Europe Bets on Cybersecurity and Cloud Power to Reclaim Digital Sovereignty

admin

Europe’s ambition to control its own digital future ran into a hard truth this week in Rome: sovereignty is not a slogan, it is a supply chain problem. From cloud servers to semiconductors, from 5G networks to artificial intelligence models, much of the infrastructure that keeps European businesses and governments running still depends on technology built outside the continent.

That gap took center stage at “Technology, Power, Rules: The New Game of European Sovereignty,” an event held at the Palazzo dell’Informazione in Rome and organized by Open Gate Italia in partnership with Adnkronos. Policymakers, regulators, telecom executives, and academics gathered to unpack a wave of new European Union legislation designed to close the gap, with cybersecurity sitting at the heart of nearly every proposal on the table.

The stakes go beyond Brussels bureaucracy. As digital infrastructure becomes inseparable from economic competitiveness and national security, the rules Europe writes now for networks, cloud services, and cybersecurity will shape who controls the continent’s data, who profits from its digital economy, and how resilient it is against future disruptions.

Why Europe Is Rethinking Digital Dependence Now

The discussion in Rome opened with a blunt diagnosis borrowed from the Draghi Report on European competitiveness, the influential 2024 assessment that mapped out where the EU has fallen behind global rivals. According to the findings referenced at the event, a substantial share of the cloud infrastructure, network equipment, semiconductors, critical components, and digital platforms used across Europe today comes from non-European providers.

That dependency is not new, but it has become harder to ignore. Supply chain shocks, geopolitical tension, and rising cybersecurity threats have pushed European institutions to treat digital autonomy as an economic and security priority rather than a purely technical concern.

The Legislative Package Driving the Debate

Participants pointed to a cluster of interlocking EU initiatives now moving through the legislative pipeline, each targeting a different layer of the technology stack:

EU Initiative Primary Focus Relevance to Cybersecurity
Digital Networks Act Telecom infrastructure and spectrum management Strengthens network resilience and investment conditions
Cloud and AI Development Act Cloud computing and artificial intelligence capacity Reduces reliance on non-EU cloud and AI providers
Cybersecurity Act 2 Revision of existing cybersecurity rules Reshapes supply chain security requirements for operators
Chips Act 2.0 Semiconductor supply chain resilience Protects hardware layer underpinning digital infrastructure

Officials at the event stressed that none of these measures work in isolation. Together, they are meant to reduce Europe’s external vulnerabilities, harden critical infrastructure, and build a more competitive homegrown technology base, all without retreating into protectionism that could scare off investment.

Competitiveness, Not Just Restriction, Is the New Priority

A recurring theme in Rome was that Brussels appears to be shifting its regulatory posture. Rather than layering on new restrictions, the European Commission is reportedly prioritizing simpler rules aimed at attracting investment alongside stronger protections.

Francesco Torselli, Member of the European Parliament for Fratelli d’Italia, welcomed that shift, noting that the Commission has made competitiveness a central objective in its digital, communications, and artificial intelligence policies by pursuing a simplified market with fewer and clearer rules, calling it a positive development for the sector.

Industry Warns Against Regulatory Overlap

Not every voice at the event was purely optimistic about how smoothly the new rules will land. Laura Rovizzi, Chief Executive Officer of Open Gate Italia, acknowledged that operators across the cloud, data center, and telecommunications sectors will need to navigate a regulatory system that must avoid internal contradictions, and said some elements of the current framework will likely need adjustment even as she praised the Commission’s broader push to adapt European industrial policy to a difficult geopolitical moment.

That tension between ambition and implementation ran through much of the discussion. Speakers repeatedly returned to the risk that overlapping mandates from different pieces of legislation could create confusion for the very companies the rules are meant to strengthen.

Telecom Operators Push for Clarity on Cybersecurity Supply Chain Rules

The debate placed particular weight on how new cybersecurity obligations will be applied to telecommunications networks, which speakers described as critical infrastructure for both economic and national security.

Vincenzo Ferraiuolo, Head of EU Affairs at Fastweb+Vodafone, argued that stable and predictable rules are essential for networks to remain investable. He said the Digital Networks Act’s approach to spectrum management moves in the right direction, but that the Cybersecurity Act 2 needs substantial revisions to its supply chain provisions to strike the right balance between Commission authority and member state control, paired with an approach proportionate to actual risk. He added that only a framework friendly to investment can genuinely reinforce Europe’s security, resilience, and strategic autonomy.

Balancing Brussels and National Governments

A further point of debate centered on the division of responsibility between EU institutions and national governments, especially regarding network security and supply chain oversight. Stefania Ducci, Head of the EU Cybersecurity Strategy and Policy Division at Italy’s National Cybersecurity Agency, and Massimiliano Fara, a cyber, digital, and telecommunications expert at Italy’s Permanent Representation to the EU, were among the officials weighing in on how that balance should be struck as the Cybersecurity Act 2 moves toward finalization.

Getting this balance wrong, participants warned, risks either fragmenting enforcement across 27 member states or centralizing decisions in ways that ignore national security considerations that vary by country.

What Comes Next for European Tech Policy

Connecting Regulation to Industrial Strategy

Beyond the legal text, speakers argued that regulation alone will not deliver digital sovereignty. High-performance networks, cloud infrastructure, computing capacity, artificial intelligence, semiconductors, and cybersecurity protections were described as interdependent parts of a single ecosystem. That means new rules need to be paired with policies that mobilize investment, fund research, strengthen supply chains, and help European technology companies scale globally.

Giulia Pastorella, a member of the Italian Chamber of Deputies for Azione, and academics including Antonio Manganelli of the University of Siena and the Centre on Regulation in Europe, along with Edoardo Carlo Raffiotta of the University of Milano-Bicocca and Italy’s AI strategy committee, contributed perspectives from both the political and research sides of the debate, underscoring how broad the coalition working on these issues has become.

Government Involvement Signals Long-Term Commitment

Giorgio Maria Tosi Beleffi, a senior telecommunications, audiovisual, and technological innovation official at Italy’s Ministry of Enterprises and Made in Italy, represented the government’s direct stake in the outcome, reflecting how closely national industrial policy is now tied to EU-level digital and cybersecurity legislation.

A Test of Whether Sovereignty Can Be Built, Not Just Legislated

The event closed without a definitive verdict on how the various pieces of legislation will ultimately fit together, but with broad agreement that continued dialogue between regulators, industry, and academia will be necessary. The real test, according to participants, will be translating the concept of technological sovereignty into measures that are concrete and sustainable while still preserving competitiveness, legal certainty, and room for innovation.

For now, the debate in Rome offered a snapshot of a broader European reckoning: building durable cybersecurity and technological independence will take more than new laws. It will require sustained investment, coordinated policy across the EU and its member states, and a regulatory environment stable enough to convince companies to build in Europe rather than simply comply with its rules from abroad