Sovereignty became a number
In October 2025 the European Commission turned digital sovereignty from a slogan into a scored, contractible procurement spec.
Before late 2025, a public buyer who preferred a European provider had only rhetoric to lean on. The Commission's Cloud Sovereignty Framework changed that: it scores providers on eight objectives via Sovereignty Effectiveness Assurance Levels, SEAL-0 (no sovereignty) to SEAL-4 (full EU supply chain, chips to software). A ~€180M sovereign-cloud procurement followed, awarded to a slate of European providers, Stackit, Scaleway, Proximus-S3NS with Mistral. Sovereignty is now something a tender can require and a provider can be graded on.
As the framework's own framing puts it, before it existed it was not even possible to measure digital sovereignty. Now it is, and that single fact reorders the public-sector AI market.
And the prize is gated by plumbing
The productivity opportunity is enormous, but it is locked behind cross-agency data integration that the EU has now made mandatory.
WEF and Capgemini estimate GovTech could unlock $9.8 trillion in public value by 2034. Yet the OECD finds most government AI stuck in pilots, a key cause being the lack of integrated data and impact measurement. The Interoperable Europe Act has made interoperability assessments mandatory since January 2025 and implements the once-only principle across borders, converting data integration from an IT project into a compliance program with a deadline.
So the winning pitch is not “more AI.” It is sovereign, integrated, measurable AI that survives an audit, exactly the layer the chart says matters and exactly the layer most public bodies have not yet built.
A Rindogatan-modelled sovereign-suitability index; the public sector tilts the most sovereign of any vertical, driven by citizen-data sensitivity and AI Act high-risk status. Not survey data.
The citizen core stays home
The systems governments most want to build sit on the data they hold in trust, which is why control, not compliance, is the deciding question.
A government holds identity, benefits, justice, and health data in trust for its citizens, and a citizen cannot opt out of their government. That makes the core systems, eligibility decisions, access to essential services, case management, ones whose judgement a state should not outsource to infrastructure it cannot control or audit. The point is accountability: a public body must be able to explain, in public, why an automated decision was made, and to guarantee the data behind it answers to no foreign jurisdiction.
Regulation reinforces this, these uses are treated as high-risk under the EU AI Act, with obligations phasing in, but the rules are in flux and they are not the reason it matters. The reason is sovereignty itself: control over the citizen relationship is the one thing a government cannot rent. That is trivial to guarantee on a sovereign, logged, governed system and impossible on an opaque external API. The figures here are modelled; the SEAL framework is the Commission's.
“The burden of proof has inverted. A public buyer no longer has to justify choosing European, the hyperscaler default now has to justify itself against a score the buyer is graded on.”
Write sovereignty into the tender
Four moves to turn the new sovereignty regime into an advantage rather than a scramble.
Translate SEAL and the AI Act's high-risk tests into a one-page requirement for every AI tender, so the sovereignty and conformity bar is explicit from procurement onward. Treat anything citizen-facing as sovereign-by-default.
Then fix the plumbing: stand up the integrated, EU-resident data foundation the Interoperable Europe Act now requires, build explainability and accountability in from day one, and govern placement centrally so no department quietly routes citizen data to a foreign API. The sovereign path is also the publicly defensible one.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.