
Europe is talking more and more about digital sovereignty. The term crops up in EU strategies, in national digitalisation plans, in debates about cloud, chips, cybersecurity, artificial intelligence and geopolitics. It’s used when politicians talk about the need for European alternatives to American tech giants. It’s used when companies discuss data security and cloud dependency. It’s used when authorities ask whether critical digital infrastructure should sit outside European control.
But the term can also become too imprecise. Because what does digital sovereignty actually mean in an age of AI? Does it mean data has to be located in Europe? That the companies behind the systems have to be European? That the cloud provider has to be subject to European jurisdiction? That the models have to be trained in Europe? That the chip has to be manufactured in Europe? That the power has to come from European energy systems? Or that public authorities and companies must be able to switch supplier without getting stuck in global platforms?
The question is not academic. Artificial intelligence is quickly becoming a new form of societal infrastructure. AI is moving into companies, public institutions, healthcare, education, research, administration, journalism, software development, defence and everyday life. When AI becomes part of society’s basic workflows, it becomes crucial who owns and controls the layers the technology is built on. And here Europe’s position is more vulnerable than the public debate often suggests. Because even European AI is often only European in its top layers.
AI consists of layers
When we talk about AI, we often talk about what the user sees: the chatbot, the image generator, the transcription tool, the case-processing system, the analysis model or the digital assistant.
But AI consists of an entire stack of technological layers.
At the bottom sit energy, raw materials, chips and GPUs. On top of that sit data centres and compute. On top of that sits cloud infrastructure. On top of that again sit foundation models, development tools and APIs. And at the top sit the concrete applications that companies, authorities and citizens use.
If Europe is only strong in the top layers but dependent in the bottom ones, its sovereignty is limited. Michael Solvang, who works on AI research and Nordic AI collaboration at NORA.ai, describes the dependency bluntly:
“If you look at the whole AI stack — from power to chips and GPUs — then in practice it’s Nvidia and AMD, and both are American. On top of that comes the infrastructure with Google, Amazon and Microsoft. Those are largely the three everyone uses.”
That doesn’t mean Europe has no AI. Europe has researchers, startups, models, industrial solutions, public projects and strong application environments. But it does mean that much of European AI development rests on infrastructure controlled elsewhere.
Mikkel Næsager from CISPE, a European industry association for cloud providers, puts it even more fundamentally: “AI is cloud. You can’t separate the two things. They’re not separate entities. When we transcribe this recording, for example, it happens in the cloud. All the AI systems people use daily are cloud-based. That’s why cloud infrastructure is absolutely central when we talk about AI growth and sovereignty.”
That’s an important shift. If AI is cloud, AI policy isn’t only about algorithms and models. It’s also about data centres, supplier agreements, jurisdiction, procurement, energy, security, lock-in and economic control.
Europe’s dependency
The European AI paradox is that Europe wants to be both a leader and dependent at the same time.
The EU wants to be a global leader in responsible AI. The EU has passed the AI Act. The EU is investing in supercomputing, AI Factories and chips. The EU talks about technological sovereignty and strategic autonomy. But when a European company builds an AI product, it will often use American GPUs, American cloud, American development tools and perhaps American foundation models. When a public institution tests generative AI, it often happens via Microsoft, Google, Amazon, OpenAI, Anthropic or other global platforms. When a citizen uses AI in everyday life, the user interface is almost always developed outside Europe.
This isn’t necessarily a problem in every single application. Global technological integration is not the same as technological subjugation. Europe neither can nor should isolate itself from American technology. But the dependency becomes a strategic problem if no real alternatives exist.
Solvang puts it briefly: “Right now there really isn’t a good alternative.”
And it’s precisely the absence of alternatives that lies at the heart of the sovereignty debate. Sovereignty doesn’t necessarily mean everything has to be European. It means Europe has to be able to choose. Switch. Negotiate. Make demands. Retain control over critical functions. And avoid a handful of foreign companies gaining veto power over digital societal functions. As Solvang puts it: “The point is that you need suppliers who offer real alternatives if you want to switch.”
Today the alternatives are often limited. Not because European players don’t exist at all, but because the American platforms are already deeply embedded in organisations’ systems, workflows, skills and contracts.
The convenience dividend
Mikkel Næsager calls it a “convenience dividend.” For years, Europe has chosen the solutions that were easiest, most mature, most integrated and most widespread. That has produced rapid digitalisation. But it has also created dependency.
“We’ve spent the last decade moving into what I call the convenience dividend. It’s simply easier to just keep buying what we’ve always bought. We are deeply dependent on certain suppliers, so there’s almost no reason to run a tender, because we already know who we’ll choose. There are very real barriers to switching — and many of them are designed to be there,” he says.
That may be one of the most precise descriptions of Europe’s digital dependency. It hasn’t arisen through one dramatic decision. It has arisen through thousands of rational choices: the most practical system, the best integration, the lowest transition cost, the strongest package, the most familiar name, the shortest path to implementation.
But over time, convenience turns into lock-in.
Companies and public institutions find it harder to switch supplier. Data, integrations, workflows, security models, licences and staff skills become woven into a handful of platforms. And when AI is built into those same platforms on top of that, the dependency runs even deeper.
That’s why AI isn’t just another wave of software. Cloud and AI are, as Næsager says, “reshaping the entire way our economy functions.”
Sovereignty is not the same as data security
One of the biggest misunderstandings in the debate is that digital sovereignty can be reduced to data security or data location. If data sits in a European data centre, it sounds sovereign at first glance. If the provider has a European cloud region, it sounds reassuring. If the system meets European security standards, the problem may sound solved. But that isn’t necessarily enough.
Ben Maynard from CISPE warns against confusing sovereignty with data residency. “One of the misunderstandings is that sovereignty is the same as security or data residency. They are very different things. Data residency doesn’t protect you at all against the Cloud Act,” he says.
The real question isn’t only where data is physically located. It’s who can access it. Which jurisdiction the provider is subject to. Who can change the terms. Who can cut off access. Who controls the keys. And whether the customer can actually move to another provider.
Mikkel Næsager frames the sovereignty test like this: “The real question is: are you immune to foreign interference? If the answer is no, then in our view it isn’t sovereign.”
That’s a strict definition. But it makes the debate more precise. Because if a European authority uses a cloud solution that technically runs in Europe but whose provider is subject to legislation outside Europe, the solution isn’t necessarily sovereign. If a European AI company builds its model on top of American cloud and American GPUs, it isn’t necessarily strategically independent. If a public sector body builds central workflows into a global platform, data location alone cannot resolve the dependency.
The EU is trying to build capacity
The EU isn’t blind to the problem. In recent years the EU has tried to move from pure regulatory power towards a more active technological industrial policy. The AI Act regulates the use of artificial intelligence, but the AI Continent Action Plan, AI Factories, EuroHPC and the Chips Act are about something else: capacity.
According to the EU, the Commission’s AI Continent Action Plan is meant to strengthen Europe’s AI development through, among other things, computing infrastructure, data access, AI use in strategic sectors, skills and simplification of rules. The plan highlights areas such as health, cars, science and industry as central to Europe’s next AI phase.
The AI Factories programme is meant to give startups, SMEs, researchers and public actors access to AI-optimised supercomputing through EuroHPC. EuroHPC describes AI Factories as hubs that use European supercomputing capacity to develop trustworthy, advanced generative AI models.
On chips, the European Chips Act is meant to strengthen the EU’s semiconductor ecosystem, make supply chains more robust and reduce external dependencies. One goal is to double Europe’s global market share in semiconductors to 20 percent.
These are important initiatives. They show that Europe has understood that digital sovereignty isn’t only about rules and values, but about physical and technical capacity. But the question is whether the effort is sufficient. At the same time, Stanford HAI’s AI Index 2025 shows that the US still produced far more notable AI models than both China and Europe in 2024: 40 from American institutions, 15 from China and three from Europe.
And even where the EU sets ambitious chip targets, the road is long. Europe’s semiconductor ambitions have been criticised as hard to realise, partly because global chip supply chains are extremely complex, capital-intensive and dominated by players outside the EU. Reuters reported in 2025 that EU countries rallied around a call for a new “Chips Act 2.0” after criticism that the first Chips Act had not attracted enough leading-edge chip production to Europe. Europe is thus trying to build sovereignty, but it isn’t starting from a neutral position. It’s starting from dependency.
How European is European AI?
That brings us back to the article’s question: how European is European AI, really?
The answer depends on which layer you look at. An AI application can be developed in Europe. It can be designed for European companies. It can comply with the AI Act and GDPR. It can use European datasets. It can be trained or fine-tuned by European researchers. It can solve a concrete European societal problem. But if it runs on American cloud, uses American chips, is built on an American foundation model and is distributed through American platforms, its European control is limited.
That doesn’t mean it’s useless. It doesn’t mean it’s illegitimate. But it does mean it isn’t automatically sovereign.
This is where the debate often becomes too superficial. Europe can easily have many AI startups and still be infrastructurally dependent. Europe can easily have strong AI regulation and still lack technological power. Europe can easily be a strong AI user and still be a customer in other people’s ecosystems. Europe can easily build European AI solutions and still send a large share of the value creation to American platforms. It’s this distinction between use and control that should be central to the sovereignty debate.
The economic question
Digital sovereignty is often discussed as geopolitics. But it’s also about economics.
If AI becomes a fundamental productive force in society, enormous value will flow through the platforms and infrastructures that deliver the technology. Subscriptions, cloud usage, API calls, model access, security packages, enterprise licences and automation systems become a new digital value stream. The question is where that value stream ends up.
Næsager warns against reducing sovereignty to a narrow question of great-power politics:
“One of the misunderstandings is that this is only about geopolitics. It isn’t. Strategic autonomy is also about controlling and capturing the benefits of digital growth. In ten years we’ll have far more cloud and AI than today. The crucial question is: who benefits from that growth?”
That question is especially important for Europe, because the continent already has many of the sectors where AI will become embedded: health, industry, energy, public administration, education, finance and transport.
If AI increases productivity in European companies but the most profitable infrastructure layers are owned outside Europe, Europe’s gain shrinks. If public institutions become more efficient with AI while locking themselves ever deeper into a handful of global suppliers, their room for manoeuvre shrinks. If European data and European expertise are used to create products where control sits elsewhere, value creation becomes asymmetric. This is not an argument for digital isolationism.
It is an argument for negotiating power.
Partnership or dependency?
Andreas Cleve from Corti warns against understanding sovereignty as a break with the US. “For me, sovereignty isn’t so much about fragmentation from the US. I think we’ll be partners with the Americans for a long time yet. For me it’s much more about the fact that we’ve given up on being anything other than consumers of key technologies. We’re not building the ability to create the innovation ourselves. We’re not building the ability to control it,” he says.
That’s a crucial distinction. Europe doesn’t necessarily need to decouple from American technology. That would be unrealistic and probably harmful. The US is Europe’s ally, and American tech companies deliver systems that European companies and authorities are deeply dependent on.
But partnership requires more than access to other people’s products. If Europe can only choose between different American platforms, that isn’t an equal partnership. If European companies can only scale by embedding themselves in American infrastructure, that isn’t real technological autonomy. If European authorities cannot define critical digital requirements without having to adapt to a handful of global suppliers, sovereignty is limited. Sovereignty, therefore, isn’t about shutting the world out. It’s about not being trapped.
The search for alternatives
There are several possible paths to greater European room for manoeuvre.
The first is European cloud. Not necessarily as one big public cloud, but as a more diverse market of European providers able to deliver secure, scalable and legally more robust alternatives to the global hyperscalers.
The second is open source. If open models become strong enough, European companies, authorities and research communities can to a greater extent build solutions without being completely dependent on closed models from a handful of companies.
The third is shared compute. AI Factories and EuroHPC can give researchers, startups and SMEs access to computing power that would otherwise be too expensive or unavailable.
The fourth is public procurement. If European authorities require interoperability, portability, transparency and the ability to switch supplier, they can reduce lock-in and create demand for alternatives.
The fifth is industrial focus. Europe doesn’t necessarily need to compete with the US on every consumer-facing AI assistant. Europe can build strong AI environments around industry, health, energy, robotics, the public sector and critical infrastructure.
But all five paths require long-term investment and political prioritisation. It isn’t enough to say “digital sovereignty.” It has to become more expensive to get locked in, easier to switch, more attractive to build European, and more strategic in how procurement is done.
The risk of digital serfdom
CISPE uses a strong term for the risk: digital serfdom.
“If we don’t act clearly and with focus now, we risk sending Europe into what we call digital serfdom,” says Mikkel Næsager.
The term may sound dramatic. But it points to a real danger. Not that Europe will suddenly lose all digital room for manoeuvre. Not that American companies will take over European societies overnight. But that the dependency becomes so gradual, so embedded and so practically convenient that it eventually no longer feels like a choice. That it becomes too hard to switch cloud. Too expensive to move data. Too complex to change workflows. Too late to build one’s own alternatives. Too slow to create domestic companies. Too unrealistic to negotiate with the largest platforms.
Digital serfdom isn’t necessarily dramatic. It can be administrative, legal, technical and economic. It can look like efficiency. It can look like innovation. It can look like ordinary digitalisation.
The crucial question
Digital sovereignty, then, isn’t about whether Europe should use American technology or not. That much is coming regardless. The question is whether Europe also has other options. Can European companies build AI without handing over too much control to global platforms? Can public authorities use AI without locking critical societal functions into a handful of suppliers’ ecosystems? Can researchers and startups get access to compute without depending on hyperscalers? Can Europe build alternatives strong enough that partnership with the US becomes a choice rather than a necessity? And perhaps most fundamentally: can Europe be a digital great power if it doesn’t control enough of the infrastructure the digital economy is built on?
The answer is still open. Europe has strong research environments. Europe has industry. Europe has regulation. Europe has public institutions that can set requirements. Europe has supercomputing initiatives, AI Factories, the Chips Act, the AI Act, and a growing recognition of the problem.
But Europe also has a deep dependency on American platforms, American chips, American cloud and American models.
It isn’t certain that Europe needs to own everything. But Europe does need to own enough.
Enough to be able to choose. Enough to be able to switch. Enough to be able to negotiate. Enough to be able to protect critical societal functions. Enough to ensure that the value of Europe’s digital growth doesn’t primarily end up elsewhere. Because the question isn’t only how European AI is today.
The question is how European Europe can afford for it to keep being.
This article was previosly published on www.ai-portalen.dk