Twelve words that decide who counts as European. Each entry says who defines the term, what the definition tests, and, in the column nobody else publishes, what it does not test.
Every entry is graded. Verified means the primary document was opened and read at the passage asserting it. Reported means the primary text could not be reached and the claim rests on a named secondary source. Where a term is not defined anywhere, that is stated, because the absence is usually the point.
Sovereignty
Defined by: nobody. No EU legal instrument defines sovereignty, digital sovereignty or technological sovereignty in operative text.
The word appears twice in binding law in ways worth knowing. The Digital Decade Policy Programme Decision (EU) 2022/2481 makes "the Union's digital sovereignty in an open manner" a binding general objective at Article 3(1)(c). Its Article 2 defines twelve terms, including "unicorn", and sovereignty is not among them. So Member States are obliged to pursue a thing the same instrument declines to define. Verified.
The other appearance is a denial. The International Procurement Instrument, Regulation (EU) 2022/1031, Article 2(1)(n), defines "country" as "any State or separate customs territory, without such term having implications for sovereignty". Verified.
What it does not test: anything. There is no legal test to fail.
The AI Act and sovereignty
Defined by: not applicable. Regulation (EU) 2024/1689 contains 68 definitions at Article 3. Sovereignty is not one of them, and the word does not appear in the Regulation at all. Verified.
It is included here because the AI Act is routinely cited as a sovereignty instrument. It is a product-safety and risk regulation. It governs what an AI system may do and who is accountable for it, not where it was built, who owns the company or whose law reaches the data.
What it does not test: ownership, jurisdiction of the provider, where the model was trained, or what hardware it runs on.
Union assurance level
Defined by: the Cloud and AI Development Act, COM(2026) 502, a proposal of 3 June 2026 and not yet law. Article 16 establishes "a Union cloud computing sovereignty framework consisting of four assurance levels", with the requirements in Annex II, and Recital 51 describes them as "four different levels of trusted offers ('Union assurance levels')". Verified at both. Article 30 then requires contracting authorities procuring cloud services to procure "as a minimum requirement, Union assurance level 1", rising with an Article 29 risk assessment. Verified. The level-by-level detail of Annex II itself remains Reported: that annex could not be retrieved from EUR-Lex.
The instrument's own term is "Union assurance levels". It does not call them sovereignty levels, and neither should anyone quoting it.
What it tests: establishment, infrastructure location, customer and metadata handling, audit, personnel nationality and clearance, and at the top level that no third country holds effective control over the software.
What it does not test: the hardware. Annex II excludes it from the sovereignty framework. The consequence is arithmetic: a cloud estate can be certified at the highest sovereignty level while running entirely on imported accelerators, because the level tests do not reach the silicon. Verified against Council document ST-10104-2026-ADD-1, checked character by character at the Annex II chapeau.
SEAL
Defined by: the Commission's own Cloud Sovereignty Framework v1.2.1, October 2025. SEAL is the Sovereignty Effectiveness Assurance Level, not "Sovereign European Assurance Level" as commonly repeated. Five levels, SEAL-0 "No Sovereignty" to SEAL-4 "Full Digital Sovereignty". Verified.
Two things about it are almost always got wrong. It is procurement scoring, not certification: it was written as the technical annex to the Commission's own €180m cloud tender, and is offered to others as a voluntary template. And a service is scored separately against each of eight sovereignty objectives, SOV-1 to SOV-8, with a composite Sovereignty Score computed alongside. The framework issues no single overall grade. Verified.
What it does not test: nothing, if used as written. It is the most complete instrument in this list. But it binds nobody: it is not law, and a supplier claiming to "be SEAL-3" is describing something the framework does not award.
Sovereign cloud
Defined by: each vendor, differently, in marketing copy. There is no legal definition.
Reading the providers' own words, a pattern holds. Every definition covers data location and the jurisdiction of the operating entity. Oracle goes furthest on ownership, stating that "the hardware and assets used to provide these cloud regions are owned, operated, and managed by EU legal entities that are separate from the existing global Oracle entities". AWS emphasises operations, "operated exclusively by EU residents" with "zero operational control outside of EU borders". Microsoft's tiers cede hardware and software control only at the private-cloud tier. Vendor claims, quoted as such.
What it does not test: in no case reviewed does the claim extend to the semiconductor supply chain. Where a European operator runs a hyperscaler's stack under licence, the software control plane remains the licensor's, and that is the open question independent commentary keeps returning to.
The clearest illustration ran in a single week of July 2026. Atos launched a sovereign cloud "designed and engineered in the EU". Five days later Zscaler and Schwarz Digits announced a sovereign security platform hosted in German datacentres and operated by STACKIT, with American software and American intellectual property at the control plane. Both used the word. One described where the engineering was done, the other where the servers sit while American software runs on them.
Domestic undertaking
Defined by: the European Chips Act 2.0, COM(2026) 504, a proposal of 3 June 2026, not yet law.
Firms from countries party to the WTO Government Procurement Agreement are deemed domestic. Membership of a trade agreement therefore confers European status for the purposes of the instrument. Verified at Article 2(31) in an earlier reading of the proposal; note that the pinpoint could not be re-confirmed in the most recent pass, when the primary text was unreachable at that provision.
The same proposal's procurement preference is an optional declaration, described in the text as "ancillary and non-decisive" at Article 30(4)(d). Verified.
What it does not test: where anything is made. It is a status test on the supplier's home jurisdiction, not on the product.
The 35% rule
Defined by: SAFE, Council Regulation (EU) 2025/1106, Article 16(10): "The cost of components originating outside the Union, EEA EFTA States and Ukraine shall not be higher than 35 % of the estimated cost of the components of the end product." Verified.
EDIP, Regulation (EU) 2025/2643 carries the same 35 % figure, and not only in Recital 27. The recital uses the non-binding construction, "should not be higher than 35 %". The operative text uses the binding one: "the cost of components originating outside the Union and associated countries shall not be higher than 35 % of the estimated cost of the components of the end product", with a parallel sentence for production capacity increased with Union funding. The perimeter is not SAFE's: EDIP measures against the Union and associated countries, or Ukraine where relevant, where SAFE measures against the Union, the EEA EFTA States and Ukraine. Same figure, different boundary. Verified.
It is a cost ceiling on non-eligible content, so equivalently a 65% floor of European content by cost.
What it does not test: what a component is. The term is not defined in the articles of either Regulation. EDIP Recital 27 draws one edge by negation, and it is worth having in front of you: "Raw materials are not considered components." A rule that turns on the cost share of components, without defining a component and excluding only raw materials, leaves the boundary to the contract. Verified.
Third-country control
Defined by: by name, in EDIP. Recital 23 requires recipients to be "established and have their executive management structures in the Union, in associated countries or in Ukraine" and not "subject to control by a non-associated third country", and Article 2, point (8) then defines the term outright: "‘control’ means the ability to exercise decisive influence over a legal entity directly, or indirectly through one or more intermediate legal entities". SAFE Article 16(3) carries the same construction into its operative text. Verified.
Of the two adjacent instruments, one declines the concept and one does not. The Foreign Subsidies Regulation (EU) 2022/2560 does not define control at Article 2, unlike the Merger Regulation which defines it through decisive influence. Verified.
The International Procurement Instrument, Regulation (EU) 2022/1031 does have a control concept, and it is at Article 3, on determining origin. Where a legal person is not engaged in substantive business operations in the territory of the country under whose laws it is constituted, "the origin of the legal person is to be that of the person or persons who may exercise, directly or indirectly, a dominant influence on the legal person by virtue of their ownership of that legal person, their financial participation therein, or the rules which govern that legal person". Dominant influence is presumed where that person holds the majority of the subscribed capital, controls the majority of the votes attaching to the shares issued, or can appoint more than half of the administrative, management or supervisory body. Verified.
What it does not test: who ultimately owns the parent. An establishment-and-management test is satisfied by an EU-incorporated subsidiary. The IPI's dominant-influence test does look at ownership, but it engages only where substantive business operations are absent in the country of constitution, so a subsidiary with real operations falls outside its reach.
Gaia-X label
Defined by: the Gaia-X Labels Document 2024. Labels attach to a service, not a provider: "Labels can only be assigned to a service, and not to a provider." Level 3, the highest, requires processing exclusively in the EEA and that "the headquarters and the main establishments of the service provider are located in the European Economic Area". Verified.
Gaia-X is explicit about the limit of its own claim: it "will not claim a service to be 'Immune' from a certain jurisdiction". Verified.
What it does not test: who owns the entity whose headquarters it just checked, the hardware supply chain, or the software control plane. A US-headquartered group's EU subsidiary satisfies the headquarters test.
EUCS, and the requirement that was removed
Defined by: nothing yet. The EU Cloud Services certification scheme has been in draft since 2020 and remains unadopted.
The May 2023 draft carried, at its highest level, a requirement that contracts be governed exclusively by the law of a Member State and that the provider's headquarters and global headquarters sit in the Union and not be under non-EU effective control. A March 2024 draft removed the sovereignty requirement and deferred it to national regulators. Sources through April 2026 describe the scheme as still unadopted and the question still open. Reported, from the EU Institute for Security Studies and contemporaneous legal commentary.
What it does not test: currently, nothing, because it does not yet exist. It is in this list because the requirement that was taken out is the exact requirement the market disputes.
Switching
Defined by: the Data Act, Regulation (EU) 2023/2854, Article 2(34), covering the move to another provider "or to an on-premises ICT infrastructure, including through extracting, transforming and uploading the data". Article 2(36) defines switching charges to include data egress charges. Reported; the definitions were read on a mirror after EUR-Lex truncated.
Article 32 is the instrument's real sovereignty provision, requiring providers to take "all adequate technical, organisational and legal measures" to prevent third-country governmental access to non-personal data held in the Union where that would conflict with Union or Member State law. Verified.
What it does not test: whether the measures work. It is an obligation of means.
Extraterritorial reach
Defined by: United States law, which is the point. The CLOUD Act reaches providers subject to US jurisdiction regardless of where data sits. The 2024 reauthorisation of FISA Section 702 broadened the definition of covered providers.
No EU instrument tests this directly, and no CJEU ruling has squarely decided the conflict. The closest are a joint EDPB and EDPS legal opinion of 2019, finding that absent an international agreement providers subject to EU law "cannot legally base the disclosure and transfer of personal data to the US on such requests", and the French Conseil d'État in the Health Data Hub case of October 2020, which held it "cannot be entirely ruled out" that US authorities would seek access, and declined to suspend the arrangement anyway. Verified.
What it does not test: everything above. This is the gap every other entry is arranged around, and the only instrument in this dictionary that reaches it is not European.
How to read this dictionary
Four questions separate what the word is doing in any given sentence: who owns it, who operates it, whose law governs it, and who made the parts. Most European instruments test the first three and stop before the fourth. When a claim sounds strong, the useful question is not whether it is true. It is which of the four it answers.
Corrections with a primary source attached are applied and credited. Where an entry is graded Reported, the primary text was not reachable at that passage and the entry should be read as provisional.
Corrections
17 August 2026. Five entries on this page were corrected, and one of them had been wrong in the publication's strongest grade. They were found by writing the Spanish edition of this dictionary from the Spanish primary texts rather than translating this one, and then reading the English where the two editions disagreed. What was published, and what the documents say:
- Third-country control. This page said the International Procurement Instrument "has no control concept at all: it operates on reciprocity between countries, not on screening the ownership of firms", graded Verified. That was wrong. Article 3 of Regulation (EU) 2022/1031 determines origin by dominant influence over ownership, with three presumption limbs. The entry now quotes it.
- Third-country control. This page said control was defined "functionally rather than by name". EDIP defines it by name, at Article 2, point (8).
- The 35 % rule. This page placed EDIP's ceiling at Recital 27 and graded it "Verified at the recital". The ceiling is also in the binding text, in the "shall not be higher than" form.
- The 35 % rule. This page said EDIP "carries the same ceiling" as SAFE. The figure is the same; the perimeter is not.
- The 35 % rule. This page said the instruments say nothing about what a component is. EDIP Recital 27 says raw materials are not components.
The original wording is quoted above in each case rather than removed, which is this publication's rule. A sixth item, on the Spanish text of the Data Act Article 32, was reported and could not be verified, so nothing has been changed on it and nothing is claimed.