-center construction: environmental review and power-grid connection. The package also does little to address capital, corporate law, and taxation, even though those are among the largest obstacles to scaling European firms, particularly startups.
This issue brief develops those points in seven steps. Section II explains CADA’s risk-based structure and the upward pressure built into its assurance levels. Section III shows why the top tiers promise more immunity from foreign control than cloud and AI providers can deliver. Section IV argues that CADA should distinguish allies from adversaries rather than EU from non-EU providers. Section v explains why demand-side procurement preferences cannot substitute for real capacity. Section VI turns to the build agenda, including permitting, grid connection, capital markets, and compute infrastructure. Section VII offers concrete recommendations. The conclusion returns to the central claim: European sovereignty in cloud and AI will come less from excluding allied providers than from building capacity, hardening systems, and making dependence mutual.
II. CADA’s Risk-Based Promise—and Its Sovereignty Trap
CADA begins from a sound premise: not every public-sector cloud use is equally sensitive, and not every risk requires an EU-only response. Section II.A explains that basic risk-based structure. Section II.B shows why that structure may be unstable in practice, as political incentives, incumbent pressure, and CADA’s own procedures may push more workloads toward the higher assurance levels. Section II.C examines the legal consequences of that shift, showing how the top tiers move from managing concrete risks to policing ownership, corporate control, software dependence, and personnel nationality. Section II.D then asks what an EU-only circle of trust can realistically achieve for the narrow set of government functions where such an approach may be coherent—and what costs it would impose.
A. CADA Starts with a Sensible Risk-Based Frame
On June 3, the European Commission proposed the Cloud and AI Development Act (CADA), the legislative centerpiece of its European Technological Sovereignty Package. The package also includes Chips Act 2.0, an EU Open Source Strategy, and an energy-digitalization roadmap.[2] In a recent ICLE issue brief,[3] I argued that the European Union should approach AI-cloud sovereignty on a risk-based basis, rather than through categorical exclusions, and that a more ambitious conception of sovereignty—“immunity from non-EU law”—would impose costs on European AI users without delivering the immunity it promises.
CADA deserves credit for its basic structure. At least on paper, it is not a bloc-wide “European-only” rule. The regime is risk-based in principle, and it does not directly bind private commercial cloud purchases. As discussed below, however, that limitation may be less significant in practice than it first appears.
The act establishes “a Union cloud computing sovereignty framework comprising four Union assurance levels” under Article 16, with the substantive criteria set out in Annex II. These assurance levels are tiers of required safeguards: the higher the level, the more demanding the sovereignty, security, and control requirements. The levels are not supposed to apply uniformly. Member states and EU institutions must conduct periodic risk assessments under Article 29 to identify which public-sector activities affect “the preservation of public order” and determine which assurance level is appropriate.
The lowest tier is the default. Public bodies whose activities are not identified as relevant to public order “shall use cloud computing services that have been recognised … as having a Union assurance level 1” under Article 30(2). Higher tiers apply only to more sensitive domains: sectors covered by the EU’s Network and Information Security Directive, known as NIS2, as well as national and internal security, border management, defense, justice, and law enforcement. NIS2 imposes baseline cybersecurity duties on operators in critical sectors, including energy, transportation, banking, health, and digital infrastructure. For those sensitive activities, public bodies “shall only procure” services at assurance levels 2, 3, or 4 under Article 30(3).
Even there, CADA includes proportionality safeguards. Article 30(4) allows public bodies to avoid the higher-tier obligation where no adequate service exists or where the cost would be disproportionate. That is an important limitation. A sovereignty requirement that mandates unavailable or unreasonably costly services would not strengthen public-sector resilience; it would merely constrain procurement.
Recital 52 states the underlying logic: “Most public services would not require the highest levels of assurance.” Only “specific cases” may require levels 3 or 4, and the required risk assessment is meant to ensure proportionality and subsidiarity. Subsidiarity is the EU-law principle that the Union should act only where member states cannot adequately address the issue themselves.
The Commission describes the design as “risk-based” in Recital 62. That framing matters because it rejects, at least formally, the categorical “effective control” rule some had urged.[4] The Commission estimates that levels 3 and 4 will apply to only about 10% of public-sector use cases.[5]
The same restraint appears in CADA’s procurement preference. Article 32 requires contracting authorities to score a bidder’s contribution “to the development of a European cloud and AI ecosystem.” But those criteria must remain “ancillary and not decisive in the award of the contract” under Article 32(2)(d). Recital 67 suggests capping them at 15 out of 120 evaluation points, “subordinate to the core contract award criteria.” A bounded Buy European preference in public tenders can be a defensible industrial-policy instrument. It is materially different from a categorical exclusion.
The main difficulty arises higher up the assurance ladder.
B. Risk-Based on Paper, Upward-Ratcheting in Practice
A risk-based design is only as sound as the risk assessments that implement it, and CADA’s incentives may push toward the higher tiers. European incumbents gain a more protected market when the highest assurance levels apply, giving them a strong incentive to argue that more workloads belong there. Cloud Infrastructure Services Providers in Europe (CISPE) has already described U.S.-linked “wrapper” arrangements—European-branded offerings that still rely on U.S. cloud providers—as “sovereignty washing.”[6] The practical implication is clear: if such structures count as sovereign, the protected market for EU-native providers becomes smaller.
CADA’s own procedures also tilt upward. The Commission may override a member state’s chosen assurance level if it considers that level inadequate under Article 29(5). A delegated-act power could turn today’s voluntary private-sector assessments into mandatory requirements for highly critical sectors under Article 31(3). A delegated act is a legally binding measure adopted by the Commission to supplement or amend nonessential elements of EU legislation. In addition, the Commission expressly anticipates that public-sector requirements may “be mirrored by private-sector entities … with subsequent spillover effects,” as Recital 66 puts it. That is how a formally public-sector rule can influence the private market.[7]
The political signal points in the same direction. Executive Vice President Henna Virkkunen, who leads the Commission’s tech-sovereignty portfolio, told reporters that the goal is to ensure no provider of critical workloads holds a “kill switch,” that “we want to make sure that our most critical sensitive data is stored in Europe,” and that U.S. companies would “struggle to reach the highest sovereignty tier.”[8]
Thus, “most public services stay at Level 1” is not a guarantee. With several incentives pushing in the other direction, the top tiers may become more important than the proportionality language suggests. Their actual requirements therefore warrant close scrutiny.
C. The Top Tiers Turn Risk Management into Control Tests
At Level 1, CADA allows third-country control, subject to limited safeguards. At Level 2, a provider controlled from outside the European Union may still qualify, but only through an EU-localized service structure. The provider must also show that it has adopted the “necessary legal, technical and organisational measures” to prevent three risks: third-country access to customer data, service disruption or degradation, and coerced compliance with third-country sanctions or embargoes under Annex II 2.1(g).
Above Level 2, CADA shifts from managing risk to policing control.
At Level 3, the provider and relevant subcontractors must be “not subject to the control of a third country or a legal entity established in a third-country,” unless the Commission has recognized that country under the associated-third-country mechanism and the provider satisfies the same separation and prevention requirements under Annex II 3.1(g) and Article 18. In this context, “control” refers not merely to ownership, but to the ability to exercise decisive influence over the provider’s operations or strategic decisions.
Level 4 makes the control ban absolute. There is no associated-third-country exception. It also adds an “effective control” test for software: a third country must not be able to “materially influence the technical evolution, maintenance priorities, security remediation, and long-term continuity” of relevant software components. Union-citizen personnel requirements appear at Level 3 and continue at Level 4 under Annex II 3.1(d), 4.1(d), 4.1(g), and 4.1(i)(ii).
The result is a significant turn from technical assurance toward legal and corporate insulation. The higher the tier, the less CADA asks whether a provider can manage specific risks, and the more it asks whether the provider can demonstrate separation from the non-EU world.
D. What EU-Only Sovereignty Can—and Cannot—Buy
There is one category of use cases for which a categorical EU-only approach is at least coherent: a narrow set of core governmental functions where member states may want to keep the circle of trust inside the European Union and are willing to bear the cost of doing so. The cost is not only financial. It may also mean accepting weaker capabilities, including the inability to use state-of-the-art AI.
That tradeoff should be evaluated clearly. The question is not whether the highest assurance level is reassuring in the abstract. It is what that level can actually deliver, and at what cost.
Consider the strongest possible case. Assume a cloud provider is as secure as current technology and operations allow. Assume also that it satisfies, as far as possible, CADA’s Level 4 requirements. That allows the analysis to isolate the maximum security benefit an EU-exclusive policy could plausibly provide.
Even under those assumptions, real independence from foreign pressure requires far more than EU ownership and organizational separation from non-EU subsidiaries, assets, or business relationships. Any asset exposed to foreign legal or extralegal pressure can become a vulnerability. Employee travel can also create risk; a third country may detain personnel and thereby exert pressure on the employer. Even a provider with no foreign customers or subsidiaries may remain vulnerable to sanctions, secondary sanctions, export controls, and other forms of economic pressure.
True independence would therefore require resilience across the whole business: hardware, software, financing, banking relationships, borrowing, and even the personal financial exposure of key employees and shareholders. That is a demanding standard. It may be easier for some state-owned enterprises than for private firms, but it would be costly and limiting in any event. It is doubtful that many proponents of EU-exclusive sovereign clouds could satisfy it in practice.
Some cloud services can be delivered under such constraints if buyers are willing to accept the costs. Others cannot. The limiting factor is often the hardware and software the provider can obtain without depending on foreign-controlled supply chains. Those limits are likely to matter most for defense and intelligence—the very domains where the highest assurance levels may appear most attractive.
The most important limitation concerns frontier AI. The frontier of commercially available AI—the most capable models at the leading edge—belongs to a small group of mostly U.S. labs, with OpenAI and Anthropic at the front and Google close behind. Unless AI-development techniques change substantially, those frontrunners are likely to remain ahead while the rest of the world trails for the foreseeable future.
Europe can access and build AI that is sufficient for many uses. EU-based labs are producing capable models, including open-weight models, meaning models whose parameters are made available for others to run or adapt. But AI that is sufficient for many uses is not the same as frontier AI.[9] That gap matters most for users in defense, intelligence, and perhaps law enforcement, where second-best capabilities may be inadequate.
Even non-frontier AI faces a second constraint: compute. Compute refers to the processing power—chips, data centers, and electricity—needed to train and run AI systems. Europe does not have enough compute capacity to meet all projected demand. The Commission’s own impact assessment projects a large and widening data-center-capacity gap, a problem discussed below. And those projections count all data-center capacity. The share that is genuinely independent of third-country leverage is far smaller, and likely close to nonexistent outside government facilities.
CADA partially recognizes this limitation. Article 30(4) lets a contracting authority depart from the assurance tiers when “no adequate or reasonable alternative … service exists.” That is precisely the frontier-AI problem. A procurement rule cannot create a missing model or supply the compute needed to run it.
There is also a problem from the opposite direction. The EU-only line assumes that all member states belong within the same circle of trust for the most sensitive workloads. That assumption merits scrutiny. Member states differ in their geopolitical orientations, including in their relationships with third countries that other member states may regard as hostile.
That matters for national security. Some member states may serve, intentionally or not, as gateways for adversaries: allowing front companies to establish themselves inside the European Union, facilitating movement of personnel, or creating opportunities for intelligence assets to operate under an EU label. If so, drawing the trust boundary at the EU border becomes less defensible. For some sensitive uses, trusting certain non-EU allies may be more rational than trusting every EU member state. I return to that point below.
III. CADA Promises Immunity, but Delivers Fragility
Beyond a narrow core of highly sensitive government functions, CADA’s top tiers promise more than they can deliver. Stripped of procedural detail, they rest on a central premise: that keeping ownership, control, and personnel inside the European Union can shield cloud services from foreign legal and economic pressure. The act targets two real risks: that a foreign authority could gain access to European data, and that a foreign authority could disrupt a critical service. It also offers one formal exception from the Level 3 ownership and control ban: Commission recognition of a provider’s home country under Article 18.
The subsections that follow test those premises. On confidentiality, ownership does not stop a production order. Legal and economic leverage—not nationality—drives disclosure risk, and data in use raises technical problems that ownership rules cannot solve. On availability, the relevant pressure points—sanctions, export controls, supply-chain chokepoints, model access, and upstream software dependencies—often reach past an EU ownership label. Article 18, the one exit from the Level 3 control ban, also appears likely to exclude the very allied providers on whose technology Europe continues to depend.
A. Foreign Leverage Does Not Stop at the EU Border
King v. OVH illustrates why EU ownership cannot do the work CADA assigns it. In that case, an Ontario court ordered OVH—a leading European sovereign-cloud provider—to produce subscriber data held on servers in France and other countries outside Canada. The court reasoned that the French company’s “virtual presence” in Canada brought it within Canadian legal reach, and it treated France’s data-blocking statute as a low-risk obstacle.[10] The result is significant for CADA’s sovereignty theory: a Canadian order reached EU-located data held by an EU-headquartered provider.
The point is not that Canada is uniquely aggressive. It is that foreign leverage can take many forms. Production orders are one example. A foreign government may also rely on sanctions, export controls, bank accounts, subsidiaries, employees, suppliers, or other assets within its jurisdiction. To be fully insulated from all such pressure, a provider would need no meaningful foreign nexus and no critical foreign inputs.
No major AI-cloud provider is likely to satisfy that standard. AI clouds depend on non-EU sourced hardware and software, including advanced chips, accelerators, networking equipment, and critical software layers. Many of the most important inputs remain substantially shaped by U.S. technology and U.S. export-control law. It is therefore reasonable to assume that virtually all existing EU providers would fail the strongest version of CADA’s “not subject to the control of a third country” test if that test were applied as a genuine inquiry into foreign leverage.
The Commission’s impact assessment appears to recognize this problem, at least in part. It notes that properly designed technical measures—such as “customer-controlled encryption, strict role segregation or data access minimisation”—“can technically constrain the practical ability of a third-country authority to access the data, regardless of the provider’s jurisdiction.”[11] In other words, system architecture can often mitigate disclosure risk more effectively than nationality-based controls.
The same document also acknowledges that ownership cannot make legal risk disappear. “[E]ven when a service is exceptionally well protected,” a legally binding third-country request may still compel a provider to grant access to data. “This risk exists independently of the technical robustness of the service.” The Commission therefore recommends “cannot comply” architectures, in which “compliance with external access requests [is] rendered technically, operationally or legally impossible.” It cites “the OVH case in Canada” as the relevant cautionary example.
That is the appropriate lesson, but only up to a point. The answer to foreign legal pressure is not to assume that EU ownership creates immunity. It is to design systems so that no provider, whether European or foreign, can disclose data it does not control.
B. Data Security Depends on What the Data Is Doing
Technical protection depends on the state of the data. CADA blurs an important distinction between data at rest, meaning stored data, and data in use, meaning data being actively processed. The distinction matters because tools that protect stored data do not necessarily protect live computation.
Start with historical data and a production order that arrives after the fact. In this setting, genuine “inability to comply” can be technically achievable. If the provider retains no data, there is nothing to produce. If the provider stores only ciphertext—encrypted data that cannot be read without a key—under client-side encryption, and the customer alone holds the keys, the provider stores data it cannot read.
That appears to be what CADA’s audit standard seeks to capture when it demands inability to access “customer data, including encrypted data” under Annex III. The phrase addresses the common case in which cloud data is encrypted, but the provider manages the encryption keys. A provider that can decrypt data on demand is not truly “unable” to comply with a disclosure order.[12] Read this way, the standard is meaningful and achievable. As the Commission’s own analysis recognizes, it can work regardless of the provider’s nationality.
But CADA outsources this technical layer to a certification scheme that does not yet exist. At Levels 2 through 4, the audited service must hold a European cybersecurity certificate under a cloud-certification scheme “to be established” under the Cybersecurity Act. Levels 2 and 3 require the “substantial” assurance level; Level 4 requires “high.” That scheme is the European Union Cybersecurity Certification Scheme (EUCS), which the proposal’s explanatory memorandum acknowledges “has not yet been adopted” and on which work “will resume.”
This is a significant dependency. EUCS has been stalled since December 2020, largely because of the same sovereignty requirements that CADA now revives through procurement rules. Its adoption has been postponed without a new deadline.[13]
Until EUCS is adopted, Annex II falls back on national certification schemes “where they exist.” That approach re-fragments cloud-security assurance along national lines, even though CADA’s premise is a single Union framework. Where no national scheme exists, providers may self-demonstrate compliance with “the highest cybersecurity standards under applicable Union law,” a phrase that does not identify a clear or uniform standard.
The unadopted EUCS candidate scheme, however, already contains the control that does the most important confidentiality work for stored data. At the “high” level, the draft requires encryption keys to be “known exclusively by the cloud customer and without exceptions.” At the “substantial” level, the same requirement allows exceptions. CADA requires only the exception-permitting certificate at Levels 2 and 3, and reserves the customer-exclusive-keys certificate for Level 4. That allocation is difficult to justify.
If EU ownership delivered immunity, requiring customer-exclusive keys in addition to Level 4’s absolute control ban would add comparatively little. If, as King v. OVH shows, ownership does not stop a production order, then key custody is the control that matters—and CADA withholds it from the lower tiers where it would often be most useful. If the Commission wants providers to be unable to comply with foreign production orders, the relevant lever already exists: adopt EUCS and require customer-exclusive key custody wherever confidentiality is critical, regardless of who owns the provider.
Even customer-held keys leave residual trust questions. Are the keys truly controlled only by the customer? Are they copied, escrowed, or exposed through support processes? These questions show where the ally/adversary distinction legitimately enters the analysis. I return to that issue below.
The problem changes when data is being processed after an order is served. This issue is especially important for AI. To train or run an AI model on data, the system must decrypt that data into memory. Encryption at rest does not solve that problem. What matters is the security of the live processing environment.
The main technical candidate for protecting data in use is confidential computing in trusted execution environments. Confidential computing refers to technologies that seek to protect data while it is being processed. A trusted execution environment is a protected area inside a processor whose memory is designed to remain unreadable even to the machine’s operator. In theory, this allows a customer to process sensitive data on another party’s cloud without exposing that data to the cloud provider. In practice, CADA has two gaps.
The first gap is that CADA does not require this protection. CADA’s sovereignty-assurance criteria and audit evidence do not require confidential computing, trusted execution, or other data-in-use protections. Nor does the underlying certification stack fill the gap. The EUCS candidate scheme’s cryptography requirements cover data in transit and data at rest, but not data in use. The NIS2 implementing rules for cloud providers likewise stop at “data at rest and data in transit.”[14]
The second gap is that even trusted execution environments may not deliver the absolute “inability to comply” CADA’s top tiers imply against an adversary with physical control of the machine. Security research has repeatedly shown that commercial enclaves can be vulnerable to physical attacks by someone who controls the hardware.[15] Vendors patch specific techniques, but physical access remains a live threat category. And the party with physical control of the server is the host—the same party CADA fears may be coerced by a non-EU government.
This creates a further difficulty for CADA’s sovereignty framing. The enclave silicon and its root of trust are themselves largely controlled by U.S. firms: Intel, AMD, and Nvidia. Thus, the leading technical response to non-EU jurisdiction often depends on U.S.-controlled chips.
Taken literally, the “unable to comply … including encrypted data” standard is not achievable with the measures CADA actually requires, at least for data in use. Read loosely, it collapses into an ownership test: a formal label that does little to prevent intrusion and cannot eliminate legal compulsion. The likely result is a protectionist proxy presented as technical assurance.
C. Resilience Beats the Kill-Switch Fantasy
The discussion so far has focused on one risk: a foreign power gaining access to European data. The Commission’s headline concern is different: that a provider could switch off, degrade, or deny access to a critical service. This is the “kill switch” problem. The practical response is not to assume the risk can be eliminated, but to ensure that users can exit, switch providers, and run critical workloads elsewhere.
CADA’s own risk taxonomy recognizes several forms of this risk: “embargos or sanctions,” “technology lock-ins,” and “sabotage.” EU ownership helps against only one narrow scenario: a foreign parent company ordering its European subsidiary to discontinue or degrade service. That is the strongest case for sovereign control in the act. It is also only a limited part of the overall risk.
Sanctions and embargoes do not require a parent company. A foreign state can sanction a European firm directly, cut it off from currency clearing or correspondent banking, restrict access to technology, or pressure its suppliers and customers through secondary sanctions. EU ownership prevents none of these measures.
For frontier AI, the most important dependency sits even further upstream: chips, software, and state-of-the-art AI models that Europe does not currently produce at comparable levels. CADA implicitly recognizes this point. To address kill-switch scenarios, the top tiers do not rely only on ownership. They require a “documented migration plan in the event that the vendor fails or a third country imposes restrictions,” controls to “block any remote features that could materially tamper with or disrupt” the system, and a “switchover plan” to “minimal viable functionality” under Annex II and Annex III.
Those requirements address resilience, not immunity. Resilience—the ability to maintain or restore service despite disruption—does not depend on the provider’s nationality.
A categorical EU-only route may even reduce resilience. Concentrating critical workloads among a small number of EU-native providers could recreate the “concentration risk” CADA’s recitals warn against. Nationality-blind multi-cloud portability—designing systems so they can run across more than one provider—would do more to reduce that risk than a formal EU ownership requirement.[16]
Higher assurance should therefore remain risk-based and grounded in technical and organizational measures. The relevant question should be whether the user can continue operating if one provider, jurisdiction, or supply chain fails. It should not be whether the provider has the preferred nationality.
The June 12 cutoff of Anthropic’s Fable 5 and Mythos 5 illustrates the limits of CADA’s approach. The cutoff occurred above the layer CADA regulates. CADA governs ownership, personnel, data location, and cloud-service structure. It does not determine who receives access to frontier AI models in the first place.
Only one CADA criterion reaches that layer: Level 4’s test of whether a third country can “materially influence … the long-term continuity” of software under Annex II 4.1. The U.S. directive confirms that a frontier American model would fail that test. But CADA’s remedy for such failure is exclusion. In effect, its answer to the frontier-AI kill switch is to forgo the state-of-the-art capability.
Nor is the Anthropic cutoff necessarily an isolated warning. On June 2—10 days earlier, and one day before CADA itself was proposed—the White House issued an executive order creating a voluntary process for developers to provide the federal government up to 30 days’ pre-release access to “covered frontier models.” The same process gives the government a role in selecting the “trusted partners” who receive those models before public release.[17] Washington is positioning itself as a gatekeeper for frontier-model distribution. Nothing guarantees Europe a place on that list.
This reality should clarify the policy choice. Europe cannot solve the kill-switch problem by assuming that ownership rules control every upstream dependency. It can reduce the risk only by building resilience: portable workloads, diversified supply chains, stronger exit rights, more compute on European soil, and enough mutual dependence that cutting Europe off would impose meaningful costs on the countries doing the cutting.
D. CADA’s Ally Problem
For Level 3, CADA offers only one exit from the control ban: Commission recognition of the provider’s home country under Article 18. Level 4 offers no such path. That structure matters because the Article 18 criteria are cumulative, and the United States could be argued to fail several of them.
To qualify, a third country must first benefit from an adequacy decision under the General Data Protection Regulation (GDPR)—that is, a Commission finding that the country’s data-protection regime is essentially equivalent to the European Union’s. It must also have no measures that allow it to control a provider in ways that conflict with the EU Data Act’s limits on third-country access to nonpersonal data. That criterion points directly to the United States’ CLOUD Act and Foreign Intelligence Surveillance Act (FISA). The country must have no measures that could compel degradation or disruption of the service, and no sanctions leverage over the provider. That criterion points to the U.S. sanctions regime. Finally, it must have “no measures … to impede the provision of state-of-the-art technologies.” That criterion points to U.S. export controls on advanced AI chips.
At the top of the ladder, CADA may therefore operate as a categorical exclusion of U.S.-controlled providers. Read that way, the design also risks colliding with trade law. U.S. and EU cloud services are “like services,” and an ownership-or-headquarters test resembles “less favorable treatment” under the World Trade Organization’s General Agreement on Trade in Services (GATS). ICLE has made this discrimination point before in the EUCS context.[18] If CADA repeats the move, the Commission would need to show that its public-order defense justifies the restriction.
The contradiction extends beyond trade law. The Commission says Europe should remain inside the Western architecture for controlling sensitive technologies. Yet CADA’s criterion barring any country with measures that “impede the provision of state-of-the-art technologies” would disqualify a partner precisely because it operates the export controls that help constitute that architecture.[19]
This is not a hypothetical tension. On June 3—the same day it proposed CADA—the European Union also moved to join Pax Silica, the U.S.-led initiative launched in December 2025 to secure semiconductor, AI, and critical-minerals supply chains against China. Under the parallel EU-U.S. trade understanding, the bloc is expected to buy at least $40 billion in American AI chips.[20] That alliance rests on the same coordinated export controls CADA may treat as disqualifying.
The result is an internal inconsistency. The Commission seeks to bind Europe more closely to the American technology stack while using CADA’s top tiers to exclude that same ally’s providers from the most sensitive workloads.
Tethering high-tier eligibility to a GDPR adequacy decision adds another source of fragility. A Schrems-style lapse could disqualify a major provider overnight. That is precisely the kind of access shock a sovereignty framework should seek to avoid.[21]
IV. Draw the Line at Adversaries, Not Allies
None of this means CADA should avoid third-country distinctions altogether. Some distinctions are necessary. But they should track the relevant risk. A provider controlled from China or Russia presents a categorically different risk from a provider controlled from an allied democracy. The reason is not, as Article 18 appears to suggest, that the provider’s home state possesses intelligence-collection capabilities. All capable states possess such authorities, including allies. A test built on capabilities alone therefore captures the United States and proves too much.
The more relevant question is motivation and constraint: whether the home state is likely to weaponize a provider against Europe, and whether the provider could meaningfully resist. Disqualifying an ally because it has surveillance authorities is not a sound risk proxy. It penalizes partners Europe depends on while doing too little to distinguish the adversaries it should treat with greater caution.
A Western provider served with an order targeting an ally may have courts, legal standing, commercial incentives, and diplomatic channels through which to resist. OVH, for example, is litigating the Canadian production order on appeal. A provider answerable to a nondemocratic adversary’s security apparatus is far less likely to have comparable ability to refuse, delay, litigate, or disclose the pressure it faces.
The EU border is also an imperfect trust boundary in the opposite direction. Treating all member states as a single circle of trust assumes a degree of geopolitical homogeneity the European Union does not have. A provider’s EU status says little about whether its owners, personnel, or facilities are located in a member state that an adversary could use as a gateway. Front companies, permissive local networks, and intelligence assets do not become harmless because they operate through an EU member state.
This is not an argument against drawing lines. It is an argument for drawing them around allegiance, conduct, and verifiable controls. A test built on those factors can assess risk both inside and outside the European Union. A test built only on the EU border cannot. It may include some providers that present unacceptable residual risk while excluding allied providers that can satisfy meaningful technical and organizational safeguards.
This is where the limits of audit-based regimes become important.[22] Assurance is partly a technical exercise and partly a trust regime. Auditors can verify whether controls exist, or at least whether they exist at the time of assessment. But they may struggle—or lack sufficient incentive—to pierce corporate structures when hostile ownership is involved. They also assess snapshots, not continuous practice.
Technical measures reduce the trust a customer must extend, but they do not eliminate it. Client-side encryption can be misconfigured, including by design. A zero-day vulnerability—that is, a software flaw unknown to the vendor and therefore not yet patched—can be targeted at a specific customer. Trusted execution environments, the protected processor areas discussed above, have also been shown to be vulnerable to some attacks by actors with physical access to the machine. These residual channels are precisely the channels a motivated adversary would seek to exploit while maintaining formal compliance.
Allegiance is therefore not a substitute for technical controls. It is a judgment about whose residual trust Europe can reasonably extend after technical and organizational controls have reduced risk as much as practicable. The system should be designed for the worst-case provider, just as a data-sharing regime must be designed for the worst-case recipient. But the worst case should be identified correctly.
Technical measures are also not the whole toolkit. The residual channels just described—the misconfigured key store, the targeted update, and the hands-on attack against a protected processor—are ultimately insider-risk problems. The relevant controls are organizational: personnel screening, security clearances, separation of duties, two-person control for sensitive operations, and monitored and logged administrative access.
These controls are not novel. NIS2 lists “human resources security” among its required risk-management measures. The European cybersecurity certificates that CADA’s own tiers presuppose also include personnel-security controls.
Two points follow. First, organizational controls, like technical controls, are not inherently nationality-dependent. Any provider can screen, clear, and constrain its staff. These controls retain their value among allies and among EU member states, where ownership tests often do little work. Second, to the extent organizational controls necessarily rest on trust, that trust is relational and verifiable among allies. Security-of-information agreements routinely provide for mutual recognition of clearances and procedures for handling classified information. No comparable assurance is available from an adversary on meaningful terms.
CADA partly recognizes this problem but relies on the wrong proxy. At Level 2, a public body may demand “additional personnel screening and Union citizenship requirements.” At Levels 3 and 4, all personnel must be Union citizens, with a national-security clearance required only “when handling classified information.” For classified material, the citizenship rule may track existing EU rules on classified information. But when extended to all personnel at the top tiers, the rule mistakes the proxy for the protection. The relevant protection comes from reliable screening and clearance, conducted by the provider’s own state or by an allied state—not from citizenship alone.
A vetted and cleared national of an allied country is a stronger answer to insider risk than an unvetted EU citizen. EU citizenship should not be treated as a security guarantee. The Commission has opened infringement proceedings against member states for investor-citizenship schemes, sometimes described as “golden passport” programs. In 2025, the Court of Justice held that Malta’s scheme—naturalization “in exchange for predetermined payments or investments”—was incompatible with EU law.[23] CADA’s personnel criteria should therefore require vetting to a defined standard, with allied clearances recognized under security-of-information agreements, rather than relying on citizenship as such.
The harder question is why Europe should extend trust to the United States, an ally with expansive disclosure laws and recent evidence of coercive leverage. Three answers are relevant.
First, for state-of-the-art AI, there is no realistic substitute. The frontier AI stack is overwhelmingly American, and the Commission’s own documents recognize that technological autarky is not available. The package itself states that Europe should remain open to like-minded partners. Alignment with allies is therefore not a concession; it is a practical necessity, notwithstanding real political frictions.
Second, an ally’s worst case differs in kind from an adversary’s worst case. The June 2026 Anthropic cutoff was abrupt and consequential. But allied coercion is more likely to be overt, reversible, and contestable through law, politics, diplomacy, and commercial pressure. Adversary coercion is less likely to provide those avenues.
Third, trust among allies is supported by institutional mechanisms, including adequacy decisions, mutual legal assistance, reciprocity, and shared security commitments. Against an adversary, verification stands largely alone, and verification alone can be defeated.
There are important limits to this argument. U.S. surveillance practices and laws, including FISA Section 702, led the Court of Justice of the European Union to invalidate the legal basis for personal-data transfers to the United States twice. More recently, the oversight board charged with reviewing the current framework’s safeguards lost its quorum after dismissals in January 2025, a gap the Commission’s own adequacy review identified. The General Court upheld the Data Privacy Framework in September 2025, but an appeal is pending before the Court of Justice. Section 702 itself has also been operating under short-term congressional extensions while renewal remains contested.[24]
But a Section 702 directive operates through a provider’s technical ability to access customer data. The appropriate response is to remove that ability where confidentiality is critical: customer-held keys, zero retention, and data-in-use protections—the “cannot comply” architecture the Commission’s own impact assessment recommends. Ownership does less because it does not address how the legal obligation operates.
Section 702 compels “electronic communication service providers,” a category defined by access rather than nationality. It covers providers “who [have] access to wire or electronic communications,” was expanded in 2024 to reach “any other service provider who has access to equipment that is being or may be used to transmit or store” such communications, and extends to any “officer, employee, custodian, or agent” of such a provider.[25] An EU-headquartered provider with a U.S. office, subsidiary, or employee may fall within that framework. What remains outside it is a service in which no entity or person within U.S. jurisdiction has access to plaintext or encryption keys. At that point, a directive can compel only ciphertext.
The recommendation follows from the diagnosis: CADA should retain a control inquiry, but retarget it from any third-country control to adversary control. Article 18 should become an openly political determination of allegiance and trust. For allied providers, CADA should rely on the technical and organizational safeguards its high tiers already identify: customer-held keys, vetted and cleared personnel, migration plans, anti-tamper controls, source-code audits, switchover plans, and portability. Those safeguards should apply on their own merits, not as accessories to an EU passport.
V. Demand-Side Industrial Policy Cannot Build What Europe Lacks
Before turning to what the package should have built, one additional defense of CADA’s top tiers should be addressed. As claims of genuine immunity from foreign legal and economic pressure become harder to sustain, this defense is likely to become more prominent.
The argument is that Levels 3 and 4 are not primarily about immunity. They are instead a form of industrial policy. The state, acting as an anchor customer, reserves a portion of public procurement for EU-native providers. That predictable demand is then expected to give those providers the revenue base needed to invest in European capacity.
Taken on its own terms, this is the strongest argument for the top tiers. It is still insufficient.
First, the restriction is unlikely to remain narrow. As explained above, CADA’s institutional machinery operates as a ratchet, pushing more workloads toward the higher assurance levels over time.
Second, anchor tenancy works best when the missing input is a creditworthy customer. Europe’s cloud and AI gap is not primarily a demand problem. The binding constraints are advanced chips that Europe does not make, grid connections that can take up to a decade to build, capital markets too shallow to finance late-stage scale, and a frontier-model gap that no procurement schedule can close. Reserved demand solves none of these problems. Even the Commission’s own impact assessment expects reliance on non-European providers to remain “inevitable” across its planning horizon.
When supply cannot meet the reservation, demand-side policy does not create the missing capability. It produces supply shaped to the reservation. Engineering talent and capital are diverted toward satisfying sovereignty criteria rather than closing the capability gap. The public sector, as anchor customer, may then accept inferior technology as the price of certification.
That failure mode has already been modeled in detail, and not by Europe’s critics. The Europe 2031 scenario, written by European researchers who want Europe to compete, describes a CADA-like instrument closely.[26] Sovereignty becomes “the new buzzword in European capitals.” Announced funds turn out to be “largely a repackaging of existing funds.” A fictional Digital Sovereignty Regulation eventually requires critical public workloads to run entirely on European software.
When the capacity to meet such a mandate does not materialize, the mandate still binds. In the scenario’s wave of AI-enabled cyberattacks, the public bodies most committed to buying European are “the ones paying the ransoms,” because peers using stronger foreign models are better able to defend themselves.
VI. Build the Capacity That Creates Leverage
The durable way to reduce dependence is not to close the market. It is to make dependence more mutual by building additional cloud and AI capacity that is located, operated, and financed in Europe. That requires greater attention to the practical constraints that determine where compute infrastructure is built: permitting, power availability, grid connection, capital formation, corporate law, tax treatment, access to advanced chips, and access to frontier models. If Europe wants leverage in the frontier-AI economy, it needs more than certificates. It needs data-center capacity, financing, and reliable energy at scale.
A. The Permit Clock Stops Before the Hard Part
CADA’s Title III is the package’s most concrete build component, and some of its streamlining measures are meaningful. Member states must designate data-center acceleration zones under Article 10, create single information points under Article 12, combine and front-load environmental procedures at the zone level, and ensure that the project permit “shall not exceed 12 months” under Article 13(5). Strategic projects also receive an aggregated baseline permit and priority status under Article 14.
These measures are useful, but they do not reach the most important constraints.
The 12-month deadline begins only “from the moment a comprehensive application has been submitted.” The zone’s single procedure covers permits “commonly required” within the area, but expressly excludes grid-connection permits. Nor does CADA waive environmental assessment. Member states must still carry out “all necessary … environmental assessments” under Article 13(3). Unlike renewable-energy projects under the EU’s third Renewable Energy Directive, data centers do not receive “overriding public interest” status, a designation that can make it easier to justify derogations from otherwise applicable environmental rules. Part of the promised acceleration also depends on a separate, not-yet-adopted regulation on environmental assessments.
The two steps CADA brackets out may be the steps that matter most: environmental review and power-grid connection. On power, CADA largely refers to other instruments. It asks member states to analyze each zone’s future energy needs “to feed into grid planning.” It says they “should facilitate” connection procedures and “should promote” power-purchase agreements. But actual connection acceleration is left to the separate European Grids Package, the Electricity Directive, and “an upcoming legal proposal.”
That gap matters because a data center can receive its 12-month permit and still wait years to be energized. For compute projects, the central question is not only whether the project may be built, but when it can connect to sufficient electricity. The time required to energize a site often determines where compute infrastructure is built.
This is the Commission’s own diagnosis. Its impact assessment finds that connecting a data center to the grid “can take between 3 and 10 years”—seven to 10 years in established hubs, and up to 13 years where congestion is worst. It also finds that grid limits have already produced “moratoria on new DC connections,” while EU industrial-power prices are two to three times U.S. and Chinese levels. The same document acknowledges that the remedy sits outside CADA: the “necessary improvements to grid availability will be driven by the Grids package.”[27]
CADA identifies the bottleneck but leaves the principal remedy to another instrument.
B. Europe Cannot Certify Its Way to Scale
The package largely omits the capital and corporate-law reforms needed to support European scale. That omission is revealing. The accompanying Commission communication repeats the basic diagnosis: Europe accounts for roughly 5% of global venture capital, compared with 52% for the United States.[28] But the proposed response is limited. The Commission proposes a consultation with the European Investment Bank on “European equity capacity at scale,” without specifying a funding amount, a binding legal instrument, or a concrete mechanism for building the financial infrastructure Europe’s technology ambitions require.[29]
The dependence the package seeks to reduce is large, and the Commission’s own documents acknowledge it. The European Union spends roughly €264 billion a year, much of it on proprietary U.S. information technology. The impact assessment finds that 58% of global data-center investment over the past five years went to the United States, while Europe’s financing landscape “lacks the depth of an integrated capital market.”[30] That is a capital-market problem, not a certification problem.
The flagship build program is also struggling. The €20 billion InvestAI envelope for AI gigafactories has reportedly seen bidding slip to July. Only two of five planned sites appear fundable before 2028, and the field of serious bidders has narrowed from roughly 70 to about 10.[31] These developments suggest that project financing and execution remain significant constraints.
The structural solution is integration: a real Capital Markets Union that mobilizes Europe’s pension and insurance pools for late-stage equity, and a pan-EU corporate form that gives founders the legal certainty they often seek abroad. The Capital Markets Union is the long-running EU project to integrate national capital markets so firms can raise financing more easily across member states.
The Commission did introduce a separate “EU Inc.” proposal in March 2026: a 28th-regime corporate form that would operate alongside national corporate laws. A “28th regime” is an optional EU legal framework that firms could choose instead of relying exclusively on one member state’s law. But the proposal arrived in a diluted form that commentators have judged insufficient to meet the challenge. In any event, it sits outside this package.[32] The pattern is familiar: the European Union acts more decisively where the lever is a rule or certificate than where the task is to build scalable capacity.[33]
Tax is another missing lever. Whether employee stock options are taxed at exercise or sale—and at labor-income or capital-gains rates—often determines whether a European startup can use equity compensation effectively. Equity compensation is especially important for startups because it allows firms with limited cash to compete for talent by offering employees a share in future upside. The spread across member states is substantial. In the most burdensome regimes, the standard startup compensation model becomes exceedingly difficult to use.[34]
Sweden’s experience illustrates how much fiscal design matters on the investor side as well. Its 2003 rule allowing tax-deferred rollover of gains from unlisted shares into new unlisted ventures is credited with helping create the angel-investor cycle behind Sweden’s unicorn record.[35] The 28th-regime proposal gestures at an EU-wide stock-option standard, but in the diluted, defer-to-national-law form its critics fault.[36]
CADA’s own impact assessment effectively brackets these questions. It states that taxation and depreciation “are dictated by national fiscal policies,” and that the cost of capital requires “macrofinancial instruments rather than operational regulations.” That is a candid acknowledgment that the binding constraints on building European cloud and AI capacity sit outside the package.[37] Assurance levels can regulate eligibility for procurement. They cannot by themselves deepen capital markets or produce the advanced chips needed for AI infrastructure.
C. Build Compute, Not Autarky
The sovereignty debate often conflates three different questions. They should be kept distinct.
The first is whether European cloud providers can operate high-quality infrastructure. On that measure, Europe is competitive. Several European providers already rank in the upper tiers of independent operator assessments. Where they trail the leading providers, the gaps tend to be operational and remediable: reliability, networking, support, and monitoring.[38] Europe’s problem is not a basic inability to operate first-rate cloud infrastructure.
The second question is capacity: how much frontier-grade compute is physically located inside the European Union. Here, Europe falls short, and it cannot catch up quickly. The Commission’s own impact assessment puts the EU data-center-capacity gap at almost 3 gigawatts today, widening to roughly 19 gigawatts by 2036 under its central scenario.[39] The inputs that would close the gap fastest—advanced accelerators and the software around them—are not inputs the European Union can produce quickly by regulatory mandate. Accelerators are specialized chips, such as graphics processing units (GPUs), designed to perform the large-scale calculations required by AI systems.
The impact assessment does not avoid the implication. It expects reliance on non-European providers to remain “inevitable,” European providers to keep “struggling to work at the frontier,” and even “highly critical use cases” to continue depending on hyperscalers.[40] Hyperscalers are very large cloud providers that operate global data-center networks at massive scale.
The third question is frontier-model capability: who builds the most capable AI models themselves, as distinct from the data centers that run them. This is the gap the package addresses only indirectly. The frontier belongs to a small group of U.S. labs. Europe’s best models are useful and increasingly open, but they are not in the same class. Additional EU compute would help, but it would not by itself close the gap. Capacity can be built, albeit slowly. The model frontier continues to move, driven by larger and faster investment elsewhere.
Capacity and model capability are the real constraints, and both point toward alignment, not autarky. The advanced silicon and software Europe does not produce are the same supply-chain dependencies that ownership rules cannot solve. The Chips Act 2.0 bets on a domestic frontier fabrication facility that reaches only pilot production in 2030 to 2033. CADA’s headline goal of tripling data-center capacity adds megawatts, not models.[41]
Europe will build frontier compute, if and when it does, on imported accelerators and a largely non-European software stack. The responsible course is to secure that supply by remaining inside the Western technology-control architecture, rather than seeking self-sufficiency the Union cannot reach on a policy-relevant timeline.[42]
The point became concrete on June 12, when a U.S. export-control directive forced Anthropic to cut every non-U.S. user, including allied users, off from its Fable 5 and Mythos 5 models overnight. The lesson is not that Europe should pursue a sovereign frontier model on an implausible timeline. It is that Europe should build what it can realistically build: compute capacity on European soil, in tens of gigawatts, under European law. The relevant question is not who owns every accelerator or whose models run on them, but whether the infrastructure on which frontier AI depends is located in Europe at sufficient scale.
That capacity would create leverage. Demand for compute will likely exceed even American supply. If Europe can offer large, modern, quickly available capacity for U.S. firms’ workloads, it can create mutual dependence that makes a future cutoff more costly. As Europe 2031 argued, what hyperscalers and AI labs most need from Europe is not another subsidy, but speed: permitting and grid connection fast enough that building in the European Union is more attractive than waiting elsewhere.[43]
The same leverage could help place model weights—the files containing a model’s learned parameters—on EU-located infrastructure under contractual and physical safeguards. That would not eliminate cutoff risk. Chips, software updates, and operators would remain exposed. But it would provide partial protection, and whether Washington would allow it depends on the leverage Europe brings to the negotiation. That is another reason to build the capacity that creates leverage.
Europe does hold one imperfect chokepoint: ASML Holding N.V., the sole maker of the extreme-ultraviolet lithography machines used to manufacture the most advanced chips. Extreme-ultraviolet lithography is the process used to pattern the smallest features on advanced semiconductors. But ASML also illustrates why chokepoints should not be overstated. The company is European-led and based in the Netherlands, but its two largest shareholders are U.S. asset managers. Its light sources are built by Cymer in San Diego, and key optics work takes place in Wilton, Connecticut. U.S. Foreign Direct Product Rule jurisdiction already reaches its sales, and Washington has used that leverage to shape Dutch export policy.[44] The Foreign Direct Product Rule allows the United States to regulate some foreign-made products when they are produced using specified U.S. technology or software.
ASML is strategically important, but it does not give Europe comprehensive autonomy.
More durable leverage would come from EU-based compute, built with allies that hold other essential inputs: chips, energy, talent, and software. The objective should not be to build only within the EU-27. It should be to ensure that, when an ally rations a strategic asset, Europe is part of the negotiation rather than merely subject to the result.
VII. Recommendations
The central claim of this issue brief is that CADA’s top tiers should require stronger security and rely less on nationality. The recommendations below follow from that premise. Technical and organizational safeguards should replace—not merely supplement—ownership and citizenship tests. Where a requirement is technical, the control details and audit evidence should come from the certification layer CADA already presupposes, extended where necessary, rather than from a parallel CADA-specific catalog.
- Retarget the control test. Replace “not subject to the control of a third country” at Levels 3 and 4 under Annex II 3.1(g) and 4.1(g) with control by a non-allied country. Convert Article 18 from a cumulative capabilities test that no major ally can pass into an openly political determination of allegiance, institutional reliability, and trust. This would also reduce CADA’s exposure under GATS.
- Adopt the certification scheme CADA presupposes. Every tier’s cybersecurity baseline depends on a certificate under a cloud scheme “to be established”—the EUCS certification scheme, which has been stalled since 2020 and remains unadopted. Now that CADA has moved the sovereignty dispute into procurement law, the technical certification scheme should be adopted on its own merits. Until then, the fallback to national schemes will re-fragment the assurance framework the act is intended to unify.
- Make technical and organizational assurance do the work, without nationality distinctions. For confidentiality-critical workloads at Levels 2 and 3, require customer-exclusive key custody or zero retention for EU and non-EU providers alike. The candidate EUCS scheme already defines customer-exclusive key custody at the “high” level, but CADA’s “substantial” certificates for Levels 2 and 3 leave that safeguard optional. The safeguard should be required.
- Close the data-in-use gap. Nothing in the current stack—CADA, the candidate EUCS scheme, or the NIS2 implementing rules—protects data in use. That is where many AI workloads present their most important risks. Annex II should state the relevant outcome: state-of-the-art protections, such as confidential computing, for high-assurance AI workloads. The European Union Agency for Cybersecurity should then develop the corresponding certification profile, so the controls remain in one framework and are audited once.
- Make the audit standard meetable. Replace “unable to comply … including encrypted data” in Annex III with concrete definitions matched to the state of the data, paired with appropriate organizational controls. Client-side encryption and processor enclaves depend on configuration and on the insiders who administer them. For data at rest, the provider should be unable to decrypt because the customer alone holds the keys, or because nothing is retained. For data in use, where genuine inability to comply cannot be promised honestly, the standard should require attested state-of-the-art protections such as confidential computing. A precise standard will be less likely to collapse into an ownership proxy; an impossible standard almost certainly will.
- Fix the personnel criteria. Replace the blanket Union-citizenship requirement in Annex II 3.1(d) and 4.1(d) with screening and clearance to a defined standard. Recognize allied clearances under security-of-information agreements. Retain citizenship requirements only where EU classified-information rules already require them, while still requiring screening.
- Treat resilience as the answer to the kill switch. Apply migration plans, switchover plans, anti-tamper controls, and portability requirements at the high tiers on their own merits, regardless of provider nationality. Address concentration risk through multi-cloud portability, rather than by moving workloads onto a small number of EU incumbents.
- De-fragilize Article 18. Decouple ongoing high-tier eligibility from the continued validity of a GDPR adequacy decision, or at least provide transition periods. A Schrems-style lapse should not become the access shock the framework is intended to prevent.
- Harden the risk-based architecture against upward drift. Require the Commission to publish reasoned justifications when it overrides member-state risk assessments under Article 29(5). Strike or sunset the Article 31(3) delegated power to mandate private-sector assurance levels. Require periodic public reporting on the actual distribution of workloads across assurance levels, so any drift from the Commission’s own 10% estimate becomes visible.
- Extend the data-center buildout fast-track to the real constraints. Bring grid-connection permits within the 12-month clock, or create a parallel binding deadline. Give data centers in acceleration zones overriding-public-interest status for environmental derogations, using the third Renewable Energy Directive as the model.
- Build compute as leverage, and use it to negotiate frontier-AI access. Treat European compute capacity as a strategic asset, not merely a utility. Build it in tens of gigawatts through partnerships with U.S. firms and by hosting their workloads. Compete on permitting and grid-connection speed rather than subsidy. The goal is mutual dependence: enough EU-based capacity that cutting Europe off would impose meaningful costs on the countries doing the cutting. Use that leverage to secure assured access to frontier models and, where feasible, to host model weights on EU soil under enforceable safeguards.
- Pair CADA with the missing instruments. CADA cannot do the build job alone. It should be paired with late-stage capital reforms, including a Capital Markets Union that unlocks pension and insurance pools; an undiluted 28th-regime corporate form; and harmonized tax treatment of employee equity.
One final drafting point: the proposal’s cross-references to the recognition mechanism appear inconsistent. Article 19 appears where Article 18 seems to be intended.
VIII. Conclusion
The Commission made several important choices worth preserving. CADA is risk-based by default, formally limited to the public sector, and paired with a meaningful permitting fast-track. But the package also retains a categorical approach at the top tiers, where sovereignty becomes a proxy for ownership, citizenship, and distance from non-EU law.
The decisive choices now move to the Council, Parliament, and implementing acts. Those choices will determine where the assurance threshold for sensitive public-sector data settles: at Level 2, where European-operated “wrapper” ventures may remain viable, or at Levels 3 and 4, where they likely cannot. They will also determine whether Article 31(3) converts voluntary private-sector assessments into mandates, what evidence auditors will accept that foreign access “is prevented,” and whether the build half of the package—especially grid connection and capital-market reform—is completed.
CADA’s top tiers are where the package departs most clearly from its stated premise.[45] An ownership cordon that excludes Europe’s closest technology partners risks producing the isolation the Commission’s broader communication disavows, but under the label of assurance. Europe does need sovereignty in cloud and AI. But sovereignty will not come from assuming that passports secure data, certificates create chips, or ownership labels build frontier models. It will come from building capacity, hardening systems, extending trust to allies where trust is justified, and drawing the relevant line against adversaries rather than against partners Europe cannot afford to exclude.
[1] Anthropic, Statement on the U.S. Government Directive to Suspend Access to Fable 5 and Mythos 5 (June 12, 2026), https://www.anthropic.com/news/fable-mythos-access (complying with a U.S. export-control directive issued on national-security grounds following an alleged jailbreak. The directive barred access by all foreign nationals, which Anthropic implemented by disabling both models for all users. Anthropic’s other models remained available).
[2] Eur. Comm’n, Commission Proposes Tech Sovereignty Package to Strengthen Europe’s Digital Autonomy and Resilience, Press Release IP/26/1187 (June 3, 2026), https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1187; Eur. Comm’n, Proposal for a Regulation of the European Parliament and of the Council Laying Down Measures to Strengthen Cloud and Artificial Intelligence Capacities in the Union (Cloud and AI Development Act), COM (2026) 502 final (June 3, 2026), https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada. Unless otherwise noted, references in the text to articles and recitals refer to COM (2026) 502 final, while references to Annex II and Annex III refer to its annexes. The press release states that the proposal aims to triple Europe’s data-center capacity within five to seven years.
[3] Miko?aj Barczentewicz, Build AI, Don’t Block Access: The European Union’s Digital-Sovereignty Trap, Int’l Ctr. for L. & Econ. (2026), https://laweconcenter.org/resources/build-ai-dont-block-access-the-european-unions-digital-sovereignty-trap. See also Miko?aj Barczentewicz, Build, Don’t Block—What the Compute Market Says About EU AI Sovereignty, EUTechReg (May 18, 2026), https://eutechreg.com/p/build-dont-block-what-the-compute.
[4] Cloud Infrastructure Servs. Providers in Eur. (CISPE), Put Cloud Sovereignty, Resilience, and Fair Competition at the Heart of CADA (Mar. 17, 2026), https://www.cispe.cloud/cloud-sovereignty-letter-march-2026; Dan Robinson, Don’t Let Hyperscalers Hijack Digital Sovereignty, EC Told, The Register (Mar. 18, 2026), https://www.theregister.com/off-prem/2026/03/18/dont-let-hyperscalers-hijack-digital-sovereignty-ec-told/5222651 (reporting CISPE’s “sovereignty-washing” critique and Microsoft’s concession, in France, that it could not guarantee data against a binding order).
[5] Eur. Comm’n, Commission Staff Working Document, Impact Assessment Report Accompanying the Cloud and AI Development Act, SWD (2026) 502 final (June 3, 2026) [hereinafter Impact Assessment], pt. 1, at 46, 71 (estimating, based on France’s SecNumCloud framework, that the “most sensitive use cases”—those falling within “sovereignty level 3” and “sovereignty level 4”—account for roughly 10% of public-sector use cases).
[6] CISPE, supra note 4.
[7] Comput. & Commc’ns Indus. Ass’n (CCIA), Discriminatory EU Cloud and AI Development Act Risks Severe Market Fragmentation (June 3, 2026), https://ccianet.org/news/2026/06/discriminatory-eu-cloud-and-ai-development-act-risks-severe-market-fragmentation.
[8] Kai Nicol-Schwarz, Europe Unveils Tech Sovereignty Package Amid Growing Concerns Over Reliance on U.S. Tech: ‘We Want to Be Sure Nobody Has a Kill Switch’, CNBC (June 3, 2026), https://www.cnbc.com/2026/06/03/europe-tech-sovereignty-us-tech-reliance.html (quoting Henna Virkkunen’s statement that providers of critical cloud workloads should not have a “kill switch,” that “our most critical sensitive data” should remain in Europe, and that U.S. firms would “struggle to reach the highest sovereignty tier” because of obligations under the CLOUD Act).
[9] Eur. Comm’n, Communication on European Tech Sovereignty Accompanied by an EU Open Source Strategy, COM (2026) 503 final (June 3, 2026) [hereinafter Tech Sovereignty Communication], https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy (describing Mistral AI as developing “high-performance open-weight large language models” that serve as a “sovereign alternative to closed-source systems”; characterizing the openEuroLLM project—co-funded with €20 million of its €38 million budget—as a “flagship initiative” to “secure European leadership in generative AI” through “high performing, ‘truly open’ European foundation models”; and noting that the GenAI4EU call allocates €50 million to “advance open AI models”).
[10] See Shanzay Pervaiz, What Canada’s King v. OVH Case Reveals—and Affirms—About Cross-Border Data Access, Priv. Across Borders (Feb. 3, 2026), https://privacyacrossborders.org/2026/02/03/what-canadas-king-vs-ovh-case-reveals-and-affirms-about-cross-border-data-access; Richard Speed, Canadian Data Order Risks Blowing a Hole in EU Sovereignty, The Register (Nov. 27, 2025), https://www.theregister.com/off-prem/2025/11/27/canadian-data-order-risks-blowing-a-hole-in-eu-sovereignty/2615140. The Ontario Court of Justice upheld a Royal Canadian Mounted Police production order against OVH’s French parent company for subscriber data stored on servers in France, the United Kingdom, and Australia. The court relied on the parent company’s “virtual presence” in Canada and treated France’s blocking statute as posing little risk of enforcement. The decision is currently on appeal.
[11] Eur. Comm’n, Impact Assessment, supra note 5, pt. 2, at 88–89 (quoting the “cannot comply” paradigm and the “OVH case in Canada”; noting that customer-controlled encryption, role segregation, and data-access minimization “can technically constrain the practical ability of a third-country authority to access the data, regardless of the provider’s jurisdiction”; acknowledging that legal compulsion “exists independently of the technical robustness of the service”; and describing architectures that “ensur[e] that the encryption keys are not accessible to the provider or are held exclusively by the customer”).
[12] Eur. Comm’n, Impact Assessment, supra note 5, pt. 2, at 88–89.
[13] Eur. Union Agency for Cybersecurity (ENISA), EUCS – Cloud Services Scheme (candidate scheme, Dec. 2020 draft), https://www.enisa.europa.eu/publications/eucs-cloud-service-scheme, Annex A, CKM-03.2, CKM-03.4 (providing that, at the “substantial” assurance level, encryption keys for customer data at rest “shall be known only to the cloud customer … with the possibility of exceptions,” while at the “high” assurance level they “shall be known exclusively by the cloud customer and without exceptions”). The December 2020 text remains the only publicly available candidate scheme. ENISA did not publish later revision drafts, and the scheme has not been adopted. Reports indicate that contested sovereignty requirements were removed from a 2024 draft and that adoption was postponed indefinitely. See Ctr. for Eur. Pol’y, EU Cloud Certification at an Impasse, https://www.cep.eu/eu-topics/details/eu-cloud-certification-at-an-impasse.html. The explanatory memorandum to COM (2026) 502, supra note 2, likewise acknowledges that the scheme “has not yet been adopted” and that work on it “will resume.”
[14] Commission Implementing Regulation (EU) 2024/2690 of 17 Oct. 2024, Annex, point 9.2(a) (requiring policies governing the cryptographic measures used to protect assets, “including data at rest and data in transit”; the provision does not address data in use).
[15] See Zitai Chen et al., VoltPillager: Hardware-Based Fault Injection Attacks Against Intel SGX Enclaves Using the SVID Voltage Scaling Interface, in Proc. 30th USENIX Sec. Symp. 699 (2021) (describing a voltage-glitching attack that defeats SGX on fully patched systems and arguing that the results “may require a rethink of the SGX adversarial model where a cloud provider is untrusted and has physical access to the hardware”); Robert Buhren et al., One Glitch to Rule Them All: Fault Injection Attacks Against AMD’s Secure Encrypted Virtualization, in Proc. 2021 ACM SIGSAC Conf. on Comput. & Commc’ns Sec. (2021) (demonstrating voltage-glitching attacks against the AMD Secure Processor and extending them to SEV-SNP attestation); Jesse De Meulemeester et al., BadRAM: Practical Memory Aliasing Attacks on Trusted Execution Environments, in Proc. 2025 IEEE Symp. on Sec. & Priv. (2025) (describing a sub-$10 DRAM-aliasing attack that defeats AMD SEV-SNP integrity protections and identifying CVE-2024-21944), together with its runtime successor, Battering RAM (2025), which defeats the boot-time aliasing checks Intel (TDX) and AMD adopted in response.
[16] Satya Marar & Jack Trotter, OECD Cloud-Computing Competition Study Offers Solutions in Search of a Problem, Truth on the Mkt. (July 21, 2025), https://truthonthemarket.com/2025/07/21/oecd-cloud-computing-competition-study-offers-solutions-in-search-of-a-problem.
[17] Exec. Order No. 14,409, Promoting Advanced Artificial Intelligence Innovation and Security, 91 Fed. Reg. 34,565 (June 5, 2026), https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security; see also WilmerHale, New Executive Order Addressing Early Government Access to Frontier AI Models (June 2, 2026), https://www.wilmerhale.com/en/insights/client-alerts/20260602-new-executive-order-addressing-early-government-access-to-frontier-ai-models. The order establishes a voluntary framework under which developers may provide the federal government with up to 30 days’ pre-release access to “covered frontier models,” a category defined through a classified national-security benchmarking process, before release to government-selected “trusted partners” and the public. The order neither requires licensing nor grants the government authority to block deployment.
[18] Eric Fruits, Lazar Radic, Mario A. Zúñiga, Miko?aj Barczentewicz & Ben Sperry, ICLE Comments to the USTR on Significant Foreign Trade Barriers, Int’l Ctr. for L. & Econ. (Oct. 30, 2025), https://laweconcenter.org/resources/icle-comments-to-the-ustr-on-significant-foreign-trade-barriers (arguing that the EUCS “immunity from non-EU law” standard is undermined by King v. OVH and that EU ownership and headquarters requirements accord U.S. “like services” “less favorable treatment,” creating potential tension with the General Agreement on Trade in Services (GATS)); see also Dirk Auer, Testimony on ‘Anti-American Antitrust: How Foreign Governments Target U.S. Businesses’, Int’l Ctr. for L. & Econ. (Dec. 16, 2025), https://laweconcenter.org/resources/testimony-on-anti-american-antitrust-how-foreign-governments-target-u-s-businesses.
[19] Miko?aj Barczentewicz, US Export Controls on AI and Semiconductors: Two Divergent Visions, Int’l Ctr. for L. & Econ. (Mar. 24, 2025), https://laweconcenter.org/resources/us-export-controls-on-ai-and-semiconductors-two-divergent-visions; see also Miko?aj Barczentewicz, US Export Controls on AI and Semiconductors, Int’l Ctr. for L. & Econ. (Mar. 25, 2025), https://laweconcenter.org/resources/us-export-controls-on-ai-and-semiconductors.
[20] See Emanuele Rossi, Why Europe Is Joining Pax Silica, Decode39 (June 2026), https://decode39.com/15107/why-europe-is-joining-pax-silica; Luca Bertuzzi, The EU Is Set to Join US-Led Chip Alliance ‘Pax Silica’ to Counter China’s AI Race, Euronews (June 1, 2026), https://www.euronews.com/my-europe/2026/06/01/the-eu-is-set-to-join-us-led-chip-alliance-pax-silica-to-counter-chinas-ai-race; Agence Europe, Member States Approve EU Participation in US ‘Pax Silica’ Initiative, Europe Daily Bulletin No. 13,880 (June 2026); U.S. Dep’t of State, Pax Silica, https://www.state.gov/pax-silica. Member-state representatives authorized the European Commission to formalize EU participation on June 3, 2026, with formal Council adoption expected on June 8. The initiative originated as a nonbinding political declaration adopted at a December 2025 summit. Reports on the parallel EU-U.S. trade understanding indicate that it includes commitments to purchase at least $40 billion in U.S. AI chips.
[21] Miko?aj Barczentewicz, Schrems III: Gauging the Validity of the GDPR Adequacy Decision for the United States, Int’l Ctr. for L. & Econ. (Sept. 25, 2023), https://laweconcenter.org/resources/schrems-iii-gauging-the-validity-of-the-gdpr-adequacy-decision-for-the-united-states.
[22] Miko?aj Barczentewicz, The European Commission’s Search-Data Trust Fall, Truth on the Mkt. (May 27, 2026), https://truthonthemarket.com/2026/05/27/the-european-commissions-search-data-trust-fall.
[23] Eur. Comm’n, Investor Citizenship Schemes: European Commission Opens Infringements Against Cyprus and Malta for “Selling” EU Citizenship, Press Release IP/20/1925 (Oct. 20, 2020), https://ec.europa.eu/commission/presscorner/detail/en/ip_20_1925 (announcing infringement proceedings against Cyprus and Malta for granting nationality—and thus EU citizenship—in exchange for “a pre-determined payment or investment” without a “genuine link” to the member state, and raising similar concerns about Bulgaria’s scheme); Case C-181/23, Comm’n v. Malta (Grand Chamber Apr. 29, 2025), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0181 (holding that “transactional naturalisation … in exchange for predetermined payments or investments” violates Article 20 TFEU and the duty of sincere cooperation under Article 4(3) TEU); see also Simon Cox, The EU Free Market Does Not Extend to Citizenship, Verfassungsblog (Apr. 30, 2025), https://verfassungsblog.de/the-eu-free-market-does-not-extend-to-citizenship.
[24] Case C-362/14, Schrems v. Data Prot. Comm’r, ECLI:EU:C:2015:650 (Oct. 6, 2015) (invalidating the Safe Harbour adequacy decision); Case C-311/18, Data Prot. Comm’r v. Facebook Ir. Ltd., ECLI:EU:C:2020:559 (July 16, 2020) (invalidating the Privacy Shield adequacy decision based on surveillance authorities under Section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12,333, as well as the lack of effective judicial redress). See also Silvia Lorenzo Perez, What the PCLOB Firings Mean for the EU-US Data Privacy Framework, Ctr. for Democracy & Tech. (2025), https://cdt.org/insights/what-the-pclob-firings-mean-for-the-eu-us-data-privacy-framework (discussing the January 2025 dismissals that deprived the Privacy and Civil Liberties Oversight Board of a quorum). The General Court upheld the third adequacy decision in Case T-553/23, Latombe v. Commission (Sept. 3, 2025); the appeal is pending as Case C-703/25 P. See also Justin Papp, FISA Section 702: Congress Passes Short-Term Surveillance Program Extension Just Before Deadline, CNBC (Apr. 30, 2026), https://www.cnbc.com/2026/04/30/fisa-section-702-congress-extension.html (reporting on Congress’ short-term extensions of Section 702 in spring 2026).
[25] 50 U.S.C. § 1881(b)(4) (defining “electronic communication service provider”); Reforming Intelligence and Securing America Act, Pub. L. No. 118-49 (2024) (adding § 1881(b)(4)(E), which extends coverage to “any other service provider who has access to equipment that is being or may be used to transmit or store wire or electronic communications,” subject to exclusions for accommodation facilities, dwellings, community facilities, and food-service establishments). Congress enacted the provision in response to a Foreign Intelligence Surveillance Court of Review decision rejecting the government’s effort to classify an entity—reportedly a data-center operator—as a covered provider. An amicus curiae before the Foreign Intelligence Surveillance Court warned that the new language could reach landlords and virtually any business with communications equipment on its premises. The government subsequently narrowed the provision’s scope, but the details of that interpretation remain classified. See Andreas Kuersten, FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act, Cong. Rsch. Serv., R48592 (July 8, 2025), https://www.congress.gov/crs-product/R48592; Restore the Fourth, Scope of FISA Sec. 702 ECSP Provision Narrowed but Remains Classified (June 4, 2024), https://restorethe4th.com/scope-of-fisa-sec-702-ecsp-provision-narrowed-but-remains-classified.
[26] Daan Juijn, Stan van Baarsen, Judith Dada, Lily Stelling, Philip Fox, Alex Petropoulos & Michiel Bakker, Europe 2031, ARQ Found. (June 2026), https://europe2031.ai. The scenario posits a “Digital Sovereignty Regulation requiring critical public sector workloads to run on 100% European cloud and AI software by 2032” and explores the consequences after frontier cyber-offensive capabilities proliferate. In its fictional 2026–2029 chronology, “[t]hose agencies most committed to the ‘Buy European’ agenda—organisations which have procured exclusively from European providers—are now the ones paying the ransoms,” while “[o]rganisations that kept an American contract on the side are doing better.”
[27] Eur. Comm’n, Impact Assessment, supra note 5, pt. 1 (finding that connecting a data center to the electricity grid “can take between 3 and 10 years”—3 to 5 years in emerging markets, 7 to 10 years in established hubs, and up to 13 years in the most congested locations; noting that grid constraints have led to “moratoria on new DC connections”; and reporting that industrial electricity prices in the European Union are two to three times higher than in the United States and China, while accounting for 40% to 50% of data-center operating costs). The report further notes, in footnote 90, that “the necessary improvements to grid availability will be driven by the Grids package.”
[28] See Mario A. Zúñiga, Draghi Report Highlights Why to Be Wary of the ‘Brussels Effect’, Truth on the Mkt. (Sept. 26, 2024), https://truthonthemarket.com/2024/09/26/draghi-report-highlights-why-to-be-wary-of-the-brussels-effect (discussing the European Union’s aspirational Capital Markets Union, venture-capital investment that remains a fraction of U.S. levels, and the tendency of European “unicorns” to relocate abroad).
[29] Eur. Comm’n, Tech Sovereignty Communication, supra note 9 (reporting EU and U.S. shares of global venture-capital investment and announcing the European Investment Bank’s “European equity capacity at scale” consultation, as well as the €120 billion and €200 billion investment figures).
[30] Eur. Comm’n, Impact Assessment, supra note 5, pt. 1 (finding that 58% of global data-center investment over the previous five years occurred in the United States; that AI-computing infrastructure can be “ten to thirty-times more expensive” than general-purpose data centers; and that the European Union’s “fragmented financing landscape lacks the depth of an integrated capital market”); see also Eur. Comm’n, Tech Sovereignty Communication, supra note 9 (reporting that the European Union spends roughly €264 billion annually, much of it on proprietary U.S. information-technology products and services).
[31] Ana-Maria Stanciuc, EU AI Gigafactory Plan Stumbles as Delays Alienate Partners, The Next Web (June 2026), https://thenextweb.com/news/eu-ai-data-centre-gigafactory-delays-funding-stumble; Christina Kyriasoglou, Gian Volpicelli & Paula Doenecke, EU’s AI Data Center Plans Stumble Due to Delays, Funding Issues, Bloomberg (June 2, 2026), https://www.bloomberg.com/news/articles/2026-06-02/eu-s-ai-data-center-plans-stumble-due-to-delays-funding-issues. Reports indicate that the €20 billion InvestAI envelope—combining EU and member-state subsidies with private capital—would support up to five AI gigafactories. The bidding process slipped to July 2026, only two of the five proposed sites appear financeable before 2028, and the number of interested consortia reportedly fell from roughly 70 to about 10.
[32] Luca Enriques, Casimiro Nigro & Tobias Tröger, Why the 28th Regime Proposal Falls Short of Europe’s Challenge, Oxford Bus. L. Blog (Mar. 19, 2026), https://blogs.law.ox.ac.uk/oblb/blog-post/2026/03/why-28th-regime-proposal-falls-short-europes-challenge; see also Eur. Comm’n, Proposal for a Regulation Establishing a 28th Regime (“EU Inc.”), COM (2026) 321 final (Mar. 18, 2026).
[33] Miko?aj Barczentewicz & Kristian Stout, How Not to Use Industrial Policy to Promote Europe’s Digital Sovereignty, Truth on the Mkt. (Oct. 5, 2022), https://truthonthemarket.com/2022/10/05/how-not-to-use-industrial-policy-to-promote-europes-digital-sovereignty; see also Miko?aj Barczentewicz & Kristian Stout, The EU’s Cybersecurity Draft Shifts Toward Hard Protectionism, Truth on the Mkt. (Nov. 14, 2023), https://truthonthemarket.com/2023/11/14/eus-cybersecurity-draft-shifts-toward-hard-protectionism (criticizing the EUCS “immunity from non-EU law” approach from which CADA’s highest sovereignty tiers descend).
[34] Index Ventures, Rewarding Talent: A Guide to Stock Options for European Entrepreneurs, https://www.indexventures.com/rewarding-talent (comparing national stock-option tax regimes and finding that the Baltic states rank among Europe’s most favorable jurisdictions, while Belgium, Germany, and Spain rank among the most burdensome).
[35] Luis Garicano & Per Strömberg, Why Sweden Has So Many Unicorns, Silicon Continent (Feb. 16, 2026), https://www.siliconcontinent.com/p/why-sweden-has-so-many-unicorns (arguing that Sweden’s 2003 reform—which defers taxation of gains from unlisted shares when investors reinvest the proceeds in other unlisted companies—helped create the country’s angel-investor ecosystem).
[36] Luis Garicano & Ulrike Malmendier, Calling Something the 28th Regime Does Not Make It One, Silicon Continent (Mar. 17, 2026), https://www.siliconcontinent.com/p/calling-something-the-28th-regime (noting the proposal’s EU-wide stock-option regime while criticizing its reliance on national law and arguing for a regime focused on young, cross-border-scalable firms with genuinely harmonized equity-compensation and tax rules for key employees).
[37] Eur. Comm’n, Impact Assessment, supra note 5, pt. 2 (reporting sensitivity analysis of the data-center financial model and finding that the weighted average cost of capital is “predominantly affected by financial market conditions and sovereign risk, necessitating macrofinancial instruments rather than operational regulations to influence it,” and that “[t]axation and depreciation are dictated by national fiscal policies”).
[38] Barczentewicz, supra note 3.
[39] Eur. Comm’n, Impact Assessment, supra note 5, pt. 1 (projecting an EU data-center-capacity gap of “almost 3 GW” in 2025, widening under the central scenario to roughly 19 GW by 2036. The assessment projects supply reaching about 42 GW by 2036, but demand growing even faster).
[40] Eur. Comm’n, Impact Assessment, supra note 5, pt. 1 (finding, under the baseline scenario, that the limited scale and scope of EU providers “makes reliance on non-European providers inevitable”; that “European service providers [are] struggling to work at the frontier”; and that dependence on hyperscalers, “particularly for highly critical use cases,” will persist).
[41] Eur. Comm’n, Proposal for the Chips Act 2.0 (June 3, 2026), https://digital-strategy.ec.europa.eu/en/library/proposal-chips-act-20. The proposal envisions a first-of-its-kind European foundry combining leading-edge manufacturing at the 3 nm node and below with chiplet integration and advanced 3D packaging. It targets pilot production between 2030 and 2033 and allocates roughly €30 billion to the foundry as part of an estimated €120 billion semiconductor-investment requirement through 2035. The proposal also replaces the original Chips Act’s goal of a 20% global market share by 2030 with the less specific objective of securing a “growing global share.” The text contains no reference to high-bandwidth memory or frontier logic chips.
[42] Miko?aj Barczentewicz, You Can’t Regulate a GPU Into Existence, Truth on the Mkt. (May 18, 2026), https://truthonthemarket.com/2026/05/18/you-cant-regulate-a-gpu-into-existence.
[43] Juijn et al., supra note 26. The Europe 2031 scenario’s closing retrospective frames compute capacity as the critical opportunity Europe failed to seize. A fictional European Commission trade official argues that Europe needed “the metal on our soil”—data centers, chips, and power supplies “anchored under European law, in jurisdictions Washington could not commandeer at six hours’ notice”—and that capacity “had to be in the tens of gigawatts.” The retrospective contends that Europe “could have got to fifteen, maybe twenty per cent [of global compute] in five years,” that the prospect of losing access to that scale of compute would have constrained U.S. action, and that speed was decisive because “bringing a single data centre online a month faster was worth billions.” It concludes that the priority should have been ensuring that the data centers “that are built are bolted to our floor.”
[44] ASML Holding N.V., Shares, https://www.asml.com/en/investors/shares. ASML is headquartered in the Netherlands and remains European-led, but its two largest shareholders are U.S. asset managers. According to the company’s disclosures as of Feb. 18, 2026, BlackRock held 6.83% of its ordinary shares and Capital Research and Management Company (Capital Group) held 5.09%. ASML’s EUV light sources are developed by Cymer in San Diego, key optics work is performed in Wilton, Connecticut, and U.S. export-control jurisdiction extends to its equipment through the Foreign Direct Product Rule. See Barczentewicz, supra note 19.
[45] Eur. Comm’n, Tech Sovereignty Communication, supra note 9 (stating that European technological sovereignty rests on “openness, partnership and fair competition”; emphasizing that it “does not mean isolation, protectionism, or tech decoupling”; and committing the European Union to remain “open to the world” while pursuing “mutually beneficial technology partnerships with countries that share our vision”).