What this area covers
Anything that changes what a European buyer or supplier is legally obliged to do: regulations and directives at the point they enter into force rather than the point they are announced, the guidelines and implementing acts that decide what the text means in practice, and the procurement rules that turn all of it into a purchase order or fail to.
Proposal or law
The distinction this area exists to hold is the one between a proposal and a law. Most European sovereignty news is a document that binds nobody yet.
Marking that honestly is most of the work here, which is why this area carried five ■ markers in issue.zero, more than the other three areas together.
The instruments
Four carry most of the weight. Two are law; two are proposals of 3 June 2026 that bind nobody yet.
The AI Act
The AI Act, Regulation (EU) 2024/1689, is in force and is not a sovereignty instrument. It carries 68 definitions at Article 3 and sovereignty is not among them; the word does not appear in the Regulation at all.
It governs what an AI system may do and who answers for it, not who owns the provider or whose law reaches the data.
Regulation (EU) 2026/1744 then moved its hardest obligations back, standalone high-risk to 2 December 2027 and product-embedded to 2 August 2028. The transparency rules were not delayed and have applied since 2 August 2026.
The Cloud and AI Development Act
COM(2026) 502 would create four Union assurance levels at Article 16, and Article 30 would oblige public buyers to procure at level 1 as a minimum, rising with the Article 29 risk assessment.
Annex II excludes hardware from the framework, so an estate can reach the top level while running entirely on imported accelerators.
Chips Act 2.0
COM(2026) 504 deems firms from countries party to the WTO Government Procurement Agreement to be domestic undertakings, and its procurement preference is an optional declaration the text itself calls "ancillary and non-decisive" at Article 30(4)(d).
The Data Act
Regulation (EU) 2023/2854 carries the only lever that helps a customer actually leave: Article 32's obligation to take adequate measures against third-country governmental access, and the removal of switching fees due by 12 January 2027.
Both sit inside the Digital Omnibus, which stalled before the summer.
The scoring instruments, which bind nobody
SEAL is the Commission's own Sovereignty Effectiveness Assurance Level, written as the technical annex to a €180m cloud tender and offered to others as a template.
The Gaia-X labels attach to a service and never to a provider. EUCS has been in draft since 2020, and its March 2024 revision removed the sovereignty requirement that the market is still arguing about.
The recurring shape
European law tests who owns a thing, who operates it and whose law governs it. It stops before who made the parts.
That is not an oversight to be indignant about. It is where each of these instruments draws its own boundary, deliberately, and it is why a sovereignty claim can be entirely true and still reach almost nothing.
When one sounds strong, the question worth asking is not whether it is true. It is which of the four it answers.
In the issues
- ▼issue.zeroThe AI Act's high-risk rules were pushed back, and it is now law.
- ▲issue.zeroThe transparency rules did not get delayed and started applying on 2 August.
- ■issue.zeroThe June Tech Sovereignty Package has four parts, and two get forgotten.
- ■issue.zeroChips Act 2.0 got as far as officials reading it line by line.
- ■issue.zeroThe Cloud and AI Development Act has a rapporteur, according to trade press.
- ■issue.zeroSEAL is a scoring tool, not a law, and it is widely described wrongly.
- ▼issue.zeroThe Quantum Act has slipped and no new date exists.
- ▲issue.zero€659m of German chip subsidies cleared state aid on 14 July.
- ■issue.zeroA European preference for public procurement is drafted but not tabled.
- ▼issue.zeroThe data half of the Digital Omnibus stalled before summer.
Sources
Every claim on this page is traced to the document it came from. The grades are the ones the issue carries. Verified means the primary document was opened and read at the passage asserting the claim. Reported means the primary text could not be reached and the claim rests on a named secondary source.
- Source Verified AI Act, Regulation (EU) 2024/1689, in force, 68 definitions at Article 3, and the word sovereignty absent from the text AI Act, Regulation (EU) 2024/1689
- Source Verified Regulation (EU) 2026/1744 moved the AI Act high-risk obligations to 2 December 2027 and 2 August 2028 Regulation (EU) 2026/1744
- Source Verified The transparency rules were not delayed and have applied since 2 August 2026 Commission transparency guidelines
- Source Verified The June 2026 Tech Sovereignty Package, and the two proposals of 3 June 2026 that bind nobody yet Commission, 3 June 2026
- Source Verified Cloud and AI Development Act, four Union assurance levels at Article 16, the Article 30 procurement floor, the Article 29 risk assessment, and Annex II excluding hardware Cloud and AI Development Act, COM(2026) 502
- Source Verified The Cloud and AI Development Act procedure file and its rapporteur Procedure file, 2026/0138(COD)
- Source Verified Chips Act 2.0, COM(2026) 504, deeming WTO Government Procurement Agreement parties domestic undertakings, and the ancillary and non-decisive procurement preference at Article 30(4)(d) Chips Act 2.0, COM(2026) 504
- Source Verified Chips Act 2.0 read line by line in Council working party Council WK 10387/2026
- Source Verified Chips Act 2.0 procedure file Procedure file, 2026/0139(COD)
- Source Verified Data Act, Regulation (EU) 2023/2854, Article 32 on third-country governmental access and the removal of switching fees by 12 January 2027 Data Act, Regulation (EU) 2023/2854
- Source Reported The data half of the Digital Omnibus stalled before the summer EDRi
- Source Verified SEAL, the Commission Sovereignty Effectiveness Assurance Level, written as the technical annex to a EUR 180m cloud tender Commission Cloud Sovereignty Framework