Europe's Digital Dependence, Explained
This is the stakes, in one place. How deep does Europe's reliance on US technology run, why does concentration turn ordinary tools into systemic risk, and why is passing an audit not the same as being sovereign? This cornerstone ties the argument together and links to the detail behind each claim.

Every argument about digital sovereignty eventually needs a number. Here is the one that anchors this whole series: around 80% of European corporate spending on software and cloud, roughly €264 billion a year, flows to US vendors (European Parliament, 2025). That is about 1.5% of EU GDP leaving the continent every year for a single category of imports. Dependence is not a feeling; it is measurable, and it is measured in euros.
This pillar page maps the stakes. Three ideas carry it, and each has a full article behind it.
What "digital sovereignty" actually means
First, the definition, because the word is abused. The EU's own Joint Research Centre defines digital sovereignty as "the EU's capacity to exercise independence in the digital realm while remaining open and connected to global networks" (JRC Policy Brief JRC146878, May 2026). The clause after the "while" is the whole point: sovereignty is not self-sufficiency, and not a wall. It is the ability to decide, operate, switch, and secure critical infrastructure without unacceptable exposure to foreign legal compulsion, single-vendor lock-in, or coercion.
| Term | What it measures |
|---|---|
| Data residency | Where data physically sits (geography) |
| Data sovereignty | Whose laws govern it, and who can compel access (jurisdiction) |
| Self-sufficiency | Building the whole stack yourself (not the goal, and not realistic) |
The dependence is real, and it is layered
Europe is weakest exactly where the future is being built, and strongest in a few deep chokepoints it cannot lose quickly. The public-cloud layer is the clearest illustration: three US hyperscalers hold roughly 70% of the EU cloud market (Synergy Research), while the largest European provider sits around 2%. In frontier AI, the gap is starker still. Yet Europe holds genuine leverage where it counts: one Dutch company, ASML, builds close to 100% of the world's EUV lithography machines.
The full layer-by-layer map, and where Europe still holds the whip hand, is in The Real Map of Europe's Digital Dependence.
Concentration turns ordinary tools into systemic risk
Dependence would matter less if it were spread thin. It is not. When millions of systems share the same software and the same provider, a local defect becomes a continent-scale failure, no attacker required. On 19 July 2024, a single content update from one security vendor crashed an estimated 8.5 million Windows devices worldwide, grounding airlines and diverting hospitals. Regulators have caught up: under DORA, the European Supervisory Authorities designated the first 19 critical ICT third-party providers for direct oversight in November 2025, on criteria explicitly about concentration and substitutability.
How convenience quietly becomes critical infrastructure, and what supervisors now expect, is the subject of When Ordinary Tools Quietly Become Critical Infrastructure.
Compliance is not sovereignty
Here is the trap that catches well-run organizations: you can pass every audit on the calendar and still be one foreign legal order, one licence change, or one provider outage away from losing control of your own operations. A US-headquartered "EU region" can be fully GDPR- and NIS2-aligned on paper while remaining reachable under foreign law, a point a hyperscaler conceded under oath at the French Senate in 2025. The audit was never designed to catch that. Europe is regulating its dependencies faster than it builds substitutes for them, and a compliance stamp does not close that gap.
Why the audit and the dependency are different problems, and what to do about it, is in Compliant but Dependent.
Where this leads
Naming the stakes is step one. The method for acting on them, selective autonomy rather than autarky, is the subject of the second pillar, Sovereignty You Can Actually Operate. The sharpest new front, keeping AI inference and data on sovereign ground, is the third, Sovereign AI, Explained.
If you would rather see what sovereign-by-default looks like as a product, explore the Soveryne Cloud Foundation, or get in touch and we'll show you your real exposure across the frameworks that apply to you.


