According to Gartner, European sovereign cloud IaaS spending is projected at 6.868 billion dollars in 2025, 12.587 billion in 2026, and 23.118 billion in 2027. The ECB estimates that international Visa and Mastercard systems process 65% of card payments in the eurozone; this figure cannot be generalized to 67% of all digital payments. European texts combine regulatory obligations and, in the case of the Chips Act, explicit instruments for developing technological and industrial capacities; their actual effectiveness remains a separate question.

The essentials

  • European sovereign cloud spending doubles in two years (6.9 to 12.6 billion USD), with a projection of 23.1 billion in 2027, according to Gartner and the Cloud Security Alliance (June 2026).
  • 67% of digital payments in the eurozone remain dependent on non-European providers, according to BNP Paribas 2026: regulation has not changed this structural dependence.
  • The Chips Act, NIS2, and data regulations define standards without creating the industrial players capable of meeting them.
  • Thierry Chopin and the Institut Montaigne emphasize that European sovereignty requires genuine productive integration, not mere normative coordination.
  • Reversing technological dependence through regulation alone remains insufficient without prior industrial capacity.

Europe Legislates Quickly, Produces Slowly

NIS2 came into force in October 2024. The Chips Act allocated 43 billion euros to European semiconductor production. The Data Act, the AI Act, the GAIA-X Cloud Rulebook: the European digital regulatory corpus is, in volume and sophistication, the most ambitious in the world. No other bloc regulates as much, as fast.

The problem lies precisely there. Regulating quickly is a competency Europe has proven it masters. Building digital infrastructures at scale follows a different logic—that of patient capital, industrial time, and risk tolerance. On these three dimensions, the gap between Europe and its competitors remains vast.

Gartner’s figures illustrate the investment dynamic, but they call for interpretive caution. Doubling sovereign cloud spending in a year reflects genuine awareness and significant mobilization of public and private funds. Amazon does not publish a figure allowing direct comparison of 12.6 billion dollars to three months of AWS infrastructure spending alone. Microsoft, AWS, and Google together invested over 150 billion dollars in digital infrastructure in 2024. Europe is not behind by one cycle: it is behind by a generation of investment.

67%: What Payments Reveal About Dependence

The digital payments figure deserves particular attention because it concerns a sector Europe believes it controls. The eurozone has an independent central bank, unified banking regulation, and a single euro payment area. Yet, according to data from BNP Paribas published in 2026, 67% of digital transactions in the eurozone transit through infrastructure whose providers are non-European, primarily Visa, Mastercard, and American mobile payment platforms.

This dependence is not new, but it has intensified as payments have become dematerialized. Every time a European consumer pays from their phone, an invisible fraction of the transaction transits through servers outside European jurisdiction, using non-auditable scoring algorithms and general terms subject to American or Irish law. Payment data regulation (DSP2, then DSP3 currently being transposed) imposes security and interoperability standards, but it has not created a European Visa.

The most serious attempt to solve this problem, the European Payments Initiative (EPI), launched in 2021 by a coalition of European banks, illustrates exactly the distance between regulatory intent and industrial reality. EPI launched Wero in 2024, a payment wallet operating in Germany, France, and Belgium. The solution exists, but its penetration remains marginal compared to now-habitual tools. Infrastructure follows; usage follows much less quickly.

Chopin’s Thesis Put to the Test

Thierry Chopin, associated researcher at the Institut Montaigne and specialist in European integration, has argued for several years that European sovereignty requires genuine integration, not mere normative coordination. This distinction is decisive. Normative coordination, producing common rules, is what Europe does best. Productive integration, creating shared industrial capacities, pooling risks and capital at continental scale, is what it systematically fails to do.

The cloud illustrates this gap with pedagogical precision. Europe has a regulatory framework defining what a sovereign cloud is (data localization, authorized personnel, resistance to extraterritorial laws like the American Cloud Act). It has national actors—OVHcloud in France, Deutsche Telekom in Germany, Aruba in Italy—capable of operating within this framework. But these actors remain fragmented by national markets and undercapitalized compared to American hyperscalers; consortiums, federations, and joint industrial projects exist, but their capacity to produce economies of scale comparable to those remains limited or undemonstrated.

The competing reading comes from a liberal market framework: Thomas Philippon, an economist whose work on market concentration and European competitiveness illuminates this issue differently. For Philippon, Europe’s problem is not the absence of regulation, but insufficient internal competition and fragmentation of capital markets. A competitive European cloud will not be born by decree: it will be born if market conditions—venture capital financing, accessible public markets, interoperability forced by competition—allow European players to grow rapidly. This reading does not invalidate Chopin: it completes it. Productive sovereignty requires both genuine integration and an internal market that allows competitive players to grow without being crushed by regulation itself.

Regulatory Stacking Can Become a Constraint

Certain compliance obligations may weigh relatively more on smaller players, but several European rules, notably on interoperability and provider switching, aim to limit lock-in for the benefit of challengers. Hyperscalers have the legal teams, compliance budgets, and financial breadth to absorb NIS2, GDPR, the AI Act, and their successive updates. A European cloud SME wanting to compete in the enterprise segment must devote a disproportionate share of its resources to compliance rather than engineering.

This mechanism has already been documented in other sectors. In finance, post-2008 regulation strengthened large banks at the expense of mid-sized players. In consumer digital, GDPR has, according to several analyses including those from the British Competition and Markets Authority, consolidated Google and Facebook’s position by making it harder for competitors without their pre-existing data masses to enter.

The concentration of digital power in the hands of a small number of players is not a market accident: it is partly the result of regulatory regimes that mechanically favor size. Europe should calibrate its cloud regulation explicitly accounting for this scale effect. GAIA-X’s Cloud Rulebook is an open and potentially useful framework, but its implementation complexity weighs more heavily on smaller players than on larger ones.

Scope and Limits of the 23 Billion Projected

Gartner’s 23.1 billion dollar projection for 2027 is a signal of acceleration. If confirmed, Europe will have tripled its sovereign cloud spending in two years. That is a serious pace. The effect of this increase will depend notably on infrastructure pooling and interface standardization between member states.

The challenge is organizational as much as financial. Cloud public markets in Europe are still largely conducted at national scale, sometimes at regional scale. A German ministry, a French hospital, a Belgian administration buy their cloud separately, according to partially different criteria, producing data in poorly interoperable environments. This fragmentation of public demand can limit the market size accessible to European players and their R&D investments.

Geopolitical fragmentation weighs on growth more than trade tensions: the same logic applies to the internal cloud market. Fragmentation costs not only efficiency; it costs industrial power.

Initiatives moving in the right direction exist. The European Space Programme uses pooled infrastructure. The GAIA-X initiative has produced standards, even if its implementation remains heterogeneous. The Important Project of Common European Interest (IPCEI) on cloud, adopted in 2021, co-financed infrastructure in several member states. These are real signals.

But between a common standard and an operational shared infrastructure, the distance remains considerable.

Structural Dependence Will Survive Regulation If the Market Does Not Consolidate

Europe’s current digital dependencies were built over twenty years of massive American investments, in a context where digital sovereignty was not a political priority. Reversing them in three or five years through regulation alone would be illusory. Reversing them in the medium term, with a combination of pooled public investment, coordinated public markets, and consolidation of European players, remains conceivable, provided these three levers are activated simultaneously.

The scenario at the 2030-2035 horizon depends on a central parameter: are member states willing to treat cloud as common infrastructure, like highways or power grids? Pooling public procurement and pursuing an explicit industrial policy could help European players achieve critical mass. If each state continues managing its digital infrastructure at national scale, dependence on non-European providers could persist.

A concrete signal to monitor in the coming years: the share of cloud public markets awarded to operators certified under the European cybersecurity scheme (EUCS), whose negotiations on sovereignty criteria were particularly disputed between member states. If this scheme integrates criteria for immunity to extraterritorial legislation without exemptions for European subsidiaries of American groups—a point that faced fierce resistance from the most Atlanticist member states—it will produce public demand oriented toward truly sovereign players. Otherwise, it will be one more label on unchanged dependence.

The other signal is financial. Financing research is not enough to create an advantage: the same logic applies to infrastructure. The amount, scale, interoperability, competition, resilience, and diversification of suppliers all matter; concentration can create economies of scale but also new dependencies. If projected spending disperses among many national providers, it risks fueling sovereign clouds of limited size, with no guarantee they can rival AWS. If it concentrates on a limited number of actors consolidated at continental scale, with standardized interoperability and interfaces, Europe could lay the foundations for common infrastructure.

The movement exists. It is not yet irreversible. Regulation has named the problem with precision; it now awaits industrial policy and budgetary coordination to give it substance.


Sources

  1. Cloud Security Alliance & Gartner, EU Tech Sovereignty: Cloud, AI & Enterprise Risk (June 2026), https://labs.cloudsecurityalliance.org/research/eu-tech-sovereignty-cloud-ai-enterprise-risk-v1-0-csa-styled/
  2. Thierry Chopin, Institut Montaigne, publications on European sovereignty and integration: https://www.institutmontaigne.org/
  3. BNP Paribas, data on digital payments in the eurozone (2026), unverified URL
  4. Thomas Philippon, The Great Reversal (2019) and analyses on competition and fragmentation of European markets, Princeton University Press
  5. Competition and Markets Authority (UK), Online platforms and digital advertising (2020), https://www.gov.uk/cma-cases/online-platforms-and-digital-advertising-market-study
  6. European Payments Initiative (EPI), https://www.epicompany.eu/
  7. IPCEI Cloud Regulation (European Commission, 2021), European Commission, DG COMP, unverified URL