Publicado a 15 de julho de 2026

AI Sovereignty: Why Europe Can No Longer Depend on Models That Can Be Switched Off From Another Continent

The European Commission itself has just put this in writing. We examine the new Action Plan on Cybersecurity and Artificial Intelligence (7 July 2026) and what it means for those building AI infrastructure in Europe.

AI Sovereignty: Why Europe Can No Longer Depend on Models That Can Be Switched Off From Another Continent

Short answer: In June 2026, two of the world's leading AI models — Anthropic's Fable 5 and OpenAI's GPT-5.6 — were restricted by order of the US government, affecting European users. On 7 July 2026, the European Commission published an Action Plan that formally acknowledges this risk and points to a path forward: start with the open-source models already available, build sovereign European capacity, and support European providers. This article explains what happened, what the new regulation says, and what European organisations should do now.

What Is "AI Sovereignty," and Why Has It Become a Critical Issue?

AI sovereignty is the ability of an organisation or a political bloc to access, operate, and control artificial intelligence systems without depending on unilateral decisions made by foreign providers or governments. Applied to infrastructure, it means that models, data, and compute capacity remain under one's own jurisdictional control — and cannot be switched off remotely. For years, this was treated as an abstract concern. It stopped being one in June 2026, when the risk materialised twice within two weeks. And on 7 July 2026, the European Commission formalised it in an official document — the Action Plan on Cybersecurity and Artificial Intelligence [COM(2026) 577 final] — which states, in its own words, that frontier AI is mostly developed outside the EU and that its availability is often shaped by opaque, third-party-led processes:

“frontier capabilities are mainly developed outside of the EU, and their availability is often determined by non-transparent, foreign-led processes. Knowledge of and access to these capabilities is therefore a matter not only of digital resilience but also of Europe's technological sovereignty.”

— European Commission, COM(2026) 577 final, Section 1

What Happened to Fable 5 and GPT-5.6? Were They Actually Blocked in the EU?

Answer: This was not a block decided by the EU — it was a restriction imposed by the US government, with global effect (which struck, among others, European users). It happened in two consecutive cases:

Case 1 — Fable 5 and Mythos 5 (Anthropic). On 12 June 2026, Anthropic received an export-control directive from the US government, invoking national security, ordering the suspension of access to these models for any foreign national. Because the company could not reliably distinguish, in real time, foreign nationals from US users, the only way to comply was to switch the models off worldwide. According to Proton, the EU itself had to appeal directly to the US administration to recover access. Service was only restored on 1 July 2026.

Case 2 — GPT-5.6 (OpenAI). Two weeks later, on 25–26 June, the US administration asked OpenAI to limit the rollout of the three GPT-5.6 variants (Sol, Terra, Luna) to a small group of partners pre-approved by the government. According to TechCrunch, OpenAI complied, but stated publicly that it does not believe this type of government-access process should become the long-term norm. The common denominator: in both cases, European organisations' access to frontier AI depended on a political decision made on another continent, without prior warning and without any appeal mechanism available to the affected companies.

Does the European Union Officially Acknowledge This Risk?

Answer: Yes, and unambiguously. The Action Plan of 7 July 2026 describes exactly the pattern seen in the Fable 5 and GPT-5.6 cases — access governed by decisions made by non-European providers, through “structured access programmes” (staged rollouts), with a lack of transparency about the criteria applied:

“Access to frontier AI with advanced cyber capabilities is increasingly governed by provider-specific and often non-European decisions, with some providers limiting access to manage risks of misuse through structured access programmes (e.g. staged model releases). While such restriction may be justified on safety grounds, this practice often lacks transparency regarding the criteria applied to determine which organisations, including companies, gain access.”

— COM(2026) 577 final, Section 2.3

The document is even more direct in naming the central risk driving the entire sovereignty thesis — that Europe will remain hostage to systems that others can simply switch off:

“Without compute, models, and data infrastructure, Europe is bound to remain a vulnerable user of frontier AI systems made elsewhere that others can suddenly switch off – with huge economic and (cyber)security implications.”

— COM(2026) 577 final, Section 4.2

And it anticipates the defence against this scenario: the forthcoming European Blueprint for structured access is expected to include contingency measures for cases where access is restricted or withdrawn by a provider or a third-country authority — precisely what occurred in June:

“The Blueprint should include contingency measures in case of restricted or withdrawn access... in the situation that access to a relevant model or system is restricted or withdrawn by a provider or a third-country authority.”

— COM(2026) 577 final, Section 2.3

What Role Does Open Source Play in This Strategy?

Answer: Open source is the immediate starting point. The Action Plan is explicit: AI capabilities already available today, including through open source, can already be used to strengthen the EU's cyber resilience.

“advanced AI capabilities that are already available today, including through open source, can already be used to strengthen the EU's cyber resilience.”

— COM(2026) 577 final, Section 1

The document reinforces this principle repeatedly, calling on operators to use “the full range of AI models and in particular those that are open source” to detect vulnerabilities and prevent attacks (Section 3). It also identifies critical open-source software as the first place to act, backing the point with data:

“98% of the total codebase contains open source, with critical infrastructure industry averaging to about 80% of codebases with high- or critical-risk vulnerability.”

— COM(2026) 577 final, Section 3.3, citing the Blackduck 2026 Open Source Security and Risk Analysis Report

This validates the correct architectural logic for any European organisation evaluating AI infrastructure: start with open-source models (Llama, Qwen, Mistral, DeepSeek) deployed on proprietary servers within European territory. An open-source model, once downloaded and deployed on-premise, has no centralised kill switch — it cannot be switched off remotely by a foreign government's decision, because there is no dependency on an external API.

DEFINITION — Kill Switch

A mechanism through which an external provider or authority can remotely deactivate access to a software service or AI model. The Fable 5 and GPT-5.6 cases show that, for third-party-hosted models, this risk is real and has already been triggered.

Is Open Source the Final Destination? Should Europe Build Its Own Frontier Models?

Answer: Open source is the starting point, not the destination. The Action Plan clearly distinguishes between two needs: using what is already available today (open source) and, in parallel, developing sovereign frontier capacity to reduce strategic dependencies.

“the EU must develop its own sovereign general-purpose frontier AI capabilities to mitigate the risk of new dependencies on what has now become a critical strategic asset.”

— COM(2026) 577 final, Section 4.2

Crucially for the domestic business ecosystem, the document places the responsibility for execution on European providers — including disruptive innovators:

“The EU must now enable European providers, including disruptive innovators, to develop, deploy and scale such advanced AI in Europe.”

— COM(2026) 577 final, Section 4

The economic rationale is presented without ambiguity: however high the cost of building Europe's own capacity may be, the cost of not building it will be higher still, and will grow every year as the capability gap widens:

“while the cost for Europe of building its own frontier AI capacity may be very large, the cost of not building it may be even larger and grow every year as the AI-capability gap widens.”

— COM(2026) 577 final, Section 4.2

What Will the EU Actually Do — and With What Funding?

Answer: The Action Plan sets out nine Key Actions and mobilises concrete financial instruments. The points most relevant to the ecosystem:

€200 million by the end of the current Multiannual Financial Framework, through the Horizon Europe and Digital Europe programmes, for AI-enabled cybersecurity technologies developed in Europe (Section 4.1).

€100 million to be invested by the EIC Fund in strategic defence-technology startups and scaleups, including cyber and AI companies, by the end of 2026 (Section 4.1).

• A European Blueprint for structured access (Key Action 2, Q4 2026), coordinated with ENISA, to ensure that European organisations — including companies — access these capabilities safely and in a timely manner.

• A secure testing platform for AI in cybersecurity use cases, managed by ENISA and the JRC (Key Action 3, Q4 2026).

• A Critical Open Source Resilience Campaign to accelerate patching of critical open-source components, through a voluntary sponsorship scheme (Key Action 6, first pilot in 2026).

• A European open-source frontier model already under development: the Commission has awarded the Frontier AI Grand Challenge to the EUROPA consortium, to build an advanced open-source model in the EU's 24 official languages (Section 4.2).

DEFINITION — On-Premise Architecture

A deployment model in which software and data reside on infrastructure controlled by the organisation itself, within its own jurisdictional perimeter, rather than on a third-party-operated cloud service. By construction, it removes the international data-transfer questions regulated under GDPR (Articles 44–49) and the risk of remote deactivation.

What Regulatory Deadlines Matter Already in 2026–2027?

Answer: Three dates structure the immediate calendar:

2 August 2026 — the Commission begins exercising supervisory and enforcement powers under the AI Act over AI systems and general-purpose models, including those presenting systemic cybersecurity risks (COM(2026) 577 final, Section 2.1). Fines can reach 3% of global annual turnover.

11 December 2027 — full applicability of the Cyber Resilience Act (CRA), which imposes security-by-design, vulnerability management, and timely patching throughout the lifecycle of products with digital elements (Section 3.1).

End of 2027 — expected full applicability of the CRA framework across the supply chain.

These dates sit alongside the framework already in force: the NIS2 Directive [Directive (EU) 2022/2555], DORA [Regulation (EU) 2022/2554] for the financial sector, and the GDPR.

What Should European Organisations Do Now?

Answer — three practical priorities:

1. Treat dependency on a single foreign provider as a business-continuity risk, not a procurement detail. The June 2026 cases show that access to frontier AI is no longer guaranteed by commercial contract — it is granted, or withheld, by political decision.

2. Evaluate open-source models in on-premise or sovereign architectures today, particularly in regulated sectors (banking, healthcare, legal, public administration, critical infrastructure). This kind of architecture reduces exposure to the geopolitical risk described above, and its technical characteristics — data location, absence of dependency on external APIs — are directly relevant to the architectural requirements found in the GDPR, NIS2, and the AI Act. Determining the specific compliance obligations that apply to any given organisation remains a matter for its own legal and compliance advisors.

3. Actively support European providers — through public-procurement criteria that give weight to data architectures located within the EEA, and through private purchasing decisions aligned with the strategy the Commission itself has just formalised.

The conclusion is the same one the European Commission put on record, on 7 July 2026, in an official document: depending on AI systems built on another continent, which others can suddenly switch off, is a strategic vulnerability. The response begins with building, today, on foundations that cannot be switched off from outside.


SOURCES

Primary source (regulation)

• European Commission, Action Plan on Cybersecurity and Artificial Intelligence, COM(2026) 577 final, Strasbourg, 7 July 2026. All marked verbatim quotations are drawn from this document (Sections 1, 2.1, 2.3, 3, 3.1, 3.3, 4, 4.1, 4.2).

• AI Act — Regulation (EU) 2024/1689

• Cyber Resilience Act — Regulation (EU) 2024/2847

• NIS2 Directive — Directive (EU) 2022/2555

• DORA — Regulation (EU) 2022/2554

• EU Open Source Strategy — COM(2026) 503 final

• Cloud and AI Development Act (CADA) — COM(2026) 502 final

News sources (Fable 5 and GPT-5.6 cases)

• Anthropic, statement on Fable 5 and Mythos 5 access — anthropic.com/news/fable-mythos-access

• Proton, “Restrictions on access to GPT-5.6 could hurt European businesses” — proton.me/business/blog/openai-gpt-5-6

• TechCrunch, “OpenAI limits GPT-5.6 rollout after government request, says restrictions shouldn't be the norm” — techcrunch.com, 26 June 2026

Data source cited in the Action Plan

• Blackduck, 2026 Open Source Security and Risk Analysis Report (referenced in COM(2026) 577 final, note 30)