For years, European technology policy was framed as a China problem — export controls, security reviews, chip restrictions. A different dependency is now driving the agenda. The cloud servers, AI models, and satellite networks running European life are overwhelmingly American. Brussels has started treating that as the more urgent risk.
The Legal Trigger Nobody Talks About
The starting point isn’t ideological. It’s legal. The US CLOUD Act allows American authorities to compel US companies to hand over data, even when that data is physically stored on European soil. A French hospital’s records sitting in an AWS data centre in Frankfurt remain, legally, accessible to US courts.
As Open Future’s analysis of EU technological sovereignty notes, this exposes a problem that goes beyond technical infrastructure: dependencies across the digital stack are political, not just operational. The European Parliament’s own committee has concluded that the EU cannot build its digital economy on infrastructure it doesn’t control.
This is the quiet trigger behind a decade of EU policy that looks, from a distance, like routine regulation. Examined together, it reads as something closer to strategic decoupling from American digital infrastructure.
Building the European Stack
The most direct response is infrastructural. Gaia-X, the Franco-German cloud initiative launched in 2020, has moved into implementation — more than 180 data spaces are now being developed to enable data sharing under European jurisdiction. The European Central Bank joined the initiative in 2022, explicitly citing the goal of digital sovereignty for Europe.
The Commission has gone further. A planned Cloud and AI Development Act aims to triple EU data centre capacity within seven years, alongside a common framework for public sector cloud procurement that would reduce reliance on Amazon, Microsoft, and Google. A 2025 framework called EuroStack advocates explicitly for a European equivalent to the dollar’s role in finance — an interoperable digital infrastructure stack mirroring the strategic weight of the single market itself.
None of this amounts to an immediate replacement for American cloud providers. The scale gap remains enormous. But the direction is unambiguous: every major EU digital initiative of the past five years has built toward reduced dependency on a small number of US companies.
Regulation as Infrastructure Policy
The Digital Markets Act and Digital Services Act are usually described as consumer protection and competition law. Functionally, they also operate as sovereignty instruments. Both target a near-identical list of American companies — Apple, Google, Meta, Amazon — and both impose obligations that push toward interoperability, data portability, and reduced platform lock-in.
This is regulation doing infrastructure work. By forcing American platforms to open their systems, the EU creates space for European alternatives. These alternatives can then enter markets that network effects would otherwise lock in. The Data Act, layered alongside these, focuses on enabling EU-controlled data flows across sectors — health, finance, industrial data — that would otherwise default to whichever cloud provider already holds the data.
President von der Leyen has called explicitly for a “data revolution and technological autonomy” to keep European data under EU control, shielded from external influence, and leveraged strategically across AI, cloud infrastructure, and critical technologies. That is not the language of competition policy. It’s the language of infrastructure strategy with a geopolitical premise.
Beyond the Cloud: Satellites and AI
The dependency problem extends past data storage. Ukraine’s reliance on Starlink for battlefield connectivity exposed how a single American company’s commercial satellite network had become critical military infrastructure for a European-adjacent conflict — a dependency no EU government could override or guarantee. The response, IRIS², is a sovereign European satellite constellation explicitly designed to avoid repeating that exposure.
AI regulation follows a similar logic, even when framed as safety policy. The EU AI Act governs compute resources, model deployment, and risk classification for systems built almost entirely by American companies — OpenAI, Google, Anthropic. Regulating AI safety and regulating dependency on foreign AI infrastructure turn out, in practice, to operate through the same policy lever. They also end up targeting the same handful of firms.
A Quiet Decoupling, Not a Loud One
None of these initiatives, taken individually, reads as anti-American. Collectively, these developments point to a clear pattern. Europe builds parallel infrastructure—cloud, satellite, AI governance, and data law—designed to reduce reliance on the United States, while it keeps formal alliance structures intact.
This connects to a broader pattern explored in The Quiet Financialisation of Everyday Life: structural shifts in Europe rarely announce themselves. They accumulate through regulation, infrastructure investment, and standard-setting until the new system is operational before most observers notice it was being built.
Digital sovereignty was never really about China. The country that controls the servers, satellites, and AI models running European life has, for decades, been an ally. Europe’s slow-motion response suggests that alliance was never the same thing as infrastructure independence — and Brussels has finally decided the difference matters.
Key Sources
- Open Future – Europe Talks Digital Sovereignty
- Wire – Digital Sovereignty in 2025: Why It Matters for European Enterprises
- European Central Bank – ECB Joins European Data and Cloud Network Initiative
- Joint Research Centre, European Commission – Supporting Science and Policy for European Digital Sovereignty
- InCountry – The EU’s Data Sovereignty Framework
Subscribe to EuroLuminant for independent European journalism.



