Europe's AI Sovereignty Talk Runs on American Servers
What happened
Brussels can pass whatever AI rules it wants. The data still has to cross the Atlantic to reach the machines running the models.
That gap is what two researchers at the AI Now Institute, Frederike Kaltheuner and Leevi Saari, laid out recently. Their argument is simple and hard to dismiss. Europe's ambitions for controlling its own AI future run straight into a basic infrastructure fact: nearly every AI system of consequence operating in Europe sits on servers owned by Amazon, Microsoft, or Google. Three companies, one country of origin, and none of it under European jurisdiction.
Sovereignty, as EU officials tend to use the word, usually means legal control over data and decisions. Kaltheuner and Saari's point is that legal control means little without control over the physical and technical layer underneath it. A regulation written in Brussels only reaches as far as the infrastructure it governs, and right now most of that infrastructure sits outside the bloc's direct reach.
This isn't a distant risk. It describes how things already work. Startups marketing themselves as building sovereign European AI still rent compute from the same three American hyperscalers, because standing up an alternative at that scale takes capital and years neither has. Government pilots branded as digitally independent frequently run on AWS, Azure, or Google Cloud once you look past the marketing.
The stakes reach past pricing and vendor lock-in. A cloud provider subject to US law can be compelled to hand over data or restrict access under American statutes, regardless of what European law says about that same data. When the infrastructure sits outside the jurisdiction trying to regulate it, oversight turns into a request rather than an enforceable right.
That's the actual governance gap in this story. Writing rules about how AI systems should behave accomplishes little if no one inside that jurisdiction can independently confirm those rules were followed on infrastructure someone else operates and controls.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.