All posts

The EU Tech Sovereignty Package, Explained: What the May 2026 Bundle Actually Changes

Four initiatives, one bundle, and headlines treating proposals as law. Here's what the May 2026 EU Tech Sovereignty Package actually binds, what it only suggests, and why "where your data sits" was never the real question.

Most of it isn't law yet

On 27 May 2026 the European Commission presented its Tech Sovereignty Package, and within a day the headlines had it forcing companies off US cloud. They didn't. The package is a bundle of four initiatives meant to cut Europe's dependence on non-EU cloud, chips, and AI infrastructure, and almost none of it binds anyone today. The motivating numbers are real: EU-based providers hold only around 15% of their own cloud market, and the spending that flows out to mostly non-EU providers runs into the hundreds of billions of euros a year. The rules that follow from those numbers are proposals. They still need the Parliament and the Council to agree, amend, and fight over them before a single line takes effect.

That distinction is the whole game for anyone making a cloud decision off the news. A Commission proposal is the opening move, not the verdict. The Cloud and AI Development Act slipped from Q1 to late May before it even landed. The version you read about will be softened on the way to becoming law.

What are the four pieces, and which one has teeth?

The package is a communication on tech sovereignty plus four workstreams sitting at very different stages.

PieceWhat it doesStatus
Cloud and AI Development Act (CADA)The centerpiece. Aims to roughly triple EU data-centre capacity, set EU-wide eligibility criteria for cloud providers, and write a statutory definition of sovereign cloud into law instead of leaving it a marketing word.Proposal
Chips Act 2.0Pivots from the first Chips Act's supply-side subsidies toward demand — pooling public buyers to make EU-designed and EU-made chips commercially viable.Proposal
EU open-source strategyLeans on open source to build European alternatives instead of reinventing every layer. Direction and money, not regulation.Strategy
Energy/infrastructure roadmapPowering all those new data centres. The least binding of the four — closer to a planning document.Roadmap

One takeaway from the structure: CADA is the piece that could rewrite procurement rules. The rest shapes funding and strategy. They matter for the long arc; they don't tell a buyer what to do on Monday.

Does it force my company off US cloud providers?

No, not if you're a private company. The procurement restrictions target public-sector bodies handling sensitive data in healthcare, finance, and the courts. A separate Commission proposal floated barring member-state governments from putting sensitive public data on US hyperscalers; private firms sit outside that scope. Regulated industries sometimes trail public-sector standards by a year or two, but as written this is a public-procurement instrument, not a private-sector mandate.

What it does introduce is vocabulary you'll start seeing in tenders. The backdrop is the long-stalled European cybersecurity certification scheme (EUCS), which ENISA was tasked to draft after the Cybersecurity Act in 2019 and which has been deadlocked since over whether to bar non-EU providers from its top assurance tier. Alongside it, the Commission has published a separate Cloud Sovereignty Framework that scores services on sovereignty rather than just baseline security — covering things like who legally controls the service, where it sits in the supply chain, where the hardware physically lives, and where data and AI processing happen. CADA is meant to pull these threads together and write sovereignty into law instead of leaving it to a voluntary, perpetually-stuck certification. The underlying questions — who controls the service, who controls the supply chain, where the data physically sits, who can be compelled to hand it over — make a decent buyer's checklist whether or not the law ever passes.

Why "where the data sits" was never the real answer

The package exists because data residency turned out to be a weak guarantee on its own. A US-headquartered provider can store your files in Frankfurt and still be reachable under the US CLOUD Act, which compels American companies to hand over data they control no matter which country the servers are in. That's the exposure the Commission keeps pointing at, and it's why a vendor like Dropbox holding your keys in an EU region doesn't actually close the gap. EU servers under non-EU corporate control don't either.

The sovereignty scoring tries to formalize this. Control over the service and the supply chain matters as much as a map pin. But there's a cleaner answer the regulation tiptoes around: if the provider holds your encryption keys, jurisdiction is the entire argument. If it doesn't, the argument mostly evaporates. A warrant served on a company that cannot read your files produces ciphertext and nothing else. We've written before about how zero-knowledge encryption changes what a subpoena can actually reach.

This is where policy and engineering quietly diverge. CADA spends most of its energy on who owns the company and where the hardware lives — useful, but it's perimeter control. End-to-end encryption is a different lever entirely. It removes the operator's ability to read your data, which makes the residency question matter less. AES-256-GCM for file contents, keys derived with Argon2id and never sent to the server, decryption only on your device. A "sovereign" provider that can still technically decrypt your files has solved a legal problem and left the technical one wide open.

What to actually do before any of this becomes law

Treat the package as a signal, not a deadline. A few moves hold up regardless of how the trilogue lands.

Start by asking your provider the only question that compresses every sovereignty criterion into one: can you read my data? Not where it's stored, not whether you're GDPR compliant — can you, the operator, decrypt it. iCloud can unless you switch on Advanced Data Protection, which ships off by default; its storage plans top out at 12 TB, but that's a plan ceiling, not a limit on the encryption. Dropbox holds the keys outright. Proton and beebeeb can't, by design. That single answer outranks most of the tiering.

Then separate "EU company" from "EU-controlled." A vendor incorporated in the EU but owned through a US parent can still be reachable under foreign law. Read the corporate structure, not the homepage. And don't wait for the certification to settle — EUCS has been stuck since 2019, and a sovereignty label arriving now could take years more to mean anything concrete. Encryption you hold the keys to works today.

For the record, beebeeb is operated by a Dutch company with data in Falkenstein, Germany, the product clients are open source, and zero-knowledge encryption is on every tier, no exceptions. If you'd rather test the "can't read your data" claim than take it on faith, the free tier is a fine place to try it.

The honest read

The package is directionally sane. Europe leans on three US hyperscalers for roughly 70% of its cloud market, and pretending that's fine hasn't worked. But the version making headlines is mostly a proposal, the binding parts are years out, and the procurement rules touch only the public sector for now. The independent move you can make this quarter doesn't need a trilogue: pick infrastructure where the operator can't read your files in the first place.

Files only you can read

Beebeeb is end-to-end encrypted, zero-knowledge cloud storage — stored in Falkenstein, Germany, open source, with a 14-day free trial on every plan. Encryption happens on your device; we only ever hold ciphertext we can’t read.

Join the waitlist See pricing How the encryption works