Hard on the heels of my piece on the Fabric, I found myself thinking about discussions last week with clients on the impact of the EU’s regulatory focus on pinning down what is meant by Digital Sovereignty. If you had not noticed the regulatory world has been and remains somewhat infatuated with defining digital sovereignty just as technology is making the boundaries sovereignty depends upon increasingly difficult to define.
Leading the charge is the EU’s proposed Cloud and AI Development Act (CADA), a good example. Its emerging sovereignty model considers where infrastructure is located, who controls providers, exposure to third country influence and, at the highest level, control and transparency across the software and services supply chain.
All perfectly rational, if the future still looks like a collection of clouds, as I wrote about earlier, my view is The Fabric changes the problem.
As cloud, edge computing, AI agents, IoT, machine customers, APIs and autonomous infrastructure converge, a transaction may no longer have a meaningful single location. An AI agent operating in France might invoke a European model, call an American API, retrieve data from a sovereign datastore, authenticate through another provider, execute computation at the edge and negotiate with another machine and in milliseconds. So which component determines sovereignty?
- The server?
- The model?
- The data?
- The identity provider?
- The software/service supply chain?
- The controlling company?
- or the autonomous agent making the decision?
No I am not being pedantic here, this matters because Europe’s sovereignty ambitions increasingly span the whole technology stack, chips, infrastructure, software, cloud and AI, precisely because strategic dependency exists at multiple layers. The danger is that regulation responds by attempting to draw ever more elaborate borders around something whose fundamental architecture is becoming borderless, composable and dynamic. Oh, and don’t get me started on Mr. Musk’s datacentres in space …
The Fabric therefore requires a different conception of sovereignty, one that is not simply ‘Where does this workload run?’ . As I have written about before (The EU’s New Sovereignty Test – Control Without Isolation) it’s about ‘Who can control it, observe it, interrupt it, change it, compel it and independently verify those facts at any moment?’ That shifts sovereignty from geography towards continuous demonstrable control.
CADA may be an important step towards European digital autonomy. However if I am even marginally correct in that The Fabric is where computing is heading, sovereignty frameworks will eventually have to regulate chains of dependency and control, rather than boxes or big sheds labelled European Cloud.
My real concern is that at EU legislative speed, by the time Brussels has finally perfected the rules for regulating the cloud and AI, the technology industry will have quietly moved on and forgotten what the cloud was and Ai will be something none of us could imagine today. Europe will then congratulate itself on another world leading regulatory framework, for yesterday’s architecture, while its businesses inherit the mother of all compliance obstacle courses. Meanwhile, the US will be building The Fabric, China will be industrialising it and Europe risks doing what it increasingly does best, regulating the future, only to complicate it across 27 implementations, while importing it from somewhere else.
Posted on September 6, 2026
0