BANNER: US and EU flags hang next to each other on a building. (Source: xJOERANxSTEINSIEKx via Reuters)
Executive summary
There is a growing trust deficit at the center of the transatlantic digital relationship, which has widened during 2026. This friction stems from shifting political priorities, in both Washington and Brussels, that have strained decades-old ties between the European Union and the United States. The tension is not limited to digital policymaking. But within the digital arena, contrasting perspectives and increasingly vocal disagreement on digital regulation, digital sovereignty, and artificial intelligence (AI) are placing these longtime allies at odds.
Yet much still unites the EU and US, particularly at the policy level. The Atlantic Council’s Democracy + Tech Initiative held two roundtables under the Chatham House Rule to address critical components of the current transatlantic tension.
One, in cooperation with the Atlantic Council’s Europe Center, focused on the implementation of the EU’s e-Evidence Regulation in August 2026 and the future of EU–US data sharing for law-enforcement purposes. The second, hosted by the Democracy + Tech Initiative, addressed questions around digital sovereignty and its implications for ongoing interoperability within the digital economy.
The discussions brought together academics, civil society representatives, industry practitioners, and current and former government officials from EU member states, the European Commission, the United Kingdom, Canada, and the US. The workshops were held in May and June 2026, respectively, and included between fourteen and eighteen representatives drawn from the above stakeholder groups.
At first glance, these topics may appear unrelated. But both workshops highlighted the same underlying tension related to the cross-border legal and operational control over data and infrastructure.
For Europe, political commitment to greater digital autonomy and control on both topics is advancing faster than the technical, legal, and administrative capacity required to operationalize that desire. For the US, an increasingly adversarial position against many of Europe’s digital priorities, including the threat of retaliatory trade sanctions, has weakened Washington’s negotiating position just as the geopolitical environment has hardened.
This EU–US trust deficit is the bond that unites both the data sharing and digital sovereignty policymaking arenas.
Within transatlantic data access, US blocking statutes and EU production orders around law-enforcement data access create a legal conflict that no amount of technical interoperability can resolve on its own. Closing that gap requires an EU–US Clarifying Lawful Overseas Use of Data (CLOUD) Act agreement. But such a pact is unlikely to be concluded and brought into force while the broader transatlantic political relationship remains frozen.
For digital sovereignty, Brussels’s eagerness to reduce its reliance on US technology infrastructure—as demonstrated by the recent European Technology Sovereignty Package published in June 2026—cannot be overcome in the short to medium term without ongoing engagement at some level with US providers. Washington’s emphasis on maintaining US technological dominance, especially within AI, is at odds with Brussels’s policymaking objectives and has created a zero-sum dynamic in how Washington interacts with non-US policymakers.
Each actor discussed in this paper (the European Commission, EU member states, middle-power countries, and the US administration) controls part, but not all, of the digital policymaking relationship between Western countries.
This policy paper’s recommendations are designed with that in mind. They are conscious of the ongoing EU–US trust gap but offer pragmatic routes forward to maintain ongoing engagement, even while the broader relationship between Washington and Brussels remains contested.
Underlying workshop themes
- A specific, identifiable set of events in 2026 re-politicized the digital sovereignty debate, froze negotiations around an EU–US CLOUD Act agreement, and hardened transatlantic positions on digital sovereignty.
- The current EU–US fragmentation is happening at both procedural and implementation levels. It includes missed e-Evidence implementation deadlines within the EU and contrasting choices regarding digital infrastructure and digital sovereignty. There has been no deliberate decision, by either the US or EU, to decouple on digital issues.
- Practitioners from both sides of the Atlantic working on digital sovereignty and law-enforcement data sharing topics are attempting to forge a path forward via limited bilateral agreements. Almost no one is waiting for a comprehensive resolution to the current transatlantic tension.
- The law-enforcement data transfer dispute is the broader digital sovereignty debate’s core legal grievance and is playing out in concrete detail. It shows how Europe’s reliance on a third country’s policy decisions might become a real constraint. US blocking statutes and the EU’s General Data Protection Regulation (GDPR) Article 48 protections block each other directly. Only a political agreement, not a technical fix, can resolve that standoff.
The transatlantic trust deficit
Both workshops treated 2026 as an inflection point in the transatlantic relationship. EU–US tensions had been growing over the previous eighteen months. But the trust deficit, in which officials on both sides of the Atlantic showed increased wariness toward working with each other on likeminded issues, is the fundamental unknown variable that will determine whether progress can be made on either digital sovereignty or law-enforcement data transfers.
Participants highlighted a geopolitical flashpoint in the first quarter of 2026 that produced, in the words of one individual in the digital sovereignty workshop, a “material shift” in how EU national capitals viewed their long-standing relationship with the US. This change—related to Washington’s repeated and continuing demands that the US acquire or control Greenland, an autonomous territory within the Kingdom of Denmark, a NATO ally—was seen as more consequential than the steady transatlantic friction over digital regulation that has been apparent for more than a decade.
Within digital policymaking, this shift toward greater EU–US friction was reinforced by three further developments, according to workshop participants.
Those included:
- The perception that prominent US technology companies had aligned themselves with the current US administration’s foreign and industrial policies and were receiving strong administration backing for their economic interests;
- Recurring complaints from high-profile EU voices that US actors were supporting far-right political parties in Europe and recasting EU online safety laws as censorship rather than regulation; and
- A recent US Supreme Court ruling giving the US president greater authority to remove Federal Trade Commission (FTC) commissioners and possibly other independent regulators. Participants viewed that decision as a threat to one of the institutional assumptions underpinning the EU-US Data Privacy Framework. That concern was subsequently echoed by the European Data Protection Board, which noted that the EU data adequacy decision with the US explicitly relied on the FTC’s statutory independence and asked the European Commission to assess whether the recent US judgment affected the framework’s continued operation.
These workshop assessments align with external research that documents the US administration’s use of diplomatic pressure, tariff and market-access threats, accusations of censorship against EU online safety regulation, and relationships with European political actors to challenge the EU’s digital regulatory agenda.
Why this trust deficit matters
These geopolitical and policymaking changes have had real-world impact.
The EU-US CLOUD Act negotiation was described in the e-Evidence workshop as substantially advanced before the change in US administration in 2025. Participants described those discussions as currently frozen. Separate research published in June similarly reported that EU-US negotiations had stalled.
A joint EU-US Justice and Home Affairs ministerial, which had appeared on the Cyprus Presidency’s public calendar for late June, was removed without explanation. This removal suggested the meeting did not go ahead as originally planned. Technical negotiations were stalled because of the new political reality.
In the digital sovereignty workshop, participants were split over the core definition of digital sovereignty. They were divided into camps related to:
- defensive sovereignty, or the pursuit of digital autonomy as protection against external coercion, access, or disruption (in this context, referring to the US or China);
- offensive sovereignty, or the pursuit of digital autonomy to build competitive strength and reduce structural weakness; and
- political sovereignty, or the use of sovereignty primarily as a response to eroded trust and a symbolic or political signal, rather than as a policy objective driven by technical or legal risk assessments.
Participants in this workshop said political sovereignty had become dominant in EU policymaking discussions since early 2026 precisely because technical and legal questions related to the topic were now filtered through a lens of diminished trust, particularly among transatlantic allies.
There were also significant differences between European and US participants regarding what was at stake in both digital sovereignty and e-Evidence discussions.
EU participants framed the core risk as coercive via extraterritorial legal reach from the US government and the possibility that dependence on US technology would be used as leverage. US participants framed the core friction as regulatory and reputational risk in which disputes over platform governance would bleed into otherwise resolvable legal cooperation questions linked to data sharing and digital infrastructure.
Both workshop topics were, in effect, downstream casualties of a transatlantic trust deficit that did not originate in either cloud policy or criminal procedure negotiations. Policymaking solutions confined to either domain are unlikely to succeed without an accompanying de-escalation of the broader EU–US conflicts.
The current transatlantic trust deficit does not explain every dimension of the capability gaps examined in the two sections that follow. But it is also not simply the backdrop to these separate administrative and financing failures. Instead, the current, broader EU–US friction actively produces specific elements of the capability gap in both arenas. It is a fundamental tension that runs throughout both workshops.
The trust deficit has hardened political sovereignty into a distinct, dominant category in Brussels that makes it harder for the European Technology Sovereignty Package to resolve the trade-offs between defensive and offensive objectives on their own technical merits. It is also the direct cause of the frozen negotiations around the EU–US CLOUD Act Agreement, whose technical discussions have stalled for political, not legal or technical, reasons.
This distinction matters. The current capability gaps that are structural (e.g., administrative capacity, financing, and national implementation choices) can be addressed through funding, sequencing, and institutional decisions regardless of the state of the relationship. But the capability gaps that are caused by the current trust deficit require an improvement in the underlying EU–US relationship.
The recommendations at the end of this paper are organized with that distinction in mind.
Capability gap: Digital sovereignty
According to workshop participants, the EU’s political ambition for greater independence—particularly from US technology providers—is running ahead of the capacity, financing, and consensus required to deliver that objective. Overt political language from EU officials and lawmakers masks that capability gap.
More importantly, specific choices within the recently published European Technology Sovereignty Package are not expected to reconcile the EU’s current limitations related to either the technical or political requirements for digital sovereignty. That digital policymaking proposal includes efforts to build the EU’s local semiconductor manufacturing, cloud computing infrastructure, and energy-related capacity.
The package’s central design flaw, as discussed in the digital sovereignty workshop, is that it does not choose between competing objectives: defensive resilience against outside coercion, offensive competitiveness to strengthen Europe’s economy, and a political response to the transatlantic trust deficit described above. Instead, it blends all three into an unstructured policy instrument designed to placate all stakeholders without prioritizing any objective.
Defensive resilience was the most concrete of the three objectives. Workshop participants tied this concept directly to a specific fear that dependence on US-headquartered cloud and software providers could be weaponized, either through extraterritorial legal reach or through an outright denial of service. Some participants described this concern, only partly in jest, as a “kill switch” risk, or shorthand for what others in the room termed “weaponized interdependence” between the EU and the US.
Views diverged sharply on how seriously to treat the kill switch threat. Some participants argued that far more consequential systems, such as the Society for Worldwide Interbank Financial Telecommunication (SWIFT) financial network, had been suspended for individual countries in the past without collapsing the broader architecture of global finance, and that cloud or AI dependency was unlikely to prove more fragile.
Others argued the opposite: that dismissing extraterritorial exposure as a low-probability scenario understated the risk because a comparable dynamic (dependence converting directly into legal leverage) was already playing out in the law-enforcement data access standoff examined in the e-Evidence workshop, as discussed below.
Currently, all three objectives—defensive, offensive, and political sovereignty—are bundled into one policy proposal via the European Technology Sovereignty Package.
This bundling is compounded by the fact that EU member states are not expected to implement the Technology Sovereignty Package in the same way. Participants highlighted discussions around scoring EU member states’ sovereignty exposure, as outlined in the European Technology Sovereignty Package, which had already surfaced disagreement regarding which risks should carry the most weight. This objective includes weighing risks such as foreign jurisdictional reach against supply chain resilience and other factors.
France was seen by participants as pushing for greater emphasis on foreign jurisdiction exposure in risk weightings than other member states. Several participants predicted that this divergence would only widen as the European Technology Sovereignty Package moved from political agreement to national-level implementation. The resulting EU-wide outcome could be considerably less uniform than either its supporters or critics currently expect.
The package’s Cloud and AI Development Act (CADA) already reflects an attempt to manage this bundling through a tiered structure. Four assurance levels run from baseline data residency to full EU ownership and control. But the criteria separating those tiers remain contested. Some participants argued the tiers should be triggered narrowly, by demonstrable national security risk. Others viewed market concentration itself as sufficient justification for stricter ownership requirements.
Advocates of stricter ownership requirements argued that interoperability and contractual safeguards would not eliminate exposure to third-country law. A provider headquartered in the US could remain subject to American legal compulsion regardless of where data was stored, which meant technical portability did not necessarily resolve jurisdictional dependency. For some workshop participants, European ownership was not, in itself, protectionism. It was a necessary condition for genuine legal autonomy.
The counterargument, however, was that applying such requirements across ordinary public- and private-sector cloud use imposed substantial costs, reduced available capacity, and potentially replaced dependence on foreign providers with dependence on European alternatives that were not yet available at comparable scale.
The financing side of the capability gap drew similar criticism.
Europe entered the current sovereignty debate with an established investment disadvantage. European Parliamentary Research Service analysis identified the US as the leading jurisdiction for private AI investment and venture financing. Against that background, several participants pointed to national-level funding commitments that they considered orders of magnitude smaller than what would be required to build cloud or AI infrastructure at a scale genuinely competitive with US hyperscalers. This was seen as evidence that political rhetoric around sovereignty was moving well ahead of the budgetary reality needed to support it.
One frequently cited example during the workshop was a national AI investment fund that participants said was several multiples too small to meaningfully shift the competitive balance. This illustrated a broader pattern of Europe’s sovereignty ambitions being announced at a political tempo that public financing commitments had yet to match.
Under the EU’s plans, a renewed focus on interoperability and open-source technologies was proposed to capture digital sovereignty’s benefits while limiting any potential fragmentation costs. But workshop participants cautioned these policymaking objectives were unlikely to be a silver bullet.
Interoperability without a credible alternative for switching, for example, was described as hollow. The term itself was also contested. Some participants used it narrowly to mean protocol-level interoperability, or shared technical standards that let systems communicate directly. Others used it more broadly to mean data-level interoperability, or the ability to move data and switch providers without being locked in. Several participants argued the latter is more relevant to digital sovereignty policy, even though EU regulatory language often uses interoperability without distinguishing between the two levels.
Open source, which underpins the European Technology Sovereignty Package, was also not seen as a standalone fix to the bloc’s dependence on external providers. Open-source development is inherently transnational. Data from 2023 showed that the US, India, and several European countries led contributions to open-source projects. By 2025, India had become the world’s largest public and open-source contributor base, while US-based developers continued to account for the greatest overall volume of contributions.
That reality undercut claims within Europe that adopting open-source tools, by itself, would provide the bloc with greater autonomy from third-party countries.
One workshop participant recounted that a European government had experimented with a foreign open-source AI model only to discover that the system carried biases the government had not anticipated before deployment. This provided a real-life case study of the ongoing mismatch between EU objectives to diversify its technological supplier base and the insufficient institutional capacity to vet potential alternatives before adoption.
For some participants who looked beyond the current transatlantic trust deficit, middle-power cooperation among the likes of Canada, the United Kingdom, Australia, and Singapore could prove a hedge against both full EU dependence on US infrastructure and the EU’s own lack of internal cohesion. But expectations for such a middle path were mixed.
One participant compared the likely outcome of greater middle-power cooperation to Brexit’s effect on financial services. Greater cooperation between such countries could lead to fragmentation at the margins of digital infrastructure rather than a clean break from the current status quo. In that outcome, the US would likely remain structurally dominant despite countries’ efforts to forge their own paths.
Another participant argued the more productive version of this middle-power alternative would resemble defense-sector industrial cooperation, including pooled investment and shared technological capability across digital infrastructure. This model already has a working precedent in areas such as shared intelligence and joint weapons development, where allied countries combine industrial and financial strength to build capacity that no single mid-sized country could sustain alone.
That is a template middle powers could plausibly apply to cloud and AI infrastructure.
e-Evidence and the US CLOUD Act: The capability gap in practice
The EU’s e-Evidence regulation comes into force on August 18, 2026. When implemented, it will allow EU law-enforcement authorities to issue so-called production and preservation orders directly to service providers, including companies based outside the EU. That differs from the current process, in which requests are routed through the provider’s home-state authorities.
This is intended to give authorities a faster, direct-to-provider channel alongside—rather than in place of—the slower state-to-state processes currently used for cross-border evidence requests, such as mutual legal assistance treaties and the European Investigation Order. Those instruments remain available and will still be used in certain cases and for other types of investigative measures. But they can take months to produce results, defeating fast-moving investigations.
The current EU-wide efforts toward implementation of the E-Evidence regulation ahead of the August deadline show the same capability gap described above during the digital sovereignty convening. Workshop participants explained that, as of late May, most EU member states had missed the deadline for transposing the e-Evidence regulation’s companion directive.
This assessment was supported by separate research published in June 2026 that found that more than three-quarters of EU member states had not completed this transposition. The European Commission had opened infringement proceedings against twenty-two member states in March for failing to communicate complete transposition. The most significant point of failure was Ireland, which housed the EU establishments of most major foreign technology companies at the heart of pending digital data requests. At the time of the e-Evidence workshop in May 2026, the country had yet to transpose the companion directive.
On July 15, however, Ireland enacted its domestic legislation to transpose the EU-wide directive and appointed Helen Martin as its first director of criminal justice international cooperation.
This is the capability gap at its starkest. An instrument that took years to negotiate at the political level may now face uneven and phased implementation because many EU member states had yet to transpose the regulation’s companion directive into national law.That step is needed to compel companies to designate the legal representatives who receive production orders under the directly applicable regulation.
A negotiated agreement would not eliminate every disagreement between the two legal systems. It would, however, provide a recognized legal route for qualifying requests, lift relevant US disclosure restrictions and establish the international-agreement basis contemplated by Article 48.
More significantly, most workshop participants assessed that the regulation’s own conflict-of-law mechanism was more bark than bite. The EU’s e-Evidence regulation includes a procedure (Article 17) for handling instances in which a European Production Order conflicts with the law of a third country like the US. That procedure sets out decision criteria, including the strength of each jurisdiction’s connection to the case, the third country’s fundamental rights protections and national security interests, and the consequences of compliance for the provider.
Participants noted these criteria form a broad, discretionary balancing test rather than a fixed rule. This limitation is not unique to the e-Evidence regulation’s Article 17. The US CLOUD Act’s own comity analysis provision, which US courts use to weigh conflicting foreign-law obligations, similarly relies on an unweighted, multifactor test. That symmetry underscores the point. No unilateral statutory mechanism, on either side of the Atlantic, has solved the underlying conflict-of-law problem. That is precisely why participants saw a negotiated EU–US CLOUD Act agreement, rather than a better-drafted Article 17, as the appropriate fix.
With no case law yet testing how courts will weigh these factors against one another, participants expected significant uncertainty in how the mechanism will perform in its first real disputes.
Separate legal analysis similarly identified the risk that US providers could be required to disclose data under e-Evidence while remaining prohibited from doing so under US law.
This example, referenced by multiple e-Evidence workshop participants, is a representation of the weaponized interdependence concern that was also raised during the digital sovereignty workshop. The underlying jurisdictional conflict is not new. So-called comity tests of this kind have always been an imperfect tool for managing interjurisdictional issues.
What has changed is whether a negotiated bilateral fix like an EU–US CLOUD Act agreement is achievable. That has become a political question, not a legal or technical one, due to the current state of the transatlantic relationship.
Both the US Stored Communications Act and GDPR Article 48 can operate as blocking statutes by creating reciprocal legal friction for providers subject to both jurisdictions. Their operation, however, is not perfectly symmetrical. The Stored Communications Act generally restricts covered US providers from disclosing communications content directly to foreign governments. Article 48 prevents a third-country judgment or administrative decision from serving, by itself, as authority for disclosing EU personal data. Where the data remains in the EU and no applicable international agreement, lawful transfer basis, or derogation exists, Article 48 can prevent compliance with a US order.
For example, a US-headquartered provider could find itself legally barred from honoring an EU production order under US law. An entity handling that same request within the EU might simultaneously face restrictions on disclosing the data to a US authority via obligations from EU member states’ domestic criminal procedure rules and from GDPR Article 48’s requirement that any such disclosure rest on a recognized legal basis.
Soon, providers caught in this conflict could have no fast, direct path to compliance absent a negotiated agreement that recognizes the other jurisdiction’s legal process. They will likely fall back on the slower mutual legal assistance channels that the European Production Order mechanism was specifically designed to bypass.
Transposition was not the only implementation concern. Separate research published in June identified unresolved capacity, cybersecurity, and operational issues within the EU’s decentralized IT system through which authorities and providers would exchange production orders and responsive information. The combination of incomplete national transposition and uneven technical readiness suggested that e-Evidence implementation would initially vary across EU member states.US
Absent a resolved EU–US CLOUD Act agreement, the existing UK–US data access agreement (under the UK–US CLOUD Act Agreement) offered an example of what partial, bilateral progress could look like. One participant described it as heavily used and highly valuable, but explicitly said it was not the “silver bullet” it was expected to be when it was negotiated. Scope limitations that appeared minor on paper, but which included restrictions on using the agreement to investigate the other party’s own nationals, had become more intractable once the agreement was in use.
The lesson several participants drew from this experience was pragmatic, not aspirational: bank the value available now from small policymaking successes and don’t wait for a US administration to re-engage. The bottleneck is not likely the EU weighing whether to accept what is on offer from the US but, more likely, the absence of active US interest in reaching a deal related to an EU–US CLOUD Act agreement.
Continued reliance on ad hoc workarounds, however, carries its own risk. New technical and legal problems will emerge that only a negotiated agreement can resolve. An EU–US CLOUD Act deal is unlikely to get easier to reach amid ongoing US disengagement.
Fragmentation by accident, not design
Taken together, the two workshops were underpinned by three connected themes that are expected to anchor transatlantic digital policymaking over the next five years.
- Fragmentation is procedural, not deliberate: Participants in both workshops did not identify a single decision point at which the EU and US decided to decouple their approaches toward digital. Instead, the current fragmentation and trust deficit emerged progressively through smaller, individual decisions. That includes missed directive transposition deadlines; divergent national regulatory regimes; specific government procurement preferences; and stalled EU–US negotiations. The e-Evidence discussion also demonstrated a divergence between EU member states even before such friction reached the transatlantic discussion.
- Legal interoperability is the missing analog to technical interoperability: Participants in the digital sovereignty workshop proposed greater interoperable, portable, standards-based systems to ward off the threat of weaponized interdependence. That has a direct comparison in the legal domain. An EU–US CLOUD Act agreement would be for each side’s legal systems what interoperability standards would be for technical ones. It would allow two distinct, sovereign systems to work together without either side ceding control outright.
- Partial, bilateral progress has become the norm: Both workshops independently arrived at what has become the de facto hedging strategy for ongoing transatlantic discussions on digital. Without comprehensive multilateral solutions, policymakers are relying on existing bilateral or coalition-based systems and are treating them as a foundation for dialogue. They are not waiting for an ideal political outcome. That includes middle-power coalitions in digital sovereignty and the UK–US data access agreement in law-enforcement cooperation, as discussed above. Such pacts offer more caution than confidence about how far bilateral progress can substitute for comprehensive resolutions.
This final point — about not letting the perfect be the enemy of the good — is a critical element of what transatlantic digital policymaking engagement will look like during the rest of the decade. For a variety of political, policy, legal, and industrial realities, comprehensive transatlantic frameworks are unlikely to be negotiated quickly. Narrower, well-scoped bilateral instruments might be able to deliver meaningful value for both EU and US policymakers without waiting for broader tensions to be resolved.
Not everything is the same
Despite underlying similarities, both workshops highlighted significant differences between the ongoing digital sovereignty and law-enforcement data transfer policy arenas that must be taken into consideration when designing correct policy responses.
- Level of discussion: The digital sovereignty discussion remains invariably strategic and philosophical. The e-Evidence conversation is based on specific legal and technical implementation questions. Pathways forward pitched at the wrong level will not be successful. Both policy topics also do not easily integrate collectively into greater transatlantic engagement. A bilateral data access agreement, for example, does not resolve Europe’s underlying cloud and AI capability vulnerabilities.
- Types of disagreement: In the digital sovereignty workshop, participants disagreed about what digital sovereignty was supposed to solve. In the e-Evidence discussion, participants largely agreed on the problem but disagreed about which specific legal mechanisms would resolve it. Those differences relate to how advanced each separate conversation is in terms of implementation.
- Transatlantic friction: The digital sovereignty discussion was more openly skeptical about US dominance within digital infrastructure, framed as part of the defensive definition of digital sovereignty as described above. The e-Evidence workshop, despite covering similar legal friction, was more collegial. Practitioners on both sides of the Atlantic shared frustration with political paralysis rather than with each other.
- The role of industry: In the digital sovereignty workshop, major US technology companies were framed primarily as objects of policy concerns and sources of dependency risk that must be mitigated. In the e-Evidence discussion, the same types of companies were described as good-faith actors working to comply with legal complexities and constraints. That tension — companies being viewed as both cooperative and adversarial, depending on the policy topic — is likely to become the norm.
- Time horizon: The digital sovereignty debate operates on a three-to-five-year horizon. The e-Evidence and CLOUD Act debate operates against a fixed, near-term legal deadline of the August implementation date. Pairing them within this project illustrates both the slow-moving structural trend of transatlantic friction toward digital and an acute flashpoint within that wider conversation.
Recommendations
The current EU–US trust deficit and its implications for digital policymaking cannot be overcome by a single actor. The recommendations below are scoped to be realistic next steps within the currently strained geopolitical environment. Some are structural and can proceed regardless of the state of the transatlantic relationship. Others directly target the trust deficit described above.
- Focus on digital policymaking that does not require trust.
- Support EU member state transposition of EU law. The European Commission should offer direct administrative and technical support to any EU member state still lacking domestic legislation to designate legal representatives ahead of the August e-Evidence application date. The commission should also issue interim guidance to clarify how voluntary cooperation can bridge any remaining legal gap where transposition is incomplete.
- Build on the tiered assurance-level structure within the EU’s Cloud and AI Development Act (CADA). CADA already establishes a graduated framework from baseline data-residency requirements to full EU ownership and control for the most sensitive public-sector systems. The European Commission should make the criteria separating these tiers explicit and narrowly defined. It should reserve the highest tiers that require EU ownership or structural separation for clearly justified national security and core state function cases. The remaining tiers should rely on interoperability and portability requirements. Workshop participants were divided on this question. The recommendation reflects a narrower, tier-based approach favored by most participants in the room, not a settled consensus.
- Keep technical and legal questions outside of politics.
- Resume CLOUD Act negotiations at a technical level. Political differences make the resolution of an EU–US CLOUD Act agreement unlikely for the foreseeable future. But workshop participants were clear that remaining technical gaps were addressable. The continuation of technical negotiations—outside the current political impasse—could prevent resolvable legal questions from remaining hostage to wider tensions.
- Washington should clarify oversight of EU–US data sharing. The US administration has a direct interest in proactively clarifying how independent oversight of the US side of ongoing transatlantic data sharing agreements will be preserved in practice. That includes a public account of how enforcement of the EU–US Data Privacy Framework will now operate. Without that, the alternative is renewed legal challenges. Both Washington and Brussels have an interest in protecting ongoing commercial data flows.
- Bank partial progress ahead of comprehensive deals.
- Pool sovereignty-related investment among smaller EU member state groups. EU capitals with aligned interests and budgets should proceed with joint procurement of sovereign cloud or compute capacity on a bilateral or multilateral basis. This is consistent with the “sovereignty by design” approach that ran through the digital sovereignty workshop. It also allows for faster decisions than deferring investments until a harmonized EU position is agreed.
- Scope middle-power cooperation narrowly and technically. These countries can pursue specific joint initiatives with the EU, such as pooled procurement of sovereign compute capacity, as described above, rather than broad political coalition statements. Workshop participants were skeptical that loosely structured middle-power cooperation would deliver meaningful outcomes.
- Build the groundwork for when the politics change.
- Expand Article 28’s existing monitoring framework. The e-Evidence Regulation requires EU member states to report annual statistics to the European Commission, which must also publish an annual report on the regulation’s outputs and impacts. The categories currently specified for that reporting do not explicitly capture instances in which a US provider declines a European Production Order citing a US blocking statute, or in which a member state defaults to mutual legal assistance instead. The European Commission should ensure these conflict-of-law instances are tracked and published as a distinct category within the existing Article 28 reporting cycle.
- Produce a joint technical-political assessment within the European Technology Sovereignty Package. The EU should commission an assessment of the most consequential trade-offs between greater European ownership of cloud computing infrastructure and what can be achieved through greater interoperability standards. This would ensure that the future implementation of the EU’s proposals is grounded in a technical feasibility assessment of what will deliver the appropriate outcome.
This paper was made possible by support from Microsoft. The Atlantic Council maintains strict intellectual independence across all of its projects and publications. The analysis, findings, and recommendations in this paper are those of the author alone. Workshop participants included academics, civil society representatives, current and former government officials, and industry representatives, including representatives of Microsoft. All participants were selected by the author. All participants spoke under the Chatham House Rule. No single participant or organization shaped the paper’s conclusions.
Workshop-derived judgments are identified as participant assessments throughout this paper. Public sources are used to establish the legal, institutional, and political context and, where available, to corroborate themes raised during the discussions.
Cite this case study:
Mark Scott, “Sovereignty without borders: Decoding the transatlantic digital relationship at a time of change,” Digital Forensic Research Lab (DFRLab), August 14, 2026, https://dfrlab.org/2026/08/14/sovereignty-without-borders-decoding-the-transatlantic-digital-relationship-at-a-time-of-change/%E2%86%97.
Image: Symbolfoto: Flaggen von USA, EU und Italien in Rom, Italien, Europa Drei Flaggen hängen nebeneinander an einem Gebäude: die Flagge der Vereinigten Staaten, die der Europäischen Union und die italienische Nationalflagge. Das Bild eignet sich als Symbolfoto für Themen wie transatlantische Beziehungen, internationale Diplomatie, EU-USA-Beziehungen, NATO, Außenpolitik, Migration, Tourismus, Hotelbranche oder italienisch-amerikanische Partnerschaften. *** Symbolic photo flags of USA, EU and Italy in Rome, Italy, Europe Three flags hang next to each other on a building the flag of the United States, the flag of the European Union and the Italian national flag The image is suitable as a symbolic photo for topics such as transatlantic Copyright: xJOERANxSTEINSIEKx No Use Switzerland. No Use Germany. No Use Austria