Bottom line: The planned Cloud and AI Development Act shifts compliance requirements from data residency to demonstrable European control over operations, ownership, and supply chain—yet uncontrolled workarounds dominate in practice.
The EU Tech Sovereignty Package addresses sovereignty risks in cloud, AI, and supply chains. A Wire study shows: government agencies and enterprises routinely share confidential information via tools without European control—a governance gap that jeopardizes regulatory compliance.
The EU Tech Sovereignty Package and the Cloud and AI Development Act
The EU Tech Sovereignty Package places cloud, AI, and supply chains at the center of regulation. The Cloud and AI Development Act, currently in the ordinary EU legislative procedure, aims to expand European data center capacity and establish an EU-wide assessment framework for sovereign cloud and AI services. This framework takes multiple factors into account: data residency in the EU, independence from third-country providers, transparency of software supply chains, as well as operations, ownership, and control under European governance. This fundamentally shifts the debate from mere data residency to demonstrable control.
Security and Governance Deficits in Collaboration Practice
A study by collaboration provider Wire among IT, security, and compliance managers in Germany, France, and the United Kingdom reveals a contradiction: 84 percent assess their collaboration environment as secure or very secure. At the same time, 48 percent sometimes or frequently share sensitive information via tools unsuitable for secure communication. Specifically, 80 percent of respondents use Microsoft Teams. 42 percent deploy consumer messaging apps such as WhatsApp or Signal in a work context. External collaboration takes place 75 percent via email, 45 percent via file-sharing links, and 42 percent via messaging apps. Board communication, crisis calls, draft contracts, and R&D projects thus follow a mix of US-dominated enterprise platforms, legacy infrastructure, and uncontrolled consumer channels—often outside central identity, device, and access management.
Pragmatic Individual Decisions Undermine Governance
The central risk lies in practice: when external partners need access on short notice, project teams resort to email, crisis teams use “whatever works right now,” a communications landscape emerges that undermines central tool governance and traceability. These pragmatic individual decisions cannot be captured by compliance rules and create blind spots for audit, incident response, and regulatory evidence—requirements of NIS2, DORA, and GDPR.
Server Location Is Not the Same as Sovereignty
A crucial point: data can be stored in European data centers and still fall into non-European dependencies through operators, administrative rights, support processes, or software supply chains. American laws such as the CLOUD Act or FISA Section 702 can impose access obligations on US providers, even if data is physically in the EU. For regulated sectors, government agencies, and critical infrastructure, this creates risks for confidentiality, auditability, and operational resilience. 75 percent of study participants assess control over operations and infrastructure as a core factor for true sovereignty—an understanding that the new EU framework aims to institutionalize.
Source: www.it-daily.net · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.