Skip to content
Cirran

By Michał Puchała · 2026-09-03 · 4 min read

EU cloud news, week of 2026-09-03

France and the Netherlands push European criteria into technology procurement, Schwarz Group plans major German cloud capacity, the EU backs practical cyber resilience, Germany opens an AI security institute, and Flatpak receives support for stronger application isolation.

This week's strongest signals came from governments deciding how European technology should be bought and built. France and the Netherlands pushed sovereignty into procurement, while German and EU-backed initiatives advanced infrastructure plans, AI oversight, cyber capacity and open-source security.

France and the Netherlands call for European criteria in technology procurement The two governments backed targeted and proportionate European content criteria in public procurement and public aid for digital infrastructure. They also called for a protective cloud-sovereignty framework for sensitive data through the coming EU Tech Sovereignty Package and revision of the Cybersecurity Act. The statement does not create procurement rules, but it signals the direction two influential member states want the EU to take. Boards serving public bodies or regulated supply chains should expect questions about supplier ownership, jurisdiction and European value creation to become more formal.

Schwarz Group plans a 240-megawatt data centre in northern Germany The group and the state of Mecklenburg-Vorpommern said the proposed Dummerstorf facility could reach its planned capacity by 2033, subject to standard approvals. It would support the group's own systems and the expansion of cloud and AI services from Schwarz Digits, which operates STACKIT, with renewable power, air cooling and planned use of waste heat. The partnership also proposes running digital building permits on STACKIT and introducing OpenDesk workstations for teachers by the end of 2026. The capacity is a meaningful market signal, but buyers still need to distinguish a long-term construction plan from services and resilience they can verify today.

The EU opens a new cybersecurity deployment call The European Cybersecurity Competence Centre is seeking proposals across AI-based security tools, protection for smaller companies, preparedness testing, regional cable hubs and support for implementing EU cyber rules. The call also covers prototypes with both civilian and defence uses, while all participating entities must meet EU security requirements. Applications remain open until 14 January 2027. For regulated organisations, the useful signal is the breadth of the programme: Europe is investing in incident readiness, infrastructure monitoring and practical compliance capacity alongside cloud and AI growth.

Germany launches its national AI security institute AISI Deutschland has begun work with the Federal Office for Information Security focused on cybersecurity and the Federal Network Agency focused on broader AI safety. Its first phase will evaluate the capabilities and risks of leading AI models, advise the federal government and share relevant findings with government, business and civil society. The institute starts as a virtual structure and will expand its remit and capacity gradually. CTOs should watch for published evaluation methods and findings, but the institute's launch does not yet provide evidence that any particular model is safe for a regulated workload.

Germany's Sovereign Tech Agency funds stronger Flatpak isolation A two-year programme will address security and maintenance gaps in Flatpak, a system used to package and run applications on several Linux-based operating systems. Planned work includes finer controls for audio and network access, support for VPN applications, research into password autofill, clearer declarations of application permissions and more integration testing. The project team says the plans may evolve as implementation begins and openly acknowledges that Flatpak's isolation still trails better-funded proprietary platforms in some areas. For technology teams, this is a practical sovereignty lesson: open source offers inspectability and choice, but dependable control still requires sustained specialist maintenance.

Together, these moves show sovereignty shifting from labels to procurement criteria, physical capacity, independent evaluation and maintained software foundations.

Thinking about migration? Book a free consultation to discuss your situation.

See the European equivalent for your stack. Compare AWS, Azure, and GCP services side by side with OVHcloud, Scaleway, STACKIT, IONOS, and Hetzner.

Open the service mapping

Thinking about migration?

Book a free consultation to discuss your situation.

EU cloud news, week of 2026-09-03 | Cirran