The Triad of Tech Sovereignty: Dependency, Openness, and Agency
Assessing Europe’s Technological Sovereignty Package
By Stefaan Verhulst and Begoña G. Otero
The European Commission’s Technological Sovereignty Package (IP/26/1187) marks an important moment in the global political economy of the digital age. Presented by Commission President Ursula von der Leyen as an existential imperative for protecting critical infrastructure, the initiative signals an increasingly assertive European response to a rapidly changing geopolitical landscape. Through proposed initiatives such as the Chips Act 2.0, the Cloud and AI Development Act, the Open Source Strategy, and the Strategic Roadmap for Digitalisation and AI in Energy, Brussels has made clear that digital infrastructure is no longer viewed merely as an engine of economic growth but as a strategic asset central to security, competitiveness, and geopolitical influence.
Together, these measures seek to strengthen Europe’s position across the full digital value chain: expanding domestic semiconductor production and advanced chip design capabilities; tripling Europe’s data center capacity over the coming five to seven years; accelerating the deployment of cloud and AI infrastructure; scaling the adoption of artificial intelligence through a network of Experience and Acceleration Centres (AI Factories); promoting open-source alternatives in cloud, AI, cybersecurity, internet technologies, and semiconductors; and integrating digital infrastructure more directly into Europe’s energy system.
Yet technological sovereignty should not be understood as an end in itself. The ultimate objective cannot simply be to manufacture more chips, build more data centers, or host more AI models within European borders. Rather, it should be to ensure that individuals, communities, businesses, and public institutions have meaningful agency over the digital systems that increasingly shape economic opportunity, democratic participation, cultural expression, and public life. Viewed through this lens, the debate around technological sovereignty is fundamentally a debate about digital self-determination: who has the ability to shape the digital systems upon which society depends, under what conditions, and for whose benefit. What follows, then, is that tackling asymmetry by creating new asymmetries is not a desirable outcome. A sovereignty that simply transfers concentrated power from foreign to domestic hands, or that substitutes one set of gatekeepers for another, would resolve the geopolitical problem while reproducing the democratic one. How an infrastructure distributes powers is not fixed by the technology itself but by the institutions and rules built around it: concentration is a choice, not an inevitability. What matters then is not who holds power over digital systems but whether that power is distributed, accountable, and open to challenge.
The Triad of Tech Sovereignty
As the global debate over technological sovereignty intensifies, this quest is increasingly unfolding across three interconnected dimensions (what we call the “Triad of Tech Sovereignty”):
- the weaponization of structural dependency, where reliance on foreign infrastructure becomes vulnerability;
- the weaponization of digital openness, where access and interoperability become mechanisms for extraction; and
- systemic asymmetries of agency, where those most affected by decisions and technical systems often have the least say.
While Europe’s latest initiatives offer substantial responses to the first dimension and growing attention to the second, the third is noticeably misaligned. By prioritizing the hard infrastructure of sovereignty over the democratic imperative of self-determination, Europe risks building an impressive industrial fortress without securing the social foundations required to sustain it.
Note that throughout this article, “weaponization” is used as shorthand for the conversion of structural dependencies and asymmetries into sources of strategic leverage. Identifying the specific actors, targets, and intentions involved in such processes is an important analytical task, but one that falls outside the scope of this article. Our concern is with the conditions that make such leverage possible, regardless of who ultimately exercises it.
The Weaponization of Dependency and the Industrial Turn
The primary catalyst for Europe’s latest intervention is what political economists increasingly describe as the weaponization of dependency. Over more than two decades, the architecture of the global digital economy has become increasingly concentrated within a small number of corporations and jurisdictions, predominantly in the United States and, increasingly, China. This concentration has created profound asymmetries in power and capability, dividing the world into technology producers and technology consumers, platform owners and platform users, infrastructure providers and infrastructure dependents.
When access to advanced semiconductors, cloud infrastructure, operating systems, foundational AI models, and digital platforms is controlled by actors beyond a country’s jurisdiction, dependency can become a strategic vulnerability. Access can be restricted, standards can be imposed, and economic or political leverage can be exercised through technological control. What once appeared to be an efficient process of globalization increasingly reveals itself as a source of systemic risk.
These vulnerabilities extend far beyond economics. Dependence on foreign-controlled digital ecosystems raises concerns about cybersecurity, resilience, democratic integrity, and national security. The concentration of technological capacity creates opportunities for surveillance, manipulation, and disruption at an unprecedented scale. In sum, the digital infrastructure upon which societies increasingly depend can no longer be considered neutral infrastructure; it is a source of geopolitical power.
Brussels’ response to the risk of dependency has been ambitious. The Chips Act 2.0 seeks to strengthen domestic semiconductor production and reduce exposure to foreign supply chains. The Cloud and AI Development Act, as well as the broader AI Continent Action Plan, seek to expand sovereign computing capacity, increase data center infrastructure, and support the development of European AI capabilities. Parallel investments in open-source technologies and the Eurostack reflect an effort to build a more resilient and autonomous digital ecosystem.
Interestingly, what distinguishes this package from earlier European digital strategies is its emphasis on productive capacity. For much of the past decade, Europe’s digital influence derived primarily from its regulatory power — the so-called Brussels Effect. The Technological Sovereignty Package signals a different ambition: to complement regulatory authority with industrial and technological capability. Europe is no longer seeking merely to govern digital markets; it is seeking to shape the infrastructures, compute resources, data ecosystems, and innovation capacities that underpin them.
These measures are both necessary and overdue. Yet they primarily address a single dimension of sovereignty: reducing dependency. It remains an open question whether they are sufficient to secure Europe’s broader digital future. That goal requires initiatives that operate across at least two further dimensions.
The Openness Trap: Data Extraction and Cultural Sovereignty
In addition to the risks of dependency, a second challenge has emerged from what might be called the weaponization of openness.
For decades, the internet was built around ideals of openness, interoperability, and a free flow of information. These principles enabled remarkable innovation, collaboration, and knowledge exchange. Yet in the age of generative AI and foundation models, openness has increasingly become a mechanism through which value is extracted rather than shared.
Large technology firms have systematically harvested publicly available data, media content, cultural artifacts, creative works, and linguistic resources at unprecedented scale. The rise of large language models has transformed vast portions of the digital commons into raw material for commercial AI systems, often without meaningful consent, compensation, or participation by those who generated the underlying content.
This dynamic has intensified concerns about digital colonialism, data enclosure (and the emerging data winter), and cultural sovereignty. European languages, cultural expressions, scientific outputs, and public knowledge repositories increasingly serve as inputs into models developed, governed, and monetized elsewhere.
As a result, policymakers and technologists are beginning to reconsider many of the assumptions that have long underpinned digital openness. Rather than treating openness as an unqualified good, they are beginning to ask who benefits and who bears the costs. A new set of more conditional frameworks is taking shape. Discussions increasingly focus on data commons, alternative licensing regimes, copyright reform, provenance mechanisms, and collective governance approaches capable of ensuring that value generated from shared resources is more equitably distributed.
Yet the challenge is not merely who controls data but who determines the terms under which data can be accessed, reused, and governed. Data commons, licensing mechanisms, and copyright reforms can help prevent extraction, but they do not by themselves create legitimacy. In this sense, the sovereignty they confer is only partial. Ultimately, the success of these efforts depends on a third dimension: whether those affected by digital systems have a meaningful voice in shaping them.
The Neglected Frontier: Agency and Digital Self-Determination
All of this leads to what may be the most consequential, yet least developed, dimension of technological sovereignty: agency. This dimension, which involves how much input citizens have into the systems and technologies that govern their lives, is arguably the most consequential for Europe’s democratic future. It carries forward the core concern of digital self-determination, a practice developed to redress three asymmetries of data, of information, and of agency. Where data and information asymmetries concern who can access data and who understands how it is collected and reused, agency asymmetry concerns who gets to decide; it is the deepest of the three, a principle long established in law and political philosophy and only now carried into the digital domain.
While dependency asymmetries concern who controls infrastructure and openness asymmetries concern who extracts value from data and knowledge, agency asymmetries concern who gets to shape the rules of the digital environment itself. Put simply, these asymmetries reflect the growing gap between those who build digital systems and those who must live with their consequences.
Digital self-determination seeks to close that gap. At its core, digital self-determination reflects the capacity of individuals, communities, organizations, and public institutions to exercise meaningful influence over how digital systems are designed, governed, and deployed. It is not simply a question of individual privacy or consent (though these too are important). Rather, it concerns the collective ability to shape digital futures in ways that align with societal values, democratic aspirations, and public priorities.
Achieving digital self-determination requires more than securing rights; it requires building and maintaining institutions. It requires mechanisms capable of capturing societal preferences and expectations, documenting them through governance arrangements, and enforcing them through accountability structures. These mechanisms can take many forms, including participatory design processes that involve affected communities, independent oversight bodies with genuine enforcement authority, or redress channels that allow individuals and institutions to challenge decisions. Most importantly, these types of mechanisms require shifting from a model in which decisions are made for communities to one in which decisions are made with them. A good example can be found in the CARE principles — Collective Benefit, Authority to Control, Responsibility, and Ethics — developed within Indigenous data sovereignty movements to ensure communities govern data about themselves.
Need for different types of agency
Agency, however, is also not a single thing, and the engagements capable of securing it cannot be uniform. Different holders of agency face different challenges, call for different forms of engagement, and require different structures of oversight; treating them as one undifferentiated “voice” is precisely what allows agency to be promised in general and delivered to no one in particular. An individual resident living beside a new data center confronts infrastructure they did not choose, with real consequences for land, water and energy use; the answer is a right of participation and environmental review, that can be exercised directly or through civil-society organizations with standing to be heard and to challenge, overseen by the competent planning and environmental authorities and, ultimately, the courts. A community whose shared data, language or culture is drawn into foreign models faces a harm that is collective rather than individual, and that aggregating individual consents cannot capture; the answer is collective governance and data stewardship, overseen by stewards mandated to act on its behalf and, where redress is needed, by representative action. A firm shut out of a concentrated market faces foreclosure or dependence on a provider that need not be dominant to dictate its terms; the answer is contestability through competition and public procurement law—applied on equal terms to any provider established in the Union, whatever its nationality, and reaching imbalances of bargaining power that fall short of outright dominance—overseen by the competition authorities and the Commission. A public institution procuring sovereign services faces opacity and capture; the answer is transparency and a right of redress, overseen by audit and administrative review. And a member state under external pressure faces fragmentation; the answer is a common European standard, overseen by an enforcement backstop at European Union level that its peers cannot quietly undercut.
Set out this way, what digital self-determination requires is not a single consultative mechanism but a stewardship architecture: a structured set of engagements, each matched to the challenge it is meant to correct and each paired with the oversight that makes it real. Such an architecture has to be built, not merely invoked. Most of these instruments already exist, data collaboratives and data-sharing agreements that turn a community’s social license into actionable terms, alongside the Union’s tools of market structure, from the Digital Markets Act and Article 102 TFEU to merger control and procurement conditionality. Read this way, competition law is not an alien instrument but the legal counterpart of a democratic commitment. What a conception of self-determination cannot do is stop at principle—naming the asymmetry without naming the means to correct it, or the institutions that must answer for it.
Social License is central to Digital Self-Determination
The notion of a social license–which holds that legal authorization alone is insufficient without broader public trust and acceptance—is central to digital self-determination. Just as democratic governments require legitimacy to govern, digital infrastructures require legitimacy—and trust—to operate. Data centers, AI systems, cloud platforms, digital identity systems, and data-reuse initiatives cannot rely solely on legal authorization or technical capability. They also require public confidence that their operation aligns with societal expectations, respects rights, and generates benefits that are broadly shared.
This is particularly relevant as Europe expands its digital infrastructure ambitions. The success of sovereign AI ecosystems, data spaces, cloud platforms, and digital public infrastructure ultimately depends not only on technological excellence but also on whether citizens perceive these systems as accountable and responsive to their concerns.
The newly released EU framework, despite its commendable ambitions in cloud and semiconductor independence, remains heavily skewed toward state-centric and market-centric solutions. It treats technological sovereignty primarily as an industrial capability challenge rather than a democratic governance challenge. As a result, Europe risks reducing dependency without expanding agency, replacing one concentration of power with another.
It would be more accurate, however, to argue that the framework does not neglect agency so much as misallocate it. The Cloud and AI Development Act proposal (CADA) distributes the authority to decide where sovereignty matters, but it places that authority largely in the hands of national administrations, which determine, case by case, which public-sector workloads require sovereign infrastructure and which do not. This is an agency architecture; it is simply one in which discretion accrues to the actors most exposed to commercial lobbying and external diplomatic pressure, and least bound by mechanisms of participation or redress. The European experience with the General Data Protection Regulation is instructive: where enforcement is devolved to member states with divergent incentives, the result has often been fragmented and permissive application, as jurisdictions compete to attract investment rather than to uphold a common standard. Absent a credible enforcement backstop at Union level, there is little reason to expect a different trajectory for cloud sovereignty. The legal detail matters here precisely because of what is at stake politically: when the question of who exercises agency is settled administratively, case by case and out of public view, it ceases to be a matter of democratic design and becomes one of bureaucratic discretion.
The risk, furthermore, is not only democratic but economic. As recent analyses of Europe’s AI market have shown, even where European infrastructure is built, value frequently continues to flow upstream to a small number of non-European providers, whether through hyperscaler hosting or through dependence on foreign models and chips. The effect is to reproduce, at the level of infrastructure, the very extractive relationship that digital self-determination seeks to overcome: sovereignty without self-determination risks being not merely undemocratic but hollow, with the public bearing the costs in expenditure, land, and energy, while the benefits accrue elsewhere.
The Intertwined Triad: Why Infrastructure Requires Broader Notions of Agency
The triad of sovereignty described here — dependency, openness, and agency — are not separate policy tracks. They are mutually reinforcing. They can also be mutually undermining; a single measure may advance one dimension while quietly eroding another, as the drive to expand data center capacity makes plain.
Efforts to reduce dependency through sovereign infrastructure ultimately depend on public adoption and institutional trust. Efforts to prevent extraction through data commons and licensing frameworks similarly depend on legitimacy and participation. Neither can succeed without addressing the need for greater agency.
Tripling Europe’s data center capacity, for example, raises questions regarding energy consumption, environmental sustainability, land use, and community impact. Likewise, encouraging businesses and governments to adopt sovereign cloud systems requires confidence that these infrastructures serve public interests rather than merely transferring control from foreign corporations to private domestic actors. Without addressing agency asymmetries, investments aimed at reducing dependency or preventing extraction are likely to encounter public skepticism, low adoption, institutional resistance, and growing legitimacy challenges.
Nowhere is this tension sharper than in how the package proposes to build that capacity. It requires member states to facilitate dedicated acceleration zones and to streamline the permitting and deployment of data centers. The legitimacy of that acceleration turns on a question the proposal must answer clearly: whether the streamlining preserves, at the level of the individual project, the environmental assessment and public participation that ordinarily underpin social license, or whether it substitutes front-loaded designation and tacit approval for case-by-case review. The distinction is not merely procedural. The Union is a party to the Aarhus Convention, which guarantees public participation in environmental decision-making, and is bound by the Environmental Impact Assessment Directive; an acceleration that narrowed project-level participation would sit uneasily with both. A self-determination test would ask, at a minimum, that accelerated permitting preserve meaningful, project-level participation rights and incorporate criteria favoring smaller and local operators, both to retain legitimacy and to ensure that the resulting capacity does not simply entrench the dominant providers the package is meant to counterbalance.
Digital self-determination therefore functions as the enabling condition that makes both sovereignty and openness sustainable. Without agency, sovereignty becomes simply a question of who owns the infrastructure rather than who benefits from it. That is a far narrower ambition than Europe’s democratic traditions should settle for.
Conclusion
The European Commission’s Technological Sovereignty Package represents an important and necessary response to a world increasingly characterized by geopolitical rivalry, technological concentration, and digital dependency. Its investments in semiconductors, cloud infrastructure, open-source technologies, and AI capabilities are critical steps toward greater resilience and strategic autonomy.
Yet, as we have argued, technological sovereignty alone is insufficient. Reducing dependency does not automatically increase agency. Preventing extraction does not automatically create legitimacy. Building infrastructure does not automatically generate trust. The deeper challenge for Europe is not simply to become more technologically sovereign but to become more digitally self-determining.
Achieving this deeper goal requires complementing investments in chips, cloud infrastructure, and AI capacity with investments in governance, participation, accountability, and social license. It requires ensuring that citizens, communities, and institutions have a meaningful voice in shaping the digital systems upon which they increasingly depend. It requires moving beyond questions of ownership and control toward questions of legitimacy and agency.
In the context of the present proposals, this implies a set of concrete and achievable amendments rather than a wholly new institutional edifice. First, the criteria governing sovereignty assurance should be tested against an articulated public interest and opened to participation, rather than left to opaque national discretion. Second, enforcement should be equipped with a backstop at Union level, so that a common standard does not dissolve into twenty-seven divergent practices. Third, the data center acceleration zones should be designed to retain Aarhus-compliant, project-level participation and to incorporate local-benefit and small-operator criteria. Fourth, public money committed through procurement and subsidies should be conditioned on openness and the creation of value within Europe, through requirements for interoperability and portability, anti-lock-in safeguards, and, where competition is foreclosed, structural remedies. Underpinning all four, agency should be operationalized through the instruments digital self-determination already offers: data stewardship, data collaboratives, and data-sharing agreements that turn social license into binding terms. Measures of this kind would give the language of governance, participation, accountability, and social license what it has so far lacked: enforceable form.
Ultimately, the future of Europe’s digital project may depend less on who owns the infrastructure than on who has a voice in shaping it. Sovereignty without self-determination risks becoming another form of centralized control. Sovereignty grounded in agency, legitimacy, and social license offers something more ambitious: a digital future that is not only more resilient and competitive but also more democratic. The aim, after all, was never to relocate concentrated power from foreign to domestic hands but to disperse it so that reducing dependence abroad does not harden into a new concentration at home.
