Europe's Sovereignty Package Draws a Line Most Clouds Will Not Cross

The Commission's Technological Sovereignty Package — Chips Act 2.0 and the Cloud and AI Development Act — grades cloud services on a four-level sovereignty scale. Defence-pushback shows the

Netics editorial card: the four-level sovereignty scale applied to cloud provisioning in Europe.
Netics editorial visual of CADA's four-level sovereignty ladder.

TL;DR

  • On June 3, 2026, the European Commission presented the Technological Sovereignty Package: the Chips Act 2.0 and the Cloud and AI Development Act (CADA), plus an EU Open Source Strategy and an energy digitalisation roadmap.
  • CADA would triple EU data-center capacity in five to seven years and introduces a common EU framework to grade cloud and AI sovereignty on four levels — from EU-resident data to full supply-chain control and freedom from third-country interference.
  • On June 25 the Commission disclosed a preliminary view that AWS and Azure should be designated gatekeepers under the Digital Markets Act (DMA) — a separate process from CADA, but the sovereignty debate reads them together.
  • The September status is where ambition meets reality: proposals are in Council and Parliament negotiation, and European defence officials are pushing back on the strictest sovereignty tiers.
  • For a French or EU SME the practical question is procurement: which of the four levels will public buyers actually require, and what evidence will they accept?

The European Commission presented its Technological Sovereignty Package on June 3, 2026. It bundles two legislative proposals — the Chips Act 2.0 and the Cloud and AI Development Act (CADA) — with an EU Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in the Energy Sector. Commission President Ursula von der Leyen framed it in security terms: "We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable and our services secure."

Netics editorial diagram: the four-level sovereignty scale
Netics editorial visual: CADA's four-level sovereignty ladder from EU-resident data (level 1) to full supply-chain control and third-country freedom (level 4).

The scale of the dependency the package answers is blunt. The EU relies on non-EU countries for more than 80% of its digital products, services, infrastructure, and intellectual property, according to EU-institution data cited in the European Parliament's January 2026 resolution on technological sovereignty (El País, September 19, 2026). The package is the first attempt to make that dependency a procurement and investment problem rather than a talking point.

CADA's four-level sovereignty scale is the operational heart

The most innovative — and most contested — part of CADA is its definition of sovereignty. The Commission wants to move beyond the idea that a cloud is sovereign simply because data physically sits in the EU. As El País's report describes the draft proposal, the framework establishes four levels:

  • Level 1: data processed and stored on infrastructure located in the EU.
  • Level 2: level 1 plus independence from third countries and transparency on the software supply chain.
  • Level 3: level 2 plus a provider that is owned and controlled from within the EU.
  • Level 4: the highest tier — full transparency and control over the software supply chain, and freedom from interference by third countries.

That scale is the anti-"sovereign washing" mechanism: a vendor can no longer claim sovereignty by geography alone. It also becomes the grading tool for public procurement. The Commission's stated rationale is that the absence of a verifiable framework lets services present themselves as sovereign without criteria — CADA is designed to close exactly that gap.

The September reporting adds teeth and friction. Cloud Computing News, on September 7, 2026, described CADA's two-article risk-assessment structure: under Article 29, member states and EU entities would map public-sector activities that use cloud services; activities in areas including national security, defence, internal security, border management, justice, and law enforcement would have to use services recognised at assurance Levels 2, 3, or 4 under Article 30. Coverage on shattered.io adds that Article 30 ties the required assurance level to the sensitivity of the workload — a rural transit authority's records system faces lighter scrutiny than a signals-intelligence platform. The same coverage describes procurement rules for "highly critical state tenders" that would let contracting authorities exclude bidders based on ownership, financing structure, or exposure to third-country data-access law. Cloud Computing News is explicit that the proposal does not impose a blanket ban on US cloud providers: it allows exceptions where compliant services are unavailable or procurement processes fail to produce suitable offers.

Screenshot of the European Commission press-corner page for the June 3, 2026 announcement
Screenshot of the European Commission press-corner page (press release IP/26/1187, "Commission proposes tech sovereignty package to strengthen Europe's digital autonomy and resilience"), retrieved September 26, 2026.

Chips Act 2.0: resilience, not self-sufficiency

The second pillar, Chips Act 2.0, starts from a structural fact: Europe accounts for just under 10% of global semiconductor production, according to a Polytechnique Insights analysis cited by El País. AI-related components are expected to represent more than 70% of the global semiconductor market by 2030 per Commission figures. The proposal aims to strengthen European capabilities, deepen cooperation with like-minded partners, speed permitting, stimulate European demand, and introduce an excellence label for Europe's semiconductor regions.

The honest framing is in the Commission's own language: the goal is not for Europe to manufacture every chip it needs — that would be unrealistic — but to ensure Europe does not lose industrial capacities that could become critical if the global supply chain breaks down. The pandemic, US-China trade tensions, and restrictions on specific components are the evidence base. For buyers, the practical effect will be a label system (the excellence label) and faster permitting for strategic projects, not a near-term domestic alternative to TSMC or Samsung foundries.

The gatekeeper signal, and the procurement lever

Two facts make clear this is not only an industrial-policy exercise. On June 25, 2026, the Commission informed Amazon and Microsoft of its preliminary view that AWS and Azure — the EU's largest and second-largest cloud services — should be designated gatekeepers under the Digital Markets Act, saying they are an important gateway between businesses and their EU customers despite not meeting the DMA's quantitative thresholds; El País notes Brussels argues the two have entrenched market positions, high switching costs, and strong lock-in effects. And in April 2026 the Commission awarded contracts worth up to €180 million over six years for sovereign cloud services for EU institutions — an anchor-customer move for European providers.

Screenshot of the European Commission news page on the sovereign cloud tender
Screenshot of the European Commission news page "Commission advances cloud sovereignty through strategic procurement" (April 17, 2026), retrieved September 26, 2026.

The procurement lever is the mechanism that makes the four-level scale binding in practice. A sovereignty framework that only policy documents use is a position paper; a sovereignty framework that sits inside tender evaluation is a market structure. CADA does the latter, which is why the defence pushback matters: Cloud Computing News reported, citing the Financial Times, that European defence officials — including from eastern and Nordic member states — are concerned the provisions could restrict the use of US cloud providers for some high-security workloads and complicate interoperability with NATO systems. That tension is not a bug in CADA; it is the design stress-test every serious sovereignty framework eventually hits.

What a French or EU SME should do now

The package will not be law this year; both proposals are in Council and Parliament negotiation. But the procurement direction is already legible, and SMEs building or buying cloud services should treat it as a decision input today, not a compliance item for 2028:

  • Map which of the four levels your own cloud and AI services would satisfy today, with evidence. "Data in the EU" is level 1; supply-chain transparency is level 2; EU ownership is level 3. The gap between your marketing and your evidence is exactly the gap CADA targets.
  • Watch the public-sector anchor: the €180 million EU-institutions contracts and the gatekeeper process for AWS and Azure define the reference point for what sovereign procurement will demand. Private-sector buyers in regulated verticals will likely inherit those expectations.
  • Treat the defence pushback as useful signal: the strictest tiers will be negotiated down or phased, so level 4 is unlikely to become a universal requirement. Level 2 — data residency plus supply-chain transparency — is the realistic floor for sensitive workloads.
  • Keep the skills argument this blog has made in view: a framework grades providers, but running sovereign infrastructure still requires the operational capability to operate it. Legislation is the demand side; skills are the supply side.

The full text of the proposals will change in negotiation. What will not change is the direction: European public procurement is moving toward verifiable sovereignty criteria, and the four-level scale is the reference model every vendor and buyer will be scored against.

Netics editorial diagram: the SME decision matrix
Netics editorial visual: the four-level scale and what a French or EU SME should verify per level before a procurement decision.

Sources

This article is grounded in the European Commission's June 3, 2026 press release (IP/26/1187), the European Commission's preliminary position that AWS and Azure should be designated gatekeepers under the Digital Markets Act (June 25, 2026), the European Commission's sovereign cloud procurement announcement (April 17, 2026), the El País report on the sovereignty framework (September 19, 2026), Cloud Computing News on CADA's defence pushback (September 7, 2026), and shattered.io's coverage of the draft's assurance levels. All pages were fetched and verified on September 26, 2026. The package was presented June 3, 2026; it remains in legislative negotiation.

Source: European Commission — press release IP/26/1187, 2026-06-03; September 2026 status per El País (2026-09-19) and Cloud Computing News (2026-09-07).

Explore the Netics approach to sovereign infrastructure and AI operations