The AI Europe Rents
Every argument for why Europe needs American frontier AI is an argument for why Europe must own the AI it uses.
On 23 July 2025, the White House published America’s AI Action Plan. American AI is to be the global gold standard and America’s allies are to build on American technology. The accompanying executive order is titled Promoting the Export of the American AI Technology Stack. Nine months later, Section 702, the statute governing surveillance access to that stack, is being renegotiated. Europe has no standing in the negotiation.
Europe’s current mitigations (residency, contracts, the Data Privacy Framework, AI Act transparency) do not address jurisdiction. Ownership does. Every argument for why Europe needs American frontier AI is an argument for why Europe must own the AI it uses.
Four tracks, folded into the Cloud and AI Development Act now before the Commission. Apply sovereignty requirements to regulated sectors and public procurement. Redirect AI spending in these sectors to European-owned providers. Commission frontier capability through a European Sovereign AI Investment Company that owns the weights produced. Underwrite European silicon through capability-triggered statutory demand. If sellers will not sell sovereign, Europe does not buy non-sovereign.
- The Plan, the Statute, the Sovereignty Claim ===============================================
America’s AI Action Plan was published by the White House on 23 July 2025 in response to Executive Order 14179 of 23 January 2025.[1] The plan runs to over ninety federal policy actions across three pillars.
The first page states the policy aim: ‘We need to establish American AI—from our advanced semiconductors to our models to our applications—as the gold standard for AI worldwide and ensure our allies are building on American technology.’[2]
The third pillar, Leading in International AI Diplomacy and Security, directs the Department of Commerce and the Department of State to establish an American AI Exports Program to deliver full-stack AI packages to America’s allies. The deliverables are named in the plan as hardware, models, software, applications, and standards.
The accompanying executive order, Promoting the Export of the American AI Technology Stack, sets up the procurement and financing machinery: federal financing through the Export-Import Bank and the Development Finance Corporation, coordinated through the Economic Diplomacy Action Group chaired by the Secretary of State.[3]
Secretary Rubio, speaking at the launch, described the objective as ensuring that ‘America sets the technological gold standard worldwide, and the world continues to run on American technology’.[4]
The Brookings Institution is not a European regulator and not an adversary of the US administration.
In an October 2025 collective analysis of the AI Action Plan, Brookings wrote that ’the American AI technology stack frame plants an American flag smack into the AI sovereignty space’.[5] Brookings read the policy for what it says. What the policy says is that Europe’s AI infrastructure is an American export destination and that European sovereignty over it is not the arrangement the US is proposing.
The statute that controls access to that infrastructure is currently being renegotiated. Section 702 of the Foreign Intelligence Surveillance Act was last reauthorised on 20 April 2024 through the Reforming Intelligence and Securing America Act, which set a sunset of 20 April 2026.[6]
In the early hours of Friday 17 April 2026, after the House Freedom Caucus rejected a clean eighteen-month reauthorisation demanded by the White House, the House passed a ten-day stopgap by voice vote at approximately 2 a.m.
The Senate cleared the stopgap by unanimous consent later that morning.[7] The statute now runs only to 30 April. The House and Senate are negotiating the terms of a longer reauthorisation in the interim.
Section 702 authorises warrantless US intelligence access to the communications and records of non-US persons processed through US-jurisdiction providers.
The 2024 RISAA reauthorisation broadened the definition of ’electronic communications service provider’ to reach, in the language of the Foreign Intelligence Surveillance Court’s own amicus, anyone with access to equipment that can be used to transmit or store electronic communications.[8]
The amicus flagged that the breadth reaches data centres, cloud providers, and, on the face of the text, AI infrastructure operators. European regulators have no role in the certifications. European deployers have no notification rights. European citizens have no standing.
The weaponisation of access under these authorities is not speculative. The six trust assumptions underpinning Position 4 sovereignty have each documented failures.[9] PRISM, ECHELON, Upstream, Merkel’s phone, Operation Dunhammer, and the BND-NSA arrangements through Bad Aibling each appear in the record.
The Danish Defence Intelligence Service investigation concluded that the NSA used its cable access in Denmark to surveil Eurofighter GmbH and Saab during their bids to replace the Danish F-16.[10] The US-made F-35 won.
The historical pattern has been written. The question here is what the pattern means when applied to an infrastructure whose absorption properties are different from those of telecommunications or cloud storage.
- What the AI Act Assumes ==========================
The EU Artificial Intelligence Act entered force on 1 August 2024. Regulation (EU) 2024/1689 is the first horizontal legal framework for AI anywhere.[11] Its risk-tiered structure reserves the heaviest obligations for high-risk systems under Article 6 and Annex III: critical infrastructure, education, employment, law enforcement, migration, justice, and public administration.
These obligations take binding effect on 2 August 2026.
Article 13 of the Act requires that high-risk systems be ‘sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately’. Article 11 requires technical documentation covering training data, intended purpose, known and foreseeable risks, and the metrics by which performance has been validated.
Article 10 requires that training, validation, and testing datasets meet quality criteria including relevance, representativeness, and appropriateness to the setting of deployment.[12]
These are substantive requirements. They are the operational heart of the Act. They rest, however, on an assumption about what a regulator can reach. Article 13 assumes that documentation is knowable, that a deployer can, on challenge, produce an account of what the system was trained on and how it performs. Article 10 assumes that data governance is inspectable.
The regulation is written as if AI systems were legal entities whose internal states could be reached through the ordinary machinery of European regulatory enforcement.
For systems trained and served on infrastructure under US jurisdiction, these assumptions do not hold in the way the Act supposes.
The technical literature on what happens to training data during training is settled. Training data is absorbed into model weights in a form from which the original records cannot be cleanly recovered but from which statistical properties of the training distribution can be extracted through queries, sometimes including verbatim passages, personal identifiers, or reconstructable images.
The Carlini-Nasr-Shokri line of papers on extraction attacks has demonstrated this against every major frontier model released since 2022.[13] The European Data Protection Board’s Opinion 28/2024 treats memorisation as the structural reason that a trained model is very likely to constitute personal data in the legal sense.[14]
The German Federal Commissioner for Data Protection has concluded that complete anonymisation of AI models is not reliably achievable by current methods.[15]
Memorisation is not an incidental property that better engineering can remove. It is a structural feature of the training objective. Models with long-tailed data distributions must memorise singleton examples to perform well on the tail, and the tail is where rare and sensitive data lives.
Differential privacy techniques reduce leakage at a cost in performance; frontier training runs do not currently use them.
What this means for Article 13 is that the documentation obligation describes a state of affairs the infrastructure does not support. Training data, once absorbed, is not separable from the weights. The weights hold the data in a new form. And for the major frontier models relevant to European deployers, the weights are held by entities under US jurisdiction.
Microsoft’s Anton Carniaux told the French Senate under oath in June 2025 that Microsoft France could not guarantee that French customer data would not be disclosed to US authorities on compulsion.[16] The Court of Justice has twice invalidated successor frameworks to Safe Harbour on the specific ground that US surveillance law is not equivalent in the sense European law requires.[17]
The Data Privacy Framework adopted in 2023 rests on the same US statutory landscape that produced Schrems I and Schrems II. In early 2025, the Trump administration removed three of five members of the US Privacy and Civil Liberties Oversight Board, the body whose oversight the Commission had cited as the framework’s key safeguard, leaving the board without a quorum.[18]
The collision is structural. The Act promises transparency over systems whose underlying assets are compellable by at least four US legal authorities, each with a different reach and each independently sufficient to force disclosure or control.
The CLOUD Act of 2018 reaches any data in the ‘possession, custody, or control’ of a US-jurisdiction entity regardless of where the data sits.[19]
In September 2025, an Ontario court ordered a Canadian subsidiary of the French cloud provider OVHcloud to hand over subscriber data from servers in France, the UK, and Australia to the Royal Canadian Mounted Police; the French jurisdiction clause was ignored and compliance ordered anyway.[20] The mechanism is the same. Jurisdiction follows the parent.
FISA Section 702 reaches communications and records of non-US persons routed through US providers, warrantless and without notification. The statute is currently under negotiation this week as the 30 April deadline approaches.
The Defense Production Act’s Title VII information-gathering authority is the one most European sovereignty analysis overlooks. In October 2023, Executive Order 14110 invoked the DPA to compel dual-use foundation model developers to report, on an ongoing basis: ownership and possession of model weights, training activities, physical and cybersecurity protections, and red-team results.[21]
The Trump administration rescinded much of EO 14110 in 2025. The statutory authority itself was not repealed. A future executive order can reinvoke it on the existing legal basis at any time.
The International Emergency Economic Powers Act provides presidential authority to block, restrict, or condition transactions during a declared emergency. It has been used for AI chip export controls already. Its reach extends, in principle, to compute access, model access, and training restrictions on equivalent legal footing.[22]
Compliance with Article 13 on infrastructure of this shape is compliance-as-performance. A deployer can document what it knows; what it knows is bounded by what the provider will disclose; what the provider will disclose is bounded by what US law permits the provider to refuse.
A regulator can demand information; the information is held in a jurisdiction whose statutes condition disclosure on considerations to which the regulator is not a party.
The European Commission has seen this. In November 2025 the Commission proposed the Digital Omnibus, a package of simplifications that would delay the binding application of Article 6 and the broader high-risk regime by up to sixteen months.
The published rationale is that member states are not ready: only eight of twenty-seven reported operational capacity for the 2 August 2026 deadline as of late 2025.[23] The rationale is true. It is also incomplete. The deeper reason is that the regulatory obligations cannot be performed on current architecture, because the architecture does not support the kind of inspection the obligations require.
The delay is the system acknowledging that the problem is not administrative.
- Sovereignty at the Stack ===========================
The five-position sovereignty framework, established earlier in this series, is the starting point for what follows.[24] The framework applies vertically as well as horizontally. A stack composed of multiple layers carries a position at each layer, and the effective position of the whole stack is determined by the least sovereign component.
If any single layer sits at Position 4, the entire stack is contaminated.
Mistral AI is the instructive case in 2026. In September 2025 the company raised €1.7 billion in Series C funding, led by a €1.3 billion investment from ASML. By January 2026 its valuation had reached €14 billion.[25] Eighteen thousand NVIDIA Grace Blackwell supercomputers are deployed in Essonne and at a German site, operated by European teams under European law.[26]
In January 2026 Mistral signed a framework agreement with the French Ministry of Defence.[27] In February 2026 it acquired the French cloud platform Koyeb, signalling vertical integration.[28] At NVIDIA’s GTC conference in March 2026 it announced Mistral Forge, a product enabling enterprise customers to train custom models on proprietary data using Mistral’s infrastructure.[29]
Mistral Large 3, released under Apache 2.0, is a 675-billion-parameter mixture-of-experts model with 41 billion active parameters per forward pass.[30] HSBC signed a multi-year production contract to run enterprise workloads on it in early 2026.[31]
At the visible layers of the stack, Mistral is European. European ownership. European operation. European law. European procurement. European industrial integration.
At the foundations, it is not. Every one of the eighteen thousand Grace Blackwell processors in Essonne was approved by the US Department of Commerce before leaving American territory. The chip architecture is American. The export licence is American.
The software ecosystem on which the model trains and serves is American-controlled at each significant layer: CUDA, cuDNN, NVIDIA firmware, PyTorch, and the LLVM compiler toolchain.[32] In May 2025 the Trump administration rescinded the Biden-era AI Diffusion Rule that had created a stable framework for European access to advanced AI chips and replaced it with case-by-case Commerce Department review.[33]
In December 2025 NVIDIA added location-verification telemetry to the Blackwell firmware. The feature was described as anti-smuggling. NVIDIA stated that it was not a kill switch, which is the kind of statement one makes when the underlying capability is real enough to warrant denial.[34]
Mistral’s sovereignty at the visible layers is real, as is its exposure at the foundations. A policy change in Washington on export licences, a firmware update on the fleet, an IEEPA invocation on AI-specific compute, or a CFIUS-style review of an inbound European transaction would each reach through the visible European layers to the foundations on which they rest.
The asset is Position 2 at the weights, operations, and procurement layers, and Position 4 at the silicon, software ecosystem, and firmware layers. The stack composes to the weaker position.
Mistral is the strongest European AI company, and the one most actively moving toward stack ownership. The paper’s point is that even Mistral is not sovereign at the foundations, and that no European AI company currently is. Sovereignty is a property that holds or does not hold at each layer.
Where a foreign state retains legal authority over any layer, sovereignty does not hold at the stack. None of the mitigations currently on offer cures this. Residency leaves the jurisdictional authority of the parent undisturbed. Contractual assurance cannot override statutory compulsion. Certification against European frameworks describes compliance rather than control.
Only ownership of the asset at each layer produces sovereignty at the stack.
- Memorisation, Incorporation, Irreversibility ===============================================
What makes AI different from prior sovereignty questions over cloud and data storage is the mechanism by which data is absorbed into the asset.
European data protection law as developed from Convention 108 in 1981 through the GDPR, Schrems I, Schrems II, and the Digital Services Act has taken as its starting assumption that data is a thing. Data is created, collected, transferred, stored, retrieved, corrected, and erased. The law’s operations on data presuppose that data remains data through those operations.
A data transfer is a transfer of a thing that is the same thing at the destination. A request for access reaches a record that still exists in legible form. A request for erasure can be satisfied by destroying a discrete object.
AI training does not preserve data as a thing. Training absorbs data into weights in a form from which the original records are not cleanly recoverable. The EDPB’s Opinion 28/2024 treats the resulting model, if vulnerable to inversion or membership inference, as very likely to constitute personal data in the legal sense.[35]
The legal complement of the technical fact is incorporation: European data that enters a US-jurisdiction AI system at training is incorporated into an asset held by a US-domiciled entity, and from that moment the data has undergone a jurisdictional transfer the ordinary operations of data protection law cannot reverse.
A GDPR Article 17 erasure request cannot operate on memorised training data without destroying the model the data has been incorporated into and retraining from scratch. No US-jurisdiction provider will do this on a European citizen’s request. No European regulator has the reach to compel it.
Schrems-era adequacy decisions were designed for transfers of data that remains data; a trained model is not data in that sense. The border has been crossed at training. The crossing is not reversible through any mechanism European law currently recognises.
Inference compounds the problem. Every query sent from a European deployer to a US-hosted frontier model is a data transfer. The prompt is sent to the provider, processed under US law, and in most commercial offerings logged for a defined period.
Fine-tuning on sensitive data is a training transfer of a different character: customer data is used to produce a modified version of the model, and the modification is held by the provider.
Zero-retention inference offerings reduce but do not eliminate the surface; contractual commitments to non-retention cannot override statutory compulsion, and the commitments are not architecturally enforced at most providers.
Confidential computing and trusted execution environments reduce the attack surface to a level where the provider cannot read plaintext even in memory, but the attestation chains root in hardware-vendor signing keys that are themselves American.[36]
Every meaningful interaction between European data and US-jurisdiction AI is, by default, a transfer of one kind or another. Training absorbs the data into the weights held by the provider. Fine-tuning produces a modified version of the model held by the provider. Inference sends the prompt across the jurisdictional boundary into the provider’s infrastructure.
Each reaches an asset held under US jurisdiction and compellable through US statute. The weights, once trained, cannot be disincorporated. The queries, once logged, cannot be un-queried.
The category of transfer regulation European law has built does not reach the category of absorption, because absorption is not a transfer event the category was designed to operate on. Europe has written transparency, access, erasure, and consent law for an infrastructure that does not preserve data in the form those operations assume.
The practical conclusion follows. The only mitigation that changes the jurisdictional status of the asset is ownership of the asset.
Residency, contractual non-retention, and certification each address questions adjacent to sovereignty without touching the jurisdictional one: they address where data sits, what the provider promises, and what auditors verify, none of which changes whose legal authority reaches the asset. Confidential computing narrows exposure at inference without changing whose asset the model is.
European ownership of the weights, European operation of the serving infrastructure, and European legal authority over the training pipeline produce an asset over which European law can exercise the operations it claims. Every other arrangement converts the regulation’s question into a request made to a foreign jurisdiction, subject to that jurisdiction’s willingness to answer.
- The Bait ===========
The argument that Europe should refuse American AI today is a position Europe cannot enforce.
American frontier AI in April 2026 is meaningfully better than anything European companies produce at the reasoning, coding, and research frontier. The gap is wide enough that European institutions would pay a real productivity price to abstain.
The strongest available European open-weight model, Mistral Large 3, is competitive for most enterprise workloads; Kimi K2.5 and the newer Qwen generations close more of the gap each quarter; Llama 4 as an open-weight base is sovereignty-adjacent and increasingly capable.[37]
These cover the large majority of enterprise AI work: document processing, classification, retrieval, summarisation, routine generation, and structured extraction, at quality indistinguishable from frontier cloud APIs for most business applications.
An analysis published in March 2026 placed the figure at roughly eighty per cent of enterprise use cases adequately served by current open-weight models, with the remaining twenty per cent requiring frontier capability at the reasoning and complex-problem-solving tiers.[38]
The twenty per cent matters. It contains the work in which AI is most transformative: the deep research, the multi-step reasoning, the coding agents that compress weeks of engineering into hours. A policy that concedes the twenty per cent concedes a meaningful share of the productivity uplift to foreign providers and a meaningful share of European institutional knowledge to foreign assets.
Over a decade the compounded cost is substantial. Finance ministers do not fund sovereignty rhetoric. They fund capability.
The right question is whether Europe can have frontier capability under European ownership, and what Europe should do if sellers will sell only under their continued ownership.
The answer runs on four tracks. Scope the sovereignty requirement to the sectors where existing regulation already requires the highest protection. Redirect the eighty per cent of in-scope spending to European-owned providers through procurement mandates.
Commission the twenty per cent of frontier capability through a European Sovereign AI Investment Company that owns the weights produced. Underwrite European silicon investment against capability-triggered statutory demand, drafted now and folded into the Cloud and AI Development Act currently before the Commission.[39]
And, as the spine of the policy, accept that if sellers refuse to sell sovereign, Europe does not buy non-sovereign. A refusal to transfer ownership is a demonstration of intent to retain control. Paying for capability that the seller reserves the right to turn off, recondition, or report on to their own government is paying for conditional access.
Europe has paid for conditional access before, in cloud and payments rails; the cumulative cost is being measured now, in this series, and the measurement is what has produced the policy frame Europe is legislating into. Repeating the mistake in AI, where incorporation is greater and reversal is less available, would be the most expensive version yet.
If the capability matters enough to justify buying it on any terms, it matters enough to require buying it on terms where the seller cannot revoke, recondition, or surveil the arrangement.
- The Scope of the Requirement ===============================
The sovereignty condition should not apply to all AI use by all European actors. It should apply where European law already requires the highest data protection, where the state is the buyer or the regulator or both, and where the harm from incorporation is concrete and measurable.
The in-scope sectors are those that European law already treats as specially protected. Public administration: government AI processing citizen data, judicial systems, welfare, education records, public employment, and the AI Act’s Annex III high-risk categories.[40] Financial services: the DORA scope of banks, insurers, and market infrastructure under the Digital Operational Resilience Act.[41]
Health: GDPR Article 9 special category data and the territory of clinical records and medical AI (Paper 22).[42] Critical infrastructure: NIS2 essential entities such as energy grid operators, water utilities, transport control systems, and telecoms.[43]
Semi-critical: NIS2 important entities, plus the AI Act’s high-risk use cases including large-scale employment decisions, law enforcement applications, and electoral systems. Defence and national security.
Out of scope: consumer AI for personal use, business use outside regulated sectors, creative and entertainment applications, general productivity tools not processing regulated data, and most academic research, with carve-outs for research conducted on regulated data categories.
This scoping does two useful things. It removes the strawman that sovereignty requires banning American consumer AI for European individuals. It does not. And it aligns the enforcement vehicle with regulatory instruments Europe already has. The AI Act, DORA, NIS2, and GDPR Article 9 already define the boundary.
The sovereignty condition extends those instruments from a storage-based framing to an incorporation-based framing. Where European law says a data category merits the highest protection, the AI systems processing that category must be owned by sovereign entities operating under European jurisdiction.
The Digital Omnibus, currently in trilogue, is the legislative moment to make the change. The delay currently proposed for Article 6 and the high-risk regime should be conditioned on the adoption of the sovereignty condition at the architectural level. Member states unwilling to accept the condition face the original August 2026 deadline on an architecture that cannot support compliance.
Member states accepting it receive the additional time to procure, commission, and transition to sovereign infrastructure. The Omnibus becomes the vehicle through which the category error in the Act’s compliance regime is corrected.
- The Eighty Per Cent: Blueprint Procurement =============================================
The eighty per cent of in-scope European AI spending that does not need frontier capability is the immediate and achievable sovereignty move. The gap here is a procurement gap.
Public sector, financial, health, and critical-infrastructure buyers continue to default to US cloud providers and US AI APIs for work European vendors could perform at equivalent quality, because the defaults are procedurally easier and because no procurement instrument mandates a different choice. European open-weight models cover this work today.
Mistral, Aleph Alpha’s regulated-sector offerings, Apertus, and the broader open-weight ecosystem meet the enterprise requirement.[44]
The procurement-mandate mechanism (Paper 26) is the standard policy instrument for this kind of gap.[45]
Member state procurement mandates, published now with binding effect on a staged timeline (thirty per cent of in-scope AI spending to European-owned providers by 2028, rising to seventy per cent by 2032), create the predictable demand against which European providers can raise capital, invest in capacity, and compete on quality. The procurement is purchase of capability at market price, conditional on sovereign ownership. European companies meeting the condition receive the contract. Companies not meeting it, or US subsidiaries operating under US parent jurisdiction, do not.
HSBC’s multi-year production contract with Mistral Large 3, signed in early 2026, demonstrates that frontier European open-weight capability can handle regulated-sector enterprise workloads without a productivity penalty.[46] The commercial proof exists.
What remains is to translate the single decision into a coordinated public-sector one, at a scale that matches the commercial opportunity European AI providers need to reach competitive depth.
- The Twenty Per Cent: A European Sovereign AI Investment Company ==================================================================
The harder problem is the twenty per cent of in-scope use cases that require capability European vendors do not yet match. Placing the order for capability that does not yet exist at European scale does not, on its own, produce the capability. Something has to commission it.
The proposal is a European Sovereign AI Investment Company: an open-architecture vehicle on the model of the European Space Agency in its governance, capitalised as an investment institution rather than a grant-funding body, open to participation by any European state that wishes to contribute capital and receive proportionate licensing returns.[47]
The vehicle commissions frontier training runs on contract from whichever supplier can deliver to specification, on terms such that the resulting weights are owned by the vehicle from inception, operated under European jurisdiction, and licensed to European users at a fee.
The funding structure is equity. Member states contribute as investors. Licensing revenue from European users repays the capital over a projected five-to-seven-year horizon. The precedents are KfW in Germany, Bpifrance in France, the European Investment Bank at EU level, and at the sovereign-wealth scale Norway’s Government Pension Fund Global.
The distinction from previous European technology policy is political as much as financial. A finance minister can defend an equity investment in a licensing vehicle more easily than a grant of equivalent scale, because the investment has a measurable return profile and the vehicle is disciplined by the need to produce returns.
The contracting mechanics must assume bad-faith behaviour on the supply side. Contracts specify capability rather than technology. The capability to be delivered is defined in terms of performance on independent benchmarks, latency, and multilingual coverage, so suppliers cannot substitute older or degraded models for the current frontier.
Payment is staged against capability milestones verified by a European technical authority before each tranche is released. At least two suppliers are commissioned per generation, so no single supplier becomes indispensable.
Operating knowledge, meaning the training recipe, the evaluation harness, and the drift detection tooling, is contracted and priced separately from the weights themselves, typically at forty per cent of total contract value, so suppliers cannot deliver inert weights and withhold the knowledge required to operate them.
Anti-solicit covenants on European staff hired to operate commissioned models prevent the pattern AMD’s 2024 acquisition of Silo AI established at a smaller scale.[48] Independent technical audit of delivered capability is published.
Failure criteria trigger exit: three consecutive rounds delivered more than a specified lag behind the then-current frontier, or two of three rounds blocked by US export review, and the vehicle shifts remaining capital to European commissioning only.
The commissioning is rolling. Frontier capability moves. A weights transfer dated 2026 is a 2027 liability. The vehicle commissions a new training run every twelve to eighteen months, sometimes in parallel across suppliers. Between major runs, smaller fine-tuning and distillation contracts keep the European weights current for specific regulated-sector domains.
The data the vehicle trains on is European. Common Crawl, The Pile, and the large public corpora used by every frontier training run are equally available to Europe as to American providers.
European multilingual data is a comparative advantage Europe has not yet used at training scale: the Data Union Strategy’s cultural-heritage digitisation, the European Data Spaces output in health and finance, and parliamentary corpora in twenty-four languages. The compute is European.
The fifteen AI factories and five gigafactories committed under InvestAI through 2027, plus the existing European HPC base at LUMI in Finland, Leonardo in Italy, and MareNostrum 5 in Spain, are sufficient to train frontier-class models for the commissioning horizon the vehicle needs.[49]
The US supplier, where a US supplier is the contractor, supplies the training recipe and the engineering expertise. The supplier’s staff work on-site or on audited access. The weights produced belong to the vehicle. The supplier walks out with the research know-how they brought in and without new weights to deploy at home.
Will US suppliers accept these terms? The empirical answer will arrive as Europe offers the contracts. The theoretical answer is that cooperation by a US supplier is consistent with both genuine structural compatibility and delayed, strategic, or tactical concession.
Europe cannot, in principle, obtain evidence that sovereign AI under US cooperation is stable; Europe can only obtain evidence that it is not, through refusal or through cooperation followed by degradation. The epistemic shape is familiar.
The permanent-archive argument earlier in this series took the same form: the hypothesis that harvested-now encrypted data will never be decrypted later is unfalsifiable in the direction that would justify relying on it.[50] The medical-inheritance argument took the same form: the hypothesis that infrastructure permitting secret access will not be accessed is unfalsifiable the same way.[51]
The institution Europe needs is not the institution that tests whether cooperation will hold. It is the institution that does not require cooperation to hold.
- The Silicon Question =======================
The silicon layer is the one at which Europe cannot, within the relevant timeframe, achieve sovereignty. The Chips Act’s €43 billion of co-investment is a ten-year programme. The optimistic trajectory for European advanced-node manufacturing at NVIDIA-competitive performance lands somewhere after 2030.[52]
The interim configuration of the European stack is, honestly, Position 4 at silicon regardless of what else Europe does.
The constructive response is layered.
First, the AI factories already committed under InvestAI and the existing European HPC base provide the compute foundation for the investment company’s commissioning programme through at least 2030. Silicon dependency is a constraint on the margin.
Second, parallel procurement of AMD MI350, Cerebras, Graphcore, Groq, and emerging European accelerator options should be mandated at a meaningful share of the European AI fleet, in the range of twenty to thirty per cent, creating optionality against any single supplier’s policy exposure.[53]
Third, and more consequentially: the silicon procurement regulation should be drafted now, ratified now, and triggered on technical capability thresholds.
The mechanism is as follows. The regulation specifies that once any European silicon option reaches defined technical thresholds on node density, training throughput, and yield at production volume, European public-sector AI procurement becomes legally required to source a rising share from compliant European silicon.
The European silicon option triggering the mandate can be produced by any European fab, or by any joint venture with sufficient European operational and ownership control. The share begins at thirty per cent in the first year of triggered application and rises to seventy per cent by year five. The thresholds are specified technically and verified by an independent European authority.
They are not ministerial discretion. The regulation triggers on any European option meeting the thresholds, not on a pre-named champion, which prevents subsidy capture.
The effect is to underwrite European silicon investment against statutory demand before the investment is made. A European consortium raising capital for an advanced-node fab in 2026 can tell investors: if we hit these specifications by 2030, the public-sector demand is legally required to purchase from us at a rising share over the following five years.
This is the mechanism by which NASA’s Commercial Resupply Services contract enabled SpaceX to raise capital against committed future demand in 2008.[54] The investor is not betting on the political durability of a grant. The investor is betting on the engineering, with the revenue pre-underwritten by statute.
Private investors can underwrite European silicon at realistic capital scale only when the demand side is structured to be statutory rather than discretionary.
The natural legislative vehicle is the Cloud and AI Development Act, the Commission proposal expected to advance in 2026.[55] Folding the capability-triggered mandate into CADA makes the measure immediate rather than theoretical. The paper recommends inclusion.
US political pressure against this regulation will be substantial.
NVIDIA specifically will argue that capability thresholds are discriminatory. US diplomatic pressure will frame the mandate as market-distorting.
The February 2026 Rubio cable directing US diplomats to oppose foreign data sovereignty measures is the template.[56] The lobbying intensity is itself evidence the mechanism bites. If capability-triggered demand did not change the investment calculus for European silicon, the American firms that benefit most from its absence would not spend diplomatic capital fighting it.
- The Shape of the Refusal ============================
The constructive response set out above amounts to five measures, each an extension of instruments Europe already uses in cloud, payments, semiconductor manufacturing, and monetary infrastructure. Scope the sovereignty requirement to the sectors where it already belongs. Redirect the eighty per cent of in-scope spending to European providers through procurement mandates.
Commission the twenty per cent of frontier capability through a European Sovereign AI Investment Company that owns the weights. Underwrite European silicon investment against capability-triggered statutory demand in CADA. Condition the Digital Omnibus delay on the adoption of the sovereignty condition at the architectural level.
None of these is radical in isolation. What is radical is the admission that the Act’s compliance regime cannot work on current architecture and that the architecture is therefore the object of the regulation.
The harder question is what Europe does if US sellers, pressed by their government under IEEPA, CFIUS-style review, or export controls, refuse to sell sovereign. The paper’s answer is that Europe does not buy non-sovereign. The refusal to transfer ownership is the seller’s demonstration of intent to retain control.
A purchase under retained control is an acceptance of Position 4 at the layer that decides.
The cost of this refusal is real and should not be minimised. If sovereign sales are blocked, European frontier capability lags the US frontier by some years. European businesses pay a productivity premium in the interim. European research institutions access the frontier through partnerships rather than operations.
European governments make decisions with tools meaningfully behind those used by US counterparts. These costs are neither trivial nor evenly distributed. The costs of the alternative are greater. Continuing incorporation of European regulated data into US-jurisdiction assets for the years it takes Europe to close the gap compounds in a way that capability lag does not.
Capability lag is recovered by later investment. Incorporation is not recovered.
There is a point that should be stated plainly. The policy the US administration has published is not a hostile document. It is an honest one. America’s AI Action Plan states what Washington believes it is building: American AI as the global standard, America’s allies running on American technology, the world continuing to run on American infrastructure.
This is what Europeans should want Americans to tell them, because the alternative is to infer it from scattered statutes, incidents, and private testimony. The July 2025 plan does the inference for us.
What remains is for Europe to respond to the plan as the plan has been written: as a framework in which Europe’s job is assigned, and in which the assignment is not consistent with European sovereignty. Europe is then free to accept the assignment, decline it, or propose a different one.
The proposal here is a different one.
Every argument for why Europe needs American frontier AI is an argument for why Europe must own its AI. A capability that depends on the seller’s continued cooperation is not a sovereign capability. The AI Europe rents is not the AI Europe has.
Sovereignty requires ownership, not residency, and the moment for building the institutions through which Europe will own its AI is this year, while the political window is open, while Section 702 is still being negotiated, and while the Digital Omnibus is in trilogue.
The digital identity question (Paper 21) is the same question asked of a different layer. The answer is the same. Ownership is the thing sovereignty is made of.
[1] Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence, 23 January 2025.
[2] America’s AI Action Plan, p. 2.
[3] Executive Order, Promoting the Export of the American AI Technology Stack, 23 July 2025, sections on the American AI Exports Program and interagency coordination.
[4] Marco Rubio, statement at launch of the AI Action Plan, 23 July 2025.
[5] Brookings Institution, America’s AI Action Plan: A Collective Analysis, October 2025.
[6] Reforming Intelligence and Securing America Act (RISAA), H.R. 7888, 20 April 2024; sunset provision for Section 702 at 20 April 2026.
[7] Short-term FISA extension passed 17 April 2026; new sunset 30 April 2026.
[8] FISA Court amicus curiae brief on the RISAA 2024 expanded ECSP definition; see Congressional Research Service, FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act, R48592.
[9] Paper 1, The Sovereignty Illusion, pages on the six trust assumptions; see particularly the Operation Dunhammer account of Danish intelligence cooperation with the NSA, surveillance of Eurofighter and Saab during the F-16 replacement bid, and the PRISM, ECHELON, Upstream, and BND-Bad Aibling disclosures.
[10] DR, Sveriges Television, NRK, NDR, Süddeutsche Zeitung and Le Monde consortium reporting on Operation Dunhammer, 30 May 2021; Danish Defence Intelligence Service internal investigation launched 2014; NSA selectors targeting Eurofighter GmbH and Saab during the F-16 replacement bid documented in the investigation.
[11] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, in force 1 August 2024.
[12] Articles 10, 11, and 13 of Regulation (EU) 2024/1689.
[13] N. Carlini, M. Nasr, E. Wallace et al., ‘Scalable extraction of training data from (production) language models’, 2023 and subsequent work. See also Royal Society, The privacy implications of large-scale language models, summary 2024: ’the process of turning training data into machine-learned systems is not one way’.
[14] European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 17 December 2024.
[15] Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI), consultation statement on AI and data protection, 2025: complete anonymisation of AI models ‘generally not reliably achievable’.
[16] Audition of Anton Carniaux, director of public and legal affairs at Microsoft France, before the French Senate’s Commission d’enquête sur la commande publique, 10 June 2025.
[17] Case C-362/14 (Schrems I), CJEU, 6 October 2015, invalidating Safe Harbour; Case C-311/18 (Schrems II), CJEU, 16 July 2020, invalidating Privacy Shield.
[18] President Trump removed three Democratic members of the Privacy and Civil Liberties Oversight Board on 27 January 2025, leaving the board without a quorum. See Paper 1 for full treatment; also CDT, ‘What the PCLOB firings mean for the EU-US Data Privacy Framework’, 2025.
[19] Clarifying Lawful Overseas Use of Data Act, 2018, 18 U.S.C. § 2713.
[20] Ontario Court of Justice order on OVHcloud Canada subsidiary, September 2025; data from servers in France, the UK, and Australia ordered disclosed to the Royal Canadian Mounted Police. See also Paper 17 of this series.
[21] Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, 30 October 2023, reporting requirements on dual-use foundation models invoking Defense Production Act Title VII authority.
[22] International Emergency Economic Powers Act, 50 U.S.C. §§ 1701-1708; used for advanced AI chip export controls under the Biden and Trump administrations.
[23] European Commission, Digital Omnibus proposal, November 2025.
[24] Paper 1 of this series, The Sovereignty Illusion, the five-position framework.
[25] Mistral AI Series C announcement, September 2025; valuation reported January 2026.
[26] NVIDIA Grace Blackwell deployments in Essonne (France) and Germany, 2025-2026.
[27] Mistral AI-French Ministry of Defence framework agreement, January 2026.
[28] Mistral AI acquisition of Koyeb, February 2026.
[29] Mistral Forge announcement, NVIDIA GTC, March 2026.
[30] Mistral Large 3 model card and release, Apache 2.0 licence, early 2026.
[31] HSBC-Mistral multi-year production contract, early 2026.
[32] The CUDA software ecosystem, cuDNN libraries, NVIDIA firmware, the PyTorch framework, and the LLVM compiler toolchain are all US-controlled by development, governance, or corporate domicile of the primary maintainers.
[33] Trump administration rescission of the Biden-era AI Diffusion Rule, May 2025.
[34] NVIDIA Blackwell location-verification telemetry feature, announced December 2025; NVIDIA statement that the feature is not a kill switch.
[35] European Data Protection Board, Opinion 28/2024.
[36] Attestation in confidential computing architectures, e.g. AMD SEV-SNP, NVIDIA Confidential Computing on Hopper and Blackwell, Intel TDX, roots in hardware-vendor signing keys controlled by US-domiciled entities.
[37] Open-weight model landscape, April 2026: Mistral Large 3 (Apache 2.0), Kimi K2.5 (1T MoE, 32B active, Apache 2.0), Qwen series, Llama 4.
[38] M. Hannecke analysis of enterprise open-weight model adoption, March 2026; estimate of roughly 80 per cent of enterprise use cases adequately served by current open-weight models.
[39] Cloud and AI Development Act (CADA), Commission proposal expected Q1 2026.
[40] Annex III of Regulation (EU) 2024/1689.
[41] Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA).
[42] Regulation (EU) 2016/679 (GDPR), Article 9, on processing of special categories of personal data. Paper 17 of this series, The Medical Inheritance, addresses health data specifically.
[43] Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2).
[44] Mistral, Aleph Alpha regulated-sector pivot, Apertus (Swiss open-weight project), and the broader European open-weight ecosystem, 2025-2026.
[45] Paper 26 of this series, The Blueprint, on the procurement-led mechanism for sovereign infrastructure.
[46] HSBC-Mistral multi-year production contract, early 2026.
[47] European Space Agency Convention and governance structure; the ESA participation model permits non-EU European states (Norway, Switzerland, the UK) to participate and is proposed here as the governance precedent for the investment vehicle.
[48] AMD acquisition of Silo AI, 10 July 2024, $665 million all-cash; Silo AI’s Nordic health-AI research partnerships transferring to US corporate jurisdiction on completion. See Paper 17, note 34.
[49] InvestAI initiative, 15 AI factories and 5 gigafactories committed through 2027; LUMI (EuroHPC, Finland), Leonardo (EuroHPC, Italy), MareNostrum 5 (EuroHPC, Spain).
[50] Paper 3 of this series, The Permanent Archive, on harvest-now-decrypt-later and the one-directional falsifiability of the cryptographic threat model.
[51] Paper 17 of this series, The Medical Inheritance: ‘a secret the infrastructure cannot keep is not a secret’.
[52] European Chips Act, Regulation (EU) 2023/1781, €43 billion of co-investment through public and private contributions.
[53] Non-NVIDIA AI accelerator options in 2026: AMD MI350, Cerebras CS-3, Graphcore Bow IPU, Groq LPU, SambaNova SN40L.
[54] NASA Commercial Resupply Services contract, December 2008, pre-committed purchase mechanism permitting SpaceX to raise capital against statutory demand.
[55] Cloud and AI Development Act proposal, European Commission, Q1 2026.
[56] Internal State Department cable signed by Secretary of State Marco Rubio, 18 February 2026, instructing US diplomats to counter foreign data localisation and sovereignty measures including GDPR. See Paper 1 of this series.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →