Europe has already designed a test for technological sovereignty.

It measures who controls the technology, which laws can reach it, where its components originate, whether European operators can maintain it independently, and what happens when a foreign supplier withdraws support.

The European Commission calls the test SEAL, the Sovereignty Effectiveness Assurance Level. At its highest level, SEAL-4, the definition is uncompromising: technology and operations must be under complete EU control, subject only to EU law, with no critical non-EU dependencies. Supply-chain sovereignty carries the greatest weight in the assessment, more than legal jurisdiction, data control, technological openness or security compliance.

Then, on 30 July, Europe opened the largest artificial-intelligence infrastructure procurement in its history.

The EuroHPC Joint Undertaking invited consortia to compete for up to seven AI Gigafactories, enormous computing facilities intended to train, deploy and operate the next generation of advanced AI systems. The public sector will become an anchor customer, acquiring guaranteed access to the computing capacity. Up to €5 billion is expected from the EU, participating states are supposed to provide at least matching support, and the programme is intended to unlock more than €20 billion in private investment. Successful facilities are expected to begin operating within 18 months of selection.

Ursula von der Leyen has presented the programme as an exercise in European technological sovereignty.

Yet the 133-page tender does not set a minimum SEAL level. It does not require the successful gigafactories to achieve SEAL-2, SEAL-3 or SEAL-4. It does not appear to mention SEAL at all.

Europe has built a ruler for measuring sovereignty.

For its largest sovereignty project, it left the ruler outside.

The standard Brussels already knows how to use

The omission matters because SEAL is not an academic proposal waiting to be tested.

In April 2026, the Commission applied the framework in a €180 million procurement of sovereign cloud services for EU institutions. Suppliers had to reach at least SEAL-2. Most of the successful European providers reached SEAL-3, meaning European actors exercised meaningful influence and the services were judged resilient against significant non-EU supply-chain disruption. Scaleway, Stackit and a Post Telecom-led partnership were among those reaching SEAL-3.

Scaleway is now a core member of AION, the French consortium seeking to build one of the new gigafactories. Its coalition includes Ardian, Artefact, Bull, Capgemini, EDF, Iliad, Orange and Scaleway, with support from a wider industrial and research ecosystem.

The Commission has therefore already assessed the sovereignty of one of the most prominent disclosed gigafactory participants. It has already developed the questions, evidence requirements, scoring methodology and assurance levels needed to distinguish data residency from operational independence and full technological sovereignty.

That makes the absence of a SEAL requirement difficult to explain.

The gigafactory tender contains substantial sovereignty conditions. Facilities must be located in the EU. The coordinator must be established and effectively controlled within the Union. Core operations, including orchestration, system administration, maintenance, privileged access and disaster recovery, must be performed within Europe under European accountability. Operational data, metadata and logs must remain in the EU. Tenderers must also address foreign legal exposure, unauthorised third-country access and extraterritorial interference.

These are serious safeguards. They are not empty language.

But they remain distributed across eligibility rules, narrative commitments and award criteria. They do not produce the standardised sovereignty classification the Commission itself created to move public procurement away from declarations and towards measurable evidence.

Europe is not buying infrastructure without protection.

It is buying infrastructure without publicly stating how sovereign the finished capability must be.

What Europe is actually purchasing

The gigafactories will solve a real problem.

European research institutions, model developers, manufacturers, hospitals, defence organisations and public authorities need access to large-scale AI computing. At present, much of that capacity is supplied through foreign-controlled cloud platforms.

Bringing physical infrastructure, operational responsibility and data governance into European jurisdiction can improve auditability, contractual control, security supervision and resilience. It can give European organisations alternatives to placing every sensitive workload inside the infrastructure of Amazon, Microsoft or Google.

For regulated sectors, jurisdiction is not branding. It is a product requirement.

But the Commission’s own sovereignty framework makes clear that jurisdiction and geography are not the same thing.

The framework asks whether a supplier is exposed to non-EU laws with cross-border reach, including the US CLOUD Act. It asks who controls encryption keys, where firmware is developed, who can issue security updates, whether European operators can maintain the system without foreign involvement, and whether the service can continue if a vendor is ordered to suspend it.

A server standing in Frankfurt does not automatically become sovereign.

The relevant question is not only where the system is located. It is who retains the authority and capability to keep it operating.

The tender’s hardware admission

The tender is unusually candid about Europe’s current technological position.

The facilities are divided into two categories. Medium-scale gigafactories must reach at least 75,000 advanced AI accelerators. Larger facilities must reach at least 100,000. Capacity is standardised in “NVIDIA H100-equivalent” units, although bidders are expected to deploy newer state-of-the-art hardware rather than the H100 itself.

The reference is only a performance benchmark. It is not a mandatory purchase order for Nvidia.

But it tells us something important. The common unit of European sovereign computing capacity is an American-designed processor.

The tender requires bidders to establish credible plans for a European-based and controlled software stack. That stack, including cloud and AI infrastructure, should become operational no later than four years after initial readiness and should incorporate open-source components and European platforms where possible.

Hardware receives much weaker treatment.

Tenderers are merely encouraged to consider European sovereign hardware during the later expansion phase. They may propose the gradual integration of European-designed chips if those products are sufficiently mature and competitive.

The distinction is revealing.

Foreign processors are assumed from the beginning.

European processors are a possible later addition.

Europe may therefore reduce its dependence on foreign cloud operators while expanding its dependence on foreign accelerator suppliers. The data centre, electricity connection, operating company and administrative staff can all be European while processor architectures, firmware, interconnects, software-development environments and critical maintenance remain controlled elsewhere.

A data centre is geography.

Sovereignty is control.

The exception inside the sovereignty rules

There is another tension inside the tender that deserves attention.

Global service providers and international industrial partners, including hyperscalers, may participate as anchor customers. The tender states that these customers may retain operational autonomy over the computing capacity and additional services they provide to their own users. It further states that those services may not be subject to the overall sovereignty conditions applied to the underlying gigafactory.

There are commercial reasons for this. Major cloud providers can bring customers, technical capability and immediate utilisation. Their participation can make the facilities financeable and reduce the risk of expensive infrastructure sitting idle.

But the exception creates a possible sovereignty gap.

A facility may qualify politically as European sovereign infrastructure while parts of its commercially available capacity are controlled through operating arrangements that do not meet the same conditions.

That does not make the project invalid. It makes transparency essential.

The public should be able to distinguish between the sovereign core, the foreign-controlled technology inside it, and services delivered by partners operating under different conditions.

Without that distinction, “European sovereign compute” risks becoming a label applied to several materially different products.

The money behind the €30 billion

The programme is also less financially settled than the headline suggests.

The tender anticipates up to €5 billion from the European Union. Of that amount, only up to €1 billion is available under the current 2021-2027 Multiannual Financial Framework. The remaining €4 billion is indicative and depends on the next EU budget, successor programmes, future financing decisions and the availability of appropriations after 2027.

Participating states are expected to match the EU contribution. Private investors are expected to provide more than €20 billion. The public sector will reduce investor risk by purchasing guaranteed access to the resulting computing capacity.

The model is rational. Frontier AI infrastructure requires enormous upfront investment, while European demand remains fragmented and difficult to predict. A credible public-sector customer can make a project financeable before the commercial market is mature.

But only the first phase of the EU contribution is legally backed by the current budget. Much of the later public financing remains subject to future political decisions.

The tender is real.

The full balance sheet is not yet secured.

This matters because private capital will not invest only on the strength of a policy speech. Investors will examine the duration of the public purchase commitments, expected utilisation, electricity prices, hardware replacement cycles and the likelihood that political support survives several budget negotiations.

Seventy-six expressions are not seventy-six projects

Interest in the programme has been enormous.

EuroHPC received 76 expressions of interest covering 60 possible sites in 16 member states.

That figure proves there is political and commercial appetite for European AI infrastructure. It does not prove that 76 viable projects are ready to proceed.

The difference between an expression of interest and an investable proposal was captured by Deutsche Telekom chief executive Tim Höttges. In February, he said that financing would require at least 35 per cent utilisation and longer-term public commitments. His summary was blunt: “Deutsche Telekom doesn’t need it. Germany needs it.”

That is not an argument against the gigafactories. It is a description of the economic bargain.

Europe wants strategically important capacity before private demand is sufficient to support it. The companies expected to build that capacity want governments to guarantee enough demand to prevent them carrying the entire commercial risk.

The final bidder list will therefore be more informative than the preliminary expressions of interest. It will reveal how many consortia can assemble the capital, power, land, customers, suppliers and governance required to submit a binding proposal.

Every gigafactory is an energy project

A medium-scale facility must eventually support a minimum IT load of 120 megawatts. The larger category must reach at least 150 megawatts. These figures cover the computing load and sit alongside additional requirements for cooling, electrical systems, redundancy and network infrastructure.

Europe enters this competition with a structural disadvantage. The Commission’s competitiveness work has found that industrial electricity prices in the EU can be two to three times those in the United States and China.

A subsidy can reduce the operator’s cost of capital. It cannot instantly create a 150-megawatt grid connection. It cannot manufacture transformers, accelerate every planning approval, guarantee cooling resources or eliminate regional differences in electricity prices.

Europe may discover that advanced processors are easier to purchase than the power required to operate them.

This is why the strongest consortia combine technology companies with infrastructure investors, energy suppliers, telecom operators and industrial customers. The gigafactory is not simply a large computer. It is a continuously financed industrial system whose economics depend on electricity, utilisation, cooling, connectivity and repeated hardware replacement.

The American off-switch is not theoretical

In June 2026, the US government ordered Anthropic to suspend access by foreign nationals to two advanced AI models, Fable 5 and Mythos 5, under export-control authority.

Because Anthropic could not reliably verify nationality in real time, it disabled both models for all customers. Access was restored later after the restrictions were lifted and new safeguards were introduced.

The episode was temporary. It concerned specific models and a specific national-security dispute. It was not an attempt to target Europe.

Its significance lies in the control structure it exposed.

A European customer could have paid for the model, integrated it into critical operations, complied with European law and accessed it entirely from European territory. None of that gave the customer the authority to decide whether the capability remained available.

That decision rested with an American company responding to an American government.

The gigafactories will bring more infrastructure under European jurisdiction. They will reduce certain dependencies and give European organisations alternatives to foreign cloud platforms.

But if essential processors, firmware, compilers, networking systems and security updates remain subject to foreign companies, export controls and legal orders, the off-switch has not disappeared.

It has moved further down the stack.

A sovereignty programme operating at hyperscaler scale

The European programme is enormous by the standards of EU technology policy.

It remains modest by the standards of the companies shaping the global AI infrastructure market.

Amazon now expects capital expenditure of approximately $220 billion in 2026. Combined spending by the largest American technology groups is expected to exceed $700 billion this year.

This is not a like-for-like comparison. Amazon’s spending supports a global commercial business spanning cloud infrastructure, logistics and other operations. The EU programme is targeted public procurement intended to unlock additional private investment.

But the scale difference establishes the environment in which Europe is competing.

Europe cannot create technological sovereignty simply by building smaller public versions of American hyperscale infrastructure. Nor can it win by trying to outspend companies with trillion-dollar valuations and global customer bases.

Its public capital must purchase something those companies cannot or will not provide: European control, verified portability, operational autonomy, supply-chain visibility and the ability to continue under geopolitical pressure.

If the programme merely finances additional demand for imported processors and proprietary systems, European taxpayers will have subsidised the market structure Europe says it wants to escape.

The value lies not only in the quantity of compute purchased.

It lies in the dependencies the contracts remove.

Publish the dependency register

The gigafactory programme needs a public dependency register.

Each selected consortium should disclose the critical components on which its facility relies: processors, interconnects, firmware, operating systems, orchestration platforms, cloud-management systems, model-development environments, networking, identity services, security tooling, cryptographic key management and maintenance support.

For every component, the register should answer a consistent set of questions:

Who supplies it?

Where is the supplier owned and controlled?

Which jurisdictions can compel the supplier to act?

Can European operators maintain the component independently?

Can the component be replaced?

How long would migration take?

What happens if licences, updates, spare parts or technical support are withdrawn?

The register should distinguish four conditions that political language frequently blends together:

European-owned.

European-operated.

Under European jurisdiction.

Capable of continuing without foreign permission.

They are not the same.

The Commission’s own sovereignty framework already provides most of the method. It requires evaluators to examine all technical layers, subcontractors and suppliers, rather than stopping at the legal entity that signed the contract. It specifically searches for hidden dependencies in hardware, firmware, software and operating arrangements.

Each gigafactory should receive a SEAL assessment when selected and again at defined intervals.

Claims of portability should be demonstrated through migration exercises.

Claims of operational independence should be tested under a scenario in which foreign vendor support is unavailable.

Material dependencies should have named owners, replacement plans and target dates.

Europeanisation should be measured as operating evidence, not described as a future ambition.

This would not undermine the programme. It would make the programme credible.

Public money should buy options, not a more expensive form of lock-in.

The case for building anyway

None of this means Europe should abandon the gigafactories.

Europe cannot develop competitive AI companies, industrial applications or frontier research without access to large-scale computing. European model developers should not be forced to train exclusively on foreign cloud platforms. Public authorities and regulated industries need environments in which legal accountability, operational responsibility and data governance remain inside the Union.

The existing network of 19 AI Factories has begun building the institutions, expertise and access models on which the larger facilities can develop. The gigafactories can create demand for European cloud platforms, open-source projects, networking technologies, software companies and, eventually, European-designed processors.

Infrastructure is a precondition for sovereignty.

It is not proof of sovereignty.

The gigafactories provide a serious answer to one urgent question:

Where can European organisations obtain advanced AI computing under European governance?

They do not yet answer the harder one:

Can Europe operate, maintain and evolve that computing capability when a non-European supplier or government says no?

The first question is being addressed.

The second is the test that matters.

What to watch

The tender closes on 12 November 2026. The distance between the 76 expressions of interest and the final qualified bids will show how much early enthusiasm survived contact with the programme’s financing, energy and governance requirements. Successful projects are expected to be selected in early 2027 and begin operating within 18 months.

But the decisive moment should come before the first processor is installed.

What SEAL level does each project achieve?

Which critical technologies remain outside European control?

Who holds the encryption keys?

Who can administer the system?

Who controls the firmware and security updates?

Can workloads be moved without being rebuilt?

Can European engineers operate the platform without foreign support?

What happens when a supplier receives an export-control order?

How long can the facility continue when somebody outside Europe says no?

Those answers will determine whether Europe has purchased a sovereign capability or simply negotiated better conditions on its technological lease.

Europe is right to build the gigafactories. It needs the computing capacity, industrial experience and jurisdictional control they can provide.

But the buildings are not the sovereignty.

Sovereignty begins when Europe can continue operating after permission is withdrawn.

Europe is buying the infrastructure.

America still has a hand on the switch.

Principal sources: European Commission Cloud Sovereignty Framework and implementation guidance; EuroHPC AI Gigafactories tender specifications and consultation results; European Commission sovereign-cloud procurement findings; Deutsche Telekom earnings transcript; Scaleway AION consortium announcement; Anthropic export-control statements; European Commission competitiveness reporting; Reuters.