Europe’s sovereign AI buildout faces a control gap
European data center operators have rapidly built sovereign AI infrastructure through neocloud investment, new hyperscaler EU regions, and national compute programs, but operational control has lagged. Sovereignty addresses where infrastructure sits and who owns it; governability asks whether operators can trace a workload’s behavior, intervene in real time, and identify who is accountable for outcomes.
Regulatory pressure is converging around that control requirement. The EU AI Act’s high-risk provisions require tested ways to halt or redirect harmful behavior, and deployer obligations can apply to operators that control how workloads run. NIS2 and the Critical Entities Resilience Directive similarly emphasize rehearsed intervention, while the FTC’s July 2026 proposed policy statement on AI accuracy signals liability under Section 5 for companies deploying systems in production.
Cross-border cloud arrangements sharpen the risk. US operators handling EU workloads, and EU operators using US cloud providers, face tension between the US CLOUD Act and GDPR. Emerging European liability frameworks also shift scrutiny toward named individuals who understood system boundaries and can answer for AI behavior, making paper compliance insufficient without working controls.