Giorgos Verdi
Earlier this summer, the European Commission unveiled a series of measures that aims to mitigate the risks of technological coercion by the U.S. government and American tech corporations. Although none of the provisions put forward are revolutionary, they mark a fundamental change in how the EU thinks of its digital dependencies: not only as a loss of economic value but as potential security vulnerabilities.
For those that have closely followed developments in the transatlantic relationship, the so-called Tech Sovereignty Package did not come as a surprise. Since President Trump returned to the White House in January 2025, he and his administration have waged a hard-edged campaign against Europe’s digital regulations.
Big Tech corporations were quick to support the President’s actions, as they eyed an opportunity to undermine European laws designed to regulate their behavior. Meta’s CEO Mark Zuckerberg set an early tone, framing the EU’s rules as a form of censorship and pledging to work with the White House.
The fight accelerated in April 2025, when the Commission fined Meta and Apple for beaching fair competition rules. These were the first fines under the EU’s Digital Markets Act, and the White House promptly attacked the action as “economic extortion.”
In August 2025, the President escalated his rhetoric. Any country that imposed digital laws and taxes on American firms, he threatened, would be faced with substantially higher tariffs and export controls on U.S. technologies.
Although these attacks did not ultimately result in policy, European policymakers around this same time also began to focus more closely on the idea that that cross-border technology platforms on which Europe depends for defense, commerce, and information could be shut down by a ‘kill-switch’ controlled by the U.S. government.
Individual corporations and the U.S. government had both demonstrated such capacities in the past. In 2022, Elon Musk imposed restrictions on Ukrainian use of Starlink communications services. In early 2025, the Trump Administration forced Microsoft to cut off the chief prosecutor of the International Criminal Court (ICC) from accessing its services.
Brussels developed its Tech Sovereignty Package to alleviate some of these concerns. More specifically, the package included a Cloud and AI Development Act (CADA), a Chips Act 2.0, and an Open Source Strategy. In cloud for example, the package plans to reserve a small portion of sensitive government contracts for European cloud companies. European countries are also encouraged to use open-source solutions when building their AI and cloud stacks.
A few days after announcing the Tech Sovereignty Package, the EU faced an actual cut-off. On June 12, Washington suspended access to Claude Mythos and Fable, Anthropic’s most powerful AI models to date, for all foreign nationals.
In its first weeks, Mythos identified more than 10,000 flaws across major operating systems and web browsers. Mythos’s capabilities sparked concerns inside Anthropic about misuse of the technology, and the corporation established Project Glasswing: a 40-company consortium that included Amazon, Google, NVIDIA, and CrowdStrike, among others.
But Glasswing left EU governments out. The European Commission confirmed limited contact with Anthropic and no access to Mythos. The exclusion caused frustration and concern. In a closed-door meeting, Germany’s top cybersecurity official, Claudia Plattner warned national lawmakers that Chinese companies like Alibaba could soon match Mythos’ capabilities, leaving Europeans vulnerable.
Even though Anthropic soon included ENISA, the EU’s cybersecurity agency in Glasswing, within days, the U.S. government’s export controls to Mythos followed. By the end of the month, however, the U.S. Commerce Department had reversed course, dropping the restrictions on Mythos and Fable.
The Trump administration reversed its cut-off of Mythos to European users within weeks. But the damage had already been done, as the action demonstrated that the U.S. was willing to cut off Europeans based on national security claims as well as over regulatory philosophy.
In the near term, Europe will remain exposed and vulnerable to export restrictions of American technologies. But in the long term, these incidents have clearly helped to galvanize European embrace of policies to promote much greater technological sovereignty. The real test comes in the next months, as policymakers from the European Parliament and the Council will give shape to the final form of the Tech Sovereignty Package.