The EU has “kill switches” in its critical systems. Can digital sovereignty fix them?

“Treating infrastructure dependency as background noise is no longer tenable,” warns Swiss privacy champion Proton.

Share
The EU has “kill switches” in its critical systems. Can digital sovereignty fix them?
Europe relies on tech hosted elsewhere in the world - creating a clear and fast-growing structural vulnerability (Image: KOBU Agency on Unsplash)

When critical systems are governed by a foreign jurisdiction, that dependency becomes a lever. That’s why European regulators, governments and businesses are re-examining who ultimately controls the digital infrastructure that powers their economies.

As Henna Virkkunen, the European Commission’s executive vice-president for tech sovereignty, security and democracy, put it when unveiling the bloc's tech sovereignty package, the goal is to ensure "nobody has a kill switch" over Europe's critical systems.

It is a structural risk for critical digital infrastructure such as identity verification, communications, and financial systems to depend on technology controlled elsewhere. Access can be disrupted by trade disputes, sanctions regimes, or shifts in a single administration's priorities, none of which the dependent country or company controls.

The European Commission itself has stated that the bloc remains structurally reliant on non-EU providers for more than 80% of its digital products, services, infrastructure, and intellectual property. Three US hyperscalers, AWS, Microsoft Azure, and Google Cloud, together control more than half of Europe’s cloud market. More than 70% of Europe's publicly listed businesses rely on US companies for productivity and communication software such as email.

This dependency did not arise from a lack of local capability. It reflects the ordinary economics of first-mover advantage and an attitude in Europe that saw technology as a cost to be mitigated rather than an investment that would drive growth. The result is a market structure where switching costs are high and alternatives, even good ones, struggle to reach critical mass.

From Efficiency Questions to Security Answers

What has changed is not the underlying architecture of the internet, but the geopolitical context around it. A series of episodes over the past two years has concretely demonstrated that technology dependency carries geopolitical and operational risk for organisations.

After the US sanctioned the International Criminal Court’s chief prosecutor in 2025, reports emerged that his Microsoft email account had been disconnected; Microsoft disputes this characterisation, saying the ICC itself ended his access. Gartner estimates European sovereign-cloud investment will more than triple between 2025 and 2027. The US CLOUD Act, which lets Washington compel American firms to hand over data regardless of where it is stored, was central to the Dutch government’s decision to block a US company’s acquisition of Solvinity, the infrastructure behind the Netherlands’ digital identity system.

The clearest illustration of this risk arrived in June 2026, when the US Commerce Department ordered Anthropic to suspend foreign nationals' access to its two most capable models, Claude Fable 5 and Claude Mythos 5. Unable to verify users' nationality at the scale of its API, Anthropic disabled both models for every customer worldwide for roughly three weeks.

The episode followed a separate June 2026 executive order establishing a pre-release vetting period for the most advanced AI models, and together they crystallised a fear that had been building across European policy circles: that dependence on foreign AI, not just foreign cloud or email infrastructure, hands a single government the practical ability to switch off access overnight.

Sovereignty Is Not the Same as "Local"

One of the more important yet easily missed distinctions in this debate is that data residency is not the same as sovereignty. Storing data on servers physically located within a jurisdiction does not, by itself, remove that data from the legal reach of a foreign parent company or foreign government. Genuine sovereignty requires alignment across ownership, operational control, legal jurisdiction, and, for many observers, auditability of the underlying technology itself.

A regional data centre operated by a foreign-owned company, subject to that company's home-country legal obligations, addresses only one layer of the problem. Auditability is what separates a claim from a verifiable fact: when a provider publishes its client-side application code under an open-source license, independent security researchers can verify that what the company says about its encryption and data handling actually runs in production, rather than taking those claims on trust.

A small number of privacy-focused providers have adopted this approach for their email, messaging, VPN, or storage clients, treating open-source code as a baseline requirement for sovereignty claims rather than an optional extra.

This nuance matters because it is increasingly being tested in the market. As sovereignty becomes a selling point, there is a real risk of “sovereignty-washing”, rebranding existing infrastructure with European or local terminology without meaningfully changing who controls it, where legal authority sits, or how the underlying software is verified.

The EU’s proposed Cloud and AI Development Act is explicitly designed to close this gap: as one legal analyst put it, “the direction of travel already goes well beyond data residency and includes ownership structures, immunity from extraterritorial laws, operational control, and supply-chain transparency”. The Commission has also proposed a single EU-wide framework to formally assess cloud and AI sovereignty.

What Businesses and Policymakers Are Actually Doing

The response has been broader than any single company’s product roadmap. Policymakers are pursuing procurement reform, funding for open-source infrastructure maintenance, and certification frameworks intended to reward providers that genuinely reduce dependency. Some governments have set explicit timelines to migrate away from foreign-controlled communication and collaboration tools: France announced in early 2026 that its roughly 2.5 million civil servants will stop using Zoom, Microsoft Teams, Webex, and GoTo Meeting by 2027 in favour of a domestically built platform, Visio, hosted on French sovereign-cloud infrastructure. Similar moves have been reported in Germany, Denmark, and the Netherlands. As one analyst tracking the trend told BNN Bloomberg, “it feels kind of like there’s a real zeitgeist shift”; a reflection of shifting political sentiment as much as a technology decision.

At the same time, sovereignty is not a binary switch that businesses can flip overnight. Migrating core infrastructure, including email, identity, document storage, and communications, entails real transition costs, and for many organisations, the honest starting point is a dependency audit rather than a wholesale platform change. Understanding which functions are genuinely critical, which data is most sensitive, and which vendors hold the most leverage over daily operations is a more useful first step than chasing a single "sovereign" label.

The Broader Stakes

Digital sovereignty ultimately sits at the intersection of three distinct concerns that are often conflated: economic competitiveness (can a region build and sustain its own technology industry), resilience and security (can critical infrastructure be disrupted by a foreign actor's unilateral decision), and rights (can citizens' data be accessed under legal standards they did not consent to and cannot appeal). Progress on one does not guarantee progress on the others, and policy responses need to be precise about which problem they are actually solving.

What is increasingly clear is that treating infrastructure dependency as background noise is no longer tenable. Whether the response comes from regulation, procurement policy, open-source investment, or simple market competition, the direction of travel, toward greater scrutiny of who really controls the digital systems that underpin modern economies, appears to be a durable shift rather than a passing trend.

Follow Machine on LinkedIn