European Digital Sovereignty: 2/2
Towards a Strategy of Reconquest, Part 2
In the first part of this article, we described a Europe massively dependent on foreign technology providers at every level of the digital chain. As promised, it is now time for the levers of action: what some European states and large companies are already doing, and the conditions for turning these isolated initiatives into a genuine strategy of reconquest.
Giving up the illusion of autarky
The first prerequisite is intellectual: giving up the myth of total autarky. “The goal is not absolute autarky or a purely French sector,” reminds Henri Verdier (former interministerial director for digital affairs, now managing director of the Inria Foundation). Sovereignty is understood as a capacity to manage one’s dependencies: knowing whom one depends on, under what conditions, with what bargaining levers and what fallback alternatives. Guillaume Poupard, former director of ANSSI, sums it up this way: “To master is to know how to benefit from technological progress wherever it comes from, to understand it and to know how to implement it autonomously and judiciously.”
Measure before acting
As announced in the first part, the two instruments launched on January 26, 2026 at Bercy are not mere public communication tools. The Digital Sovereignty Observatory maps dependencies at the macroeconomic level; the Digital Resilience Index (IRN), for its part, is aimed directly at organizations.
Its operational value lies in its 360-degree logic: software, data, infrastructure, skills, governance, resilience to shocks. An IT department that undertakes the exercise obtains a snapshot of its dependencies by layer and, above all, a basis for discussion with senior management, which was sorely lacking until now. For the main obstacle has never been disagreement over the diagnosis, but the absence of a common language to express it.
Three concrete uses. Prioritize: not all dependencies are equal, and the exercise brings up the real breaking points, often the identity directory rather than the business applications. Quantify: it forces an assessment of the exit cost of each critical component, the provisioning that was absent from historical purchasing decisions. Track: measured every year, the index turns an intention into a trajectory. The exercise has an uncomfortable virtue: it almost always reveals that the strongest lock-in is not where one expected it.
Public procurement
Once the diagnosis is made, the most powerful lever is public procurement. In France, LaSuite, a sovereign collaborative suite from DINUM (Tchap, Docs, Visio, Fichiers…), is already used every month by more than 500,000 public officials in 15 ministries, with a goal of rolling out the videoconferencing component across all State services by 2027. And in October 2025, the European Commission approved the creation of the EDIC Digital Commons: a European consortium for digital infrastructure (European Digital Infrastructure Consortium), a legal vehicle allowing several member states to jointly fund and operate a shared infrastructure. Founded by France, Germany, Italy and the Netherlands, and officially launched on December 11, 2025 in The Hague, it aims to jointly develop and deploy sovereign tools: LaSuite on the French side, OpenDesk in Germany and MijnBureau in the Netherlands. It is the first mechanism that treats these components no longer as parallel national projects, but as a common good to be financed collectively.
The distinction matters: having digital commons guarantees autonomy, whereas an organization can be autonomous without contributing to them, and is then left alone to finance what others pool.
Those who have already taken action
The movement is no longer theoretical. It is progressing on two fronts, with different logics: public actors, who have the lever of procurement and an obligation to deliver political results; and large private groups, who act only if the economic equation holds. The former open the way, the latter demonstrate that it is practicable.
On the public sector side
The International Criminal Court
The episode detailed in the first part (cutoff, suspension or self-suspension, the characterization remains disputed) produced a consequence that is not disputed: in November 2025, the ICC announced the replacement of its Microsoft office suite with OpenDesk. An international institution demonstrated that a migration away from the dominant ecosystem was achievable within a few months, under constraint. This precedent now weighs heavily in the decisions of European administrations, and it directly feeds the momentum from which the EDIC Digital Commons stems.
The French Ministry of the Economy and Finance
The ministry has operated for several years NUBO, an interministerial cloud based on the community edition of OpenStack, hosting more than 440 application projects on more than 10,000 virtual machines at the end of 2024: one of the most accomplished examples of an operational sovereign open source cloud at the scale of a state.
Nubo’s technical stack: OpenStack as the foundation, complemented by open source components for orchestration, monitoring and storage.
The Cour des comptes (French Court of Audit) has nevertheless noted that this internal cloud, like its equivalent Pi run by the Ministry of the Interior, remains underused relative to the State’s overall digital budget, proof that political will is not enough without real adoption by the administrations themselves.
The German authorities
They illustrate both the ambitions and the difficulties of the exercise. The state of Schleswig-Holstein chose to move its entire administration to free-licensed solutions, abandoning Microsoft, not without technical difficulties that persisted several weeks after the switch. This is a point too often glossed over in the debate: a successful sovereign migration is not a painless migration, and underestimating this phase of friction is the best way to make it fail politically.
Sweden
The country illustrates a more discreet but structuring approach: applied research. Its national institute RISE is actively working on the development of open standards for digital public services, in a logic of pooling close to that pursued by the EDIC Digital Commons. This is a strategy that relies less on creating national champions than on influencing the definition of common technical rules, a lever often underestimated but decisive in the long run to prevent European standards from also being written elsewhere.
On the industry side
Airbus
In July 2026, at the end of a call for tenders estimated at €50 million over ten years, the aircraft manufacturer selected the French provider Scaleway to host its most critical applications: ERP, manufacturing execution systems, CRM and product lifecycle management. The reasoning is openly stated by Catherine Jestin, Airbus’s executive vice-president for digital, quoted by Le Monde Informatique: “I need a sovereign cloud because some information is extremely sensitive,” from a national as well as a European standpoint.
Two lessons go beyond the Airbus case. First, the European offering exists: the consultation attracted around fifty candidate solutions, which qualifies the narrative of a market with no credible alternative. Second, the ecosystem is starting to work as a system: Scaleway is a partner of Mistral AI, whose models are already deployed on its infrastructure, allowing Airbus to accelerate its AI trajectory in the same move.
This decision is not isolated. Airbus was among the signatories of the open letter addressed in March 2025 to Ursula von der Leyen by more than 90 companies and organizations (Dassault Systèmes, OVHcloud, Bpifrance…) calling for a European sovereign infrastructure fund; in May 2026, the group joined ASML, Ericsson, Mistral, Nokia, SAP and Siemens to form the “European Tech Creators.” The symbolism is strong: the company born as a model of European industrial cooperation against Boeing is becoming a pioneer of digital sovereignty.
These examples, public and private alike, must not however mask a paradox. According to Bitkom’s Cloud Report 2025, while 82% of German companies want to see large European cloud providers emerge that can compete with the American hyperscalers, 65% of them refuse to accept any functional, financial or comfort-related limitation in order to change provider. The challenge is therefore not only to create alternatives but to make them competitive enough that organizations choose them without accepting a functional regression.
Open source as sovereignty infrastructure
Open source holds a central place in any serious reflection on digital sovereignty, provided two symmetrical pitfalls are avoided: dismissing it as insufficient, or treating it as a magic solution.
To dismiss it would be to ignore three properties that no proprietary model offers: auditability (verifying what the software actually does), reversibility (changing provider or bringing things in-house without being locked in to a single vendor) and continuity (accessible code does not disappear with the company that wrote it). The VMware affair, detailed in the first part, illustrates all three in the negative. This is why Henri Verdier advocates a committed policy of support for the great digital commons (Linux, the Internet, OpenStreetMap, Wikipedia), whose virtue is not to give Europe control, but “to prevent anyone else from taking it.”
To treat it as a magic solution would be just as costly. First because it is not free: it shifts spending from licensing to integration, operations and security maintenance. Migrating from VMware to Proxmox or OpenStack does not eliminate the dependency; it converts it into a need for in-house skills, in a market where these profiles are scarce. Next, because open source has its own weaknesses: Log4Shell (a critical remote code execution vulnerability) and then the backdoor discovered in the xz utility (an open source library) served as reminders that critical components of global infrastructure sometimes rest on a handful of volunteer maintainers. Finally, because open source does not mean beyond the reach of American law: the platforms that host and distribute this code, GitHub, the Linux Foundation, Apache, fall under United States legislation.
The conclusion is not to give up, but to stop reasoning in terms of license cost. A credible open source strategy has to be budgeted: skills, support, upstream contribution. This is precisely what mechanisms like the EDIC Digital Commons finance, and what most organizations forget to provision.
Drawing inspiration from platform states: Singapore and India
The model most often cited as a reference is that of Singapore. The city-state built its digital sovereignty around a dedicated agency, the Government Technology Agency (GovTech), following a clear principle: the state develops and makes public digital infrastructure of general interest (digital identity, government APIs, payment tools, data consent platforms) that private companies can use and on which they build their own services. Data remains under public control, the infrastructure is open to all, but the private sector retains its space for innovation.

In practice, this gives us Singpass, the national digital identity: 97% of residents aged 15 and over, or 4.5 million users, use it for public services as well as to open a bank account or take out insurance with private players. Alongside it sits a set of reusable components (electronic signature, payment, inter-agency data exchange) that a startup can integrate without rebuilding what already exists. The state acts as an infrastructure provider rather than a service provider.
This model creates a fundamentally different situation from American SaaS: the private sector “does not control the data, does not control the infrastructure and cannot unplug the others,” as Henri Verdier puts it when discussing India’s approach to the public technology stack.
Aadhaar, India’s digital identity system, has enabled the financial inclusion of hundreds of millions of citizens; its model has since spread in open form with MOSIP (Modular Open Source Identity Platform), now adopted by several countries to deploy their own digital identity, and complemented on the payment side by UPI (Unified Payments Interface), the interoperable instant payment infrastructure. India has thus built a public technology stack without depending on the American giants.
For Europe, this approach translates concretely into initiatives such as Gaia-X (controlled data interoperability according to European standards) or the European digital identity eIDAS 2.0, currently being rolled out across member states. Gaia-X’s limitation is that it allowed the American hyperscalers to sit on its governance bodies, a structural paradox that has durably weakened its credibility as a sovereign project.
Fostering European champions
Christophe Grosbost, strategy director at Innovation Makers Alliance (IMA), already cited in the first part, defends a proven model: a European industrial alliance, massive investment and openly assumed protectionism, on the Airbus model.
ASML, already mentioned in the first part as an upstream equipment maker, offers the most accomplished illustration. The world’s only manufacturer of the EUV lithography machines essential to the most advanced semiconductors, the Dutch company holds more than 80% of the global lithography market, and a very real strategic lever, since its best American and Asian customers, TSMC, Samsung and Intel, cannot do without it. This is the strategy of interdependence: building technological components that others need.
This logic is beginning to take collective shape. In May 2026, Airbus, ASML, Ericsson, Mistral, Nokia, SAP and Siemens formed the “European Tech Creators,” a coalition bringing together an aircraft manufacturer, a lithography equipment maker, two telecom players, a generative AI champion and one of the largest enterprise software vendors in the world. The signal is twofold: these industrial groups intend to weigh collectively on the continent’s digital infrastructure choices, and above all they are beginning to choose one another as suppliers. ASML, for instance, relies on Mistral‘s models to accelerate innovation on its lithography systems. This may be where the essential is at stake: an isolated champion remains vulnerable, an ecosystem that orders from itself much less so.
Regulation as normative power
Finally, law remains the most immediately available lever. GDPR, Digital Markets Act, Digital Services Act, AI Act: Europe imposes constraints where it cannot impose its industrial power. But the text that concerns IT departments most directly is also the most recent. On June 3, 2026, the Commission adopted its proposal for a Cloud and AI Development Act regulation (CADA, COM(2026) 502), centerpiece of its Tech Sovereignty Package. The text treats cloud and AI as strategic infrastructure, analogous to roads or railways, and seeks to close a structural data center capacity gap, with the ambition of tripling European capacity within five to seven years.
But the provision to watch lies elsewhere, and it is much more concrete: the creation of a “cloud sovereignty framework” applicable to most providers serving the public sector. In other words, a sovereignty rating framework enforceable in public procurement. It is also the element set to become one of the main political battlegrounds during the trilogues between the Council and Parliament. For IT departments, the stakes are simple: the criteria that emerge from this negotiation will become the common vocabulary for evaluating a cloud provider, in the public sector first, and by capillarity in the private sector afterward. The market, moreover, has not waited for the regulator to apply this criterion.
Provider origin is already a de facto purchasing criterion: a German provider is preferred by all the companies surveyed, a European provider by 61% of them, while an American provider is deemed unacceptable by 57%. CADA would thus merely codify an already established purchasing practice. Based on Bitkom Research, Cloud Report 2025.
A sign that this regulatory pressure is being taken seriously: Microsoft, AWS and Google have all launched “European sovereign cloud” offerings, accompanied by data localization and local governance commitments. These initiatives testify to the balance of power that Europe can still exert over its market. They also mark its limit. At the January 2026 Digital Sovereignty Meetings, Michel Paulin, former CEO of OVHcloud, defended a deliberately non-incantatory reading of the subject: an industry is sovereign only if it grows and gains market share, and the narrative of a Europe with no credible alternative mainly sustains de facto monopolies. Failing that, the vocabulary of sovereignty becomes a veneer: sovereignty washing. For an American cloud managed from Europe by European staff remains a cloud whose source code, updates and control mechanisms stay in the hands of companies subject to American law.
Going further: the European Digital Sovereignty Tech Radar
To help you navigate the European alternatives mentioned in this article (digital workplace, cloud, AI and cybersecurity), Davidson and DECeNZ have developed an interactive Tech Radar that catalogs the solutions and positions them according to their level of maturity and recommended level of adoption.
The goal of this radar: to offer a concrete starting point for identifying alternatives, comparing available solutions and challenging one’s technology choices. But it is not meant to remain fixed. It is designed to evolve with usage, feedback and the expertise of the ecosystem. Is a solution missing? Does a piece of information deserve clarification? Have you tested a tool and want to share your feedback? All contributions are welcome to enrich and develop the radar.
Davidson x DECeNZ interactive IT Sovereignty Tech Radar
And now, over to you!
The Tech Radar is open to contributions. Whether you are an expert in a technology, a user of a European solution, or simply have identified a player who deserves to be listed, we are interested in your perspective.
You can help us by: proposing a new solution to add to the radar, completing or correcting information, sharing feedback on a listed technology, or challenging the maturity or adoption level assigned to a solution.
A solution to recommend to us? Feedback to share? Your contributions are welcome!
Conclusion: breaking out of comfortable inertia
It is not too late. Europe has talent, industrial champions, a globally recognized regulatory framework, and a market powerful enough to carry weight in negotiations.
But several conditions must be met simultaneously. First, a lasting political will: not cyclical announcements with every geopolitical crisis, but multi-year commitments on public procurement, industrial investment and technology trade-offs. Second, a change of doctrine in IT purchasing, where the question is no longer only “what is the best functional solution?” but “what level of control am I prepared to give up, and under what conditions?” Finally, a culture of strategic digital, which places the CIO at the executive committee level and treats technology choices with the rigor reserved for industrial decisions.
This last condition is the most demanding, because it cannot be bought. Taking back control of your cloud, your collaborative tools or your software chain requires teams capable of operating what they have chosen: administering an OpenStack, securing an open source chain, arbitrating an architecture without relying on the vendor’s support. It is a skills project as much as a technology one, and it is prepared years before the migration. The organizations that succeed in their sovereignty trajectory will not be those that signed the best contracts, but those that kept, in-house, the ability to understand what they are buying.
The real question is therefore no longer whether Europe is dependent (it is, massively, at every level of the digital chain, and its CIOs contributed to this in good faith, guided by rational short-term criteria). It is whether Europe can break out of the comfortable inertia that this dependency has established, before someone else decides on its behalf when and how to pull the plug.
You can discover our other articles at Davidson.fr/blog.
And to keep up with our news and the topics we care about, follow us on LinkedIn.
An initiative led by DECeNZ
DECeNZ is a collective of five French digital services companies (Davidson, Ekimetrics, Constellation, Norsys, Zenika) bringing together more than 5,000 employees. Born out of the Convention des Entreprises pour le Climat (CEC), it is based on a simple idea: pooling the expertise and R&D teams of its members to produce tools directly usable by digital players. In twelve months of cooperation, the collective has thus developed six open source commons. The goal is to move beyond mere observation of digital’s impact in order to provide methods and tools for concrete action.
This approach is built around three complementary axes. The first, eco-design, looks at how to design digital products and services while limiting their resource consumption, with work on LCA, accessibility, eco-design and frugal AI. The second, ethical digital, addresses the consequences of technology choices and how to integrate ethical criteria into decisions, for example through the analysis of AI-related risks or the assessment of a service portfolio’s impact against the SDGs. The third, climate knowledge, aims to give decision-makers the keys to understanding these impacts and changing their practices, through initiatives such as Climate Q&A, the serious game Little Big Map or contributions to The Shift Project.
These three dimensions naturally lead to another question: which technologies do we choose to place at the heart of our information systems, and on whom do we become dependent by using them? This is precisely the challenge of digital sovereignty.