“Rules without switchability leave the regulated party in control of the switch — Europe's credible strategy is converting regulatory power into tested”
Europe's Five Cards — and the Two It Will Actually Play: A Deployability Audit

A deployability audit of Europe's five response levers to US tech coercion.
On this page
Forensic Summary: Three US actions in 2025–26 converted Europe's theoretical technology dependency into demonstrated, weaponisable leverage: the denial of frontier AI model access to foreign nationals, the cascade of US sanctions through ordinary digital infrastructure affecting an International Criminal Court judge, and visa bans on EU enforcement officials. Against this backdrop, analysts at the Centre for European Policy Studies (CEPS) and the Centre on Regulation in Europe (CERRE) identify five EU response levers — market regulation, procurement and portability, physical capacity, talent, and economic counter-leverage. This audit subjects each to a deployability test. The conclusion is that Brussels will operate at scale on only two: regulation and procurement-backed demand shaping. The other three are strategic investments, not crisis-ready substitutes. For legal and compliance officers, the operative framing is "continuity under coercion" — not autarky, and not passive dependency.
1. The Context
Europe's technology dependency on US platforms is not new. What changed in 2025–26 is that Washington demonstrated, in three distinct episodes, that dependency can be activated as leverage — and that the activation mechanism need not be a formal trade measure.
The Anthropic model denial. On 12 June 2026, Commerce Secretary Howard Lutnick's written letter required Anthropic to block all foreign nationals — including the company's own foreign-born employees working inside the United States — from accessing its two newest models, Fable 5 and Mythos 5. Anthropic cited a claimed jailbreak vulnerability as the stated justification; it disputes the severity and notes comparable capabilities exist in OpenAI's GPT-5.5. Anthropic took both models offline for all users to comply. Bloomberg's reporting confirms the directive was a written letter threatening civil and criminal penalties — converting frontier AI access into a nationality-based licence question. The legal basis and proportionality remain contested.
The International Criminal Court sanctions cascade. The Trump administration sanctioned ICC judges and prosecutors, including Slovenian national Beti Hohler, over the court's arrest warrants for Israeli Prime Minister Netanyahu. Judge Hohler reports cancelled credit cards and blocked Apple ID/iCloud, Amazon, Airbnb and PayPal accounts; a European bank closed her account and euro transactions within Europe were rejected. Max von Thun of the Open Markets Institute, writing in The Guardian, places this in the wider dependency architecture: app stores, Amazon, Visa/Mastercard and PayPal are ordinary European life until US sanctions make them unavailable. The chilling effect extends further — firms and banks over-comply to protect their own US exposure, severing nominally European transactions even when no EU law has been broken.
Visa bans on EU enforcement officials. On 23 December 2025, Washington imposed visa bans on five Europeans, including former Commissioner Thierry Breton — described by US officials as a Digital Services Act (DSA) "mastermind" — alongside anti-disinformation campaigners. This followed the Commission's first DSA non-compliance decision on 5 December 2025: a €120m fine on X for deceptive blue-check design, insufficient advertising-repository transparency and restricting researchers' data access. A US federal judge later paused the visa policy, but the coercive signal had already been sent.
The critical lesson is not that every US supplier is unreliable. It is that an EU customer's access can be contingent on a foreign government's changing political or security judgement. That is the condition compliance officers must now plan for.
This analysis extends prior coverage in this publication — specifically "Atlantic Fault Lines Deepen: US Tech Policies Threaten EU Digital Autonomy" (/analysis/atlantic-fault-lines-us-tech-policy-eu-autonomy) and "The Collision Course: Trump's Tariffs vs. EU Tech Enforcement" (/analysis/tariff-enforcement-collision) — by moving from diagnosis to a structured deployability test of Europe's actual response options.
2. The Mechanics (Silicon)
The dependency stack: where the choke points sit
The exposure is concentrated at several layers, each with different vulnerability profiles.
Cloud infrastructure. AWS, Microsoft Azure and Google Cloud hold approximately 70% of the European cloud infrastructure market. European providers together account for roughly 15%, with SAP and Deutsche Telekom each at approximately 2%, according to Synergy Research data from 2025. A European Parliament study finds roughly 80% of EU corporate cloud-and-software spend goes to US vendors. Asterès and Cigref estimate EU companies' annual purchases of US-benefiting cloud and software services at €264bn — approximately 1.5% of EU GDP. That figure is an exposure metric, not a loss estimate; boards conflating the two will either over- or under-react.
Jurisdictional exposure. EU-local data hosting does not by itself neutralise US Clarifying Lawful Overseas Use of Data Act (CLOUD Act) or Foreign Intelligence Surveillance Act (FISA) jurisdictional exposure. This is a widely misunderstood legal gap. A US-owned subsidiary operating a data centre in Frankfurt remains subject to US legal process. CERRE's Zach Meyers makes the essential distinction: risk-mitigation obligations are preferable to excluding foreign technology wholesale, but the jurisdictional exposure is real and must be addressed structurally, not merely contractually.
Semiconductor and compute. Europe possesses an exceptional upstream choke point — Dutch firm ASML Holding (ASML) is the sole producer of extreme ultraviolet (EUV) lithography equipment essential to the most advanced chips. But Europe holds only roughly 10% of world semiconductor manufacturing capacity and depends heavily on the US and Asia for sub-5nm and AI chips. The Commission's June 2026 Chips Act 2.0 proposal explicitly acknowledges dependency in advanced fabrication and design. CEPS cautions that AI gigafactories risk replicating dependence through Nvidia chips and the proprietary Compute Unified Device Architecture (CUDA) layer unless they are interoperable, multi-vendor and open-source capable.
The ASML leverage asymmetry. This is the most important mechanical point for compliance officers to understand. ASML's leverage is real but temporally mismatched to the coercion risk. Ceasing lithography tool sales harms counterparties years later, as fabs exhaust existing equipment. A cloud service cutoff harms Europe immediately. Europe's strongest upstream card cannot be played as a same-day circuit breaker.
AI model access. In 2024, US institutions produced 40 notable AI models, China 15 and Europe three, according to the Stanford University Human-Centered Artificial Intelligence Institute (Stanford HAI) 2025 AI Index. US private AI investment was $109.1bn. The scale gap is not closing quickly enough for European alternatives to substitute for frontier US models in the near term.
The five cards: what each lever actually is
CEPS's EuroStack framing supplies the systemic-dependency diagnosis. CERRE's restraint is equally important: sovereign provision should be confined to critical niches, foreign technology should remain available, and public support should target areas where Europe can credibly lead — not a sealed, end-to-end European stack. The five levers operate within those boundaries.
| Card | Mechanism | Deployability | |---|---|---| | 1. Market regulation | Condition market access; impose continuity and assurance obligations | High | | 2. Procurement and portability | Require exit capability; aggregate demand for alternatives | High (new contracts) / Medium (legacy) | | 3. Physical capacity | Build chips, compute, networks, energy | Medium (policy) / Low (crisis time) | | 4. Talent and capability | Retain researchers; convert science into commercial platforms | Medium, improving | | 5. Economic counter-leverage | Anti-Coercion Instrument; trade measures | Medium (legal) / Low (political/operational) |
3. The Constraints (Stone)
Card 1: Regulation — constrain behaviour, impose continuity obligations
What it can do. The EU has institutions, precedents and enforcement capacity. The DSA, Digital Markets Act (DMA), AI Act, cybersecurity and data rules, and the proposed Cloud and AI Development Act (CADA) — proposed 3 June 2026, not yet in force — together constitute a regulatory architecture that can condition market access and impose real costs. The X fine demonstrates that enforcement is operational. CADA's four assurance levels convert "sovereignty" into auditable, risk-based requirements: Level 1 requires EU data location; Level 2 requires independence from third-country interference and supply-chain transparency; Level 3 requires EU ownership and control plus further conditions; Level 4 requires full supply-chain control and absence of third-country interference. CADA also envisages a EuroCloud Federation and encourages open-source use and reuse across EU public procurement.
What it cannot do. Regulation cannot create GPUs, substitute a frontier model, or compel a foreign government to licence a service. It can intensify US-EU conflict and raise compliance costs for European operators as well as US platforms. CERRE's key warning: protectionist regulation can depress technology diffusion and competitiveness. The risk-mitigation approach is preferable to wholesale exclusion.
The critical gap. Regulation without switchability leaves the regulated party in control of the switch. If a US provider exits or is denied access, and no credible European alternative exists at scale, the regulation has imposed costs without creating resilience. This is the core EU strategic failure mode.
Current law status. DSA, DMA and AI Act transparency obligations (as of 2 August 2026) are current law. CADA is a Commission proposal as of 3 June 2026 — not yet operational. For detailed AI Act compliance obligations and the August 2026 deadline, see prior coverage at /analysis/eu-ai-act-compliance-chasm-august-2026.
Card 2: Procurement and portability — make exit technically possible
What it can do. Governments and critical-sector buyers can require data portability, escrowed configurations, multi-cloud capability, open standards, tested failover and EU-operated continuity for specified high-risk workloads. This is the most credible non-regulatory card because it spends money already under public control and builds a market without requiring immediate bans. CADA, when enacted, would require public bodies to undertake risk assessments, apply appropriate assurance levels, use EU-added-value criteria and participate in common procurement. It matches CERRE's recommendation: keep markets open while requiring fall-backs, and focus sovereign solutions on truly sensitive data and use cases.
What it cannot do. Procurement cannot conjure capacity. Switching a large population of customers at short notice is technically difficult, and European suppliers would lack the capacity and still rely on imported chips and server hardware. A procurement policy without migration funding, exit rehearsals and demand aggregation is a paper sovereignty label.
The critical gap. Contractual portability clauses are not the same as tested portability. An organisation that has never rehearsed a failover to an alternative provider does not have operational resilience — it has a document. The distinction matters enormously in a sudden-denial scenario.
Card 3: Physical capacity — chips, compute, networks, energy
What it can do. Chips Act 2.0 builds on more than €52bn mobilised under the original Act, with faster permitting, strategic projects and supply-chain platforms. The Commission's broader objective is to triple EU data-centre capacity within five to seven years. CADA seeks to accelerate sustainable data-centre capacity.
What it cannot do. Fabs and gigafactories take years to build. Their economics require cheap reliable power, scarce skilled labour, customer commitments and access to global component chains. CERRE estimates the proposed €55bn digital-leadership allocation is far short of the roughly €300bn often cited for a full European stack. The CEPS "Goldilocks" analysis of AI gigafactories is precise: without interoperability, multi-vendor sourcing and open-source orchestration, gigafactories replicate the CUDA dependency they are meant to solve.
Deployability verdict. Medium in policy; low in crisis time. This card's payoff is strategic and cumulative — a decade-scale investment, not a 2026 remedy.
Card 4: Talent and commercial capability
What it can do. Stanford HAI's 2026 AI Index reports that the flow of AI researchers and developers moving to the US has dropped 89% since 2017 and 80% in the last year alone, while Switzerland and Singapore lead researchers per capita. European recruitment is more plausible than at any point in the prior decade. Europe leads globally in scientific output, according to CEPS's mapping of technology specialisation.
What it cannot do. Talent does not automatically stay where a grant is awarded. Without rapid compute access, founder financing, stock-option competitiveness, a genuine Single Market and customers, Europe trains people for US or Chinese platforms. The conversion gap between research depth and commercial platform dominance is the structural problem. The board metric should be retention and scale-up output — founders, specialised engineers, patents commercialised, European-hosted workloads — not graduates alone.
Card 5: Economic counter-leverage — the Anti-Coercion Instrument
What it is. The Anti-Coercion Instrument (ACI), Regulation 2023/2675, has applied since 27 December 2023. It can address third-country pressure intended to change EU or member-state policy, using measures across goods, services, investment, public procurement, intellectual property and export controls. Its guidance treats even unwritten actions as potential third-country measures — directly relevant to the informal coercion pattern demonstrated in 2025–26.
What it cannot do. A Commission examination, Council determination and consultations mean the ACI is not a same-day circuit breaker. Its multi-stage process is structurally mismatched to sudden service denial. Use against the US could provoke countermeasures against the very cloud, software, chip and payment dependencies Europe is trying to reduce. The ACI requires proportionality and attention to adverse effects on EU operators.
Deployability verdict. Medium legally; low politically and operationally. The ACI's best role is deterrence, calibrated signalling and leverage preservation — not retaliation after critical services have already disappeared. Europe should visibly hold this card, not casually play it.
4. Scenario Analysis
Scenario A — Low friction (base case, 12–18 months)
Trigger. Routine US-EU divergence continues: DSA and DMA enforcement, higher cloud prices, export-licence uncertainty, but services remain available. The Anthropic episode is treated as an isolated incident rather than a policy template.
Exposure. The recurring economic exposure is the €264bn per year estimate of EU purchases benefiting US cloud and software suppliers. A separate Asterès/Cigref 2026 model estimates cloud and software price inflation could remove €107bn in annual value added and 1.4 million jobs by 2030 — a stress-test scenario dependent on survey-based price trajectory assumptions, not a central forecast.
Compliance posture. This is the window to act without crisis pressure. Regulation plus procurement: portability clauses, dual sourcing, workload inventories, tested exits. CADA's assurance-level framework, once enacted, provides the classification vocabulary. Organisations should begin workload classification now against CADA Levels 1–4, even though the regulation is not yet in force, because the underlying risk assessment is sound regardless of legislative timing.
Probability assessment. Most likely near-term outcome. The economic interdependence between the US and EU creates mutual incentive to avoid escalation. But the three 2025–26 episodes demonstrate that low-friction conditions can shift without warning.
Scenario B — Medium friction (base case, 18–24 months)
Trigger. Targeted denial of a frontier model, a sanctioned entity, or restricted service for specified critical users. The Anthropic and ICC cases are demonstrations of this class. A second export-control directive covering additional frontier models, or expanded sanctions affecting a European critical-infrastructure operator, would constitute medium-friction escalation.
Exposure. High operational disruption for affected entities. A 5% redirection scenario in Asterès/Cigref implies approximately 178,000 jobs and €12bn value added — a long-run industrial model, not an outage estimate. Economy-wide loss from a targeted denial cannot be credibly quantified from public evidence.
Compliance posture. Ring-fence critical workloads now. Pre-authorise alternatives. Establish EU-operated identity, payment and archival continuity for the narrow set of functions where forced service withdrawal is intolerable. Map every API dependency on US-origin frontier models and document the alternative workflow — even if that alternative is degraded capability rather than a direct substitute.
The over-compliance risk. As the ICC case demonstrates, organisations outside the US may pre-emptively sever ties with sanctioned entities or restricted services to protect their own US business relationships. Legal and compliance officers should establish clear internal guidance on when over-compliance is legally required versus commercially motivated — the two have different governance implications.
Scenario C — High friction (risk case, tail event)
Trigger. Broad licence restrictions, a US legal order or sanctions pressure that interrupts a hyperscaler, frontier model or payment layer across sectors. This would require a significant escalation in US-EU political relations — a trade war extending explicitly into digital infrastructure, or a security determination that European access to US cloud services constitutes a national security risk.
Exposure. No credible public model quantifies GDP loss from a European cloud cutoff. The appropriate conclusion is unquantified but potentially systemic, because cloud infrastructure underpins enterprise software and critical services. The €264bn annual spending figure is a scale indicator, not a business-interruption estimate.
Compliance posture. Crisis continuity planning: prioritise health, energy, defence, finance and public administration. Invoke the ACI only alongside allied diplomacy. Accept that Europe cannot hot-swap the full stack today. The organisations that will function in this scenario are those that have already rehearsed failover, not those that have contractual portability clauses they have never tested.
Probability assessment. Low in the near term, but no longer implausible. The three 2025–26 episodes were each individually dismissed as exceptional before they occurred. The appropriate board posture is to treat this scenario as a planning constraint, not a forecast.
5. Action Plan for Legal and Compliance Officers
The following six actions are sequenced by urgency and operational feasibility. They are grounded in the CEPS/CERRE analytical framework and the specific coercion mechanisms documented above.
Action 1: Map the kill switches — now, before a coercive event
Conduct a structured audit of every critical workflow's dependency on US-origin services. The audit should cover: supplier nationality and control structure; US-person dependencies in the supply chain; model APIs and their export-control status; identity and authentication services; payment processing; code repositories; cloud regions and data paths; and the export-control terms in every material vendor contract.
This is not a theoretical exercise. The Anthropic episode demonstrated that a written letter from a US government official can convert a production API into a nationality-based licence question within days. Organisations that have not mapped these dependencies cannot assess their exposure, let alone respond to it.
The CADA assurance-level framework — Level 1 through Level 4 — provides a useful classification vocabulary even though CADA is proposed legislation, not current law. Applying it now to your workload inventory creates a compliance-ready baseline when the regulation is enacted.
Action 2: Classify workloads by consequence, not ideology
Define the narrow set of workloads where forced service withdrawal is intolerable — public-order-critical functions, regulated financial services, health data, defence-adjacent operations. Apply CADA-equivalent Levels 3–4 continuity requirements to that set. Apply lighter-touch portability requirements to the remainder.
Avoid costly over-classification. Requiring full supply-chain control and absence of third-country interference for every internal workflow is neither economically viable nor analytically justified. The CERRE restraint applies here: sovereign provision should be confined to critical niches.
For organisations that have deployed agentic systems in regulated contexts — loan processing, credit decisioning, public-sector automation — the AI Act's high-risk classification obligations (current law as of 2 August 2026) and the CADA assurance-level framework operate in parallel. A high-risk AI system processing loan applications that runs on a US hyperscaler with no tested failover has both an AI Act compliance exposure and a continuity exposure. Map them together.
Action 3: Make exit executable, not merely contractual
Require machine-readable data export, infrastructure-as-code portability, escrow or continuity licences, tested restoration and annual failover exercises. Contractual portability clauses are necessary but not sufficient. An organisation that has never rehearsed a failover to an alternative provider does not have operational resilience.
The distinction between contractual and operational portability is the single most important practical point in this analysis. Prior coverage at /analysis/caidas-sovereignty-tiers-legal-architecture-or-hyperscaler examined how CADA's tiered framework interacts with hyperscaler qualification — the same logic applies here. A sovereignty label on a contract is not a sovereignty capability in an infrastructure.
Action 4: Understand the CLOUD Act and FISA exposure — and document it
EU-local data hosting does not neutralise US CLOUD Act or FISA jurisdictional exposure. This is current law, not a proposal. A US-owned subsidiary operating in Frankfurt remains subject to US legal process. Legal officers should document this exposure explicitly in their risk registers and in any data processing agreements that assert EU-jurisdiction data protection as a complete remedy.
The European Parliament study cited in the research is the primary reference. Where your organisation's legal analysis relies on EU data location as a complete jurisdictional shield, that analysis requires revision.
Action 5: Establish a pre-wired economic-security response
Create an ACI evidence file now. Document every instance of informal or formal US government pressure on technology suppliers that affects your organisation's access to services. The ACI's guidance treats unwritten actions as potential third-country measures — which means the Anthropic directive, even if contested as to its precise form, is potentially within scope.
Do not treat the ACI as a same-day remedy. Its multi-stage process — Commission examination, Council determination, consultations — means it operates on a timescale of months, not days. Its value is deterrence and leverage preservation. An organisation that has documented the evidence and briefed its government relations function is in a materially better position than one that has not.
Action 6: Engage procurement collectively
Individual organisations cannot aggregate sufficient demand to shift the market. The CADA EuroCloud Federation concept, and the broader CEPS/CERRE recommendation to focus sovereign solutions on critical niches, both point toward collective procurement as the mechanism for building viable European alternatives.
Legal and compliance officers should engage their sector associations and public procurement counterparts now — before a coercive event creates crisis-driven procurement decisions. The Asterès/Cigref model suggests that a 15% redirection of EU cloud and software spend to European production by 2035 could support approximately 463,000 jobs and €37bn of value added. That redirection requires coordinated demand, not individual switching decisions.
The Two Cards Europe Will Actually Play
Brussels will operate at scale on regulation and procurement-backed demand shaping. It has legal machinery, an addressable market and immediate administrative pathways for both. Physical self-sufficiency will continue to be announced rather than rapidly achieved. Talent and counter-coercion remain enabling or deterrent instruments, not crisis-ready substitutes.
The open-source dimension — covered in prior analysis at /analysis/open-source-sovereignty — is the connective tissue between regulation and procurement. CADA's encouragement of open-source use and reuse across EU public procurement is not incidental; it is the mechanism by which procurement creates durable alternatives rather than merely shifting vendor dependency.
The bottom line for compliance officers is precise: Europe's problem is not insufficient rules. It is that rules without switchability leave the regulated party in control of the switch. The credible European strategy is to convert regulatory power into procurement-backed technical exit, while patiently accumulating the physical capacity and talent that make the threat of exit real. Your organisation's compliance programme should reflect that strategy — not wait for it to be completed.
References
Primary sources and research
- CEPS, EuroStack: A European Alternative for Digital Sovereignty — https://www.ceps.eu/ceps-publications/eurostack-a-european-alternative-for-digital-sovereignty/
- CERRE, Zach Meyers, Can the EU Reconcile Digital Sovereignty and Economic Competitiveness? — https://cerre.eu/publications/can-the-eu-reconcile-digital-sovereignty-and-economic-competitiveness/
- Anthropic, statement on Fable/Mythos access restrictions — https://www.anthropic.com/news/fable-mythos-access
- Bloomberg, Lutnick's Letter to Anthropic Warned of Curbs on Top AI Models, 16 June 2026 — https://www.bloomberg.com/news/articles/2026-06-16/lutnick-s-letter-to-anthropic-warned-of-curbs-on-top-ai-models
- JusticeInfo, Living With US Sanctions Means Living in Constant Uncertainty (Beti Hohler) — https://www.justiceinfo.net/en/156847-living-with-us-sanctions-means-living-in-constant-uncertainty.html
- Open Markets Institute / The Guardian, Max von Thun, Europe Is Starting to Break Up With US Big Tech — https://www.openmarketsinstitute.org/publications/europe-is-starting-to-break-up-with-us-big-tech-but-its-still-abiding-by-the-silicon-valley-rulebook
- European Commission, Commission Fines X €120 Million Under the Digital Services Act, 5 December 2025 — https://digital-strategy.ec.europa.eu/en/news/commission-fines-x-eu120-million-under-digital-services-act
- Reuters, US Targets Former EU Commissioner and Activists With Visa Bans, 23 December 2025 — https://www.reuters.com/legal/government/us-targets-former-eu-commissioner-activists-with-visa-bans-over-alleged-2025-12-23/
- European Commission, Cloud and AI Development Act (CADA), proposed 3 June 2026 — https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act
- EUR-Lex, CADA full proposal text — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52026PC0502
- Synergy Research, European Cloud Providers Local Market Share Now Holds Steady at 15% — https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15
- European Parliament, EU Corporate Cloud and Software Dependency study — https://www.europarl.europa.eu/RegData/etudes/STUD/2025/778576/ECTI_STU%282025%29778576_EN.pdf
- European Commission, Chips Act 2.0, June 2026 — https://digital-strategy.ec.europa.eu/en/policies/chips-act-2
- CEPS, The EU's Gigafactory Strategy Needs a Goldilocks Approach — https://www.ceps.eu/the-eus-gigafactory-strategy-needs-a-goldilocks-approach/
- Asterès/Cigref, Technological Dependence on American Software and Cloud Services, 2025 — https://www.cigref.fr/wp/wp-content/uploads/2025/05/TECHNOLOGICAL-DEPENDENCE-ON-AMERICAN-SOFTWARE-AND-CLOUD-SERVICES-AN-ASSESSMENT-OF-THE-ECONOMIC-CONSEQUENCES.pdf
- Asterès/Cigref, Cloud/Software Price Rises in Europe, 2026 — https://www.cigref.fr/wp/wp-content/uploads/2026/05/Cigref-Asteres-Cloud-Software-Price-Rises-Europe-2026.pdf
- European Commission, Anti-Coercion Instrument, Regulation 2023/2675, in force 27 December 2023 — https://policy.trade.ec.europa.eu/enforcement-and-protection/protecting-against-coercion_en
- Stanford HAI, 2026 AI Index Report: Research and Development — https://hai.stanford.edu/ai-index/2026-ai-index-report/research-and-development
- Stanford HAI, 2025 AI Index Report — https://hai.stanford.edu/ai-index/2025-ai-index-report
- CEPS, Mapping Technology Specialisation, Complexity and Relatedness — https://www.ceps.eu/ceps-publications/mapping-of-technology-specialisation-complexity-and-relatedness-of-the-eu-and-selected-global-partners/
Related Silicon & Stone coverage
- "Atlantic Fault Lines Deepen: US Tech Policies Threaten EU Digital Autonomy" — /analysis/atlantic-fault-lines-us-tech-policy-eu-autonomy
- "Europe's Open Source Gambit: The Sovereignty Play Nobody's Talking About" — /analysis/open-source-sovereignty
- "The Collision Course: Trump's Tariffs vs. EU Tech Enforcement" — /analysis/tariff-enforcement-collision
- "CAIDA's Sovereignty Tiers: Legal Architecture or Hyperscaler Licence to Stay?" — /analysis/caidas-sovereignty-tiers-legal-architecture-or-hyperscaler
- "EU AI Act: What 2 August 2026 Actually Requires (and What Moves to 2027–28)" — /analysis/eu-ai-act-compliance-chasm-august-2026
- Supply Chain × Scenario Modelling
- Supply Chain × Long-Memory Filter
- Policy × Scenario Modelling
- Policy × Long-Memory Filter
- Talent × Scenario Modelling
- Talent × Long-Memory Filter
5 of 6 cells applied
What to do next
- 01Conduct a structured kill-switch audit mapping every critical workflow's dependency on US-origin services, covering supplier control structure, model API export-control status, identity, payment, and cloud data paths — before a coercive event forces the exercise under pressure.
- 02Classify workloads by consequence using the CADA Level 1–4 assurance framework now, even though CADA is proposed legislation, to build a compliance-ready baseline and avoid costly over-classification of non-critical systems.
- 03Distinguish contractual portability from operational portability: require machine-readable data export, infrastructure-as-code portability, and annual tested failover exercises — a clause that has never been rehearsed is not a resilience capability.
- 04Document CLOUD Act and FISA jurisdictional exposure explicitly in risk registers and data processing agreements; EU-local data hosting does not neutralise US legal process over US-owned subsidiaries, and any legal analysis asserting otherwise requires revision.
- 05Build an ACI evidence file now by recording every instance of informal or formal US government pressure on technology suppliers affecting your service access, and brief government relations counterparts — the instrument operates on months, not days, so its value is deterrence, not crisis response.
Relevant for:
Go deeper: AI Act Compliance Toolkit
The structured governance toolkit: catalogue systems, classify risk, collect vendor evidence, and plan against the phased AI Act timetable.
Get it — From £79Related Intelligence
Brussels Has Five Tools to Fight Washington's Tech Aggression — Only One Is a Rulebook
The EU's response to US tech coercion spans five instruments — regulation is the weakest. CAIDA's structural contradiction and the interim dependency window
CAIDA's Sovereignty Tiers: Legal Architecture or Hyperscaler Licence to Stay?
CAIDA's tiered cloud framework lets AWS, Azure, and Google qualify as sovereign providers.
The Collision Course: Trump's Tariffs vs. EU Tech Enforcement
30% tariffs. €35M fines. The Atlantic just got wider.