TL;DR: In July 2026, European digital sovereignty quietly crossed a threshold: it became measurable. On July 16, the European Commission published implementation guidance for its Cloud Sovereignty Framework — the same eight-objective scoring model it used to award its €180 million sovereign cloud tender — giving any organization a concrete benchmark for assessing its providers. On August 2, enforcement of the AI Act's general-purpose AI provisions begins, and the Commission's new Cybersecurity and AI Action Plan makes clear that which model processes which data, and where is about to become an auditable question. The era of sovereignty-as-slogan is ending; the era of sovereignty-as-scorecard has started. But run the scorecard against a typical European stack and you'll find one layer that never gets a line item: the one that connects everything else. That's not an oversight you can afford anymore.
We've argued throughout this series that European digital sovereignty is, at bottom, an integration problem — that a sovereignty chain is only as strong as its weakest link, and that the weakest link is usually the layer nobody thinks to classify. When the Commission published its Technological Sovereignty Package in June, that argument became legislative direction. This month, it became arithmetic.
From framework to yardstick
The Cloud Sovereignty Framework itself isn't new — the Commission introduced it in October 2025 and used it to run the EU's first-ever cloud procurement with explicit sovereignty criteria, the €180 million tender awarded in April to four European provider groups: Post Telecom (with CleverCloud and OVHcloud), STACKIT, Scaleway, and Proximus.
What changed on July 16 is that the Commission, responding to questions about how it actually applied the framework, released a public explainer and implementation guidance. The framework scores providers across eight objectives — strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability — and the guidance shows how those objectives translate into an evaluation. The Commission's stated intent is to move sovereignty assessment away from abstract principles toward concrete, standardized metrics.
Read that carefully, because it changes who this document is for. A scoring methodology used once, internally, for one tender is procurement trivia. A published methodology with implementation guidance is a yardstick — one that any European organization, public or private, can now hold up against its own stack. And one that procurement teams, auditors, and boards will start holding up whether you invite them to or not.
There's a detail in the tender worth pausing on. The Commission set the minimum eligibility bar at the second of its assurance levels — a deliberate signal that non-European technology, wrapped in strict local operational controls, can meet a baseline. European cloud vendors criticized the choice; they wanted foreign-exposed stacks excluded outright. But the Commission's position is the more instructive one: sovereignty is not a nationality test applied to logos. It's a chain property, assessed level by level, layer by layer, across the whole supply chain. Which is exactly why the layer you forget to assess is the one that determines your real score.
August 2: the AI column stops being theoretical
The framework's "data and AI" objective might have seemed like the softest of the eight — until this month. On July 7, the Commission presented its Action Plan on Cybersecurity and Artificial Intelligence. It creates no new obligations by itself; it's a coordinating framework across the AI Act, NIS2, DORA, the Cyber Resilience Act, and the Cyber Solidarity Act. But it lands three weeks before a date that does carry obligations: on August 2, 2026, enforcement of the AI Act's general-purpose AI provisions begins, with the General-Purpose AI Code of Practice specifying what compliance looks like for advanced model providers.
The Action Plan sketches where this is heading: an EU capacity for evaluating advanced AI models, a blueprint for structured access, a secure testing platform — and, notably, a Critical Open Source Resilience Campaign. Open source is no longer a footnote in Brussels' thinking; it's named infrastructure, on the resilience agenda in its own right.
For organizations, the practical consequence is the one we flagged when the June package landed, now with a date attached: which AI model processes which data, in which jurisdiction, under whose control stops being an architecture-diagram nicety and becomes something you may need to demonstrate. If your honest answer today is "whichever model the integration happens to call, we'd have to check" — that's the gap.
And if anyone doubts the appetite for enforcement, consider that one day after publishing the Action Plan, the Commission referred four member states to the Court of Justice over incomplete NIS2 transposition. The machinery is running.
Run the scorecard. Find the missing row.
Here's the exercise we'd suggest to any European CIO this quarter. Take the eight objectives. List the layers of your stack: cloud infrastructure, identity, collaboration, data platforms, the AI models you've adopted. Score each one. Most organizations that have taken sovereignty seriously will find respectable marks across the board.
Now find the row for your integration platform — the layer that moves data between all the others, holds credentials to every system it touches, and increasingly decides which AI model sees what.
For most organizations, that row doesn't exist. The integration layer was procured years ago as a productivity tool, evaluated on connector counts and feature checklists, never on jurisdiction, supply-chain transparency, or operational control. If it's a US-controlled proprietary iPaaS, then every one of your carefully scored sovereign layers communicates through a component that would fail the very assessment you just passed everywhere else. The framework measures the chain; the chain runs through the link you never measured.
This is not a hypothetical weakness. On the eight objectives, the integration layer is arguably the most exposed layer in the stack: it touches the most data (data and AI), holds the most credentials (security), sits under a vendor's jurisdiction (legal), depends on that vendor's continuity (operational — a lesson June's Fable model-suspension episode taught the hard way), and is typically the least transparent component you run (supply chain, technology).
What a passing grade looks like
We won't pretend neutrality here: FastHub was built to be the layer that survives this scorecard, and the design choices map directly onto it.
Legal and jurisdictional: built in Finland, operated from the EU, hosted 100% on EU infrastructure — no parent company subject to a foreign directive.
Supply chain and technology: constructed entirely from open-source components — Kubernetes, Keycloak, Open Policy Agent, Apache Camel, Quarkus. The highest sovereignty tiers demand full supply-chain transparency; open source is the only architecture that can prove it rather than promise it. You cannot fully audit what you cannot read.
Data and AI: model-agnostic orchestration with policy enforcement in the integration flow itself — which model, which data, which jurisdiction, as configuration rather than as a consulting engagement. When August 2 questions arrive, the answers are in the audit log, not in a scramble.
Operational: deploy on our managed EU cloud or your own infrastructure, and swap the model or the cloud underneath without rebuilding the integrations. If switching is a config change, you have a fallback; if it's a multi-week project, you have a dependency with extra steps.
The point isn't that FastHub ticks boxes. The point is that in July 2026 there are boxes — public, standardized, and about to be applied by people who buy things. Sovereignty used to be a debate you could have at a summit. Now it's a score you carry into a tender. And it will be computed across your whole chain, including the layer that holds the chain together.
Make sure that layer is on your scorecard before it shows up on someone else's.
FastHub is an AI-native integration platform built in Turku, Finland — constructed entirely on open-source technologies and hosted 100% within the EU.