
This article is part of our curated Growth Hub — five pillars on sovereignty, AI, cloud economics, data and security. Visit the Growth Hub.
On the road we are on today, European digital sovereignty is a pipe dream. Not because the goal is wrong, but because the distance is enormous and the method is wrong. What has to be built is, by any honest estimate, twenty-plus years of work. It can be compressed into three to five. But only if we give up the fantasy of a pure, home-grown, centrally planned stack and replace it with something far less elegant: accept the gaps, decentralise, take the help that is on the table from the US and China, build cheap energy at scale, and let a lot of people try things and fail in public.
That is not a comfortable message. It is the only one that survives contact with the numbers.
Key takeaways
- Europe is behind on every layer of the stack — cloud, models, chips, energy, skills, capital — and by more than one product cycle on most of them. Sequential self-sufficiency is a two-decade programme.
- Regulation reshapes demand but does not create supply. The Cloud and AI Development Act sets the rules for 2027 and capacity targets for 2030; it does not build a single data centre.
- Sovereignty means the ability to decide and the ability to walk away — not self-sufficiency. That standard is reachable in three to five years.
- Open-weight models from the US and China, run on European-controlled infrastructure with European-held keys, are more sovereign than European models consumed through a foreign API.
- Cheap, abundant energy is upstream of everything else. Without gigawatts, every compute plan is decorative.
Where European digital sovereignty actually stands
Start with the audit, because most sovereignty debates skip it.
Cloud. European providers hold well under a fifth of their own home market. Roughly four out of five euros spent on professional cloud services in the EU go to American companies. The Commission’s own justification for the Cloud and AI Development Act, tabled on 3 June 2026 as part of the Tech Sovereignty Package, describes an annual outflow in the hundreds of billions and a structural dependency that touches hospitals, grids, and payment systems. We priced this dependency in detail in Europe, Stop Renting Your Future.
Models. The frontier is set in San Francisco, Seattle, and increasingly in Hangzhou and Beijing. Europe has one serious frontier lab and a handful of strong research groups. Every open-weight model that matters was trained on hardware Europe does not make, in data centres Europe does not own, with energy prices Europe cannot match.
Chips. The advanced accelerators that train and serve those models come from a single US designer, fabricated in Taiwan, on lithography machines from the Netherlands. The European link in that chain is real and it is exactly one link.
Energy. Compute is electricity with a thin layer of silicon on top. Industrial power in Germany costs several times what it costs in Texas or Sichuan. Grid connections for a new hyperscale site take years. Permitting takes longer. The Commission’s own act lists energy access, land, and permitting as the constraints on building capacity here at all.
Skills and capital. The engineers who know how to run planet-scale infrastructure mostly work for the companies we are trying to reduce our dependence on. The venture capital that could fund alternatives is a fraction of what is available in the US, and it is more risk-averse.
Put it together. Cloud, models, chips, energy, skills, capital: Europe is behind on every layer, and behind by more than one product cycle on most of them. Building all of it ourselves, sequentially, with public money and public procurement as the engine, is a two-decade programme. That is not pessimism. That is arithmetic.

Why the current approach cannot close the gap
There are three versions of the sovereignty plan in circulation. None of them gets us there in five years.
Sovereignty by regulation. Define four assurance levels, audit providers, steer public procurement toward the highest tier, and wait for the market to follow. The Cloud and AI Development Act does exactly this, and it is not useless: it turns a vague preference into a testable contract clause. But regulation reshapes demand. It does not create supply. You can require Level 4 sovereign cloud for a ministry; you cannot conjure a Level 4 provider with the scale, tooling, and reliability to run it. The act’s own timeline points at 2027 for entry into force and 2030 for capacity targets. That is the schedule for the rules, not for the infrastructure.
Sovereignty by champion. Pick a few large companies, fund them, and call the result a European hyperscaler. This has been tried, repeatedly, under different names. The failure mode is always the same: a consortium optimised for political balance rather than engineering velocity, shipping slowly, and losing every head-to-head evaluation against the incumbents.
Sovereignty by purity. Only European chips, only European models, only European code, only European operators. This is the version that feels most like sovereignty and delivers the least. It means refusing the most capable tools available today in exchange for tools that may exist in 2035. In the meantime, every European organisation that needs to get work done quietly keeps using the American stack, and the gap widens.
All three share a hidden assumption: that sovereignty means self-sufficiency. It does not. Sovereignty means the ability to decide, and the ability to walk away. Those are much cheaper to build than a complete parallel industry, and they can be built fast.
The plan that can work
Five principles. None of them are new individually. The combination is what nobody in Brussels wants to say out loud.
1. Accept the shortcomings
Set the target at control, not at independence. A European organisation is sovereign enough when it can answer three questions: Who holds the keys to my data? Can I move my workloads within a quarter if a supplier, a court, or a government turns hostile? Can I keep operating for ninety days if a foreign provider is cut off?
That standard is reachable in three to five years for most public bodies and regulated enterprises. It tolerates American hardware and Chinese model weights. It does not tolerate a single provider holding the encryption keys, the identity system, and the only copy of the data at the same time. Aim for eighty percent control now instead of one hundred percent control never. Our Digital Sovereignty Decision Matrix maps exactly this: which of the three sovereignty levels each workload actually needs.
2. Decentralise, and mean it
Europe will not build one hyperscaler. It might build three hundred medium-sized operators who interoperate. That is a worse story for a press conference and a better one for resilience. A federation of regional providers on shared open standards, common identity, portable workloads, and mutual failover is harder to buy, harder to sanction, and harder to switch off than any single champion. It also matches how Europe actually works: thousands of mid-sized companies, dozens of legal systems, no single decision-maker.
The public sector’s job here is to write the interfaces, fund the shared plumbing, and buy from the federation. Not to own it.

3. Take the help. From both sides.
This is the part that makes people uncomfortable, so it needs to be said plainly.
The open-weight models coming out of the US and China are a gift. Not a trap, a gift. Meta’s Llama family, Alibaba’s Qwen, DeepSeek, and the models Mistral builds on top of the same ecosystem can be downloaded, inspected, fine-tuned, and run entirely on infrastructure that Europe controls. The weights are the expensive part. Someone else paid for them. The training compute is sunk. What remains is inference, and inference can run in a data centre in Frankfurt or a rack in a Bavarian town hall.
Where the model was trained matters far less than where it runs, who holds the keys, and whether you can swap it out. A Chinese model running air-gapped in a European data centre, with European fine-tuning data and a European audit trail, is more sovereign than a European model consumed through an American API. This is the operating principle behind our agentic AI work: model choice is a procurement decision, control of the runtime is the sovereignty decision.
The same logic applies to the hyperscalers. Their reference architectures, their open-sourced tooling, their trained engineers who come home, and their willingness to build EU-operated, EU-owned deployments under sovereignty contracts are all assets. Use them to learn faster. Contract them under terms that keep the exit door open. Refusing help because of where it comes from is a luxury that a continent twenty years behind cannot afford.
4. Abundance and cheap energy, or nothing
Every sovereign compute plan that does not start with gigawatts is decorative. The compute needed to serve a European public sector and industrial base with modern AI is measured in gigawatts of continuous load. That means permitting reform measured in months rather than years, direct grid connections for compute sites, long-term power purchase agreements, and a willingness to build generation of every kind, including the kinds that are politically awkward.
Cheap, abundant, reliable energy is the single highest-leverage lever on the list, because it is upstream of everything else. It is also the one where Europe has the most catching up to do and the least time. The Cloud and AI Development Act’s target of tripling EU compute by 2030 is only credible if the power to run it exists first.

5. The freedom to try, fail, and do it differently
The American stack was not designed. It emerged from thousands of companies trying things, most of which failed, in a legal and cultural environment that treated failure as tuition. Europe cannot copy the outcome without copying the process.
Concretely: procurement that buys outcomes rather than specifications, so a twelve-person company in Tallinn can win a contract against a consortium. Regulatory sandboxes that are actually used, with real data and real workloads. A tolerance for three regional providers solving the same problem three different ways, because the one that works will be found faster that way than by committee. Fewer grand programmes, more small bets with short feedback loops.
This is the cultural shift, and it is the hardest one. It is also the only thing that turns twenty years into five.
What three to five years of digital sovereignty actually looks like
Year one. Every public body and regulated enterprise runs the three-question audit above and writes down the honest answers. Encryption keys move to European-controlled HSMs — the BYOK and HYOK patterns that end security-review threads. Identity is federated, not delegated. Exit clauses go into every new contract. Open-weight models are deployed on European infrastructure for the first real workloads. Energy permitting reform starts, because nothing downstream works without it.
Years two and three. A federation of regional operators exists on shared standards and starts winning public contracts. Sovereign inference capacity is meaningful, running mostly non-European models under European control. The first gigawatt-scale compute sites are under construction with dedicated power. Failed experiments are visible and nobody has been fired for running them.
Years four and five. Most sensitive public workloads can fail over to European-controlled infrastructure within days. European models are competitive in the domains that matter to Europe, trained on European compute, because the compute finally exists. The dependency has not disappeared. It has become a choice rather than a condition.
That is what sovereignty looks like in practice. Not a wall. A door that we hold the key to.
What this means for your organisation
If you run infrastructure, security, or digital strategy for a European organisation, none of this waits for Brussels. The three-question audit is a week of work. Moving keys and identity under your own control is a quarter. Standing up an open-weight model on hardware you own is a month, and it will teach you more about your real dependencies than any policy paper.
Start there. The continent gets sovereign one organisation at a time, or it does not get there at all.
Start with the audit — we will run it with you
Insight42 designs and implements sovereign cloud and AI architectures for enterprises and public-sector organisations: the three-question audit, EU-held key management, exit-capable cloud architecture, and open-weight models running under your control. Request a sovereignty assessment and we will map your organisation against the three sovereignty levels, workload by workload.
Related reading
- Digital Sovereignty as a Growth Strategy: Why Control Wins Deals in Regulated Markets
- Europe, Stop Renting Your Future: The Cloud Dependency Trap Nobody Wants to Price In
- Sovereign Cloud Germany: Digital Sovereignty for the Public Sector
More insights like this in our Growth, Innovation & Digital Strategy hub.