The European Commission's Tech Sovereignty Package, unveiled on 3 June, signals a departure from the EU's reliance on regulatory frameworks like the GDPR, DSA, DMA and AI Act. Instead, it pursues an industrial strategy to artificially expand both the supply of and demand for AI data centres across the continent. Yet observers argue the package is fractured by contradictions, conflating competitiveness with genuine digital self-determination and repackaging deregulation as industrial progress.
An industrial push built on speculative foundations
The Commission's approach rests almost entirely on the unproven assumption that AI is an inevitable technological future that all economies must adopt immediately or risk falling behind globally. The Cloud and AI Development Act (CADA), a core component of the package, aims to "regain and retain control over data and cloud computing services" and "expand domestic computational capacity" to drive widespread AI adoption.
To realise this vision, CADA proposes substantial public and private funding for "Cloud and AI Leadership Initiatives" to develop, test and deploy "advanced AI technologies," including autonomous vehicles, drones, robots and sector-specific industrial AI in healthcare, defence and the public sector. The regulation would also require member states to establish national "experience and acceleration centres for AI" and adopt strategies mandating the "AI first" principle across public and private organisations.
On infrastructure, member states must designate "Data Centres Acceleration Zones" where permit procedures are expedited, energy supply guaranteed, and environmental assessments fast-tracked—an approach that risks creating tension in communities facing imposed infrastructure expansion.
Sovereignty for whom?
The fundamental flaw in the EU's sovereignty strategy, as embodied by CADA, is its focus on territorial control over data, infrastructure and supply chains rather than the ability to manage vendor dependencies and technology itself. Building technology within Europe becomes an end in itself, redirecting public resources toward an unproven sector developed in overvalued markets populated by heavily indebted firms that may collapse. This obscures a more pressing question: What technology should Europe build, who owns it, and whom does it serve?
There is no guarantee that large EU-based AI and data centre corporations will treat personal data more responsibly, respect the environment more carefully, or protect democracy better than their American counterparts. Digital sovereignty, properly understood, concerns people's ability to control the technology they depend on, not national territorial control.
The package cannot be separated from the Commission's broader deregulation agenda, particularly the so-called "Digital Omnibus," which weakens the AI Act and GDPR while CADA redirects public funds to private enterprises. When fundamental rights are eroded in the name of European tech sovereignty, the question becomes: whose sovereignty does this serve?
Military dimensions
Data centres are not neutral infrastructure. They enable specific political objectives, including military operations. Until recently, Israeli military intelligence used Microsoft's Azure platform in the Netherlands for mass surveillance data storage. Google and Amazon Web Services signed a $1.2 billion contract with Israel's armed forces called "Project Nimbus," which included constructing multiple Israeli data centres. OpenAI and Anthropic models have supported US military planning and analysis, with the latter nearly triggering a military confrontation with China.
CADA contributes to the EU's militarisation agenda by funding "highly secured" computing infrastructure for training, testing and deploying defence-related AI models. Its "sovereignty framework" for assessing "cloud and AI independence" will also shape national defence procurement policies.
Environmental costs
The Commission's plan to massively expand AI data centres arrives as Europeans already experience acute climate crisis effects. The EU is already exceeding its internationally agreed emissions budget, and CADA threatens to worsen this trajectory.
The proposal aims to "triple EU capacity (…) and reach the needed capacity by 2035." Current European data centre energy consumption stands at approximately 13 Gigawatt by the end of 2026. Tripling that would require 39 GW of electricity—equivalent to the annual power consumption of over 70 million people. A typical nuclear reactor produces about 1 GW.
While the Commission promises "clean energy" and "sustainable" data centres in acceleration zones, research indicates this will not prevent dramatic greenhouse gas emission increases. CADA does not address wider environmental and social harms: carbon emissions, excessive water consumption, raw material extraction, e-waste, displacement of communities and wildlife, and public health impacts.
Aware of these risks and growing public opposition—as local communities mobilise to protect living conditions and protest rising electricity prices and water use—CADA proposes that member states create "single information points" to inform the public "with the aim of increasing public acceptance of the data centre project."
Dependence on US technology persists
The Commission argues that without CADA, European AI companies depend on foreign, US-based "hyperscaler" infrastructure, posing threats to fundamental rights and data protection through "third-country jurisdictions" with "laws mandating data access and transfer." Yet this argument rings hollow from an institution that actively maintains and expands such data transfers through agreements like the 2022 "EU-US Data Privacy Framework" and new biometric data-sharing arrangements negotiated with the Trump administration.
In reality, EU data centres will continue relying on US investors and tech companies, which will capture most wealth and entrench their power over European critical infrastructure while externalising negative effects onto EU communities.
A path toward genuine digital self-determination
The EU must recognise that fundamental rights are not obstacles to technological independence; they are prerequisites. Europe's rights-based order makes the continent attractive and supports building an economy that works for everyone.
Rather than pursuing an AI-focused strategy, the EU should prioritise technologies that foster digital self-determination by asking:
- Does it avoid problematic dependencies and vendor lock-in?
- Does it protect data security and user privacy?
- Does it prevent market concentration and contribute to fair competition in the EU?
- Is the technology interoperable with open standards and is the code open for inspection and re-use (open source)? Can it contribute to the digital commons?
- Are the technology's governance and business models compatible with democracy and human rights?
While vendor jurisdiction may matter—to avoid service providers subject to authoritarian rule or hostile foreign pressure—it is not a sufficient sovereignty measure. CADA's assumption that Europe must invest in polluting AI data centres to achieve digital sovereignty appears contradictory at best, and fundamentally flawed at worst.
The Commission has already outlined better approaches in its accompanying EU Open Source Strategy:
- Strengthen and promote a vibrant open source ecosystem, with particular focus on public interest, non-profit digital infrastructure and their governing bodies
- Promote and support open and interoperable digital ecosystems for public administrations, including EU institutions, and become a real anchor customer for them
- Strengthen the open source social media space by supporting open and decentralised social media solutions and platforms
- Build out the EU's Open Source Programme Office (OSPO)
- Reinforce digital standards and international outreach
A decentralised, open source, public interest-oriented tech ecosystem would provide Europe and its people with better digital resilience and renewed digital self-determination than pursuing an imaginary "AI race" against the US and China with little regard for environmental, societal and financial risks.



