Europe launches Technological Sovereignty Package

  • June 22, 2026
  • William Payne

The European Commission has launched an industrial strategy to transform the continent’s technological sovereignty that is likely to impact the future development, deployment and operation of every EU or national funded IoT or smart technology programme throughout Europe. Launched at the beginning of June, the Technological Sovereignty Package is designed to engineer a EU sovereign digital stack that can independently support the continent’s critical infrastructure without any foreign dependencies.

The aim to the new strategy is the construction of a localised, autonomous technology ecosystem to protect Europe’s smart grids, intelligent transport networks, and municipal infrastructure, without dependence on non-EU companies or governments. The new strategy is certain to directly impact the deployment of smart energy, healthcare technology, smart city, transportation, industrial automation, and IoT cloud infrastructure across the European Union.

Background & Strategic Objectives

At present, the EU relies on foreign providers for the vast majority of its advanced semiconductor manufacturing, hyperscale cloud computing, and AI inference capacity. As industrial IoT (IIoT) and smart city deployments scale, this dependency is increasingly being viewed in Brussels and national capitals as an acute operational risk.

According to an analysis by UK industry body techUK, European policymakers increasingly view advanced semiconductors, cloud infrastructure, and computing capacity not merely as commercial products, but as strategic assets with direct implications for economic security. The package represents a transition from supply-side protections to demand-side mandates. To offset the massive capital advantages of US hyperscalers and Asian foundries, the EU is using its regulatory leverage to mandate interoperability, enforce open-source adoption, and ring-fence public sector procurement. According to techUK, the objective is to fracture the vertically integrated monopolies of foreign technology providers, forcing them to compete on a modular, European-defined playing field where domestic firms can capture specific layers of the IIoT and edge computing stack.

Main Legislative Components

The Technological Sovereignty Package is constructed across four interconnected pillars, each designed to address a specific layer of the digital and physical infrastructure stack.

The Cloud and AI Development Act (CADA)
CADA is the regulatory engine of the package, aimed at tripling EU data centre capacity within five to seven years while enforcing strict jurisdictional control over compute infrastructure. At its core is a four-tier sovereignty framework that categorises cloud and AI services based on operational control, supply chain dependencies, data location, and cybersecurity assurance.

For public sector bodies and critical infrastructure operators—including municipal transit authorities and smart grid managers—CADA mandates sovereignty risk assessments that will dictate procurement. High-tier workloads will be legally restricted to infrastructure that is immune to extraterritorial legal orders. To enforce this, CADA introduces “Union added value” non-price criteria into public procurement, effectively functioning as a legal mechanism to channel capital toward providers demonstrating EU-based design and operational control.

In a briefing on the new package, international legal firm Covington notes that this framework leaves room for national variation, potentially fragmenting the internal market. British newspaper Sunday Times supplement Raconteur has reported that European cloud executives are lobbying to import defence-procurement-style “effective control” criteria into CADA, which would explicitly exclude firms subject to extraterritorial legal orders from non-EU jurisdictions.

Recognising that software mandates are meaningless without physical compute capacity, CADA introduces Data Centre Acceleration Zones. These zones are designed to bypass the EU’s notoriously sluggish physical permitting processes, streamlining land acquisition, water cooling rights, and grid interconnects to accelerate the deployment of the physical infrastructure required for industrial AI and edge processing. Furthermore, CADA establishes an “open-source-first” principle for public cloud infrastructure, deliberately steering state capital away from proprietary foreign ecosystems.

Chips Act 2.0
Where the original 2023 Chips Act focused heavily on research and legacy nodes, Chips Act 2.0 is a pivot toward high-performance AI silicon (sub-3nm architectures) required for advanced edge inference and autonomous infrastructure. Acknowledging the brutal learning curves and capital intensity of advanced foundries, the legislation shifts focus to commercialisation.

The most critical mechanism in Chips Act 2.0 is the establishment of Demand Accelerators. These state-backed instruments will link chip producers directly to industrial buyers through guaranteed off-take agreements, ensuring that new foundries have the anchor customers required to remain solvent. To address the physical bottlenecks of semiconductor manufacturing, the Act mandates a 12-month fast-track permitting process for new foundries, an unprecedented override of local bureaucratic friction.

However, the strategic viability of this approach is contested. According to an analysis by the Centre for European Policy Analysis (CEPA), European chip demand comes primarily from the automotive sector and industrial applications, which rely on 28/22 nanometre technology, not cutting-edge AI chips. CEPA argues that without strong domestic AI demand, a state-backed mega-fab for sub-3nm chips risks becoming an expensive, politically sensitive project whose output would largely be exported to the United States.

The EU Open Source Strategy
The Commission’s Open Source Strategy adopts an approach to Open Source that will treat it in future as a state-backed industrial lever. By committing €2 billion over seven years and enforcing a “public money, public code” directive, the EU is attempting to weaponise open-source software to counter foreign proprietary monopolies and prevent vendor lock-in across its critical infrastructure.

The strategy introduces an Open-Source Maintenance Instrument to provide sustained financial support for the lifecycle of critical repositories, moving beyond project-launch funding to address the chronic underfunding of core digital infrastructure. According to the Centre for European Policy (CEP), while the maintenance instrument is conceptually sound, the €2 billion funding envelope is thin for a strategy intended to replace €264 billion in annual proprietary IT spending.

Strategic Roadmap for Digitalisation and AI in Energy
The most immediate physical constraint on Europe’s digital sovereignty is energy. Estimates published by Europe’s electricity industry federation Eurelectric suggest that data centres could account for around 28% of the growth in European electricity consumption by 2030. The Strategic Roadmap explicitly ties the compute ambitions of CADA and the Chips Act 2.0 to the physical realities of the smart grid.

The Roadmap mandates tripartite agreements between data centre operators, public authorities, and energy providers to integrate new compute loads into national grid planning. It enforces a stringent rating scheme for data centre efficiency, measuring water usage, renewable energy integration, and waste heat reuse. Simultaneously, it mandates the deployment of AI across the energy system itself, utilising edge nodes and IIoT sensors to automate grid optimisation and demand-side flexibility. This ensures that hyperscale and edge facilities do not merely draw from the grid, but act as dynamic, dispatchable loads that stabilise municipal power networks.

Strategic Summary

The Technological Sovereignty Package is an attempt by the EU to architect a self-sustaining digital industrial base. However, there are macro risks associated with its execution.

The EU’s attempt to institutionalise open-source software carries a distinct risk of regulatory overreach. By attaching stringent compliance, security, and sovereignty mandates to state funding, the Commission risks chilling the very volunteer maintainers it seeks to empower. Top-down regulation inherently conflicts with the decentralised, borderless nature of open-source developer cultures. Furthermore, the strategy largely ignores the continent’s deep structural dependency on US-hosted infrastructure; the vast majority of European open-source collaboration remains physically and operationally tethered to Microsoft-owned GitHub. Legislating a sovereign software ecosystem while relying on foreign-owned version control and repository hosting presents a glaring architectural vulnerability.

The package’s success is dependent on capital efficiency that is currently hostage to internal EU budget battles. The funding required to operationalise CADA’s acceleration zones, the Open Source Strategy, and the Chips Act 2.0’s Demand Accelerators is tied to the Multiannual Financial Framework (MFF). Here, the industrial strategy faces geopolitical headwinds: an ongoing conflict between northern European member states demanding strict cost-cutting and southern member states fiercely protecting legacy agricultural subsidies. This internal conflict could well defund the European Competitiveness Fund, which a majority of EU member states want to cut. This would cut off funding from precisely the start-up companies that the European Commission’s new strategy needs to achieve its objectives.