The Agenda That Requires a Position
The European Digital Decade — the European Commission’s framework for achieving specific digital transformation targets by 2030 — has been part of EU policy vocabulary since 2021. In September 2026, it is no longer a policy aspiration. It is an active regulatory and investment framework that is shaping what European enterprises can do, where they can do it, and what they must do to remain compliant.
The regulatory components of the European Digital Decade agenda are now substantially complete in legislative terms. The AI Act is in force, with prohibited practices in effect since February 2025 and general purpose AI provisions applying from August 2025. The Data Act has been in force since September 2025. The European Health Data Space is being implemented across member states. DORA has been enforcing against financial services since January 2025. The Digital Markets Act is reshaping the platform landscape that enterprises use.
Alongside the regulation, the European digital infrastructure investment agenda is creating strategic opportunities and constraints. The Important Projects of Common European Interest in microelectronics, cloud infrastructure, and quantum computing are making European industrial policy more concrete than it has been in decades. The IPCEI Cloud and Edge initiative is building European cloud infrastructure alternatives to the hyperscalers, with implications for enterprise cloud strategy.
For European enterprise technology leaders, this agenda requires a position: not passive acknowledgement that regulation exists, but active strategic choices about how to position the enterprise in the regulatory and investment landscape the Digital Decade is building.
The Sovereign Cloud Question That Needs a Straight Answer
The sovereign cloud debate in European enterprises has been running for four years without producing a clear consensus. The debate started with data residency: can European enterprises use US hyperscalers for personal data governed by GDPR? The early answer from supervisory authorities was nuanced; the post-Schrems II answer was more restrictive; the EU-US Data Privacy Framework restored some clarity; and the sustained advocacy from European regulators and policymakers for European cloud alternatives has kept the debate alive despite the restored legal transfer mechanisms.
The honest position for most European enterprises in September 2026 is this: the legal and regulatory case for mandatory sovereign cloud adoption across all enterprise workloads is not made. The EU-US Data Privacy Framework provides a legal basis for transatlantic data transfers for most enterprise use cases. The hyperscaler EU regions, combined with the contractual protections that can be negotiated, provide a defensible compliance position for most GDPR use cases.
The cases where sovereign cloud is genuinely required are narrower: workloads subject to sector-specific data sovereignty requirements (defence, critical national infrastructure, sensitive public sector), personal health data in the emerging European Health Data Space framework, and workloads where an enterprise’s risk appetite or customer contractual obligations create sovereign cloud requirements beyond what regulation mandates.
The cases where sovereign cloud is a strategic preference are broader: enterprises that want to reduce hyperscaler dependency for commercial or geopolitical risk reasons, enterprises that want to demonstrate European sovereignty commitment to government customers or regulators, and enterprises that see competitive differentiation in European data sovereignty positioning.
Strategic preference is a legitimate basis for cloud decisions. The mistake is treating strategic preference as regulatory mandate. Enterprises that have adopted sovereign cloud at significant cost and performance trade-off on the premise that regulation requires it should review that premise against the current regulatory landscape.
The AI Act Reality Check
The EU AI Act is the most significant AI regulatory development globally, but its practical impact on most European enterprises in 2026 is more limited than the discussion volume suggests.
The prohibited practices provisions — which cover social scoring, real-time biometric identification in public spaces, and subliminal manipulation systems — affect very few enterprise AI deployments. Most enterprise AI does not operate in the prohibited categories.
The high-risk AI system provisions — which cover AI in employment decision-making, credit assessment, education, biometric categorisation, safety-critical applications, and certain public service applications — are more relevant to enterprise AI but are still narrower than broad enterprise AI adoption. An enterprise using AI for document summarisation, code generation, customer service routing, or data analysis is almost certainly not deploying high-risk AI under the Act’s definitions.
The general purpose AI provisions that apply to GPAI model providers affect the hyperscalers and AI vendors that enterprises use, not the enterprises themselves. Enterprises should understand what obligations their AI vendors are subject to and what evidence of compliance those vendors provide, but the compliance burden sits primarily with the provider, not the deployer.
What the AI Act does create for most enterprises is a governance obligation: the need to understand which AI systems they are deploying, whether any of those systems fall into restricted categories, and what documentation and conformity assessment obligations apply. The AI governance programme that most enterprises need is a classification and documentation programme, not a technical overhaul of their AI deployments.
The enterprises that are treating AI Act compliance as an existential challenge to their AI programmes are likely overstating the scope of the requirements. The enterprises that are ignoring the AI Act entirely are creating regulatory risk they should not. The middle ground is a proportionate governance programme that maps AI deployments to the Act’s risk categories and maintains the documentation the Act requires.
The Digital Infrastructure Investment Opportunity
The European digital infrastructure investment agenda, separate from regulation, creates a genuine strategic opportunity for European enterprises that the regulation-focused discussion often misses.
The IPCEI Cloud and Edge initiative is building European cloud infrastructure that, over the next three to four years, will provide meaningful alternatives to the hyperscalers for a wider range of enterprise workloads than European cloud alternatives currently support. The investment scale is substantial enough to produce infrastructure that can compete on capability, not just on sovereignty.
The European quantum computing programme is creating research and pre-commercial capabilities that will have practical enterprise applications within the Digital Decade timeframe. Enterprises in sectors with long planning horizons — financial services, healthcare, logistics — should be tracking the quantum roadmap.
The European semiconductor investment under the EU Chips Act is reducing European dependence on non-European chip manufacturing. The direct enterprise impact is limited, but the supply chain stability implications for enterprises with significant hardware infrastructure investment are material.
The strategic opportunity is positioning: the European enterprises that engage with the Digital Decade investment agenda as partners and early adopters, rather than passive recipients of regulation, are better positioned for the infrastructure landscape of 2028 and 2030 than those that do not.
The Field CTO’s Assessment
After five years of active engagement with the European digital regulatory landscape, my honest assessment is that the Digital Decade agenda is more coherent than its critics acknowledge and more complex than its advocates admit.
The regulatory framework is substantial, consequential, and in most cases well-designed for the problems it is trying to solve. The AI Act is more carefully scoped than early commentary suggested. The Data Act is addressing genuine market failures in data access and portability. DORA is producing operational resilience capability that European financial services needed. NIS2 is raising cybersecurity standards across critical sectors that were underinvested.
The implementation challenges are real. Regulatory complexity is cumulative across the regulation stack, and the enterprise that is subject to DORA, NIS2, the AI Act, GDPR, and the Data Act simultaneously faces compliance programme demands that require genuine prioritisation and resource allocation.
The sovereignty debate is real but sometimes disproportionate. European data sovereignty matters for specific high-sensitivity contexts. It does not require dismantling efficient cloud architectures for workloads where the regulatory and risk case for sovereign cloud is not made.
The strategic opportunity is underexploited. European enterprises that treat the Digital Decade agenda primarily as compliance burden are missing the commercial positioning and infrastructure investment dimensions that make the agenda an opportunity as well as a constraint.
Position the enterprise in relation to the Digital Decade deliberately, with clear-eyed assessment of what regulation actually requires and what strategic choices the investment agenda makes available. That clarity is what converts a complex regulatory landscape into a navigable one.
