Regulating Other People’s Technology: Europe, AI and Digital Sovereignty
LinkedIn article, 5 September 2026
Europe has become remarkably good at regulating technologies it did not develop and does not control. The EU AI Act is perhaps the clearest example. To understand its logic, think of a hammer. I imagine that, just as we feel about AI today, this is more or less how our ancestors must have felt when they invented the hammer: a multi-purpose tool they could carry with them anywhere and use for anything. A hammer can crack a nut, repair a house or become a weapon.
The same tool can also produce very different outcomes: one can neatly drive in a nail and stop, or continue hammering until whatever only needed fixing in the first place is destroyed.
The law can classify the risks presented by different hammers and impose corresponding obligations. But this leaves a deeper question untouched: who made the hammer, who controls it, and who can decide that Europeans may no longer use it?
1. Regulating the hammer: two opposed models
How does the European legislator approach AI? By regulating its different forms according to risk. In the example of the hammer, a spiked hammer clearly intended as a weapon is prohibited; a reinforced, stronger-than-ordinary hammer, visibly more powerful but still capable of many uses, is permitted only under conditions; a simple hammer, on the other hand, is permitted without further ado.
The advantage of this risk-based approach is obvious: it offers practical answers straight away. It tells us what we may do, and what we may not, with each of the hammers around us. This is, however, also its fundamental limitation. If a new type of hammer does not fit easily into the law’s categories, the categories—or the rules attached to them—must be revised.
What would be another, different approach? For the law not to regulate types of hammer, but their uses. What new actions and behaviours did the invention of the hammer make possible? If there are new ones, new rules may be needed; if not, the old ones will suffice.
The difference, however, is that human actions and behaviours cannot be regulated exhaustively through risk levels. No legislator can predict all of them and place them in categories in advance. This second approach therefore requires a different type of law: not risk-based, but principles-based. In other words, general rules of universal application.
Data protection law is the best-known European example of principles-based regulation. Because we are humans living in societies, we have always processed personal data. For most of human history, however, we had no specific body of law governing such processing. When computers made automated personal-data processing possible on a new scale, a new body of law emerged to regulate the new forms of human activity that computers had enabled. It did so on the basis of general principles, not by categorising different types of processing. In the GDPR, for example, the principles in Article 5 and the legal bases in Article 6 apply horizontally; only then do more specific distinctions come into play.
Conversely, risk-based AI regulation begins with specific AI systems and applications, without an equivalent set of general principles applying horizontally to every use of AI. Going back to the example of the hammer, we categorise the different types of hammer without first laying down general principles governing the use of all hammers.
In other words, the GDPR is built from principles outwards. The AI Act is built from categories of risk inwards.
The two models should not be confused. Risk also has a role in data-protection law, just as principles inevitably appear in AI regulation. But these are bridges between two systems, not their organising logic. They do not change their DNA. The GDPR remains principles-driven; the AI Act remains risk-driven.
There is no definitive answer as to which type of law is better. Risk-based laws may be more appropriate when regulating products; principles-based laws when regulating behaviour. Nevertheless, historically we have had no law of the hammer or the horse, no law of electricity, the computer or even the internet. This does not mean that these technologies are unregulated. It means that law has normally regulated the activities, sectors, uses and harms connected with them, rather than adopting a universal “Law of Electricity” or “Law of the Computer” merely because the technology exists. Frank Easterbrook’s famous “Law of the Horse” objection to a separate law of cyberspace made precisely this point.
AI law may therefore prove historically exceptional: a body of law organised around a general-purpose technology itself, rather than only around the actions and behaviours that technology makes possible.
2. The AI Act: regulation by risk
Having explained the two opposed regulatory models—the principles-based and the risk-based—and having already noted that the AI Act follows the latter, only a few words are needed here on the Act itself. Its provisions have, after all, been discussed at considerable length in the relevant literature. The AI Act, Regulation (EU) 2024/1689, was adopted comparatively quickly, only three years after the European Commission presented its proposal. For legislation of this scale, this was unusual and demonstrates broad political agreement among the Member States that AI had to be regulated, even if many details remained contested. There were objections and numerous changes, but the basic regulatory model was never ultimately called into question: a risk-based approach, distinguishing between categories of risk so that AI systems and uses falling within the Act’s scope can be classified accordingly. This approach was, after all, most consistent with existing European legislative techniques, once the Commission chose to regulate AI systems largely through the product-regulation logic of the New Legislative Framework.
The Act’s risk-based architecture is therefore clear: certain AI practices are prohibited altogether. High-risk systems are subject to extensive obligations. Particular systems and uses are subject mainly to transparency obligations. Systems presenting minimal or no risk are, for the most part, left alone. General-purpose AI models are governed through separate duties, with additional obligations where they present systemic risk.
The AI Act became generally applicable on 2 August 2026. However, the principal obligations for high-risk systems will apply later: on 2 December 2027 for the sensitive uses listed in Annex III and on 2 August 2028 for high-risk AI embedded in regulated products. The AI Omnibus, which entered into force on 27 July 2026, only days before the Act became generally applicable, extended these timelines and simplified parts of the framework.
The AI Act also introduces institutional and procedural innovations, notably the European Commission’s AI Office and regulatory sandboxes. Enforcement is shared rather than removed from the Member States: national authorities supervise most AI systems, while the AI Office has direct powers particularly in relation to general-purpose AI models and certain AI systems based on them. A detailed presentation of these features, however, would go far beyond the scope of this note.
3. Regulation is not control: digital colonialism
Outside Europe, the AI Act confirms a familiar, admittedly stylised, picture of a tripolar world: the United States holds military power, China economic power, while Europe sets the rules. The EU was the first jurisdiction to adopt a comprehensive horizontal AI law. South Korea’s AI Basic Act, in force since January 2026, also regulates high-impact and generative AI through transparency and safety obligations. The United States still has no equivalent horizontal federal statute, while China continues mainly through sectoral and application-specific instruments, with a stronger emphasis on state security, social stability and content control.
Europe therefore hopes that the AI Act will reproduce the “Brussels Effect” associated with the GDPR: access to the European market will encourage companies—and perhaps other legislators—to follow European rules. This may well happen. But regulatory influence is not the same thing as technological control.
At the level of everyday digital life, the technologies most Europeans encounter are, to a very large extent, other people’s technologies. The dominant general-purpose AI models and assistants are American or Chinese. Europe has serious AI companies, but none yet operates at comparable global scale. The same pattern of dependence appears in hyperscale cloud services, mobile operating systems, search, office suites, app stores, social networks and messaging.
Europe is not technologically empty. It retains strengths in telecommunications, industrial software, cybersecurity and specialised systems. But these do not amount to control of the mass-market ecosystems through which Europeans work, communicate, store information and access AI.
The European Commission now describes the problem in unusually direct terms. In June 2026 it stated that the EU remained structurally reliant on non-EU providers for more than 80 per cent of its digital products, services, infrastructure and intellectual property. The same Communication noted that EU providers’ share of the European cloud market had fallen from 29 per cent in 2017 to 15 per cent in 2022 and had since remained stagnant, while three non-EU hyperscalers controlled more than 70 per cent of that market.
Is this necessarily a bad thing? In theory, perhaps not: European law applies to products and services offered in Europe and protects individuals and users within its scope. Any non-European company wishing to offer products and services in the Union must comply with the applicable European rules. The scale and purchasing power of the EU internal market cannot easily be ignored. Europe may be a user of technologies developed elsewhere, but at least it is a powerful one—a “power user”.
Consequently, the products and services offered to European users can be brought into line with European law. The GDPR, the Digital Services Act, the Digital Markets Act and now the AI Act demonstrate the Union’s ability to impose conditions upon market access. The problem, however, runs deeper. It is political, not simply legal. Ultimately it concerns control and, in the final analysis, digital sovereignty—not mere use.
Control means deciding how a technology is designed, where its infrastructure is located, who receives first or preferential access, and whether it will continue to be available. These decisions are unlikely to be insulated from the power of the AI company’s home state—that is, the country in which it is headquartered. If that government demands special treatment, the company’s management may find it difficult to resist, even with the best intentions. Such treatment may concern preferential access to capabilities, surveillance obligations, export controls or restrictions on distribution.
At the purely legal level too, I believe that the two forms of power are different. A measure adopted by the home state can reach the company itself, its infrastructure and its strategic decisions. A European measure will more often determine whether, and under what conditions, the product or service may be offered in Europe. A European prohibition may therefore alter or remove the European version; a home-state restriction can determine whether the company may provide the technology at all.
Governments which finance and politically support such companies will also normally obtain earlier and better access to the resulting technologies. The digital divide is thereby perpetuated, and perhaps widened.
This is a form of digital colonialism. Europe retains legal power over its market, but strategic control over many technologies on which that market depends lies elsewhere. It can regulate the hammer offered for sale in Europe. It does not follow that Europe made it, controls its design, or can prevent somebody else from taking it away.
4. Can Europe become a developer again?
Digital sovereignty has been a European objective for several years, but the current geopolitical climate has turned it from an aspiration into a necessity. The Commission now places it within the broader objective of technological sovereignty: Europe’s ability to develop, control and scale the technologies, infrastructure, services, data and digital ecosystems on which its economy, security and society depend.
This does not have to mean technological autarky or isolation. It does mean having sufficient European capacity, choice and control so that interdependence does not become dependence, and dependence cannot easily be weaponised.
The stakes are not only economic. In my open-access book Archipelago, I argue that the state is an information platform, and the European Union the first archipelago of such platforms. From that perspective, digital sovereignty is not simply a matter of preferring European products. It concerns who builds and controls the informational infrastructures on which public power itself increasingly depends.
How, however, can Europe transform itself from a “power user” into a developer? The distance is enormous. Financing one European chatbot will not do it. Europe needs computing capacity, chips, energy, data, talent, scaling capital and complete ecosystems in which its technologies become ordinary choices rather than worthy but unused alternatives.
It also requires political capital. Europeans will have to reconsider habits that have become automatic: where files are stored, which office tools and messaging services are used, which clouds support public administration, and which AI assistants mediate access to information. A European alternative that is never chosen does not create sovereignty.
Is the effort hopeless? Not necessarily. The first step has been taken: the problem has been identified and the objective set. Only a few years ago, discussions about data localisation and digital sovereignty were dismissed as nearly reactionary. Today, technological sovereignty is official European policy. The 2026 European Technological Sovereignty Package brings together initiatives on chips, cloud and AI with an EU Open Source Strategy. Together with the growing network of AI Factories and the AI Gigafactories initiative, these measures show that Europe has at least begun to move from defensive resilience towards building capacity.
Declarations and funding programmes will not be enough. Europe will have to accept costs, failures and perhaps inconvenience. It will have to use procurement and public investment strategically, allow successful companies to scale, and resist treating regulation as a substitute for industrial and technological policy.
Still, Europe’s present position is neither natural nor ancient. Before the smartphone era, mobile telephony was to a remarkable extent a European affair. European companies and the GSM standard shaped global communications. Minitel in France and ISDN in Germany held their ground for as long as they could. Europe did not lose the ability to invent; it failed to control the integrated platforms that came afterwards.
The AI Act demonstrates something Europe can do exceptionally well: classify, regulate and enforce the conditions under which technologies enter its market. Digital sovereignty begins where this regulatory power ends. It asks whether Europe can also develop and control the systems on which it increasingly depends.
Despite the self-pity and navel-gazing that characterise Europe today, until only a few years ago optimism, and hopes for the technological—and indeed the digital—future, were (also) European.
_____________________________________
This is an adapted and updated English version of a contribution first published in Greek by diaNEOsis in July 2026. The original study reflected information available up to 30 June 2026; this version has been updated to 5 September 2026.