European Digital Sovereignty 1/2
A Strategic Dependency Assessment, Part 1
The European Union depends on foreign technology providers for most of its software, cloud and digital infrastructure. We take stock of this dependency: its scale, its layers, its origins, and the concrete risks it poses to the continent’s economy and sovereignty.
Europe on Foreign Technological Life Support
The European Union operates in a state of deep technological dependency, one that affects its software, its cloud infrastructure and a substantial share of its critical digital services. According to a study by Asterès commissioned by Cigref, 80% of European spending on business software and cloud services goes to American companies. These flows also support nearly 2 million direct and indirect jobs in the United States. But the dependency is not limited to financial flows: it is structural. Beyond spending alone, Europe relies on third countries for more than four-fifths of its digital products, services, infrastructure and intellectual property. In other words, the continuity of Europe’s economy and public services rests on chains that the continent controls only partially, if at all. This situation is not the result of recent negligence. It was built over several decades on an implicit assumption: American technologies were reliable, transatlantic relations were stable, and economic efficiency took precedence over any strategic consideration. Donald Trump’s return to the White House, his threats over Greenland, his pressure on European allies and the International Criminal Court affair have brutally reminded us that this dependency can also become a political risk.
A Dependency in Multiple Layers
This dependency does not take a single form: it appears at several levels, each revealing a specific weakness.
Raw materials and hardware
Europe accounts for less than 10% of global semiconductor production, far behind Asia and the United States. But for raw materials, the dependency is not where one might expect. Extraction has become more dispersed: China’s share of rare earths has fallen from about 95% in 2010 to 60% today, and less than 2% of the world’s cobalt comes from Chinese mines. The bottleneck is downstream, in refining, where China processes 79% of cobalt, 68% of lithium, 95% of manganese and nearly 90% of rare earths, of which it produces 92% of permanent magnets (Ifri / Annales des Mines, 2025). Opening mines outside China therefore solves nothing: the dependency lies not in the resource but in the ability to process it. And Beijing has been using this lever since 2023: export licenses on gallium and germanium, extended to seven rare earths and then, in May 2025, to 240 product lines, and, as early as December 2023, a ban on exporting the refining technologies themselves. The geopolitical lever is no longer a hypothesis: it has been activated.
Map of France’s dependence on strategic metals (ADEME)
The production of the most advanced chips, essential to artificial intelligence, is highly concentrated in the hands of three players: TSMC (Taiwan), Intel (United States) and Samsung (South Korea). None is European, but it would be wrong to conclude that Europe is absent from the chain. On the contrary, it holds two decisive segments: upstream equipment, where ASML, ASM International, Carl Zeiss and Belgium’s imec are indispensable, and mature chips, where Infineon, STMicroelectronics and NXP remain global players. What Europe does not control is leading-edge foundry, the link where AI chips are manufactured. The 2023 European Chips Act, with a budget of €43 billion, aims to raise Europe’s share of global production to 20% by 2030, but according to the European Court of Auditors this target will very likely be missed: current projections point to around 11.7%.
Submarine cables
Less visible but just as strategic: 99% of global data traffic travels through submarine cables. In November 2024, the French state acquired 80% of the capital of Alcatel Submarine Networks (ASN), positioning France as a major player in a critical sector that is often invisible but vital to any ambition of sovereignty over data flows.
Main global submarine cable routes and nodes (Géoconfluences, 2024).
The cloud
Beyond applications, there is infrastructure. Amazon Web Services (AWS), Microsoft Azure and Google Cloud capture more than 70% of the European cloud market. This is all the more striking given that European providers’ market share has shrunk from 29% in 2017 to just 15% in 2025. The largest European players, SAP and Deutsche Telekom, each account for only 2% of the continental market. The cloud is not simply data hosting: it has become the digital factory of the European economy. A restriction of access would cause an immediate systemic shock.
The digital workplace and the SaaS model
The dependency shows up on every desk, quite literally. The business email of millions of European organizations relies on Microsoft 365 or Google Workspace. Customer relationships rely on Salesforce, IT processes on ServiceNow, graphic production on Adobe, software development on GitHub (owned by Microsoft), virtualization on VMware, monitoring on Datadog, and cybersecurity on CrowdStrike or Palo Alto Networks. This layer is the most visible and, paradoxically, the least discussed, because it is perceived as a commodity. Yet it is the layer that carries authentication: in an organization standardized on Microsoft 365, the identity directory governs access to the entire information system, including applications that have nothing to do with office software. And that access has become revocable. In the era of perpetual licenses, a vendor that went bankrupt or ended its commercial relationships did not immediately deprive its customers of their tools: the software kept running on the company’s own servers. The SaaS model has removed that safety net. The right to use is by nature suspendable, and it controls the front door: a cutoff would cause not inconvenience but a shutdown. No more login, and therefore no more email, no more CRM, no more collaboration tools, no more software chain to develop and secure applications. It is not a matter of losing your emails; it is a matter of losing access to your own information system.
Payments
Finally, in everyday payments, Europe remains largely structured around dominant networks such as Visa and Mastercard, while pan-European alternatives are still being rolled out. According to the ECB, 61% of card transactions in the euro area go through international payment systems. Meanwhile, Wero is making gradual progress: peer-to-peer payment is already available, online payment is due to launch in 2026 and in-store payment in 2027 (Banque de France, 2026).
Why Did IT Departments Become Dependent?
The “best of breed” logic
For twenty years, the dominant doctrine in the IT departments of large European companies was “best of breed”: for each function, the best tool on the global market, regardless of origin. Email? Office 365. Server virtualization? VMware. CRM? Salesforce. Development platform? AWS or Azure. Each time, the gap in maturity, integration and availability of skills was real, and a CIO who chose a less capable European alternative exposed themselves to criticism from both peers and senior management.
The acceleration of the cloud
The rise of the cloud from the 2010s onward hardened this logic by adding an irresistible financial argument: no more server fleets to depreciate, elastic capacity, reduced CAPEX, faster projects. The CIO could go before the executive committee with measurable short-term savings. The long-term question, which jurisdiction do our data fall under, and what happens if this access is interrupted?, was rarely asked at the time of purchase; and when it was, the vendors’ answer (data centers in Europe, GDPR compliance) seemed sufficient.
The trap of silent lock-in
None of these decisions was irrational. Their aggregation was. In organizations whose application architecture was built natively within a hyperscaler’s ecosystem (managed services, proprietary databases, serverless components), we find in the field that the cost estimate for an exit approaches that of a partial redevelopment. This cost is almost never provisioned at the time of the initial decision. The trap closed gently.
How to measure dependency? The Digital Resilience Index
For a long time, this dependency was hard to measure, which contributed to its silent acceptance. On January 26, 2026, at the first Digital Sovereignty Meetings organized at Bercy, two instruments were launched to address this: a Digital Sovereignty Observatory, which maps dependencies at the macroeconomic level, and a Digital Resilience Index (IRN, Indice de Résilience Numérique), aimed directly at companies, which measures their dependencies across 360 degrees: software, data, infrastructure, skills, governance, and resilience to shocks. Their value lies in making visible what remained opaque, starting with those exit costs that historical purchasing decisions never anticipated. We will return in the second part to how an organization can use them.
The 8 pillars of digital resilience (Digital Resilience Initiative, 2026)
The major risks: from geopolitical abstraction to concrete reality
Systemic economic risk
In the United States, a presidential decree could prohibit American companies from supplying their products and services to the European Union, simultaneously striking several vital layers of the continent’s digital economy. The hypothesis stopped being theoretical the day Donald Trump demonstrated, toward China as well as toward international institutions, his willingness to use technological levers as instruments of foreign policy. The dependency is admittedly reciprocal: the €264 billion spent each year by European companies directly finances American innovation and jobs. But it is deeply asymmetric: a rupture would be catastrophic for Europe in the short term, and merely costly for the United States.
Financial risk: when the supplier alone decides the price
Even before any extreme geopolitical scenario, dependency exposes European organizations to an immediate and concrete financial risk: unilateral price increases. When a supplier holds a monopolistic position on a critical technology component, users are structurally powerless against a revision of its commercial policy. The most spectacular example in recent years is VMware.
After Broadcom’s acquisition of VMware for $69 billion in November 2023, the vendor carried out a radical overhaul of its licensing model: elimination of perpetual licenses, mandatory three-year subscriptions, forced bundling of products, and billing based on potential cores rather than actual usage. The result was swift: members of CISPE (Cloud Infrastructure Services Providers in Europe) reported price increases of between 3x and 10x. European cloud operators saw their EBITDA (earnings before interest, taxes, depreciation and amortization) threatened with falling to zero, with some contracts in force for more than ten years terminated unilaterally without sufficient notice.
Furthermore, in January 2026, Broadcom announced the termination of its Cloud Service Provider program in Europe, effectively excluding all its partners except a small group chosen at its own discretion, which led the German association VOICE to file a complaint with the European Commission.
The lock-in described above takes its most tangible form here. Migrating from VMware to open source alternatives such as Proxmox or OpenStack is technically well understood, but it represents a project of twelve to thirty-six months for an estate of several thousand virtual machines: in practice, several years during which the supplier alone sets the terms.
VMware is not an isolated case. Microsoft has announced a general increase in its Office pricing starting in July 2026, and AWS and Azure cloud prices have risen steadily in recent years. The risk is clear: seeing European technology spending grow without any counterpart or control, for lack of the ability to switch quickly to alternatives.
The International Criminal Court affair: when dependency becomes concrete
In February 2025, Donald Trump announced sanctions against the International Criminal Court in response to investigations into Israeli officials. What followed is instructive, less for its brutality than for its ambiguity. According to Associated Press, prosecutor Karim Khan lost access to his Microsoft email and had to migrate to Proton Mail, a Swiss service with end-to-end encryption. Microsoft disputes this account: its president Brad Smith publicly stated that the company never ceased or suspended its services to the Court, while acknowledging that it had “disconnected” the individual targeted by the sanctions. Elements reported by the Dutch press suggest an even subtler scenario: having been informed that it must cut the prosecutor’s access or see all of its services threatened, the Court itself is said to have carried out the suspension.
This dispute over characterization is in fact the heart of the matter. For if this account is accurate, the “kill switch” did not even need to be activated: it was enough for the American legal constraint to be relayed to the customer for the customer to cut itself off. No contractual clause protects against this mechanism, precisely because technically it is not a service interruption. A few weeks earlier, during a visit to Brussels, this same Brad Smith had promised that his company would defend the interests and data of Europeans against pressure from Washington. The International Criminal Court, for its part, drew its conclusions: in November 2025, it announced the replacement of its Microsoft office suite with OpenDesk, an open source solution delivered by the German Centre for Digital Sovereignty.
The episode recalls a truth that is often underestimated: faced with a foreign government order, a supplier’s contractual commitments carry little weight. This is not a matter of bad faith; it is a matter of applicable law.
The CLOUD Act and its implications
Since 2018, the CLOUD Act has authorized US government agencies to demand access to data stored by American providers, regardless of their geographic location. Concretely, AWS can be legally compelled to provide US authorities with data belonging to European companies hosted in data centers located in Frankfurt or Dublin.
This law creates a direct tension with the European data protection framework. Companies using American cloud services find themselves in a situation of irresolvable legal contradiction. It is in this context that ANSSI’s SecNumCloud label was born. But experts are unequivocal: this cybersecurity label is not a sovereignty label in the strict sense. Indeed, if this label were to certify strict sovereignty, no player could obtain it today.
A diplomatic cable signed by Secretary of State Marco Rubio has also ordered American diplomats to actively lobby against European data sovereignty laws. The regulatory war is now explicit and openly acknowledged.
The specific risk of artificial intelligence
Artificial intelligence is now the most sensitive terrain of European digital sovereignty, for reasons that go beyond the usual technological stakes.
A structural dependency in the AI chain
GPUs and AI accelerators are dominated almost exclusively by Nvidia and its Blackwell and Rubin series, with AMD and Intel as challengers, all American. The start-ups seeking alternative architectures (Cerebras, Unconventional AI, Oxmiq Labs) are also American. Europe is structurally absent from this market, which is nonetheless the hardware substrate of any AI ambition.
But the dependency does not stop at hardware. The dominant large language models (OpenAI’s GPT, Google’s Gemini, Anthropic’s Claude) are American. Training these models requires colossal computing capacity, hosted on American cloud infrastructure. The training data, the built-in biases, the development priorities: all of this is decided across the Atlantic, according to logics and values that are not necessarily those of Europe.
Concentration of AI computing power in the hands of American giants (EPOCH AI)
A matter of cognitive and democratic sovereignty
Christophe Grosbost, strategy director at Innovation Makers Alliance, puts this dimension in radical terms: “AI has become more strategic than nuclear weapons. If a nation does not control its AI, it becomes dependent intellectually, economically and politically.” A country that relies on foreign AI models for its public services, its justice system, its healthcare or its education delegates part of its decision-making capacity to systems whose parameters, orientations and potential drifts it does not control. Algorithmic biases are not neutral.
The first signs of resistance
Europe is not without resources. Mistral AI, founded by French researchers, is developing high-performing, open source language models that embody a “European-style” AI: transparent and respectful of the regulatory framework. ASML’s entry into its capital, to the tune of €1.3 billion, is symbolically strong. The EuroHPC program is deploying supercomputers dedicated to research and AI. And in January 2026, the European Council amended the EuroHPC regulation to support the creation of AI gigafactories on the continent.
This initial assessment highlights a simple reality: digital sovereignty cannot be decreed; it must be built. The second part, available soon, will present the levers of action available to companies and public bodies to reduce their dependency and regain room for maneuver. We will also unveil our Tech Radar of European digital sovereignty, to give you a concrete overview of the solutions that exist in Europe.
In the meantime, find our other articles on the website of the DECeNZ consortium, of which we are a member, as well as on our blog.
And to keep up with our news and the topics we care about, follow us on LinkedIn.