The EU and the UK are legislating for technology sovereignty, with a focus on AI, cloud services, semiconductors and digital infrastructure. On this episode of “SkadBytes,” Jonathan Stephenson and Alistair Ho unpack the EU’s proposed European Technological Sovereignty Package, including the Cloud and AI Development Act, the Chips Act 2.0, the EU’s open-source strategy and its strategic road map for digitalisation. They also explore the expected role of private capital in expanding Europe’s data centre and semiconductor capacity and the UK’s state-backed Sovereign AI Fund. The conversation highlights why, for companies operating in or investing across European technology markets, these initiatives could shape procurement, funding opportunities and market access.
Episode Summary
Europe has spent a decade writing the rulebook on technology. Now it wants to build the stack. In this episode of “SkadBytes,” Jonathan Stephenson and Alistair Ho, attorneys from Skadden’s IP and technology team in London, break down the EU’s newly unveiled European Technological Sovereignty Package, a four-part digital plan encompassing the Cloud and AI Development Act (CADA) and Chips Act 2.0. Jonathan and Alistair explore CADA’s plan to triple EU data center capacity by 2035, the tiered sovereignty requirements for cloud providers, and what the framework means for U.S. and UK-based businesses. They also compare Europe’s approach with the U.K.’s commercially minded Sovereign AI Fund — and what both mean for investment opportunity.
Voiceover (00:00):
Welcome to “SkadBytes,” a podcast from Skadden exploring the latest developments shaping today’s rapidly evolving tech landscape. Join host Deborah Kirk and colleagues as they deliver concise insights on the pressing regulatory issues that matter to tech businesses, investors and industry leaders worldwide.
Jonathan Stephenson (00:22):
Welcome back to “SkadBytes.” I’m Jonathan Stephenson. I’m joined today by my colleague from our IP and technology team here in London, Alistair Ho. On our previous “SkadBytes,” we gave you an update on where AI regulation was heading in the EU and the U.K., and what really that meant in practice. Today, we are staying with that thread, but shifting the lens from Europe writing rules for technology to Europe trying to build it.
(00:47):
So let’s set the scene. Back on the 3rd of June 2026, the European Commission unveiled its European Technological Sovereignty Package. What do we mean by that? That’s a really ambitious set of measures designed to strengthen Europe’s capacity in semiconductors, AI, cloud and open source. And I should flag straight away that this is a proposal. It’s not law, at least not yet. It’s in preliminary committee readings now with the trilogue phase, and that’s where the commission, parliament and council negotiate a final text, actually expected early to mid-2027, so we’re really early on this one.
(01:23):
So what we’re looking at is the commission’s opening position. And as with any EU legislation, there will likely be some movement between this initial draft and any final law. By way of a brief overview, and we’ll come to discuss these measures in more detail, the four-part digital package focuses on bolstering EU infrastructure through the Cloud and the AI Development Act, or CADA, for data centers, and a Chips Act 2.0 for advanced AI processors. Complementing that, an open-source strategy mandates public sector software usage while the strategic roadmap for digitalization and AI in energy aligns infrastructure, sustainability, really with technological growth.
Alistair Ho (02:08):
Yeah, exactly. And the drivers here are pretty clear. At its heart, this package of legislation and guidance is aimed at strengthening the competitiveness, resilience and strategic autonomy of the EU and its member states in this fast-changing digital world. So the EU relies on non-EU countries for over 80% of its key digital products, services, infrastructure and IP, and it spends approximately €264 billion a year buying U.S. tech solutions. So this package is aimed at enhancing the EU’s ability to act independently, developing and controlling technologies, data and infrastructure while reducing that reliance on non-EU providers.
(02:42):
That said, the commission has been careful to clarify that this doesn’t mean tech decoupling or isolation. It’s just meant to stay grounded in openness and fair market competition, aimed at keeping the market open to trusted partners who play by these European rules. So rather than walking through the package section by section, we thought we would pull out some of the key themes running through it and focus on where it departs from the previous EU approaches we’ve seen. Jonathan, why don’t you kick us off with that?
Jonathan Stephenson (03:05):
Sure. So for me, one of the biggest points here is that the Tech Sovereignty Package is really a move from regulating developed technology to actually regulating and providing for an EU ecosystem. And this is not new at all, because for the past decade, in addition to digital policy being about rules, and I’m thinking of legislation that might sound familiar to our listeners, such as the GDPR, the Digital Markets Act, the Digital Services Act, the Data Act and the AI Act, which are generally concerned with setting the terms on which digital markets operate, the EU has also historically thought about its tech infrastructure. And here, I’m thinking about the Digital Decade and an update to the Digital Decade, which was really a report and a plan on how, up to 2030, the EU were going to develop that tech infrastructure.
(03:54):
The package we’re looking at here points in a slightly different direction. It focuses more on building, and that’s building capacity across semiconductors, cloud infrastructure, AI and digital services. It helpfully and arguably belatedly acknowledges that these things are interconnected, and it really envisages that these are all components of a single stack rather than separate sectors to be policed at one time. And so, the proposed Cloud and AI Development Act is really the centerpiece of that thinking. Its starting point is a straightforward and well-known appreciated problem. Europe simply does not have enough of the cloud and data center capacity, by that we mean current infrastructure, that needs to develop and run AI at the scale that it intends to.
(04:40):
So if adopted in its current form, the act would be hard pushed to close that gap. Member states would each have to designate at least one data center acceleration zone, and where qualifying, projects benefiting from streamlined permitting, aggregated baseline permits, and crucially, a maximum permit granting window of 12 months.
Alistair Ho (05:03):
Yes. And in addition to being a qualifying project, the commission can also designate certain projects as strategic. So based on certain criteria, such as sustainability, innovation, supporting public sector functions or quantum computers, for example, if a project is designated as strategic, that unlocks additional public support and preferential access to EU funding. So both qualifying and then being designated as strategic, the two main incentives there, are essentially getting to market faster and spending less to build out each megawatt of capacity, which is super critical.
(05:30):
And governments are increasingly seeing computing infrastructure as a critical national infrastructure in the same bracket as energy grids or transport networks. So that’s why CADA’s headline number is so eye-catching, tripling the EU’s data center capacity over the next five to seven years, with the aim of giving the union the capacity it needs by 2035. So that raises the obvious question, what does that capacity number look like? Is that enough? Is that too much? It sounds great for AI developments, of course, but is that the right number?
Jonathan Stephenson (05:57):
Great question. Let me unpack that a little bit. A key strategy underlying the package is to stimulate domestic demand, not just from the supply chain. Traditional industrial policy, including the original 2023 European Chips Act, focused on subsidizing supply, mobilizing over €52 billion in public and private investment, mostly for semiconductor manufacturing. Historically though, Europe’s domestic demand has been concentrated in legacy mature node chips used in automotive and industrial sectors rather than the leading-edge advanced microchips required to power AI models.
(06:37):
So the Cloud and AI Development Act works together with the Chips Act 2.0 to accelerate the build out of domestic AI centers and cloud infrastructure. Essentially, the intention is to create the ecosystem needed to absorb Europe’s advanced chip production. The other lever here is procurement. As drafted, the proposal would require public authorities to treat union-added value as a non-price criterion when awarding cloud and AI contracts. And union-added value considers things like whether the tender strengthens the EU’s digital supply chain, integrates EU-developed technologies, or uses hardware designed or manufactured in the EU. In practice, that could create a structural advantage for providers with significant EU-based operations, and could really certainly incentivize other companies to deepen their European footprint.
Alistair Ho (07:35):
Yeah, exactly. So the key motivation essentially is to create a customer base for all this additional capacity that the strategy is looking to create as well. I think that ties in quite nicely to something, another point we wanted to pick up on here, which is how the CADA actually applies these sovereignty requirements to the providers of cloud and AI infrastructure services within its scope, and that’s essentially done through an assurance-level system. So that’s where it introduces these cloud sovereignty requirements on the providers through a tiered system, following a classic EU-graduated approach designed to essentially operationalize the considerations we’ve discussed.
(08:07):
So at Level 1, if a cloud provider wants to handle even basic public sector data, they have to meet requirements such as keeping the data processing, physical assets and customer data strictly inside the EU. That’s Level 1, that’s the basics. Where a contracting authority determines that relevant activity affects public order or public security, then that’s not enough. You need to look at sector Levels 2 and above. So Level 2 adds requirements for EU-based personnel, specialized cybersecurity certifications, and legal protections to ensure a foreign government can’t access the data held.
(08:36):
And then, you hit the highest security tiers, so Levels 3 and 4, and those essentially require the cloud or AI provider to be genuinely owned and controlled by an EU entity. Level 4, of course, being the strictest of the two, and that’s likely to apply to mission-critical, highly sensitive activities, such as defense and national security sectors, which is a classic for EU regulations. So that demands effective EU control over the entire software stack, so no third-country company can even have a say in how the software is designed, developed or updated, that whole chain of development.
(09:07):
The reason why the commission structured it in this way is to prevent total market shock. So they want to keep the vast majority of the commercial tech market wide open to global hyperscalers, while ring-fencing only the most sensitive government defense and critical infrastructure workloads under those strict tier three, tier four levels we discussed.
Jonathan Stephenson (09:25):
Exactly that, Ali. And the commission has really been very responsive to some of the historic criticisms here, and it’s really already indicated that only a relatively small fraction of public sector workloads will actually require those ultra-strict upper levels. But for tech companies, the flip side could be considerable uncertainty. Which level a provider needs to meet relies entirely on risk assessments carried out by member states and EU entities, and until those are completed, some visibility as to what the results of those are, providers won’t know exactly where their contracts sit.
(09:59):
And that uncertainty is actually a really good bridge to the honest counterweight here, and that is that none of this is a done deal. The package, and we’ve noted that already, has been delayed three separate times before the commission finally unveiled it, which alone tells you how heavily contested and really discussed and considered these rules are behind closed doors in Brussels. I’d also flag the financial backing needed to execute all of this. The commission’s own impact assessments are extremely candid about the large investment gap. They estimate Europe needs around €120 billion just to shore up the semiconductor ecosystem under the Chips Act 2.0, and plus a huge additional 200 billion, mostly in private capital, over the next decade to actually triple that sovereign data center capacity. The public purse can’t fund this alone, and the EU is clearly looking to, and dependent on, private investors to step in and help close that gap.
Alistair Ho (11:01):
Yep, completely agree on a macro level. And building on that, another caveat is that the regulation’s actual “procurement teeth” may be softer than the headline suggests. So initial estimates only show that in those strict upper tiers I mentioned earlier, roughly 1% to 10% of highly sensitive government and defense contracts would be caught, so then the other 90% of the public sector cloud market will then remain open to global non-EU suppliers. Because the commission is leaving actual enforcement and risk mapping to individual member states, market analysts are left with a lot of unanswered questions, a lot of uncertainty about how this will be regulated and whether that will be regulated uniformly. The assessments as well will be undertaken by the member states themselves, and the bodies they’re in, so how the assessments will take place also has another sort of uncertainty there as well.
Jonathan Stephenson (11:44):
Yeah. And so, we’ve captured some of the key points that we’ve seen in this package, contextualized it a little bit, but that really raises a key question, which you just flagged, Ali, and I think a lot of firms operating from outside the EU will definitely have, and I’m thinking particularly about our clients in the U.S., which is how this whole sovereignty framework treats providers based in third countries. Ali, how does the drafting handle that?
Alistair Ho (12:07):
Yes, and there’s actually a constructive answer in the current drafting of the CADA. So it includes a mechanism that allows the European Commission to recognize certain third countries as providing sufficient assurances. So essentially, if a country has a strong enough data protection and security alignment, its tech firms can potentially bypass some of the stricter localized requirements, particularly in the lower tiers. So for U.K.-based providers, this could be significant, of course, given the scale of the U.K.-EU digital trade and the fact that the U.K. already holds an official data adequacy position with the EU. Securing this special recognition could be a strategic priority for the British government and the wider tech industry in the U.K., and might help preserve that EU market access, which, of course, is crucial.
Jonathan Stephenson (12:42):
For sure. How far all of this goes depends on whether the legislative package successfully passes in its current form. We certainly already can really see some signals to the market about where this is headed. Investment decisions, procurement and tech opportunities in Europe may increasingly be shaped by their industrial policy, not just standard regulation. And so, for businesses working in digital infrastructure, semiconductors, AI, that could spell really big opportunity, new strategic products, increased funding, and really a surging European demand for localized tech.
Alistair Ho (13:18):
Yep. It’s worth mentioning that this way of thinking — treating tech sovereignty as an investment story — that isn’t unique to Brussels, of course. Other jurisdictions are thinking about it, too. As our listeners may be aware, the U.K. is already running its own version of this playbook, the U.K. Sovereign AI Fund, and that’s a £500 million state-backed venture fund launched by the Department for Science, Innovation and Technology. And that’s a core pillar of the government’s updated AI Opportunities Action Plan.
(13:42):
And just comparing the two approaches, what makes the U.K. approach interesting is just how commercial it is. So instead of leaning on regulations or market restrictions, the British state is acting like a venture capitalist, essentially. The fund provides early-stage equity capital, typically a million to 10 million pounds per startup, but it pairs that money with the muscle of the state. So we’re talking fast-tracked talent visas, specialist R&D grants and fully funded access to the U.K.’s national supercomputer network, where startups get up to a million free GPU hours to train their models.
(14:13):
So, so far, the software and AI unit has backed an initial cohort of startups. A handful have received direct equity investments, while others have been awarded major compute allocations. And so, the investments so far are essentially clustered in the areas you’d expect: AI infrastructure, advanced computing hardware, drug discovery and engineering biology.
Jonathan Stephenson (14:29):
Yeah. I think this is definitely an area to watch and a really interesting discussion. I think that might be the throughline for clients when they’re thinking about where to deploy capital. Both the EU package and the U.K. fund seem to be reframing sovereignty as an opportunity, public money and public demand being used to help companies reach scale rather than simply rules to comply with. And for a U.S.-headquartered or other third-party headquartered business, weighing up the U.K. and the European markets, that’s a shift worth reading closely. The direction of travel could well be towards states acting as an anchor and really trying to anchor those customers and co-investors, and that’s entirely what we’ve seen in some of the industry-led conferences and other meetings of mind that we’ve attended which are already discussing these topics. So Ali, any closing thoughts before we wrap?
Alistair Ho (15:24):
I think I’d just reemphasize that we’re watching a genuine change in approach here, from defensive regulation towards active capability building, so sovereignty has become one of the most visible themes in technology policy. As you say, a lot of conferences we attend, a lot of discussions we have with clients touch on these topics on both sides of the Channel. The ambition is real, the sovereignty push is real, and what remains to be seen is what these measures deliver in practice, and a lot of that will turn on funding and how consistently they’re implemented across the EU particularly, especially since we’ve said the EU package is still only a proposal and so may see a lot of changes before it gets enforced.
Jonathan Stephenson (15:58):
Yeah. So that’s the lay of the land at present. Europe is looking to move from arguably the rule-maker to the builder, and the U.K. is backing up not dissimilar intentions, with capital and a set of open questions on funding and enforcement, all of which will really shape how so much of this actually lands. If any of the themes we’ve discussed touch on what you’re working on and what you’re thinking about in your businesses, we’d be glad to continue the conversation. Thanks, as always, for listening to “SkadBytes,” and we will see you next time.
Voiceover (16:28):
Thank you for joining us for today’s episode of “SkadBytes.” If you like what you’re hearing, be sure to subscribe in your favorite podcast app so you don’t miss any future conversations. Additional information about Skadden can be found at skadden.com.
Listen here or subscribe via Apple Podcasts, Spotify, YouTube or anywhere else you listen to podcasts.
See all episodes of SkadBytes: Tech Innovation Meets Regulation


