Updated augustus 7, 2026
Summary: The European Technological Sovereignty Package (3 June 2026) combines Chips Act 2.0, the Cloud and AI Development Act and a revised Open Source Strategy into a framework that forces regulated organisations to reassess supplier concentration, hardware procurement and sovereign AI strategies. Compliance officers and CISOs who treat this package as a procurement trigger rather than a policy statement will gain the clearest path to audit-ready sovereignty.

The European Technological Sovereignty Package, published on 3 June 2026 under reference COM(2026) 502, is a binding legislative and strategic framework designed to reduce the European Union’s structural dependence on non-EU digital supply chains. For compliance officers, CISOs and IT decision-makers in regulated sectors, the package is not background policy: it directly reshapes the criteria by which cloud, AI and hardware procurement decisions will be evaluated, audited and, in some cases, mandated.

Three Pillars, One Coherent Framework

The package integrates three distinct but interdependent instruments into a single coherent framework for EU digital supply chain policy.

Chips Act 2.0 extends the original 2023 Chips Act by strengthening investment incentives and export-control mechanisms for advanced semiconductor manufacturing within the EU. It is not merely an industrial policy instrument: by shaping which chips are available to European cloud and AI operators, it determines the hardware layer on which sovereign infrastructure can ultimately be built.

The Cloud and AI Development Act (CADA) is the structural centrepiece. It requires Member States to develop national cloud and AI strategies within defined timeframes, establishes criteria for what constitutes a sovereign or trusted cloud environment, and creates a framework for AI model deployment that keeps inference workloads within auditable EU-controlled infrastructure. CADA does not replace GDPR, NIS-2, DORA or the AI Act; it operates as the infrastructure-layer complement to those instruments.

The EU Open Source Strategy 2026 provides the software governance dimension. By anchoring public-sector and regulated-sector technology procurement to open-source alternatives where feasible, it removes the legal ambiguity that previously made open-source adoption in regulated environments difficult to justify at board level. Taken together, the three pillars address the full stack: silicon, cloud infrastructure and software licensing.

Key framing: The package’s three instruments are deliberately co-designed so that a hardware decision under Chips Act 2.0, a cloud procurement decision under CADA and a software licensing decision under the Open Source Strategy 2026 are all traceable to the same sovereignty objective. Procurement teams that treat them as separate policy tracks will miss the integrated compliance logic.

The 80% Dependency Figure and What It Means for Risk Assessments

The package’s own impact assessment acknowledges that the EU currently relies on non-EU countries for over 80% of key digital products and services. That figure has direct, quantifiable implications for supplier concentration analysis under two existing regulatory frameworks.

Regulatory Framework Relevant Provision How the 80% Figure Applies
DORA (Regulation (EU) 2022/2554) Article 28: ICT third-party risk management; concentration risk A >80% non-EU dependency ratio across the sector qualifies as a systemic concentration risk that competent authorities are required to monitor. Regulated financial entities must document their contribution to that concentration and demonstrate exit strategies.
NIS-2 (Directive (EU) 2022/2555) Article 21: Risk management measures; supply chain security Critical and important entities must assess the security of their ICT supply chains. A supplier operating under US jurisdiction (CLOUD Act, FISA 702) is a documented foreign-jurisdiction risk that must appear in the risk register, not simply in the vendor contract.

For compliance officers, the 80% figure is now a quotable Commission acknowledgement that the status quo represents a structural risk, not a theoretical one. It can and should be cited in internal risk assessments and in audit documentation as evidence that the risk category is sector-wide and not organisation-specific.

“Europe must stop being a rule-maker that imports the technologies it regulates. Sovereign cloud and AI capacity is not a luxury; it is a strategic precondition for competitiveness.”
Mario Draghi, The Future of European Competitiveness (Draghi Report)

See how Qsentinel solves this in practice.Start a 10-user pilot →

Using the Draghi Report as a Strategic Justification Tool

The Draghi Report, formally titled “The Future of European Competitiveness” and commissioned by the European Commission in 2024, predates COM(2026) 502 but is explicitly referenced in the package’s recitals as foundational analysis. Its recommendations on sovereign cloud and domestic computational capacity are therefore not aspirational: they are the analytical basis on which the package’s legislative choices rest.

For a CISO or DPO presenting a sovereign infrastructure business case to a board, the Draghi Report provides two things that internal risk assessments rarely can. First, it provides an independent economic framing: dependency on non-EU digital infrastructure is a competitiveness risk with measurable GDP implications, not just a compliance checkbox. Second, it provides political cover: investment in sovereign alternatives is explicitly aligned with EU-level strategic direction, which reduces the internal objection that such investment is premature or speculative.

The average cost of a data breach globally reached USD 4.45 million in 2023 (IBM Cost of a Data Breach Report 2023). When combined with potential GDPR fines under Article 83(4) and (5) and DORA penalty frameworks, the financial case for sovereign infrastructure investment becomes straightforward to model. The Draghi Report adds the macro-level framing that connects the organisation’s individual risk exposure to a broader structural argument the board will recognise from political discourse.

Member State Obligations and Organisational Alignment

CADA places explicit obligations on Member States to publish national cloud and AI strategies. These strategies will define, among other things, which cloud environments qualify as trusted for use by public-sector bodies and, by extension, for regulated private-sector entities that contract with public bodies or that fall under sectoral regulation referencing national strategy criteria.

Regulated organisations should treat their own sovereignty roadmaps as needing to align, not merely coexist, with national frameworks. Practically, this means three things. First, procurement contracts signed now for multi-year cloud or AI services should include sovereign-transition clauses that allow renegotiation once national strategy criteria are published. Second, data protection officers should begin mapping which data categories are most exposed to foreign-jurisdiction risk, so that national strategy criteria can be applied selectively and efficiently when they arrive. Third, IT decision-makers should engage with national competent authorities at an early stage to understand how CADA criteria will be transposed, since transposition timelines will vary across Member States.

Procurement risk: Organisations in Member States that are slow to publish national cloud strategies should not interpret the delay as permission to defer sovereignty planning. DORA and NIS-2 obligations on concentration risk and supply chain security apply regardless of whether the national CADA strategy is in place.

The Co-Design Mandate and Hardware Procurement

One of the less-discussed but operationally significant elements of the package is the co-design mandate: the requirement that Chips Act 2.0 semiconductor initiatives and CADA cloud-stack development proceed in coordination, so that EU-certified sovereign infrastructure is designed from the hardware layer upward rather than assembled from whatever components the market happens to supply.

For organisations procuring servers, GPUs or network hardware for sovereign infrastructure today, this creates a concrete procurement decision: hardware acquired under multi-year contracts with non-EU vendors may not align with forthcoming national cloud strategy criteria that reference CADA-compliant infrastructure. The signal from the package is that EU-produced or co-designed hardware will increasingly be the reference point for sovereign infrastructure certification.

A minimum prudent response is a hardware supplier dependency review conducted alongside the DORA ICT third-party risk register update, documenting which hardware components originate outside the EU, what the contractual exit terms are, and what EU-sourced alternatives currently exist. This review is also directly useful for NIS-2 Article 21 supply chain security documentation.

The European AI Continent Action Plan and Long-Term Sovereign AI Strategy

The European AI Continent Action Plan, adopted in 2025 and incorporated by reference into the European Technological Sovereignty Package, organises EU-level AI ambition around five domains: computing capacity, data availability, skills, AI algorithms and regulatory simplification. The plan targets the deployment of at least 200,000 AI-optimised GPUs across EU infrastructure by 2030 (European Commission, European AI Continent Action Plan, 2025).

For organisations building private AI deployments on open-source models such as Mistral or Llama, the five-domain nexus provides a stable strategic anchor. It signals that EU-level investment in sovereign GPU capacity and in open-source model ecosystems will continue, which means organisations that commit to private AI infrastructure today are aligning with, not running ahead of, the regulatory and investment direction. Organisations that instead deepen dependencies on US hyperscaler AI APIs are moving in the opposite direction from the trajectory the package establishes.

“Digital sovereignty is not about protectionism. It is about ensuring that European citizens, businesses and governments can trust the systems they depend on.”
European Commission, official position statement accompanying COM(2026) 502

The skills and regulatory simplification domains are also directly relevant to procurement. On skills, the plan supports EU-level training programmes for AI and cloud infrastructure roles, which will gradually reduce the talent scarcity argument that currently leads some organisations to prefer hyperscaler managed services over self-operated sovereign infrastructure. On regulatory simplification, the plan commits to reducing the compliance overhead for organisations that choose EU-certified sovereign alternatives, which should over time reduce the total cost of ownership argument that currently favours incumbent US providers.

Translating the Package into a Procurement Action Plan

For compliance officers and IT decision-makers, the package creates a concrete sequence of actions rather than an abstract policy aspiration. The first step is updating the DORA ICT concentration risk assessment to reflect the Commission’s own 80% dependency acknowledgement as a systemic baseline. The second step is reviewing existing cloud and software contracts for foreign-jurisdiction exposure under the CLOUD Act, FISA 702 and related instruments, and identifying which contracts lack sovereign-transition clauses. The third step is mapping the organisation’s data categories against CADA criteria as they emerge at national level, prioritising the most sensitive categories for early migration to CADA-aligned infrastructure. The fourth step is engaging with hardware procurement cycles to introduce EU-sourced alternatives for the components most likely to be referenced in forthcoming national cloud strategy criteria.

None of these steps requires waiting for full national transposition. DORA and NIS-2 obligations are already in force. The package provides the strategic justification, the political momentum and, through COM(2026) 502, the legislative anchor to make sovereign infrastructure investment not just defensible but necessary.

Frequently Asked Questions

Does the European Technological Sovereignty Package create direct legal obligations for private regulated organisations?

The package is primarily directed at Member States, which must develop national cloud and AI strategies within defined timeframes. However, those national strategies will inform and in some cases mandate procurement criteria for regulated sectors, particularly financial institutions under DORA and critical infrastructure operators under NIS-2. Organisations should monitor their national transposition process closely.

How does CADA interact with existing GDPR obligations?

CADA does not replace GDPR but operates alongside it. Where GDPR sets conditions for lawful data processing, CADA addresses the structural layer below: which cloud stacks are used, where compute runs and how AI models are deployed. Organisations that satisfy CADA-aligned procurement criteria will typically also reduce their GDPR exposure to third-country transfers under Articles 44 to 49 of the GDPR.

What is the practical relevance of the Chips Act 2.0 and CADA co-design mandate for a CIO buying servers today?

The co-design mandate signals that future EU-certified sovereign infrastructure will increasingly require hardware produced or co-designed within the EU semiconductor ecosystem. CIOs who lock into multi-year contracts with non-EU hardware vendors now risk non-alignment with forthcoming national cloud strategy criteria and potentially with future DORA ICT concentration guidance. A rolling review of hardware supplier dependency is the minimum prudent response.

How does the Draghi Report support a business case for sovereign cloud investment internally?

The Draghi Report provides an independent economic framing: it argues that continued dependency on non-EU digital infrastructure is a structural competitiveness risk, not merely a regulatory compliance issue. Compliance officers can cite it as external validation when presenting sovereign infrastructure investment proposals to boards, alongside the quantified risk exposures under DORA Article 28 on ICT third-party risk and NIS-2 Article 21 on security measures.

What does the European AI Continent Action Plan’s five-domain nexus mean for an organisation deploying private AI?

The five domains are computing capacity, data availability, skills, AI algorithms and regulatory simplification. For an organisation deploying private AI on open-source models such as Mistral or Llama, the plan provides a roadmap anchor: it signals EU-level investment in sovereign GPU capacity and open-source model ecosystems that an organisation can align its own roadmap with, rather than depending indefinitely on proprietary US hyperscaler AI services.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does the European Technological Sovereignty Package create direct legal obligations for private regulated organisations?
The package itself is primarily directed at Member States, which must develop national cloud and AI strategies within defined timeframes. However, those national strategies will inform and in some cases mandate procurement criteria for regulated sectors, particularly financial institutions under DORA and critical infrastructure operators under NIS-2. Organisations should monitor their national transposition process closely.
How does the Cloud and AI Development Act (CADA) interact with existing GDPR obligations?
CADA does not replace GDPR but operates alongside it. Where GDPR sets conditions for lawful data processing, CADA addresses the structural layer below: which cloud stacks are used, where compute runs and how AI models are deployed. Organisations that satisfy CADA-aligned procurement criteria will typically also reduce their GDPR exposure to third-country transfers under Articles 44 to 49 of the GDPR.
What is the practical relevance of the co-design mandate between Chips Act 2.0 and CADA for a CIO buying servers today?
The co-design mandate signals that future EU-certified sovereign infrastructure will increasingly require hardware produced or co-designed within the EU semiconductor ecosystem. CIOs who lock into multi-year contracts with non-EU hardware vendors now risk non-alignment with forthcoming national cloud strategy criteria and potentially with future DORA ICT concentration guidance. A rolling review of hardware supplier dependency is the minimum prudent response.
How does the Draghi Report support a business case for sovereign cloud investment internally?
The Draghi Report provides an independent economic framing: it argues that continued dependency on non-EU digital infrastructure is a structural competitiveness risk, not merely a regulatory compliance issue. Compliance officers can cite it as external validation when presenting sovereign infrastructure investment proposals to boards, alongside the quantified risk exposures under DORA Article 28 on ICT third-party risk and NIS-2 Article 21 on security measures.
What does the five-domain nexus of the European AI Continent Action Plan mean in practice for an organisation building a private AI deployment?
The five domains are computing capacity, data availability, skills, AI algorithms and regulatory simplification. For an organisation deploying private AI on open-source models such as Mistral or Llama, the plan provides a roadmap anchor: it signals EU-level investment in sovereign GPU capacity and open-source model ecosystems that an organisation can align its own roadmap with, rather than depending indefinitely on proprietary US hyperscaler AI services.