Insights & Strategies for Service Providers | Dstny Blog

What is the EU Tech Sovereignty Package?

Written by Joshua Moynehan | Aug 10, 2026, 1:40:37 PM

As its name suggests, rather than a single action the EU Tech Sovereignty package is a bundle of coordinated initiatives tied together. Because of this its remit spans the full technology stack including semiconductors, cloud and AI infrastructure, EU-wide legislation, open-source software, and the energy systems underneath all of it.

Even though a lot of the package is still in the proposal phase, under the guidance of the EU Commission there are a few clearly stated goals which are consistent and clear:

  • Strengthen Europe's digital autonomy
  • Widen the choice in core technologies that EU organisations have
  • Reduce structural dependence on non-EU suppliers
  • Support the EU's ambition to become an AI continent

In a sentence, the main objective of the package is to create a union which is digitally sovereign wherever possible. This means greater control over the infrastructure, data, and supply chains that European society runs on, rather than reliance on systems ultimately governed by other countries' laws and priorities.

What is the EU Tech Sovereignty Package comprised of?

Split into four main components, the package has clear rollout boundaries and a vision for the short, medium and long-term shape of digital Europe. These four components are:

The Cloud and AI Development Act (CADA)

CADA is the part most directly relevant to cloud and SaaS providers. It targets two vulnerabilities: a shortage of EU data-centre capacity, and over-dependence on less than a handful of non-EU cloud providers.

First, it aims to expand infrastructure with a headline target to at least triple EU data-centre capacity within five to seven years, backed by an estimated €200 billion in mostly private investment which is coupled with some new rules for building large-scale data centres.

Secondly, it uses public procurement to steer demand toward more sovereign services.

Third, and most consequentially, it introduces a single EU-wide framework for assessing cloud and AI sovereignty. This system classifies services from level 1 (data processed and stored in the EU) up to level 4 (no interference from any third country), based on control, supply chain, data treatment, location, and security.

For providers, CADA could have dire consequences. As proposal becomes law and law becomes a new way of working, those that don’t address CADA could see themselves being cut off from valuable markets even in their own country.

The Chips Act 2.0

You can't have sovereign AI and cloud without the silicon underneath it. The Chips Act 2.0 is the Commission's move to expand Europe's semiconductor capability and support the next generation of computing infrastructure that AI demands.

The proposal focuses on accelerating permitting procedures for chip projects, supporting strategic semiconductor investments, and strengthening partnerships with trusted international allies. The thinking here is that a more resilient European chip supply chain is, ultimately, part of a more resilient European cloud.

The EU Open Source Strategy

The EU Open Source Strategy positions open-source software as a lever for sovereignty and a way to reduce dependence on proprietary systems controlled by a handful of foreign vendors. It is the blueprint to building shared, transparent digital foundations Europe can maintain itself.

Because of this, services built on open, auditable foundations align with the sovereignty direction and may increasingly be viewed favourably in European procurement and partnership decisions.

The Strategic Roadmap for Digitalisation and AI in Energy

The final component of the package is a roadmap that connects the digital agenda to the main physical constraint that is fairly omnipresent - Energy. Data centres and AI are enormous consumers of power, and Europe's grid has to accommodate them without undermining its climate goals.

This roadmap itself rests on three pillars:

  • "Energy for AI" which integrates data centres into the energy system more sustainably

  • "Digitalisation and AI for the energy system" which accelerates AI and digital solutions such as the smart-meter rollout

  • "Data for AI and the energy system" which creates a framework for cross-border energy data sharing. In this area, the European Commission are already putting their money where their mouth is, including Horizon Europe funding for AI in energy which estimates that AI-driven optimisation and maintenance could generate savings of up to €94 billion a year in Europe by 2035.

     

How does the package contribute to overall EU digital sovereignty?

Together the four components of the EU Tech Sovereignty Package tell one story. Chips provide the foundation, CADA builds and governs the cloud and AI layer, open source keeps the software stack open and auditable, and the energy roadmap keeps the whole thing powered and sustainable. EU cloud sovereignty is the thread running through all of them, with the ambition to control the infrastructure, data, and supply chains Europe depends on, rather than depending on providers beyond its legal reach.

This is why the package is best understood as a long-term direction, not a one-off rule to wait out. It reflects a durable shift in how Europe intends to govern technology.

Why is this being put together now?

Presented at the start of June 2026, the Tech Sovereignty Package is in fact part of a larger movement of defined changes which we’re labelling as the EU compliance cascade. The framing behind it is simple - Europe has world-class demand for cloud, AI, and advanced computing but it depends heavily on suppliers outside its borders for most of its needs. This reliance has been creating risk and driving loss of autonomy for European providers for years, which thanks to recent geo-political outcomes and technological advancements that are outside of the boundaries of previous legislation, is bubbling to the surface.

This isn’t the first time that something like this has been attempted. The EU recently drafted separate legislation for the European Cybersecurity Certification Scheme for Cloud Services (EUCS) which was heavily sanitised following US lobbying that would cut the scheme’s ability to gain immunity from foreign laws and influences. These are the same immunities that the likes of CADA are trying to enforce once and for all.

The sovereignty package is the EU Commission’s newest way of reducing these increasingly apparent structural dependencies whilst actively widening the choice that organisations have for in core technologies to ultimately give Europe the capacity to pursue its ambition of becoming an AI continent on its own terms.

What the EU Tech Sovereignty Package means for Service Providers

Three major implications stand out for Service Providers when it comes to these changes in both infrastructure and the rules around delivering services anywhere in Europe.

  • Sovereignty has become a selling point. Through CADA's assurance levels and procurement rules, your ability to demonstrate control over service, supply chain, data, and infrastructure will increasingly determine which European contracts you can win. For now this is limited to public sector but there is undeniable precedent for Enterprise following suit in these kinds of things as they see the gaps that they can now cover.

  • The whole stack is in scope. Because the package spans chips, cloud, software, and energy, pressure to get your whole stack in line is growing. Compute availability, open-source posture, data-centre siting, and energy sourcing all feed into how "sovereign" and how viable your European offering is.

  • This layers onto existing rules. The package doesn't replace GDPR, the Data Act, the AI Act, NIS2, DORA, or the pending EU Cloud Services Scheme - it adds a sovereignty dimension that interacts with and compounds them. Total compliance complexity goes up, which makes early mapping of your obligations more valuable, not less.

The Tech Sovereignty Package signals a more assertive era of European policy which is willing to use funding, procurement, and certification to reshape the market in favour of control and resilience. Expect certification and sovereignty credentials to become competitive moats, expect providers to face pressure to localise and restructure, and expect the effects to ripple well beyond Europe, much as GDPR reshaped global data practices.

Not sure how the EU Tech Sovereignty package affects your roadmap or your organisation as a whole? If you'd like to understand where your services stand and what to prioritise, book a consultation with our team. We'll help you map your position across the package and plan your next steps.