In a recent move, the European Commission has fined Google €890 million for breaching the Digital Markets Act. This underlines how seriously Brussels now takes digital enforcement. The decision is more than a high-profile case against a major tech platform. It also offers a timely reminder that the EU is no longer content with simply writing digital rules, it increasingly wants to make sure those rules translate into real control.
Europe spent the last decade becoming very good at writing rules for the digital economy, and far less successful at controlling the infrastructure those rules depend on. Six months into 2026, the European Commission seems to have reached the same conclusion.
Since January, the Commission has rolled out a string of initiatives that point to a real strategic shift. On 20 January 2026, it proposed a cybersecurity package to strengthen supply-chain scrutiny and reinforce ENISA's coordinating role. The next day came the Digital Networks Act, modernising the legal framework for connectivity. Then, on 3 June 2026, it unveiled the European Technological Sovereignty Package, bundling the Chips Act 2.0, the Cloud and AI Development Act (CADA), the EU Open Source Strategy, and a roadmap on digitalisation and AI in energy.
Taken together, these moves suggest something bigger than another round of tech regulation: the EU is starting to think about the infrastructure beneath its rules, not just the rules themselves.
Beyond the rulebook
What's changing in 2026 is not that the EU has abandoned regulation, it's that it's recognising the limits of regulation alone. The Commission's new vocabulary is full of words like resilience, autonomy, and strategic dependency, and that shift in language reflects a more realistic view of power in the digital age.
For the past decade, Europe's strength was rule-making. The General Data Protection Regulation (GDPR), the Digital Markets Act (DMA), and the Digital Services Act (DSA) gave Brussels real leverage over global tech firms. But rules don't manufacture chips, build data centres, or secure cloud supply chains. Every time a European hospital or ministry runs a digital service, there's a good chance it's sitting on Amazon, Microsoft, or Google servers and no regulation changes that fact on its own.
That's the real story of 2026: a shift from legal sovereignty (the ability to make and enforce rules) to infrastructural sovereignty, whether Europe can actually rely on digital systems it can steer, audit, and sustain under pressure.
Why the new package matters
The strongest feature of this agenda is that it treats sovereignty as a layered problem rather than a single fix. The Digital Networks Act treats connectivity itself as critical infrastructure needing resilience and investment at European scale. The cybersecurity package applies the same logic to ICT supply chains, aiming to cut dependence on risky third-country suppliers.
The most consequential piece is CADA, which aims to build up Europe's cloud and AI capacity through research funding, data-centre expansion, and a new sovereignty framework. This matters because cloud is no longer a niche issue, it is the operating layer beneath public services, business processes, and AI tools. European cloud providers hold only around 15% of the EU cloud market, according to Synergy Research Group, leaving the vast majority in the hands of US hyperscalers, which is exactly why CADA reframes sovereignty as a matter of infrastructure and procurement, not just legislation.
Chips Act 2.0 pushes the same logic a layer deeper, treating semiconductors as a strategic dependency. That's telling: cloud and AI sovereignty ultimately rest on hardware, and Europe can't claim technological autonomy while its compute stack depends on outside suppliers. The EU Open Source Strategy rounds out the package by linking open source to reduced lock-in and long-term control over critical digital components, widening the debate from "is this European-owned?" to "is this actually governable?"
Where the strategy still falls short
Recognising the problem isn't the same as solving it. The biggest risk is assuming that more capacity automatically means more control. Extra European data centres do not create sovereignty on their own if the financing, chips, and software running through them still come from elsewhere.
That tension shows up clearly in early expert reaction. Global Policy Watch reads the package as a genuine attempt to build capacity across the full tech stack, while IEEE Spectrum is more skeptical, questioning whether the demand-side tools are strong enough to stop dominant foreign providers from simply adapting without ceding real market power. Politico Europe reports that critics see the package as too lenient toward US tech giants, still leaving large parts of the European market open to them. The sharpest critique comes from SOMO, which warns that rapid data-centre expansion could actually deepen Europe's dependence on US Big Tech if the buildout mainly serves foreign cloud demand financed by existing external capital. Even without fully buying that argument, it raises the right question: who actually captures the value when new infrastructure gets built?
There's also a conceptual problem. The package uses the word "sovereignty" constantly, but its meaning stays slippery, there's a real difference between infrastructure that's located in Europe, owned in Europe, or governed in Europe. Blur those lines, and sovereignty risks becoming a marketing label rather than an actual redistribution of power.
Finally, there's a democratic gap. The European Partnership for Democracy points out that the package is framed almost entirely around competitiveness and economic security, with little attention to democratic accountability. If sovereignty is really about control, the question isn't only whether that control sits in Europe, it is who exercises it, and under what public rules.
Three tests for a real sovereignty agenda
Judging where this leaves the EU, I would apply three tests. Does the package shift the balance of control, not just add capacity? Does it hold up under real geopolitical pressure? And does it serve the public interest, rather than treating competitiveness as the only goal?
Europe is no longer resting on its regulatory reputation alone, it is starting to ask how to actually shape chips, cloud, and AI. That's a necessary step. But it isn't sovereignty yet.
The real test is whether the EU can turn capacity-building into control. Get that right, and 2026 could mark the start of a more mature European digital strategy. Get it wrong, and Europe may just end up managing its dependencies more actively, without ever truly escaping them.
Lukas Hergarten, MA Candidate at Maastricht University