Europe’s Digital Sovereignty Agenda Must Include Digital Public Infrastructure
Nicholas Gates / Sep 25, 2026
“Behind the scenes - European Parliament in Strasbourg” by European Parliament, CC BY 4.0
Europe has settled the question of whether it has a dependency problem when it comes to its digital infrastructure. The European Commission's Tech Sovereignty Package, published in June, and the European Parliament's 2025 report on European technological sovereignty and digital infrastructure identify the same vulnerabilities: cloud and storage services, communication platforms, identity, and payments. The November 2025 Franco-German Summit on European Digital Sovereignty in Berlin produced intergovernmental pledges of European preference.
The question, then, is not the scope of the dependency problem or whether Europe should address it. New instruments like the Digital Commons (DC-EDIC) and the Open Internet Stack have been launched and are now being implemented, with lip service to funding and/or building sovereign digital infrastructures. While such efforts are commendable, and some Member States are doing their own work, activity is notably absent in one area: Digital Public Infrastructure, or DPI. While DPI activity is happening in the EU and its Member States, policy recognition has been slow to emerge, and the bloc has not organized those capabilities into a coherent approach in support of European digital sovereignty.
I argue that the European debate around digital dependency and how to operationalize digital sovereignty in practice is lacking; not in focus, but by omission. Rather than primarily focusing on what it can regulate and mitigate, Europe should also focus on what it can build and deliver. In this regard, I believe European engagement on DPI will be vital for securing the EU’s digital sovereignty agenda in the years ahead.
The test that European digital sovereignty currently fails
While multi-Member State initiatives and the prospect of more European Commission funding are promising, the scope of new instruments remains under-defined and evolving, with implementation expected to be slow (and possibly quite bureaucratic). What remains unsettled is what Europe actually intends to build and what it can actually operate itself, or across its Member States.
Most of the current debate concerns what to stop depending on: which vendors to exclude, which data to localize, which procurement conditions to attach. That is structural exposure reduction, the form of sovereignty EU instruments deliver most readily, and which is at the heart of the vision of digital sovereignty pushed by the Tech Sovereignty Package. It is not the same as the capacity to build, operate, maintain and replace foundational systems.
Whether structural exposure reduction is sufficient turns on one practical question: Could the EU change or replace a given component without rebuilding what sits on top of it? A European provider that is as difficult and expensive to leave as the one it replaced may relocate rather than remove it. Building the capability to deliver means retaining the ability to (for example) move data or exit a contract, and the EU can begin doing this almost immediately, with identity, payments, and data exchange as a starting point.
Consider the EU Digital Identity (EUDI) Wallet. The EU has established common rules, technical specifications, and an open-source reference implementation, while member states are responsible for providing wallets. More than 550 companies and public authorities across 26 member states, as well as Norway, Iceland and Ukraine, are participating in the large-scale pilots. The wallet ultimately operates within a broader technology stack that includes devices, operating systems and other components that European institutions do not fully control. The pattern will recur wherever European infrastructure sits on components the EU neither maintains nor governs.
The ability for the EU to not just set the rules for its digital infrastructure but to ensure the bloc and its Member States can build and maintain it is vital. Enabling that ability through the capabilities of the state is what we call the capability to deliver. That capability centers on the technologies, institutions, and practices necessary to actually operationalize, build, and maintain digital infrastructure with higher degrees of public control. DPI is the most developed body of practice globally for supplying it.
Why Digital Public Infrastructure for Europe?
DPI is a globally recognized approach to building public digital services with society-wide applications — critical digital capabilities at the foundation of digital infrastructure and enabling public service delivery. As described by its most ardent practitioners, DPI represents foundational, society-wide digital systems, principally digital identity, instant payment rails, and trusted data exchange, built on open standards and shared across public and private users.
The G20 reached the first multilateral governmental consensus on DPI under India's 2023 presidency. The UN's Global Digital Compact treats it as a driver of inclusive digital transformation, and the World Bank has built dedicated programs around it. DPI language now appears in the core digital strategies of dozens of countries across Africa and Latin America, and regional bodies have adopted it as an organizing concept for cooperation.
While it is focused on three core capabilities, the paradigm and way of thinking might be vital in unlocking an “ecosystemic approach to digital policy and digital sovereignty”, linking the digital infrastructure and public services delivery logics in a way that supports European digital policy goals. While DPI is not the only solution for building capability, when deployed well, it can and should be an important part of the recipe for operationalizing European digital sovereignty. The time is right for European policymakers to consider what DPI could bring to the bloc.
In terms of policy recognition, the EU is somewhat thinly represented in the DPI space, and where it appears, it does so as a funder and occasional convener rather than as a builder. Part of the reason is categorical: the bloc treats DPI principally as a development concept, relevant to partner countries rather than to itself. The Directorate-General for International Partnerships (DG INTPA) does substantial bilateral work that is rarely cited in multilateral fora, while the Directorate-General for Communications Networks, Content and Technology (DG CNECT) and the European External Action Service (EEAS), which hold the policy and diplomatic mandates, have not defined a DPI position at all. Even with DG INTPA, their voice is less heard in international convenings around the topic, including at the UN and the Global DPI Summit.
The story of what is actually happening in Europe tells a different story than the vocabulary and framing might suggest. Many Member States possess workable DPI implementations and have been more visible in beginning to connect this work to the global community of practice around DPI and Digital Public Goods (DPGs). FranceConnect provides a unified authentication layer across French public services for tens of millions of users. The Government of France is a member of the Digital Public Goods Alliance (DPGA), part of the 50-in-5 campaign, as well as hosting its upcoming Annual Members Summit in Paris in November. Italy runs SPID, the Public Digital Identity System for identity and its pagoPA platform for payments at the scale of one of the EU's largest populations. Estonia's X-Road data exchange layer has been implemented in 40 countries globally, and Denmark's MitID made digital-by-default the norm for dealings between citizens and the state. Denmark requires digital self-service in a number of government services, subject to exemptions and alternatives. Some connective tissue exists, too. For example, eIDAS 2.0 supplies a governance architecture for mutual recognition of national identity schemes, with large-scale pilots involving more than 550 companies and public authorities.
The constraint in Europe is therefore not the absence of DPI. It is that no one treats these systems as a single class of infrastructure worthy of investment and maintenance, let alone a critical component of Europe’s proposed digital sovereignty agenda. Because they are not read that way, these important systems are not funded for maintenance, not governed in common, and not connected as much as they could. Each was built by a single state with unified authority over standards, procurement, and delivery. Reproducing that coherence across twenty-seven Member States is a coordination problem nobody currently owns.
What acting on DPI might look like
Whatever one thinks about the DPI paradigm, these capabilities are vital for the functioning of the modern state in the digital era. Failing to participate actively in a global community of practice around DPI means missed opportunities for sharing and learning that might be critical for Europe as it builds its own vision of digital sovereignty within and between countries across the bloc.
The Government of Brazil's Pix and the Government of India's Aadhaar were built incrementally, tested in public, and organized around politically legible problem statements. The Government of Ukraine's Diia delivers over 100 government services and has outpaced many Member States on adoption. European delivery teams are largely not in the rooms where those lessons are exchanged, because Europe sends funders and policy officials rather than implementers. The result is a partnership offer of money and finished frameworks, when the DPI conversation asks for co-development.
A more reciprocal Brussels Partnership would start by making the EU's own implementations visible, then bring them into multilateral fora as contributions rather than exports.
What would this look like inside of Europe? Moving on DPI does not require a European DPI strategy, an EU-wide definition, or a new legislative cycle. The instruments are already in hand. The Interoperable Europe Act provides governance mechanisms that could connect national systems without replacing them. The revision of the Public Procurement Directives and public procurement more broadly has already begun to permit open standards as evaluation criteria, and Commission guidance could treat procurement of digital infrastructure explicitly as industrial policy. The European Competitiveness Fund, once it materializes, will be a vehicle for investment in foundational systems. The Digital Commons EDIC, which brings France, Germany and other Member States together to build and maintain shared infrastructure, is the most concrete near-term mechanism available.
The Tech Sovereignty Package also proposes a European Digital Public Infrastructure Steward Organization within the EU Open Source Strategy. It is worth having if it takes on the type of work nobody is currently doing: keeping a register of the DPI capabilities Member States run, resourcing and connecting what exists rather than only funding new development, and acting as a single point of contact across DG CNECT, DG INTPA, the EEAS and national agencies. Without a budget and a delivery mandate, it will add another coordination layer to a landscape that already has several.
Some simple next steps are available. Member States that haven’t already can register their implementations on the DPI Map and their digital public goods in the Digital Public Goods Alliance registry. This requires no new funding and addresses the visibility gap directly. In the medium-term, the Multiannual Financial Framework cycle, the 2027 high-level review of the Global Digital Compact, and the implementation of the Global Europe Instrument provide opportunities to connect domestic European work with international DPI cooperation.
The choice for Europe is not between regulating and building. It is between continuing to set rules for infrastructure that others operate, and acquiring the capacity to operate infrastructure whose rules Europe sets and can change. DPI does not single-handedly solve that problem, but it is a step in that direction, and it helps build the institutional muscle the bloc so clearly needs to realize digital sovereignty at scale.
Authors

