Ultimately, Europe needs more AI companies of its own. It needs competitive models, but there’s much more than models and the more immediate sovereignty question is what happens underneath it.
Choosing a European model only gets an organisation so far. If the data, backups and compute that feed it still sit on infrastructure Europe does not control, sovereignty is partial at best. In some cases, a foreign model running on European-controlled infrastructure may offer more practical control than a European model running on foreign infrastructure.
Below the model layer
The US directive in June that forced Anthropic to suspend foreign-national access to Fable 5 and Mythos 5 was a warning shot for all countries in the world, particularly Europe. It clearly showed how quickly access to critical AI tools can change when geopolitics, regulation and commercial infrastructure collide.
But the risk does not stop at model access. AI systems are at their most valuable when connected to the records, documents, workflows, communications and operational data of the organisations using them. For governments, defence agencies, banks, healthcare providers and industrial companies, that context is often the most sensitive information they hold.
So sovereignty cannot only mean choosing a European model. It has to mean knowing where the data is stored, where it is backed up, where inference happens and which legal regime controls the infrastructure.
A European AI model running on non-European infrastructure is not fully sovereign. In some cases, a foreign model running on European-controlled infrastructure may offer more practical control than the reverse.
AI runs on context and that context is data
AI does not work in isolation. It becomes useful when it can draw on the information around an organisation such as emails, contracts, technical files, customer records, internal policies, incident reports, operational logs and sector-specific datasets.
That information is the context layer. It is also the part of the stack that organisations least want to lose control of.
This is why storage, backup and compute are key considerations, not simply background IT choices. They decide where the context lives, who can access it, which laws apply, and how much resilience an organisation has if access, pricing or policy changes.

AI is now critical infrastructure
AI has moved from experimental software into the infrastructure of decision-making. It now sits alongside defence planning, intelligence analysis, logistics, public services, healthcare systems, financial supervision and industrial operations.
As a result, infrastructure decisions are now national-security decisions.
For defence and security, the issue is especially important. AI will increasingly support how information is gathered, interpreted and acted on. It will help process satellite imagery, monitor cyber threats, organise logistics, summarise intelligence and support command workflows.
None of that can be treated casually if the underlying data pipelines, storage environments or compute capacity are outside Europe’s effective control.
This is the part of the sovereignty debate that gets less attention because it is less glamorous than models. Chips, storage, backups, data centres and cloud contracts do not generate the same headlines as a new foundation model. But without them, sovereign AI remains fragile.
Remembering Europe’s cloud lessons
Europe has already learned this lesson with the cloud, as we analysed before. Regulation matters and Europe has been willing to regulate aggressively, but it is not the same as capability.
GDPR, data residency requirements and procurement rules can shape behaviour but they do not create infrastructure capacity by themselves. If European organisations have no credible alternatives, they will keep relying on the same external platforms, even for increasingly sensitive workloads.
The answer is not for Europe to build everything alone. That is unrealistic and unnecessary. But Europe does need a clearer separation between commodity workloads and strategic workloads.
Not every dataset requires sovereign infrastructure. Not every AI experiment needs to run in a European cloud. But the default should change for sensitive public-sector, defence, healthcare, financial and industrial use cases.
Sovereignty does not mean building everything alone
Those workloads should be built around European storage, European backup, European compute and cloud environments governed by European law. That means being able to audit systems, move workloads, control access and maintain service even if geopolitical, commercial or regulatory conditions change.
AI workloads are sensitive and need protecting, and they need a European home before they need a European wrapper.
The model layer is, of course, important. Europe should support European AI companies and invest in models that reflect European languages, markets, regulations and values. But that is the top of the stack and much lies under the surface within the infrastructure layers.

Where is your AI data stored?
Rebuilding or planning an entire technology stack takes time, but the process should start with basic questions such as: Where is our AI-relevant data stored? Where is it backed up? Where does inference happen? Who controls the cloud environment?
These are not questions for IT procurement teams, they begin at the top when planning strategy and governance. But it also depends on the options and availability.
Europe’s AI industry cannot regulate its way into AI sovereignty, it must build, buy and prioritise the infrastructure that makes sovereignty real. That means treating data storage, backup and compute as strategic assets, not simply background utilities.
Europe will continue to debate the models to be built, but data centres, backup systems, procurement contracts and compute environments are what will ultimately define the full play. Because sovereignty starts with where the data lives.