Digital Sovereignty Package vs. CLOUD Act Exposure
Standard: EU Digital Sovereignty commitments, May 2026 Tech Sovereignty Package
The stated standard
The May 2026 Tech Sovereignty Package commits the Union to "strategic autonomy in critical digital infrastructure" and instructs member states to prioritise "sovereign cloud solutions" in public procurement. The accompanying communication uses the word "sovereign" or "sovereignty" throughout, and frames the package as ending Europe's dependency on foreign-controlled infrastructure.
The observed practice
The package's implementing guidance permits member states to count hyperscaler "sovereign region" offerings — US-owned entities operating EU-located infrastructure through EU-registered subsidiaries — toward the sovereignty targets. Under the Ownership-Control Criterion, every such offering fails the only test that matters: the ultimate parent remains subject to the US CLOUD Act, which reaches data in the possession, custody, or control of US-owned providers regardless of server location or subsidiary structure. Nothing in a "sovereign region" arrangement survives a lawful order served on the parent.
The result is a sovereignty programme whose flagship deliverable is sovereignty washing with official endorsement: public money, spent under a sovereignty mandate, procuring infrastructure that remains within foreign jurisdictional reach — while European-owned providers compete against the endorsement.
Verdict: FAIL
The package fails its own stated standard. It does not reduce CLOUD Act exposure; it relabels it. The gap is not one of implementation lag but of design — the implementing guidance was written to accommodate the offerings that fail the test.
What would change this verdict
This entry moves to PARTIAL if implementing guidance is amended to require ultimate ownership and control within EU jurisdiction for anything counted toward sovereignty targets. It moves to CONFIRMED-RESOLVED if such a requirement is adopted and at least one major member state re-tenders accordingly. It will be updated in either direction as evidence arrives.
This site practises what it audits: CVPE.eu is hosted on EU-owned infrastructure with no US data transfers and no CLOUD Act exposure.