Europe Declares Digital Independence: The EU's Tech Sovereignty Package Explained

On Wednesday, June 3, 2026, the European Commission unveiled what it is calling the most comprehensive and ambitious strategy to reduce Europe's reliance on foreign technology in the bloc's history. Its tech sovereignty package — the most comprehensive attempt yet to reduce the bloc's dependence on foreign technology — targets cloud computing, artificial intelligence, semiconductors, and open-source software in a single coordinated push. The package was presented by Henna Virkkunen, the European Commission's Executive Vice-President for Tech Sovereignty, Security and Democracy, who framed the entire initiative in language that left no ambiguity about Europe's motivations and its determination to act: "We want to be sure nobody has a kill switch."

The statement was not metaphorical. It was a direct reference to a specific, real incident that crystallized Europe's digital vulnerability in an unprecedented and deeply personal way.

The "Kill Switch" Moment That Changed Everything: The Microsoft-ICC Incident

To understand the urgency behind the EU's June 3 package, you must understand the event that made abstract fears about digital dependency suddenly concrete and undeniable. When the Trump administration sanctioned the International Criminal Court's top prosecutor earlier this year, Microsoft cancelled his email account. The incident was brief and bureaucratic. It was also, for European policymakers, clarifying. If a single American company could cut off a senior international official's communications at the stroke of a pen, what else could be switched off?

This is the question that the European Commission's Technological Sovereignty Package is designed to answer — not with rhetoric, but with legislation. The Microsoft-ICC incident demonstrated that Europe's dependence on US cloud providers is not merely a commercial or competitive issue. It is a geopolitical vulnerability that can be activated, deliberately or incidentally, by any US administration decision, executive order, or sanction regime that touches American technology companies — regardless of where their European customers are located or what European law says about data sovereignty.

The Scale of the Problem: €264 Billion Per Year and 70% Cloud Market Share

Before examining the specific components of the package, it is essential to understand the scale of the dependency problem the EU is confronting. The numbers are stark and have been suppressed in European public discourse for far too long:

  • US cloud companies control more than 70% of the EU cloud market while the EU produces less than 10% of global semiconductors and is almost entirely dependent on the United States and Asia.
  • The EU itself said it currently spends €264 billion a year mostly on US proprietary IT products and services.
  • AWS, Microsoft Azure and Google Cloud currently account for around 70% of Europe's cloud market, and the US Cloud Act means American authorities can compel those providers to hand over data regardless of where it is stored.
  • AI-related components are expected to account for more than 70% of the global semiconductor market by 2030, and Europe still leans heavily on third countries for advanced design and production.

European Commission President Ursula von der Leyen captured the existential dimension of these numbers with directness: "We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable and our services secure." Virkkunen was equally blunt about what the package represents: "Today's package marks a major shift in how Europe approaches technological sovereignty. It is time for Europe to be in control of its data, of its supply chains, and of its future in a clean and sustainable way."

The Four Pillars of the EU Tech Sovereignty Package

The headline items are two new legislative proposals: a Chips Act 2.0 and a Cloud and AI Development Act (CADA), alongside an Open Source Strategy and a roadmap for digitalising the energy sector. Here is a comprehensive breakdown of each pillar:

Pillar 1: Chips Act 2.0 — Rebuilding Europe's Semiconductor Backbone

The original EU Chips Act of 2023 committed €43 billion to double the EU's global semiconductor market share to 20% by 2030. That target is now considered unrealistic by most analysts — but the new Chips Act 2.0 is not a retreat from ambition. It is a recalibrated strategy focused specifically on the semiconductors that matter most in the AI era. The first act introduced a range of measures seeking to secure semiconductor supplies and increase the EU's global share of the market. The new act aims to address overdependence on third countries for chip design and manufacturing and insufficient preparedness for crises. The Chips Act 2.0 will look to build capacity in cutting-edge semiconductor technologies that power AI. The Commission said it would "prioritize" building a foundry for advanced semiconductor manufacturing capabilities within the bloc.

The Chips Act 2.0 also introduces a new excellence label for European semiconductor regions, designed to create a recognizable quality standard for European-made chips that can compete in global procurement decisions. Critically, the legislation includes emergency powers: it would grant Brussels emergency powers to prioritize chip production during supply crises, including the ability to override existing commercial agreements — a provision that responds directly to the catastrophic chip shortages that crippled European automotive and industrial production in 2021–2022 and revealed the danger of single-source dependency on East Asian semiconductor supply chains.

Pillar 2: The Cloud and AI Development Act (CADA) — Four Sovereignty Tiers and a Framework for Digital Independence

The Cloud and AI Development Act (CADA) is the most legally significant component of the package — and the one that will most directly affect US cloud providers operating in Europe. The Cloud and AI Development Act creates four sovereignty tiers for public-sector cloud use. This tiered framework is designed to give European governments and public institutions the legal tools to require that their most sensitive data and workloads run on infrastructure that meets specific sovereignty standards — up to and including requirements that exclude non-European providers entirely from the most sensitive categories.

As part of the proposals, CADA is being introduced to "mitigate the risks stemming from the EU's reliance on third countries for cloud computing services" by implementing an EU-wide framework setting out different levels of sovereignty needed for cloud computing for sensitive workloads at public organizations. Virkkunen was explicit about the US Cloud Act as the mechanism that makes current US cloud arrangements fundamentally incompatible with the highest sovereignty tier: "She added it would be difficult for US companies to reach the highest levels of sovereignty because of the US Cloud Act, which allows US law enforcement to request user data from American companies, regardless of where the data is stored. 'We want to make sure that our most critical sensitive data is stored in Europe,' she said."

The ambition of CADA extends beyond just restricting US cloud access: to accelerate deployment, the Act will streamline permitting processes and identify suitable sites for new facilities. The ambition is to ensure that European organisations can run AI workloads on European infrastructure, rather than routing them through US hyperscaler data centres governed by US law. According to CNBC's exclusive coverage of the package launch, the proposals must still be approved by all 27 EU member states — a legislative process that could take years and will face significant lobbying from US technology companies and their European industry partners.

Pillar 3: The Open Source Strategy — 3 Million European Developers as a Strategic Asset

The third pillar of the package is perhaps the most forward-looking: a comprehensive EU Open Source Strategy designed to scale European-built alternatives in cloud, AI, cybersecurity, and semiconductors. The Open Source Strategy looks to scale European-built alternatives in cloud, AI, cybersecurity and semiconductors, drawing on a developer base of more than 3 million across the continent. This strategy recognizes that software sovereignty cannot be achieved through hardware investment alone — it requires building a viable, competitive, and well-funded ecosystem of European-developed open-source alternatives to the proprietary US software platforms that currently dominate the enterprise technology market.

The Open Source Strategy has several dimensions: encouraging wider adoption of existing European open-source projects in public sector procurement; funding new open-source development in areas of strategic priority; creating interoperability standards that reduce lock-in to proprietary US platforms; and building the developer community infrastructure — education, grants, and collaborative platforms — that will sustain a multi-generation European open-source movement.

Pillar 4: Strategic Roadmap for AI and Digitalisation in Energy

The fourth pillar addresses the intersection of digital sovereignty and energy infrastructure — one of the most critical and under-discussed dimensions of Europe's technology dependency. The Package comprises four components: two legislative proposals — (i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0 — alongside two strategic plans: the Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy. The energy digitalisation roadmap recognizes that smart grids, renewable energy management, and industrial AI applications in the energy sector require enormous computing infrastructure — and that this infrastructure must be sovereign if Europe's energy transition is to be insulated from foreign technology dependencies and potential geopolitical weaponization.

What This Means for US Big Tech: AWS, Microsoft Azure, and Google Cloud

The implications for US cloud giants are significant and immediate. The four-tier sovereignty framework in CADA effectively creates a legal architecture that could exclude AWS, Microsoft Azure, and Google Cloud from the most sensitive government procurement categories across all 27 EU member states — a combined market worth hundreds of billions of euros annually. The US Cloud Act's extraterritorial reach over US cloud providers means that no amount of European data center investment by US hyperscalers can guarantee the highest sovereignty tier under CADA's framework. This creates a structural competitive disadvantage for US cloud providers in European public sector markets that cannot be resolved through engineering alone — it would require a change in US law.

Virkkunen was candid about this dynamic, openly acknowledging that it would be difficult for US cloud companies to achieve the highest sovereignty classification. For US cloud providers, the strategic response will likely involve accelerated investment in European joint ventures and partnerships with European cloud providers — structures where the data processing, storage, and management are genuinely conducted by European-owned and European-governed entities, with the US hyperscaler providing the underlying technology platform under license.

The Credibility Question: Will This Package Actually Work?

European digital sovereignty initiatives have a complicated history. The original 2023 Chips Act's 20% global market share target by 2030 is now widely considered unachievable. The GAIA-X cloud sovereignty project — announced in 2019 with enormous fanfare — struggled to gain commercial traction against the entrenched dominance of US hyperscalers. Even Forrester's 2026 European Predictions notes that while European firms will intensify the quest to reduce their dependence on global resources and achieve sovereignty over their technology stack and digital platforms, no European enterprise will shift entirely from US hyperscalers in 2026.

The Commission is aware of this credibility gap. The Chips Act 2.0's more targeted focus on AI-specific semiconductors — rather than the broader and harder-to-achieve market share targets of the first act — reflects a more pragmatic assessment of what is achievable. The CADA's tiered approach — rather than a blanket ban on US cloud providers — similarly reflects the political reality that a complete de-coupling from US cloud infrastructure is neither feasible nor desirable for most European businesses in the near term.

What the package does represent is a genuine, legally binding shift in the direction of procurement requirements and regulatory pressure that will, over time, create market space for European cloud and AI providers that currently cannot compete with the scale, investment levels, and product breadth of US hyperscalers. The €264 billion annual spending figure is the prize that the EU is trying to redirect toward European providers — and with the legislative architecture of CADA and Chips Act 2.0 now formally in development, the pressure on member states to prioritize European alternatives in public sector IT procurement will be stronger than at any previous point in the EU's digital history.

The Broader Geopolitical Context: US Tariffs, the Iran War, and Europe's Strategic Wake-Up

The June 3 package does not exist in a geopolitical vacuum. It arrives at a moment of profound and accelerating European discomfort with US reliability as a technology partner. The Trump administration's use of financial sanctions to prompt Microsoft to deactivate a senior ICC official's email account was one flashpoint. The broader pattern of the Trump administration's transatlantic policy — including tariff disputes, NATO spending demands, and the general prioritization of US bilateral interests over multilateral rules-based frameworks — has accelerated the EU's determination to reduce technological dependencies that could be weaponized. The efforts by Brussels have gained urgency as leaders worry about dependence on technologies from foreign providers, which they say could be "weaponized" against Europeans.

Virkkunen put the geopolitical framing most succinctly: "Europe wants to be in the position to make its own choices, avoiding risky dependencies on single dominant suppliers, one company or one third country. Because we live in a world where geopolitics and technology go hand in hand. Those who champion technological innovation will shape the future, and we must ensure that Europe plays a leading role in this." The June 3 Tech Sovereignty Package is Europe's most comprehensive answer yet to that challenge — and its success or failure will help determine whether Europe remains a technological dependency of the United States and China, or builds the digital infrastructure to exercise genuine strategic autonomy in the decades ahead.