The European Commission has unveiled its long-awaited digital sovereignty package, aiming to reduce the continent's reliance on US technology amid growing security concerns. The move follows incidents such as the Trump administration's sanctions against International Criminal Court judges, which left them unable to use US-based services like credit cards and online accounts. This has highlighted Europe's vulnerability to political pressure from Washington.
The package's centrepiece is the Cloud and AI Development Act (Cada), which proposes a ranking system for cloud providers handling public-sector data. Under the plan, the most sensitive operations would be reserved for providers meeting the highest sovereignty standards, effectively favouring European firms like France's OVHCloud over US giants such as Amazon Web Services and Microsoft Azure.
However, critics argue the framework has significant flaws. The strictest security level, which would exclude US tech companies, applies only to a narrow segment of public cloud procurement, representing a small fraction of overall European cloud spending. Enforcement is also delegated to individual EU governments, many of which may implement rules weakly to attract US investment or avoid pressure from Washington.
On artificial intelligence, the Commission's approach has been criticised for largely deferring to the vision of US big tech firms. Rather than establishing careful, evidence-based adoption, Brussels appears to prioritise rapid deployment regardless of societal consequences. This contrasts with calls for ethical progress, such as those in Pope Leo's recent encyclical on AI.
Given that the EU relies on non-EU countries for over 80% of its technology and 70% of its cloud computing, the sovereignty package is a belated recognition of the dangers posed by dependence on US tech. Yet without stronger enforcement and a more critical stance on AI, Europe risks remaining bound by Silicon Valley's rulebook.



