Data Sovereignty / Source date:

EuroStack's proposal for European digital infrastructure

EuroStack is an industry and policy proposal, not an adopted EU framework. Its dependency estimate is attributed to the report's authors.

Illustration reviewing sample supplier-origin and exit-format records; not an official EuroStack facility or adoption result.

The February 2025 EuroStack report is a proposal by its authors, not an adopted EU framework. Its roughly 80% digital-infrastructure dependency figure is the authors' estimate, not a verified universal import statistic. It proposes capacity across chips, connectivity, cloud and platforms. RISC-V is not European-origin technology: its official history records UC Berkeley development beginning in 2010. It has attracted hundreds of signatories and a great deal of attention. What it has not attracted is much analysis of what it would mean for a company that has to buy software next quarter.

Every previous European sovereignty initiative tried to regulate the behaviour of foreign suppliers. This one proposes to buy differently, which is a far more consequential idea and a far less comfortable one

Here is what an enterprise should take from it, separated from the politics.

What the proposal actually argues

Three claims, of descending strength. The dependency is structural. Compute, foundational software, cloud platforms and the models built on them are overwhelmingly supplied from outside Europe, and contractual protections do not change who controls the supply. This part is simply true and is the paper's strongest contribution. Regulation has not worked. Data protection, competition enforcement and digital market rules have shaped conduct without altering the underlying market structure. Also largely defensible. Procurement preference can fix it. Public buying power, directed at European suppliers, could create the demand to sustain a domestic stack. This is where reasonable people diverge, and where the enterprise implications live.

What it would mean in practice

Supplier-origin criteria must be verified in the particular tender or binding rule. The report's proposal alone does not establish a current qualification requirement for every public or regulated buyer. That has a supply chain consequence most vendors have not modelled: your own technology choices become a factor in your customers' evaluations. A European public buyer applying origin criteria to a supplier will eventually ask what that supplier's platform runs on.

What to do with this now

Not much, structurally. But two things are cheap and useful. First, know your own stack's origin — not for ideology, but because you will be asked. Second, keep substitutability in mind at the layers where it is achievable: data formats, identity, and anything with a standards-based alternative. Compute and foundational models are not realistically substitutable for a mid-sized company and pretending otherwise wastes effort.

Practical Guidance for EU Sovereign Cloud Strategy Consultation

  • Map your stack's supplier origins before a customer asks.
  • Watch national tender language; it moves before EU policy does.
  • Preserve substitutability in formats and identity, not in silicon.
  • Distinguish the analysis from the remedy when briefing executives.
  • Cost any European-preference response rather than assuming it.
  • Track the RISC-V and chip initiatives as signals, not as options.
  • Keep exit plans current for the layers you could actually exit.
  • Do not restructure architecture on a proposal that is not yet policy.

The Regional Angle

The first implication for Gulf-based organisations is commercial rather than philosophical. Regional companies selling technology-enabled services into Europe — and there are more of them each year in logistics, fintech, energy services and business process delivery — may encounter supplier-origin questions that have nothing to do with their own nationality and everything to do with the platforms underneath them. A regional provider running on a non-European cloud, serving a European public buyer, is exposed to a criterion it cannot influence. Worth knowing before it appears in a tender rather than during one. The second is that the Gulf is running a structurally similar programme with a different vocabulary and, in some respects, more momentum. Saudi and Emirati national digital strategies pursue domestic capability, local data centre build-out, national cloud designations and now national model development, using procurement preference as one of the main instruments — exactly the mechanism EuroStack proposes. Regional executives reading the European debate should recognise it as a description of decisions their own governments have already been making, which makes the European experience genuinely informative about what works and what merely relocates the dependency. The third point is about position rather than exposure. A company operating between Europe and the Gulf faces two sovereignty regimes with overlapping requirements and no mutual recognition, and the natural instinct is to treat that as double compliance cost. The more useful reading is that the evidence both regimes ask for is largely the same evidence — where processing occurs, who operates it, which entity holds the keys, what happens on withdrawal — and shared evidence can support separate reviews but does not prove compliance with both regimes. Maintain jurisdiction-specific requirements and confirm applicable procurement and legal duties.

The objection worth taking seriously

The strongest objection is that the remedy contradicts the diagnosis. If European dependency is structural, the reason is that European suppliers have not been competitive at the layers that matter, and procurement preference addresses that by guaranteeing demand for products chosen for origin rather than quality — which is a description of how uncompetitive industries are sustained, not created. Europe has run versions of this experiment before, in cloud and in search, and the results were expensive. Meanwhile European enterprises would be handed inferior tools while competing globally against firms using the best available. That critique has history behind it and the burden of proof sits with the proposal, not against it. The part that survives is the diagnosis, which is worth separating from the remedy because they will be argued as a package. Whether or not procurement preference is wise, the observation that contractual and regulatory protections do not change who controls the supply is correct and has direct operational consequences for any enterprise — it is the reason exit planning, format portability and identity independence are worth real effort while sovereign branding usually is not. Read the paper for the analysis, hold judgement on the industrial policy, and act on the part that would be true regardless of what Brussels decides.

Common Questions

Is this EU policy?

No. It is an influential proposal with substantial backing, and elements of its thinking are visible in national procurement. Treat it as a direction of travel rather than a requirement.

Should we move off non-European providers?

Not on the basis of this. If you sell into European public procurement, understand your exposure to origin criteria; otherwise the cost is not currently justified.

What is realistically substitutable?

Formats, identity, storage and increasingly application layers. Compute, accelerators and frontier models are not, for almost anyone.

What should we expect over the next twelve months?

Expect origin criteria to appear in national tenders before any EU-level instrument. Expect European cloud providers to market aggressively against this backdrop. Expect the hardware layer to remain the weakest link in any version of the proposal. And expect the debate to sharpen as artificial intelligence capability concentrates further outside Europe.


EU Sovereign Cloud Strategy Consultation — we separate the parts of the sovereignty debate that change your architecture from the parts that only change the conversation.

Continue reading

Talk to OPS

Start with the operating problem.