The US Executive’s Guide to European Digital Sovereignty
An independent reading of what Europe’s digital rules actually require of a US company — what is genuine obligation, what is noise, and what is still moving. No vendor affiliations; interpretation, not sales-enablement.
A free guide · delivered to your inbox

Published from the Atlantic edge — neutral ground between Washington and Brussels.
The problem: reach, then preference
The AI Act’s reach is extraterritorial. If your AI touches the EU market or affects EU residents, you are likely in scope — wherever you are headquartered. That is the first half of the exposure, and it is settled.
The second half is newer and softer. The EU’s 2026 Tech Sovereignty Package is reshaping procurement preference — where European buyers and public bodies would rather their data, models and keys sit. It is not a single statute with a single deadline; it is a direction of travel that is already showing up in enterprise questionnaires and contract clauses.
Genuinely required, versus the noise
- Transparency duties under Article 50 — disclosing AI interaction and labelling synthetic content
- A current inventory of the AI systems you place on, or operate into, the EU market
- Your role for each system — provider or deployer — because the duties differ sharply
- Treating the date as a single “compliance cliff” to clear and forget
- Re-architecting onto an EU-only stack before a buyer has actually asked for it
- Box-ticking evidence that no European buyer’s questionnaire genuinely gates a deal on
Operative now, versus adopted-but-pending
Operative from 2 August 2026: the Article 50 transparency duties and the penalty and governance regime that gives the Act teeth. This is the part that binds first.
Adopted but pending: the heavy high-risk obligations were re-timed, not removed — standalone high-risk (Annex III) on 2 December 2027, embedded high-risk (Annex I) on 2 August 2028. The re-timing is adopted, not yet settled law until publication, so treat the later dates as a planning horizon, not a reprieve. The work that actually takes time — the inventory, the vendor evidence — is not gated by any of these dates.
A two-minute self-check
Three questions that separate a real exposure picture from a comfortable one. If you cannot answer all three cleanly, the inventory is the place to start.
In-scope systems
Can you produce a straight list of the AI systems already in use across your teams — and say which touch the EU market or affect EU residents?
Model provenance
For each system, do you know the model, the data behind it, and the vendors in the chain — with provenance and licence status you could evidence?
Key custody
Where do inference, weights and keys sit, who can reach them, and where could a US administrative override still reach EU data?
Get the guide
Enter your email and the guide arrives in your inbox. You will also receive the Silicon & Stone briefing — two editions a week, free, read from the US side.
Tuesday: the Stone Briefing — structural analysis of the AI power shift. Friday: the Practical Move — what to do about it. Unsubscribe at any time.
When you want this read against your own systems rather than in general, the Post-Omnibus Briefing is the fixed-price, fixed-scope engagement — what the AI Act now requires of your business, and the decisions to take this quarter.