AI, data, the cloud: the next phase of European digital sovereignty
The first half of the European gameon artificial intelligence has been played out mainly on the regulatory front.The AI Act, due to come into force in 2024, remains a significant step: a technology capable of impacting employment, healthcare, security and public administration cannot be left to market forces alone. But a match is not won by defence alone. Whilst the EU was building the world’s first major regulatory framework for AI, a genuine European industrial plan covering the cloud, computing power, data and strategic providers remained weak, fragmented and belated.
The May 2026 Omnibus AI Agreement
The developments in May 2026 mark the start of the second phase, or at least they should. On 7 May, the European Parliament and the Council reached a political agreementon the AI Omnibus, the part of the Digital Omnibus dedicated to artificial intelligence. The Digital Omnibus was presented by the Commission in November 2025 to simplify European digital law and reduce overlaps between the AI Act, the GDPR, the Data Act, cyber regulations and the ePrivacy Directive. The agreement is not yet applicable law: it is a political agreement, pending the formal procedures.
Planned postponements and simplifications
In any case, this agreement stipulates that the rules for certain high-risk AI systems (such as biometrics, critical infrastructure, education, employment, migration, asylum and borders) will be postponed until 2 December 2027. For systems integrated into regulated products, such as lifts or toys, the date will instead be 2 August 2028. The Commission has justified the postponement on practical grounds: to ensure that the obligations come into force once technical standards and guidelines are available. The package also includes more scope for sandboxes, strengthening ofthe AI Office and simplifications for SMEs.
The context: competitiveness and Europe’s lagging behind
This adjustment is not without its reasons. Following the entry into force of the AI Act, European businesses, major tech firms, industry associations and some national governments have highlighted the risk of overly burdensome implementation for an ecosystem that is already lagging behind. The Draghi Report linked this to a loss of competitiveness, administrative burdens, market fragmentation and a lack of investment capacity. If capital, cloud infrastructure, foundational models and computing power grow elsewhere, regulation risks becoming the tidy enclosure of a dependency. In 2024, the United States produced forty significant AI models, China fifteen, andEurope only three.

From regulatory constraints to industrial capacity
The second phase, therefore, cannot simply be a technical correction of the first. It must shift the focus from mere compliance to capability. This is where the issue of US and Chinese hyperscalers becomes a concrete reality. The problem is not merely where the servers are physically located, but which legal system governs those who control them. A provider subject to US jurisdiction may receive requests from US authorities even for data stored outside the United States: the CLOUD Act stems from this logic. In the Chinese case, legislation on national security and intelligence imposes obligations to cooperate with the authorities.
Digital sovereignty and technological dependence
For public data, healthcare, research, defence and critical infrastructure, this is a critical issue, directly linked toimmunity from non-EU legislation and, more generally, to political autonomy. Digital sovereignty does not mean closing off the European market, but rather the ability to avoid permanent dependence on entities subject to the sovereign decisions of others. No Member State can achieve this alone: the national scale is too small, the players too diverse, and the investment too high. Only at the European level can public demand, capital and market confidence be directed towards operators capable of ensuring European control and technological independence.
The challenge for the second half: building a European team
A “buy European” approach can create the conditions in which choosing European products is not merely a symbolic gesture, but a rational and strategic choice. If the first half was about laying down the rules of the game, the second must be about building a European team capable of holding its own on the pitch.
After May 2026, the challenge posed by the AI Act and forthcoming measures on digital sovereignty will no longer be merely about better regulation, but about steering the market, investment and public demand towards a genuinely European technological capability. Because the next generation of digital infrastructure must not only comply with the Union’s values: it must also be designed, developed and governed within the Union.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 – AI Act
- European Commission, “EU agrees to simplify AI rules to boost innovation and ban ‘nudification’ apps to protect citizens”, 7 May 2026
- European Commission, ‘Digital Omnibus on AI Regulation Proposal’, 19 November 2025 – COM(2025) 836 final
- European Commission, ‘Digital Omnibus Regulation Proposal’, 19 November 2025 – COM(2025) 837 final
- US CLOUD Act – Clarifying Lawful Overseas Use of Data Act, Pub. L. 115-141, Division V, 2018; 18 U.S.C. § 2713
- National Intelligence Law of the People’s Republic of China, 2017, as amended in 2018
- Mario Draghi, “The future of European competitiveness – A competitiveness strategy for Europe”, 9 September 2024, European Commission
- Stanford Institute for Human-Centered Artificial Intelligence (HAI), “AI Index Report 2025”








