KONSTANTINOS KOMAITIS
  • About me...
  • Write. Share. Ignite.
  • Byline
  • Media
  • Books
  • "Internet of Humans" podcast

Write. Share. Ignite.

EU’s Tech Sovereignty Package: the Good, the Really Good, the Bad and the Ugly

6/3/2026

 
Picture


The EU’s long-awaited Tech Sovereignty Package is not just another EU digital strategy paper but an attempt to redefine Europe’s relationship with technology power, especially after years of relying heavily on US cloud providers, Asian semiconductor supply chains, and foreign software ecosystems. The paper essentially says: Europe can no longer afford to be mostly a regulator while others build the infrastructure.

The easiest way to understand the package is this:

  • Europe believes it became too dependent on non-European technology.
  • It fears those dependencies are now geopolitical risks, not just business risks.
  • So the EU wants to build more of its own technology stack: chips, cloud, AI, software, data infrastructure, open source ecosystems, and standards.
  • At the same time, it insists this is not “digital protectionism” or “decoupling.”

The package has four major pillars:
  1. Chips Act 2.0
    Build more semiconductor capacity inside Europe.
  2. Cloud and AI Development Act (CADA)
    Expand European cloud and AI infrastructure and reduce reliance on foreign hyperscalers.
  3. EU Open Source Strategy
    Use open source software as a sovereignty tool and reduce vendor lock-in.
  4. AI and Digitalisation in Energy
    Build greener and more energy-efficient digital infrastructure.

What makes this document important is that it openly frames technology as geopolitical power. The language is much sharper than earlier EU digital policy documents, using phrases like “strategic liabilities,” “foreign interference,” “trusted partners,” “jurisdictional reach,” and “supply chain weaponisation.”
So here is the “good, really good, bad, and ugly.”

The Good
1. Europe is finally addressing a real problem

The core diagnosis is mostly correct.

Europe missed much of the platform era and it became highly dependent on:
  • US cloud providers;
  • US software ecosystems;
  • Asian semiconductor manufacturing;
  • foreign AI infrastructure;

​The document openly admits that more than 80% of Europe’s digital products, services, infrastructure, and IP come from outside the EU.
That is not sustainable if:
  • geopolitics worsen;
  • export controls increase;
  • sanctions spread;
  • or infrastructure becomes politicised.

The EU is no longer treating technology merely as a market issue. It now sees it as strategic infrastructure, similar to energy or defense.

That shift is overdue.

2. The open source strategy is surprisingly strong

This is probably the most intellectually coherent part of the package.

The EU finally understands that open source is not just about software philosophy but about reducing dependency and increasing strategic flexibility.

Several ideas here are genuinely important:
  • public money/public code;
  • open source-first procurement;
  • interoperability requirements;
  • reducing vendor lock-in;
  • support for open digital commons;
  • funding maintenance of critical open source infrastructure;
  • European stewardship foundations for strategic codebases.

The proposal for an “Open Source Maintenance Instrument” is especially important.

One of the biggest weaknesses in global open source ecosystems is that critical infrastructure is often maintained by underfunded volunteers. Europe is correctly identifying maintenance and stewardship as strategic issues.
The emphasis on interoperability is also significant. The package repeatedly stresses portability and the ability to switch providers.

That could genuinely improve competition.

3. The document understands ecosystems better than earlier EU policy

Past EU digital policy often focused too heavily on regulation. This paper is different as it talks constantly about:
  • supply-side support;
  • demand-side measures;
  • public procurement;
  • scaling;
  • industrial ecosystems;
  • financing;
  • skills;
  • infrastructure;
  • and market creation.

That matters because you cannot regulate your way into technological leadership. The paper finally acknowledges that Europe needs:
  • industrial capacity;
  • compute;
  • manufacturing;
  • procurement power;
  • and scale.

That is a major conceptual shift.

4. The document is trying to preserve openness
This is important and should not be ignored. The paper repeatedly says sovereignty does not mean isolation or decoupling.
​
That distinction matters because there is a meaningful difference between:
  • building resilience,
    and
  • building digital nationalism.
The EU is trying to position itself somewhere between:
  • US market concentration,
    and
  • China’s state-controlled digital model.
Whether it succeeds is another question, but the attempt matters.

The Really Good

1. The package quietly recognizes that cloud dependence is a political problem

This may be the most consequential part of the entire paper. The document openly states that dependence on foreign cloud providers creates risks related to:
  • foreign jurisdiction;
  • surveillance;
  • public order;
  • and extraterritorial reach.

That is really about US legal reach and the EU has been struggling with this issue since Snowden, Schrems, the Cloud Act debates and transatlantic data transfer disputes. This document, therefore, effectively says:
Europe cannot build strategic AI capability while most compute infrastructure remains externally controlled.

2. The focus on procurement could actually change markets


The procurement parts may sound boring, but they are potentially transformative. The document correctly identifies that procurement rules often favor incumbent proprietary vendors.
If Europe genuinely shifts public procurement toward:
  • open standards;
  • interoperability;
  • reusable public code;
  • and open source-first systems
then this could:
  • create viable European software ecosystems;
  • reduce lock-in;
  • and create space for smaller firms.

This is one of the few areas where Europe can realistically move markets at scale.

3. The package understands that AI sovereignty is impossible without compute sovereignty


This is another strong point. The paper links chips, cloud, AI infrastructure, data centers, and energy systems
as one interconnected stack. That is strategically correct. Too many AI policy discussions treat models as the center of power. This document understands that: compute, infrastructure, energy and cloud control matter just as much.

The Bad


1. “European technology stack” language is risky

The phrase “full European technology stack” appears several times. That sounds coherent politically, but technologically it is much harder.
Modern digital systems are deeply global:
  • semiconductors;
  • open source libraries;
  • cloud architecture;
  • AI models;
  • Standards;
  • developer ecosystems; and,
  • cybersecurity tooling,
    all depend on international interconnection.

The risk is that sovereignty language slowly shifts from resilience, to localization expectations, to implicit protectionism.

That is where things can become problematic for the open internet.

2. There is tension between openness and sovereignty

The paper says:
  • Europe wants openness,
  • interoperability,
  • and global cooperation.
But it also proposes:
  • sovereignty classifications,
  • trusted provider structures,
  • European control requirements,
  • and “exclusive EU oversight” for strategic systems.
Those goals may eventually collide.
The central question becomes:


How much foreign participation is acceptable before something is no longer considered “sovereign”?
The document never fully answers that.

3. The economic assumptions may be too optimistic

The paper assumes Europe can simultaneously:
  • reduce dependencies;
  • build domestic alternatives;
  • stay globally competitive;
  • and avoid fragmentation.
That is difficult.

Digital ecosystems benefit enormously from:
  • scale;
  • network effects;
  • capital concentration;
  • and developer gravity.

Europe has talent and research capacity, but historically it has struggled to scale digital champions. The package acknowledges the investment gap, but it may still underestimate how hard it is to compete with:
  • US hyperscalers;
  • Chinese state-backed ecosystems;
  • and global AI capital concentration.

4. There is a lot of industrial policy optimism


The document assumes coordination will work smoothly across:
  • Member States;
  • Regulators;
  • public procurement;
  • infrastructure;
  • standards;
  • and industrial policy.

History suggests Europe often struggles with execution.

The danger is that this becomes:
  • many strategies;
  • many governance frameworks;
  • many funding instruments;
    but not enough operational delivery.

The Ugly


1. Sovereignty could become a justification for fragmentation


This is the biggest risk for the open Internet.

The document insists it supports openness. But parts of the framework could gradually normalize:
  • regional technology blocs;
  • sovereignty-based infrastructure requirements;
  • local control mandates;
  • trusted vendor lists;
  • and differentiated market access.

If replicated globally, this could accelerate:
  • fragmentation of digital infrastructure;
  • fragmentation of cloud ecosystems;
  • and fragmentation of technical governance.

In practice, the Internet works best when:
  • systems interoperate globally;
  • standards remain open;
  • and cross-border infrastructure remains trusted.

A sovereignty-first logic can slowly weaken those assumptions.

2. “Trusted” language can become political very quickly


The document constantly refers to “trusted” partnerships and providers.
But trusted by whom? Based on what criteria? Political alignment? Jurisdiction? Ownership?
Supply chain? Security certification?

Once governments start classifying technology ecosystems politically, markets can become increasingly geopolitical.

That may be unavoidable to some extent. But it also changes the character of the Internet from globally interconnected infrastructure,to competing geopolitical technology spheres.

3. The package could unintentionally strengthen bureaucracy over innovation

There is a tension throughout the document:
  • simplification rhetoric on one side;
  • heavy governance architecture on the other.

The EU often excels at frameworks, standards, and governance processes.

It is less successful at creating:
  • fast-moving innovation ecosystems;
  • venture scale;
  • or global digital champions.

If implementation becomes overly compliance-heavy, Europe may create:
  • more reporting;
  • more certification;
  • more sovereignty assessments;
    without generating enough actual innovation capacity.
 
Could this impact the open Internet?
Yes — potentially in both positive and negative ways.

Positive impact


The package could strengthen important open Internet principles by:
  • promoting interoperability;
  • reducing vendor lock-in;
  • supporting open standards;
  • investing in open source;
  • and decentralizing digital power.

Those are healthy counterweights to extreme concentration in a few global firms.
The open source parts especially could reinforce:
  • transparency;
  • portability;
  • decentralization;
  • and user choice.

That is broadly aligned with the spirit of the open Internet.

Negative impact


But the sovereignty framing could also contribute to Internet fragmentation.

If “digital sovereignty” evolves into infrastructure localization, sovereignty certification, jurisdiction-based access controls, or political trust blocs, then interoperability across regions could weaken over time.

The Internet would still technically exist as one network, but operationally it could become more segmented and geopolitical.

In many ways, this package reflects a larger global shift: the Internet is increasingly being treated not just as communications infrastructure, but as strategic state infrastructure.

That changes everything.

Final assessment


This is probably one of the EU’s most strategically important digital policy documents in years.

At its best, it is:
  • realistic about geopolitical dependency;
  • smart about open source;
  • serious about industrial capacity;
  • and more economically grounded than earlier EU digital policy.

At its worst, it risks:
  • turning sovereignty into techno-nationalism,
  • contributing to fragmentation,
  • overestimating Europe’s execution capacity,
  • and replacing dependency with bureaucratic complexity.

The most important unresolved question is this:
Can Europe build technological resilience and strategic capacity without undermining the openness and interoperability that made the Internet valuable in the first place?

​That tension sits at the center of the entire package.
 


Comments are closed.

    Categories

    All
    5G
    Accountability
    Acpa
    Appeal
    .bank
    Book On The Current State Of Domain Name Regulation
    Cartagena
    Cctlds
    China
    Civil Society
    Coica
    Collaboration
    Conference
    Copyright
    Copyright Infringement
    Counterfeit Goods
    Criminal Activity
    Czech Arbitration Court
    Dag4
    Dakar
    Default
    Democracy
    Digital Sovereignty
    Dns
    Domain Name
    Domain Names
    Domain Names.
    Encryption
    E-PARASITE ACT
    Europe
    Fair Use
    Free Speech
    Froomkin
    G20
    Gac
    Giganet
    Gnso
    Governmental Advisory Committee
    Gtlds
    Hargreaves Report
    Icann
    Icann Board
    In Rem
    In Rem Jurisdiction
    Intellectual Property
    Intergovernmental Organizations
    International Olympic Committee
    Internet
    Internet Governance
    Interoperability
    Ioc
    Irt
    Jurisdiction
    Justice
    Licensing
    Lobbying
    Loser Pays Model
    Morality And Public Order
    Mueller
    Multistakeholder
    Multistakeholder Participation
    Multistakholderism
    Naf
    Nairobi Treaty
    Ncsg
    Ncuc
    #netflix
    Network Neutrality
    New Gtld Applicant Guidebook
    New Gtlds
    New Kids On The Block
    Ngos
    Ninth Circuit
    Nominative Use
    Nominet
    Non-profits
    Not-for-profit
    Npoc
    Olympiad
    Olympic
    Online Infringement
    Online Infringement And Counterfeits Act
    Open Internet
    Paris Convention
    Pddrp
    Permissionless Innovation
    Phising
    Pipa
    Poll
    Ppdrp
    Preliminary Gnso Issue Report On The Current State Of The Udrp
    Procedural Justice
    Protect Act
    Protect Ip Act
    Public Policy
    Red Cross
    Registrant
    Registrars
    Regulation
    Review
    Rule Of Law
    Russia
    S.3804
    Scorecard
    Senate Bill S.3804
    Senate Hearing
    Senator Leahy
    Sopa
    Sovereignty
    Sti
    Stop Online Piracy Act
    #streaming
    Supplemental Rules
    Technological Sovereignty
    Tmc
    Trademark
    Trademark Bullying
    Trademark Clearinghouse
    Trademark Lobbying
    Trademark Owners
    Trademarks
    Transparency
    Udrp
    Urs
    Us Congress
    Us Department Of Commerce
    Uspto
    Wipo
    WSIS

Proudly powered by Weebly
  • About me...
  • Write. Share. Ignite.
  • Byline
  • Media
  • Books
  • "Internet of Humans" podcast