On 3 June 2026, the European Commission presented its Technological Sovereignty Package as the moment Europe finally takes digital independence seriously. Henna Virkkunen, the executive vice president whose brief now includes tech sovereignty, framed it as the point where Europe stops leaning on American cloud providers and Asian chipmakers. The package’s Cloud and AI Development Act would rank cloud providers by how sovereign they are and steer sensitive public contracts toward the favored tier. Its revised Chips Act would give Brussels emergency authority over chip output.
The framing assumes sovereignty is something Europe can regulate its way toward. The legislative corpus says otherwise.
I mapped the EU digital regulation corpus, 34 binding instruments running from the eCommerce Directive of 2000 to the European Health Data Space Regulation of 2025, and asked one question. Where does the law assert control over digital infrastructure, over data flows, or over foreign actors? The corpus returns five distinct mechanisms. Together they form what I would call the sovereignty legal stack. It has been under construction for more than a decade, one instrument at a time.
The first mechanism is sovereignty by infrastructure. The Data Governance Act (DGA) does not merely regulate data sharing. It builds the institutions through which sharing must run. It imposes structural neutrality on data intermediaries and subjects data altruism organizations to an EU rulebook. The linchpin is a governance layer for the Common European Data Spaces that runs through EU-controlled bodies rather than Member-State or private ones. Whoever writes the interoperability specification governs the market that runs on it.
The second is sovereignty by adequacy. The DGA lets the Commission decide which third countries may receive protected European public-sector data, on the condition that those countries offer protection essentially equivalent to EU standards. This is the adequacy doctrine the Court of Justice built for personal data in Schrems I (Case C-362/14, 2015) and Schrems II (Case C-311/18, 2020), quietly exported to non-personal data. The doctrine migrated from privacy law to industrial policy.
The third is sovereignty by jurisdiction, the most aggressive mechanism in the corpus and the least discussed. The GDPR, the AI Act, the DMA, and MiCA all reach conduct occurring anywhere in the world so long as the effect is felt inside the Union. A cluster of provisions then requires non-EU providers to designate a legal representative inside the EU, which converts extraterritorial rules into domestic liability. The price of non-compliance is exit from the EU market.
The fourth is sovereignty by access rule. The Data Act requires cloud providers to resist unlawful third-country governmental access to data held in Europe. The target is the US CLOUD Act, under which American authorities can compel American providers to disclose data wherever it sits. Note what the EU did not do. It did not mandate localization. Data may leave the Union. The rule is that protections travel with it, which means the compliance question is not where the server sits but which legal order follows the data.
The fifth touches citizens directly. By the end of 2026, every Member State must offer a European Digital Identity Wallet built to an EU-controlled specification under eIDAS 2, a public alternative to the credential layers run by Apple and Google. MiCA adds the monetary counterpart by placing large stablecoins, whatever currency they reference, under direct supervision by the European Banking Authority.
Five mechanisms. Dozens of provisions. More than a decade of drafting. Europe did not start pursuing digital sovereignty in June 2026. It has been legislating sovereignty continuously since 2014, with considerable legal sophistication.
The sovereignty legal stack is real. It governs how foreign technology behaves inside Europe. It has not produced European technology. Sovereignty in the law is not sovereignty in the technology, and no amount of mandating the first will conjure the second. Law can clear the path to capacity. It cannot command capacity into being, which is what the June package tries to do. Control is not capacity. Jurisdiction reaches conduct. It does not build fabs or train engineers, and it does not attract customers.
The strongest objection to this reading comes from Anu Bradford. Her Brussels Effect describes how EU rules become global defaults because multinational firms standardize on the strictest regime they face. On that view, regulatory power is leverage, and the legal stack is the asset. Now, the Brussels Effect is real for rules, and firms do export GDPR compliance worldwide. But exporting a rule is not the same as capturing the industry the rule governs. The historical case for demand-side power runs through procurement, and it cuts the other way. American defense contracts in the 1950s and 1960s bought most of the early output of the semiconductor industry and carried Fairchild Semiconductor and Texas Instruments to scale. Procurement anchored demand for products that already existed and needed a buyer of first resort. A procurement preference in 2026 cannot conjure a European hyperscaler, because there is no early output to buy at the scale the assurance tiers presuppose.
A stack that does not build capacity would be a harmless disappointment if it stopped there. It does not. The same layering that fails to produce European technology actively burdens it, and Brussels is only now acknowledging the cost. The rulebook is so layered that a single event can trigger several regimes at once. A single intrusion at one firm can set three clocks running at once, a GDPR notification, a NIS2 filing, and, from September 2026, a Cyber Resilience Act report, each answering to a different authority.
The Commission’s own November 2025 Digital Omnibus is the admission. The instrument exists to unpick duties its earlier laws piled on top of one another. The firms Brussels most wants to grow are the ones that pay the highest price. An incumbent swallows one more compliance workflow and outlasts one more round of guidance. A young company trying to reach 27 national markets meets the same thicket with a fraction of the legal staff. What this produces is not autonomy. It is dependence with a compliance department.
Brussels has drawn the opposite lesson. The June package extends the same legislative instinct from software to hardware, with procurement preferences for sovereign clouds and crisis powers over chip supply. The corpus predicts how this ends. Another layer on the stack. The better project is less glamorous, and it is not the Omnibus. The Omnibus edits duties inside the instruments. It narrows the definition of personal data and merges incident reporting into a single entry point. A firm that sells across 27 national markets still faces 27 enforcement environments and 27 sets of procedures, because the scaling problem sits in the structure of the rulebook rather than in any single duty. What would reach it is making it as easy for a European firm to scale across the Union as it is for an American rival to scale across 50 states. If sovereignty arrives, it will arrive as capacity, and capacity is built from scale, capital, talent, and customers. None of those can be legislated into existence. The most Brussels can do is quit putting obstacles in their way.
**
For paid subscribers, the full audit follows. It maps the sovereignty stack provision by provision across the 34-instrument corpus, states how the map was built and verified, names every article behind each of the five mechanisms, reproduces the operative text of the key provisions, identifies the two provision clusters the mapping links with full confidence, and states what each mechanism means for cloud strategy, market access, and compliance design. Every citation and every extract was verified against the corpus.



