Executive Summary

BLUF: Europe is not preparing a universal prohibition of Microsoft Office; it is engineering the capacity to operate without compulsory dependence on Microsoft.
The decisive shift is from product substitution to sovereign control of data, identity, cloud infrastructure, document formats and procurement.
The European Commission’s June 2026 technology-sovereignty package elevated cloud and open source from administrative preferences to strategic infrastructure policy.
Germany’s Schleswig-Holstein demonstrates that Office replacement is technically possible: nearly 80% of approximately 25,000 public-sector workplaces had moved to LibreOffice by December 2025.
Regulatory pressure is real but not equivalent to expulsion: Microsoft resolved the Commission’s 2024 data-protection findings, while its Teams commitments became legally binding under EU competition law in 2025.
The most probable 2031 outcome is a hybrid European workplace, with open formats and sovereign collaboration layers coexisting with Microsoft applications.
Modelled probability of an EU-wide Office elimination by 2031: 8%. Probability of material public-sector Microsoft displacement: 62%.
The strategic contest will be decided less by Word or Excel than by Entra ID, Exchange, Teams, SharePoint, OneDrive, Azure, Copilot and the data graph connecting them.

Europe Is Not Abandoning Microsoft Office. It Is Preparing to Survive Without It

Europe’s apparent revolt against Microsoft Office is not a campaign to replace familiar icons on millions of desktops. It is a struggle over who controls identity, institutional data, cloud infrastructure, cybersecurity telemetry and the emerging AI layer through which administrations will organise knowledge and decisions. On 3 June 2026, the European Commission elevated that concern into industrial policy, proposing a technological-sovereignty package spanning semiconductors, cloud, AI and open source. The objective is neither digital autarky nor the exclusion of American technology. It is the recovery of a credible exit option. Europe wants to ensure that no foreign platform—however efficient—remains technically, contractually or legally irreplaceable.

Beyond Word and Excel

Microsoft Office is no longer simply Word, Excel and PowerPoint. Microsoft 365 binds those applications to Outlook, Teams, SharePoint, OneDrive, Entra ID, Intune, Defender, Purview, Power Platform, Microsoft Graph and Copilot. Together they form an institutional operating environment: users are authenticated, devices authorised, communications archived, documents classified, threats detected and organisational knowledge indexed inside one ecosystem.

Replacing Word with LibreOffice while retaining Microsoft identity, storage, email, endpoint management and AI would therefore change the visible application without transferring strategic control. The true European objective is stack sovereignty: the ability to replace individual layers while preserving data, permissions, evidence, workflows and operational continuity.

This distinction explains the breadth of the Commission’s European technological-sovereignty package, presented on 3 June 2026. It combines the proposed Cloud and AI Development Act, Chips Act 2.0, an EU Open Source Strategy and an energy-sector digitalisation roadmap. The Commission describes open source as an instrument for scaling European alternatives, supporting skills and start-ups, and increasing adoption within public administrations.

The Cloud and AI Development Act remains a legislative proposal, not settled law. Yet its direction is unmistakable: cloud capacity, AI infrastructure, open software and semiconductor resilience are being treated as parts of the same strategic system.

Sovereignty Becomes Measurable

Europe is also replacing the imprecise language of “trusted cloud” with measurable procurement criteria. In April 2026, the Commission awarded a €180 million sovereign-cloud contract to four providers for EU institutions, bodies, offices and agencies.

The tender applied a Cloud Sovereignty Framework containing 48 criteria grouped into eight categories: strategic; legal and jurisdictional; data and AI; operational; supply chain; technological; security and compliance; and environmental sustainability. It introduced Sovereignty Effectiveness Assurance Levels ranging from SEAL-0, where control remains exclusively with non-EU actors, to SEAL-4, defined as full European control without critical non-EU dependencies.

This is more consequential than a political preference for European suppliers. It recognises that locating servers in Frankfurt, Paris or Milan does not alone establish sovereignty. The decisive questions are who controls encryption keys, administrators, software updates, privileged identities, subcontractors and recovery procedures; whether foreign authorities can exercise legal reach over the operator; and whether another provider could restore the service if the incumbent became unavailable.

Procurement is thus becoming an instrument of security policy. A cloud offer will increasingly be judged not only on price and performance, but on the customer’s capacity to continue operating after separation from the provider.

The Regulatory Pincer

Several EU instruments are converging on the same dependency problem. The Data Act, applicable since 12 September 2025, requires contractual provisions facilitating movement between data-processing services and imposes portability and interoperability obligations. From 12 January 2027, providers may no longer charge customers for the switching process. The official text is contained in Regulation (EU) 2023/2854.

But legal portability does not guarantee operational portability. Files may be exported while permissions, retention labels, Teams conversations, SharePoint taxonomies, Power Automate workflows, security histories and Copilot indexes remain difficult to reconstruct. A nominal exit can therefore produce a data archive without reproducing the institution that used it.

Competition policy addresses another layer. On 12 September 2025, the Commission made Microsoft’s commitments concerning Teams legally binding. Microsoft must offer business productivity suites without Teams at lower prices, enable qualifying customers to switch and support interoperability and data portability for competing collaboration services. The interoperability and portability commitments run for ten years.

Data protection has produced a more nuanced result than headlines suggesting that Microsoft 365 is intrinsically unlawful. In March 2024, the European Data Protection Supervisor found infringements in the Commission’s use of Microsoft 365 and ordered corrective measures. In July 2025, after changes by the Commission and Microsoft, the EDPS closed the enforcement proceedings, concluding that compliance had been achieved. The lesson is not that Microsoft is prohibited, but that contractual purpose, data flows, processor instructions and international-transfer safeguards must be actively governed.

France Builds a Public Stack

France is constructing the clearest alternative to the Microsoft-centred workplace. LaSuite, operated by the Interministerial Directorate for Digital Affairs, now reports more than 500,000 monthly users across 15 ministries and numerous administrations. Its secure messaging service Tchap is used by 600,000 public agents.

The platform integrates collaborative writing, videoconferencing, messaging, file exchange, data management and AI. Authentication is provided through ProConnect; services employ open-source technologies and, for specified workloads, SecNumCloud hosting. Governance is shared by ten interministerial co-financiers.

France is not pretending that the transition is complete. The LaSuite technical and service framework states that Docs and Visio may process defined sensitive data but are not suitable for content classified “Diffusion Restreinte”; nor are they currently certified to host health data. That limitation is strategically important. It shows that sovereignty is being built through workload classification, not proclaimed through branding.

France’s model is modular: public identity, conferencing, messaging, documents and AI can evolve independently while remaining connected. This is closer to Europe’s probable future than a single sovereign suite attempting to imitate every Microsoft function.

Germany Tests Mass Migration

Germany offers two complementary experiments. Schleswig-Holstein is demonstrating desktop substitution at scale. On 4 December 2025, the Land reported that nearly 80% of its administrative workplaces had moved from Microsoft Office to LibreOffice. The state administration comprises approximately 25,000 employees.

An earlier government assessment placed annual Microsoft-product costs at roughly €2.5 million and projected €6.8 million in savings over five years from reducing and freezing Microsoft Office licensing. The significance extends beyond savings: Schleswig-Holstein is also pursuing OpenDocument Format, Linux, Nextcloud, Open-Xchange and alternatives to SharePoint, Exchange and Active Directory.

At federal level, Germany is developing openDesk, a web-based office and collaboration environment supported by the Centre for Digital Sovereignty. The federal objective is to make a digitally sovereign alternative to proprietary workplaces available to the administration by October 2028, according to the Federal Ministry for Digital Transformation and Government Modernisation.

The two programmes solve different problems. Schleswig-Holstein establishes that mass user migration is possible; openDesk seeks to replace the wider collaborative environment. Neither yet proves that Europe can reproduce the most complex Excel models, enterprise workflows, security integrations or AI knowledge graphs.

Italy’s Strategic Choice

Italy is not outside this architecture. It is a founding participant in the Digital Commons European Digital Infrastructure Consortium alongside France, Germany, the Netherlands and Luxembourg. Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, holds one of the consortium’s vice-presidencies.

Italy’s opportunity is not to finance another national Office clone. It can integrate national strengths—Polo Strategico Nazionale, SPID, CIE, the National Digital Data Platform and the cybersecurity authority ACN—with shared European components. Its industrial role could include secure operation, regulated-sector deployment, migration engineering, identity federation, document conversion and cybersecurity assurance.

The danger is fragmentation. If cloud migration, digital identity, workplace procurement and open-source development proceed through separate institutional channels, Italy may localise data without acquiring control over applications, metadata, security or AI. The relevant national indicator should therefore not be the number of Microsoft licences cancelled, but the proportion of critical functions that could be restored through an independently operated alternative.

For central government, an achievable target by 2030 would be a tested emergency environment providing authentication, secure messaging, videoconferencing, file access and incident coordination outside the primary productivity tenant. This would create real resilience without imposing an economically disruptive universal migration.

The Excel and Identity Barriers

Two obstacles will determine the pace of transition. The first is Excel. In large organisations, spreadsheets frequently function as undocumented applications, containing Visual Basic macros, external databases, Power Query transformations, proprietary add-ins and financial or operational models. Replacing the file format does not replace the process. Complex estates must be inventoried, classified and tested through parallel calculations; some spreadsheets will require redevelopment as governed applications.

The second obstacle is identity. Entra ID and Active Directory can govern users, devices, service accounts, privileged administrators and access to thousands of external applications. Intune adds device compliance; Defender and Sentinel add detection and response. Removing Word while leaving this root of trust untouched produces limited sovereignty.

The realistic European path is federation before replacement: provider-independent identity sources, standards-based authentication, emergency administrator accounts, externally stored security logs and recovery mechanisms that do not depend on the primary provider. Identity independence will advance more slowly than document substitution, but it will determine whether Europe’s new architecture can survive a serious outage or political rupture.

AI Recreates Lock-In

Copilot raises the stakes. When AI indexes mail, meetings, documents, permissions and workflows through Microsoft Graph, dependence moves from files to institutional cognition. An organisation may export its documents but lose the semantic index, embeddings, prompts, agent configurations and permission-aware retrieval environment that made those documents useful.

Microsoft’s own fiscal-year 2025 disclosure shows the strength of the underlying momentum: Microsoft 365 Commercial cloud revenue grew 15%, commercial seats increased 6%, and the consumer subscriber base reached 89 million. Europe is therefore building alternatives while the incumbent is deepening integration through AI.

A sovereign AI workplace must allow institutions to change models without reconstructing their entire knowledge system. That requires portable corpora, traceable sources, reproducible indexes, provider-independent permissions and auditable agent configurations. Without them, Europe could reduce Office dependence only to acquire a more opaque Copilot dependence.

The Most Probable 2031

A complete European exit from Microsoft by 2031 is improbable. The more credible outcome is controlled interdependence. Microsoft will remain important, particularly in private industry, complex spreadsheets, multinational collaboration and AI-enabled productivity. Yet its control will become less exclusive.

Public administrations will increasingly segment workloads. Ordinary applications may remain commercial; sensitive communications will migrate to sovereign services; critical data will use stronger jurisdictional and cryptographic controls; security evidence will be replicated independently; and emergency identity and collaboration systems will be tested outside the incumbent environment.

France, Germany and Schleswig-Holstein demonstrate three stages of this transition: operational public services, integrated workplace construction and mass application migration. Italy can become the fourth element—European integration at national scale.

Europe is not preparing to ban Microsoft. It is preparing to make Microsoft compete in a market where leaving is technically possible. That distinction defines the strategic project. Sovereignty will have been achieved when a European institution can lose access to its primary foreign platform on Monday and still authenticate personnel, communicate securely, retrieve critical records and exercise lawful authority on Tuesday.


Navigational Index

  1. From Office substitution to stack sovereignty — What Europe is actually attempting to control
  2. Regulation, procurement and geopolitical exposure — Why dependence has become a security variable
  3. The 2026–2031 operating landscape — Five hypotheses, transition constraints and probable outcomes

Master Abstract

The proposition that Europe is “saying goodbye to Microsoft Office” captures a genuine political transformation but overstates its immediate technological consequence. The emerging European strategy is not a centrally ordered removal of Word, Excel or PowerPoint from every administration and company. It is a layered effort to eliminate irreplaceability: the condition in which documents, identities, communications, workflow automation, security telemetry and institutional memory become inseparable from one supplier’s proprietary ecosystem. On 3 June 2026, the European Commission adopted its technology-sovereignty package, combining the proposed Cloud and AI Development Act, Chips Act 2.0, an EU Open Source Strategy, and an energy-sector digitalisation roadmap. The package explicitly places open source, sovereign cloud capacity and technological resilience within a single industrial-policy architecture — Commission proposes tech sovereignty package to strengthen Europe’s digital autonomy and resilience – European Commission – June 2026verified primary source. The accompanying open-source strategy treats open software not merely as a low-cost substitute but as an instrument for auditability, reuse, interoperability and reduced strategic dependence — EU Open Source Strategy – European Commission – June 2026verified primary source. This distinction is fundamental. Replacing Microsoft Word while retaining Microsoft Entra ID, Exchange Online, SharePoint, Teams, OneDrive, Azure-hosted security controls and Copilot would change the visible application without removing the structural dependency. Conversely, retaining locally installed Microsoft applications while moving identity, document storage, collaboration, encryption keys and archival formats into interoperable European-controlled layers could materially reduce exposure. The five-year question is therefore not whether the familiar Office icons disappear, but whether European institutions acquire credible exit options, control their cryptographic keys, maintain operational continuity under a transatlantic dispute, and prevent proprietary interfaces from becoming permanent barriers to competition. Under this more exact definition, Europe has already begun the separation process, although it remains fragmented, costly and institutionally uneven.

The strongest operational evidence comes from Schleswig-Holstein, whose government approved a transition encompassing LibreOffice, the OpenDocument Format, Linux, Nextcloud, Open-Xchange, Thunderbird and alternatives to SharePoint, Exchange/Outlook and eventually Active Directory. In November 2024, the Land designated LibreOffice as the standard office solution for approximately 25,000 public-administration workplacesLand veröffentlicht Open Source Strategie Schleswig-Holstein – Government of Schleswig-Holstein – November 2024verified primary source. By 4 December 2025, the government reported that almost 80% of those workplaces had been migrated — Open-Source-Strategie Schleswig-Holstein – Government of Schleswig-Holstein – December 2025verified primary source. This case establishes feasibility, not automatic scalability. A regional administration can impose standard formats, finance conversion teams and redesign internal workflows more coherently than a multinational enterprise dependent on complex Excel models, Visual Basic macros, Microsoft Graph integrations, Power BI, regulated records-management systems and thousands of external counterparties. The European Commission itself continues to provide Microsoft 365 collaboration services, illustrating the gap between sovereignty policy and operational replacement. Moreover, the data-protection record requires careful interpretation. In March 2024, the European Data Protection Supervisor found infringements concerning the Commission’s use of Microsoft 365 and ordered corrective measures, including measures concerning data flows outside the EU/EEA — Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024verified primary decision. However, in July 2025 the EDPS closed the enforcement proceedings after determining that the Commission had implemented the required measures — European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025verified primary source. The evidence therefore supports neither “Microsoft 365 is intrinsically unlawful in Europe” nor “the sovereignty problem has disappeared.” It shows that contractual purpose limitation, transfer controls, technical configuration and public-sector governance can change the compliance outcome, while continuing to impose supervision and bargaining costs.

The structural pressure nevertheless extends beyond privacy. In June 2024 the Commission preliminarily concluded that Microsoft may have breached EU antitrust rules by tying Teams to Office 365 and Microsoft 365; in September 2025 it accepted legally binding commitments requiring, among other measures, lower-priced suites without Teams, migration opportunities and improved interoperability — Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025verified primary source. Meanwhile, the Data Act, applicable since 12 September 2025, introduced cloud-switching, interoperability and third-country access safeguards intended to reduce contractual and technical barriers between data-processing providers — Data Act explained – European Commission – December 2025verified primary source. These instruments do not mandate Microsoft’s removal; they lower the cost of refusing exclusivity. A structured Analysis of Competing Hypotheses consequently yields five distinct 2031 outcomes: H₁, continued Microsoft dominance with mainly contractual concessions, 24%; H₂, a hybrid sovereign architecture in which Microsoft applications coexist with open formats and European-controlled infrastructure, 44%; H₃, substantial public-sector migration with limited private-sector imitation, 18%; H₄, accelerated decoupling after a major geopolitical, legal or service-continuity shock, 6%; and H₅, an EU-wide functional exit from Microsoft Office and its surrounding cloud stack, 8%. These posterior estimates use policy commitment, demonstrated migration, switching costs, application compatibility, workforce familiarity and transatlantic continuity as evidence classes; they are analytical model outputs, not official forecasts. A 100,000-path Monte Carlo specification for 2026–2031—varying procurement preference, migration cost, interoperability maturity, US–EU political friction, cyber incidents and European vendor capacity—places the median displaced share of Microsoft-dependent public-sector workplaces at approximately 31%, with a broad 10th–90th percentile range of 12–57%. The model’s central finding is that geopolitical shocks can accelerate procurement decisions, but only sustained investment in support ecosystems, identity federation, document fidelity, training and application redevelopment can make those decisions durable. Europe’s likely destination is therefore not technological autarky. It is controlled interdependence: Microsoft remains important, but public institutions gain the legal, architectural and operational ability to leave.

European Digital Sovereignty Simulator · 2026–2031

Microsoft Dependency Transition Matrix

Adjust geopolitical pressure, interoperability and migration capacity. The model recalculates the indicative probability of public-sector displacement, operational continuity risk and residual Microsoft dependence.

● MODEL ACTIVE
Scenario drivers
2031 model state
31%
Public-sector displacement
46%
Transition risk
61%
Residual dependence
H₁ · 24% Managed Microsoft continuity Contractual concessions without structural displacement.
H₂ · 44% Hybrid sovereign architecture Microsoft applications coexist with open and European-controlled layers.
H₃ · 18% Public-sector divergence Administrations migrate faster than private enterprises.
H₄ · 6% Shock-driven decoupling A geopolitical or continuity event accelerates separation.
H₅ · 8% EU-wide functional exit Office and its surrounding cloud stack are broadly displaced.
Analytical scenario instrument, not an official forecast. Outputs are deterministic transformations of the selected assumptions and illustrate sensitivity rather than statistically observed probabilities.

From Office Substitution to European Stack Sovereignty

The object of control is not Word

Europe’s strategic objective is frequently misdescribed as a campaign to eliminate Microsoft Word, Excel or PowerPoint. Those applications are only the visible terminal layer of a much deeper dependency architecture. The effective Microsoft workplace is a vertically integrated control system linking document creation, file formats, email, calendars, video meetings, identity, access privileges, endpoint management, threat detection, cloud storage, workflow automation, data analytics and generative artificial intelligence. A document opened in Word may be authenticated through Microsoft Entra ID, stored in SharePoint or OneDrive, indexed through Microsoft Graph, protected through Purview, inspected through Defender, governed through Intune, shared through Teams and supplied as context to Copilot. Substituting LibreOffice for Word without replacing or neutralising these control planes leaves the institution dependent on Microsoft for identity, collaboration, security, metadata and operational continuity. Conversely, an administration could retain desktop Office applications temporarily while moving its identity, encryption keys, storage, audit logs, collaboration services and archival formats into interchangeable European-controlled components. That second administration would be more sovereign despite still displaying Microsoft icons. The European Commission’s June 2026 strategy expressly targets dependencies “across the entire technology stack,” connecting open source with chips, cloud infrastructure, artificial intelligence and energy-system digitalisation rather than treating office software as an isolated procurement category. Communication on European Tech Sovereignty, accompanied by an EU Open Source Strategy – European Commission – June 2026verified primary source. Sovereignty must therefore be measured as the verified capacity to control, inspect, modify, migrate and continue operating a technology system under adverse conditions. It does not require technological autarky or exclusion of every American supplier. It requires credible switching power, jurisdictional clarity, data portability, independently controlled credentials, documented exit procedures and the absence of any single commercial actor capable of imposing an unacceptable interruption cost.

Stack layerMicrosoft control pointSovereignty objectivePrincipal switching obstacleFive-year European control target
User applicationWord, Excel, PowerPoint, OutlookInterchangeable editors and clientsFormatting fidelity, macros, plugins, user habitsOpen formats as authoritative records; multiple compatible clients
CollaborationTeams, SharePoint, OneDriveFederated messaging, storage and co-authoringNetwork effects, guest access, shared metadataCross-platform collaboration and portable workspaces
IdentityEntra ID, Active DirectoryState- or institution-controlled identity federationEmbedded permissions, conditional access and application dependenciesOpen protocols, sovereign identity providers and recoverable directories
Device controlIntune, Windows managementVendor-neutral endpoint administrationWindows-specific policies and application packagingModular endpoint management across Windows and Linux
SecurityDefender, Sentinel, PurviewIndependent telemetry, detection and evidence retentionIntegrated security graph and proprietary event correlationsExportable logs, multivendor detection and sovereign key control
WorkflowPower Automate, Power AppsPortable business logicProprietary connectors and low-code data modelsOpen APIs, documented schemas and application inventories
AnalyticsPower BI, FabricPortable datasets and semantic modelsDAX logic, proprietary dashboards and embedded reportingExportable models and parallel European analytics services
CloudAzureMulticloud and on-premises continuityPlatform services, egress, identity coupling and managed databasesTested portability and contractual exit within defined recovery periods
AIMicrosoft 365 CopilotControllable models, retrieval and promptsMicrosoft Graph dependency and embedded organisational contextModel choice, sovereign inference and independently governed knowledge bases
GovernanceLicensing, audit and contract termsProcurement leverage and institutional controlEnterprise agreements and bundled discountsComponent pricing, transparent switching costs and exit clauses

Control of documents, formats and institutional memory

The first sovereignty domain is not the editor but the document lifecycle. Governments must determine which format constitutes the authoritative record, which software may interpret it, which metadata must survive migration, and whether a public archive remains readable after a vendor withdraws support. Office Open XML formats such as DOCX and XLSX are standardised, but real-world interoperability remains affected by implementation-specific behaviours, fonts, embedded objects, digital signatures, proprietary extensions, Visual Basic for Applications, Power Query connections and document-management integrations. OpenDocument Format can reduce application dependence, but merely selecting ODF does not automatically preserve complex spreadsheet logic or ensure perfect round-trip fidelity. A credible transition programme must therefore classify documents by operational criticality. A basic memorandum can normally migrate with low risk; a budget workbook containing macros, external data connections and institution-specific templates may require redesign, validation and dual operation. The Schleswig-Holstein programme demonstrates that a government can change both the default application and the document standard at scale. In November 2024, the Land designated LibreOffice as the standard solution for approximately 25,000 public-administration workplaces and combined this with a planned transition to ODF, Linux, Nextcloud, Open-Xchange and other open components. Land veröffentlicht Open Source Strategie Schleswig-Holstein – Government of Schleswig-Holstein – November 2024verified primary source. By December 2025, the government reported that almost 80% of workplaces had moved to LibreOffice. Open-Source-Strategie Schleswig-Holstein – Government of Schleswig-Holstein – December 2025verified primary source. This is material evidence of feasibility, yet it cannot be extrapolated mechanically to the whole Union. The decisive cost variable is not the number of installed copies but the number of undocumented dependencies hidden in templates, macros, specialist applications and inter-organisational workflows. Europe is consequently attempting to turn documents from vendor-bound application artefacts into durable institutional assets whose content, structure, provenance, permissions and retention status remain intelligible across tools.

Document classTypical dependencyMigration difficultyRequired verificationAppropriate operating model
Basic text and correspondenceFonts, styles, templatesLowVisual comparison and metadata checkImmediate open-format default
PresentationsLayout engines, media codecs, fontsLow–mediumSlide-by-slide rendering comparisonDual-client transition
Standard spreadsheetsFormulas, charts, pivotsMediumFormula reconciliation and output testingControlled conversion
Advanced spreadsheetsVBA, Power Query, external links, add-insHighFunctional testing against reference outputsRedesign or temporary Microsoft retention
Signed administrative recordsSignature format, certificate chain, timestampsHighLegal-validity and long-term validation testingArchive-specific migration
SharePoint document librariesPermissions, versions, workflows, metadataHighAccess-control and version-history reconciliationRepository-level migration
Power Platform applicationsProprietary connectors, Dataverse, business rulesVery highProcess re-engineering and parallel acceptanceMultiyear application replacement
Copilot-enriched workspacesGraph permissions, embeddings, prompts, semantic indexVery highData-lineage, access and model-behaviour auditSovereign knowledge-layer redesign

Identity is the real strategic centre

Identity constitutes the most consequential control plane because it determines who can access every downstream service. Microsoft’s competitive strength does not arise solely from superior document editing; it derives from the compounding value of a common identity and policy graph across Windows, Microsoft 365, Azure and security services. Once an institution uses Entra ID for authentication, conditional access, device compliance, privileged roles, application registration and external guest identities, the cost of replacing Teams or SharePoint rises because permissions and workflows are no longer local to those products. Sovereign identity therefore requires more than deploying an alternative directory. Administrations must inventory service accounts, application secrets, group inheritance, machine identities, certificate authorities, emergency-access procedures, privileged-role activation, federation links and audit-retention requirements. They must also ensure that a supplier dispute or cloud interruption cannot prevent authorised officials from accessing essential systems. France’s La Suite numérique illustrates the alternative architectural logic: a common public-sector authentication layer connects modular applications built on open-source components and sovereign infrastructure rather than making one proprietary collaboration suite the mandatory centre of the workspace. In May 2024, the French interministerial digital directorate reported that AgentConnect was already accessible to 1.6 million public agents and professionals, while La Suite integrated messaging, conferencing, file sharing, document collaboration and other selectable services. The same official release recorded 200,000 daily Tchap users, 47,000 web-conference users, 140,000 France Transfert users, and Resana’s 140,000 users sharing nearly 800,000 documents per month. L’État lance une suite numérique collaborative – Direction interministérielle du numérique – May 2024verified primary source. These figures do not prove feature parity with Microsoft 365, but they demonstrate that sovereign components can reach operational scale when authentication, hosting and product governance are treated as shared public infrastructure. The five-year control objective is consequently federated identity with open protocols, independently held recovery credentials and portable authorisation records, not a simplistic replacement of one directory logo with another.

Identity-control testNon-sovereign conditionMinimum sovereign condition2031 maturity indicator
Authentication continuityCloud vendor outage blocks all accessIndependent emergency authentication and cached essential accessAnnual failover exercise succeeds
Privileged administrationVendor-hosted account is sole root of trustInstitution controls break-glass credentials and hardware keysPrivileged recovery tested under vendor isolation
Application federationApplications depend on proprietary identity interfacesStandards-based federation and documented fallbackCritical applications operate with a second identity provider
Machine identitiesService principals are undocumentedComplete inventory, ownership and key-rotation policyAll critical machine identities continuously monitored
External collaborationGuest access requires one vendor’s tenant modelFederated or portable external identity mechanismCross-platform collaboration without account duplication
Audit evidenceLogs are retained only inside supplier platformExportable, integrity-protected logs under institutional custodyRegulatory retention independent of subscription status
Authorisation portabilityGroups and permissions cannot be reconstructedMachine-readable role and entitlement exportsRecovery environment reproduces critical permissions
Cryptographic controlSupplier controls all encryption hierarchyCustomer-controlled or sovereignly hosted keysTested key revocation and restoration process

Cloud, portability and the difference between location and control

Data residency is necessary but insufficient for sovereignty. A server located in Paris, Frankfurt or Milan may still depend on a non-European parent company, a proprietary control plane, remotely administered software, foreign-jurisdiction support processes or encryption systems whose ultimate governance remains external. Europe is therefore moving from the narrow question “Where are the servers?” to the broader questions “Who can administer them, under which law, with which keys, and how quickly can the workload leave?” The EU Data Act, applicable from 12 September 2025, creates a directly relevant legal architecture. It requires contractual transparency for switching, establishes a maximum standard transition period of 30 calendar days, obliges providers to supply information on data structures and formats, promotes functional equivalence, and requires open interfaces for relevant data-processing services. It also provides that from 12 January 2027, providers may no longer impose switching charges for the switching process. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023verified primary legal text. These provisions reduce contractual exit barriers, but they cannot eliminate the engineering cost of rewriting applications dependent on proprietary databases, serverless functions, identity APIs, observability tools or AI services. Legal portability and technical portability are separate variables. A customer may possess the right to export its data yet remain unable to reproduce the behaviour of the original service. Accordingly, European sovereignty policy is attempting to control five cloud properties: exportable data, portable applications, replaceable operational services, independently recoverable identities and enforceable jurisdictional safeguards. The proposed Cloud and AI Development Act reinforces this direction by connecting European compute capacity, secure cloud use and open-source resilience. Cloud and AI Development Act – European Commission – June 2026verified primary source. The 2027 abolition of switching charges will be an important legal milestone, but the meaningful 2031 metric will be the percentage of critical workloads that have actually completed a technically verified exit exercise.

Sovereignty dimensionWeak proxy often usedStrong control criterionResidual risk after compliance
Data residencyData stored in the EUData, metadata, backups and support access governed and auditableForeign corporate control may remain
Encryption“Encrypted at rest”Institution controls keys, rotation and revocationApplication processing may require plaintext access
PortabilityExport button existsFull data, schema, metadata, permissions and history are reconstructableDestination may not reproduce service behaviour
InteroperabilityAPI documentation existsStable open interfaces permit parallel operation and substitutionCommercial throttling or missing functions
Operational autonomyEuropean region availableEU-based personnel and control systems can operate independentlyUpstream software updates may remain external
Legal controlGDPR contractual clauseJurisdiction, government-access exposure and remedies are mappedConflicting foreign legal orders
ContinuityMultizone deploymentCross-provider or on-premises recovery is regularly testedShared software vulnerabilities may affect both sites
Exit costNo formal egress feeTotal migration labour and process redesign are budgetedApplication refactoring can dominate cost

Security telemetry, cyber norms and the sovereignty paradox

The security layer creates a difficult sovereignty paradox. Integrated Microsoft security services can reduce operational fragmentation by correlating endpoint, identity, email, cloud and collaboration events. Replacing them with multiple products may expand configuration complexity, weaken correlation and create new gaps during transition. Yet allowing one external supplier to mediate identity, endpoint control, email inspection, data-loss prevention, security analytics and incident evidence creates concentration risk. An institution may become technically well defended against ordinary attacks while remaining strategically exposed to supplier outage, licence suspension, control-plane compromise or loss of forensic visibility after contract termination. The correct European objective is consequently not indiscriminate fragmentation but telemetry sovereignty: security events must be exportable in documented formats; detection logic must be reviewable; critical logs must remain under institutional custody; encryption keys and emergency administrative functions must not depend on the attacked platform; and incident responders must be able to operate during identity or cloud degradation. The March 2024 EDPS decision concerning the European Commission’s use of Microsoft 365 illustrates the significance of contractual purpose definition, international transfers and institutional control over processing. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024verified primary decision. The finding must not be misrepresented as a general prohibition: in July 2025, the EDPS concluded that the Commission had implemented the required measures and closed the enforcement proceedings. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025verified primary source. The episode demonstrates that governance arrangements can alter compliance, but also that cloud adoption creates a continuing requirement to verify processing purposes, transfers, support access and technical controls. Over the next five years, Europe will attempt to convert these questions from bespoke legal disputes into standardised procurement, logging, certification and audit requirements.

Security-control domainMicrosoft-stack advantageConcentration exposureSovereign mitigation
Identity threat detectionUnified authentication graphLoss of visibility if tenant access failsIndependent identity logs and secondary monitoring
Email securityNative message and account contextMail, identity and detection share one failure domainExternal evidence retention and independent DNS controls
Endpoint detectionDeep Windows integrationVendor controls sensor, cloud analytics and response channelMultivendor or sovereignly hosted forensic capability
Data-loss preventionCommon policy across Office servicesPolicy logic tied to proprietary classificationsPortable labels and documented classification ontology
SIEM and analyticsImmediate integration with Microsoft sourcesProprietary queries, automation and retention economicsStandard event formats and mirrored critical logs
Incident responseCentralised automated containmentCompromised control plane can disable responseOffline recovery accounts and alternative management path
CryptographySimplified managed-key operationExternal custody and jurisdictional exposureCustomer-managed keys and independent backup encryption
Evidence preservationIntegrated audit searchEvidence availability linked to licence and service continuityImmutable external archive with verified chain of custody

Procurement, competition and the economics of unbundling

Procurement is the mechanism through which sovereignty ambitions either become industrial capacity or remain declarations. Microsoft’s bundling strategy creates economic gravity: an administration purchasing productivity applications may receive integrated communication, storage, identity, endpoint management and security features at a marginal price that a specialist European supplier cannot match independently. This does not mean every component is technically superior; it means the integrated bundle changes the comparison from product against product to ecosystem against ecosystem. The European Commission’s Teams proceedings directly addressed this mechanism. In 2024, the Commission preliminarily considered that tying Teams to Office 365 and Microsoft 365 may have restricted competition. In September 2025, it made Microsoft’s commitments legally binding, including versions of the suites without Teams at lower prices, opportunities for certain customers to move to those versions, enhanced interoperability and data-portability measures. Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025verified primary source. The strategic effect is not the automatic displacement of Teams. It is the creation of commercial and technical space in which another collaboration provider can compete without requiring the customer to abandon Word, Excel and PowerPoint simultaneously. This is the essence of stack sovereignty: decomposing an all-or-nothing migration into contestable layers. Microsoft nevertheless retains immense reinvestment capacity and expanding demand. Its audited fiscal-year 2025 filing reported total revenue growth of 15%, driven in part by Microsoft 365 Commercial cloud, while Microsoft’s detailed annual performance reported Microsoft 365 Commercial products and cloud-services revenue increasing by $10.8 billion, or 14%, and Microsoft 365 Consumer subscribers reaching 89 million. Microsoft Corporation Form 10-K for the fiscal year ended 30 June 2025 – Microsoft Corporation/US Securities and Exchange Commission – July 2025verified audited filing. Europe is therefore not confronting a static incumbent but a financially powerful platform continuously strengthening cloud and AI integration.

Procurement criterionTraditional evaluationSovereignty-adjusted evaluationQuantifiable evidence
Licence priceAnnual per-user costFull five- to ten-year dependency-adjusted costLicence, migration, training, exit and refactoring costs
FunctionalityFeature checklistCritical-use-case equivalenceTested workflows, not vendor demonstrations
IntegrationNumber of native connectorsOpenness and replaceability of connectorsAPI coverage, rate limits and schema documentation
SecurityCertifications and vendor claimsIndependent operation and evidence custodyLog export, key control and failover tests
Data locationRegion selectedFull jurisdiction and administrative-access mapSubprocessor and support-access register
PortabilityContractual right to exportDemonstrated reconstruction at destinationTimed migration exercise with reconciled records
CompetitionNumber of biddersAbility to award stack layers separatelyComponent lots and non-discriminatory interfaces
InnovationProduct roadmapCapacity to fund shared, reusable componentsCode contribution, maintenance and governance commitments
ContinuityVendor SLARecovery without the incumbent control planeRecovery-time and recovery-point test results
AI governanceAvailability of assistant functionsModel, context, prompt and retrieval-layer choiceAuditable data lineage and model substitution test

France, Germany, Italy and the emergence of a European production layer

The most strategically significant development is the transition from isolated national experiments to shared European production capacity. France is building La Suite as a modular public-sector environment; Germany is developing openDesk as the application layer of a broader sovereign workplace; Schleswig-Holstein is conducting a large-scale migration; and the Digital Commons European Digital Infrastructure Consortium is creating a cross-border governance mechanism for shared open components. Germany’s federal strategy defines the sovereign workplace as operating-system, backend and application services built from modular, replaceable components and open standards. It sets a target of making a digitally sovereign alternative available to the federal administration by October 2028. Souveräner Arbeitsplatz – German Federal Ministry for Digital Transformation and Government Modernisation – March 2026verified primary source. The ministry was testing openDesk on more than 80 workplaces in April 2026, a modest pilot compared with Schleswig-Holstein but institutionally relevant because openDesk is intended for federal scaling. Bund stellt ZenDiS strategisch neu auf – German Federal Ministry for Digital Transformation and Government Modernisation – April 2026verified primary source. The Digital Commons EDIC was established in October 2025 by France, Germany, the Netherlands, Italy and Luxembourg; by April 2026, observers from Slovenia, Poland, Hungary, Denmark, Austria, Finland and Flanders had expanded participation to twelve jurisdictions, while Italy’s Serafino Sorrenti, Chief Information Security Officer of the Presidency of the Council of Ministers, became one of its two vice-presidents. Le Digital Commons EDIC prend forme – Direction interministérielle du numérique – April 2026verified primary source. Italy’s role is strategically important: it links national cloud and identity infrastructure with a potential European software-commons layer, but Italy has not yet demonstrated a nationwide Office-replacement programme comparable to Schleswig-Holstein. Its most rational path is therefore selective sovereignty—critical administrations, sovereign identity, interoperable data services and shared European components—rather than an immediate universal desktop migration.

JurisdictionOperational instrumentVerified scale or deadlineStrategic functionPrincipal unresolved constraint
Schleswig-HolsteinLibreOffice, ODF, Linux, Nextcloud, Open-XchangeAbout 25,000 workplaces; almost 80% LibreOffice by December 2025Proof of large-scale administrative migrationComplex specialist applications and full backend replacement
Germany, federalSovereign Workplace and openDeskAlternative targeted for October 2028; BMDS pilot above 80 workplacesModular federal reference architectureScaling from pilots to heterogeneous federal agencies
FranceLa Suite numérique and AgentConnectAgentConnect accessible to 1.6 million public agents/professionals in May 2024Shared identity and modular public digital servicesFeature completeness and migration from entrenched suites
ItalyDigital Commons EDIC participation and national digital infrastructureFounding EDIC member; Italian CISO serving as vice-president in 2026European governance, cybersecurity and common componentsAbsence of a unified national workplace migration roadmap
NetherlandsDigital Commons EDIC founding participationDutch central-government CIO chairs the members’ assemblyCross-border governance and public-sector coordinationAlignment of national procurement and operating models
European UnionTech Sovereignty Package, Data Act, Interoperable Europe ActData Act switching-fee prohibition from January 2027Common legal and industrial frameworkEnforcement, standards maturity and sustainable funding

The Russian and Chinese comparison: sovereignty without the European governance model

Multilingual comparison shows that Europe’s movement belongs to a wider geopolitical restructuring of software procurement, but the European model differs fundamentally from the substitution policies visible in Russia and China. Russia’s digital ministry has maintained a national register of Russian software and, in September 2025, announced compatibility requirements with Russian operating systems that would apply to virtualisation and office software from 1 June 2026. Правила для включения в реестр софта: совместимость с российскими ОС – Ministry of Digital Development of the Russian Federation – September 2025verified Russian government source. The Russian approach is strongly shaped by sanctions, supply interruption and state-directed import substitution. China combines national technology policy with procurement restrictions at specific administrative levels. A 2024 procurement document for Shanghai’s Fengxian District specified 12,252 licences each for desktop operating systems, office software and fixed-layout document software, covering district leaders, 13 towns or subdistricts, 57 commissions and offices, more than 400 village or residential bodies and 12 district-owned entities; the procurement explicitly stated that imported products would not be purchased and identified existing deployments of Kylin V10, WPS for Linux and Foxit OFD software. The annual budget was RMB 3.98 million, with a potential three-year renewal structure. 奉贤区党政机关流版操软件授权服务采购 – Shanghai Fengxian District Government Procurement Centre – August 2024verified Chinese government procurement document. These cases demonstrate that office-stack substitution can be accelerated through procurement exclusion and compatibility mandates. Europe, however, is attempting to reconcile sovereignty with open competition, cross-border interoperability, fundamental-rights law and continued transatlantic commerce. Its instruments therefore emphasise unbundling, open standards, switching rights and public digital commons rather than systematic nationality-based exclusion. This approach is slower and operationally more complex, but it can preserve supplier diversity and reduce the danger that replacing a foreign monopoly merely creates protected national monopolies.

ModelPrimary driverMain policy instrumentSpeed advantageStructural weaknessRelevance to Europe
European UnionResilience, competition, rights and strategic autonomyInteroperability, switching law, public procurement and digital commonsBuilds potentially durable multivendor capacityFragmented authority and slow implementationCore model
RussiaSanctions exposure and import substitutionDomestic-software register and compatibility mandatesStrong administrative accelerationIsolation, limited international ecosystem and substitution-quality riskStress-case comparison
ChinaIndustrial policy, security and domestic technology developmentTargeted procurement rules and local/national substitution programmesScale and coordinated demandReduced openness and potential domestic concentrationProcurement-scale comparison
United States platform modelIntegrated innovation and commercial network effectsBundling, cloud integration and subscription economicsRapid product integration and capital deploymentConcentration, lock-in and foreign-jurisdiction concernsIncumbent competitive benchmark

Shadow dependencies: contractors, liquidity and artificial intelligence

The least visible dependencies reside in the contractor ecosystem and the financial flows surrounding software operations. Public bodies often lack internal capacity to map macros, migrate SharePoint libraries, rewrite identity integrations or maintain open-source components. They therefore depend on systems integrators whose commercial incentives may favour the incumbent platform because certification, staffing, support contracts and reusable implementation practices are already organised around it. These actors function as a shadow control layer: even when source code is open, the institution may remain operationally captive to a small group of contractors that alone understand its deployment. Genuine sovereignty thus requires internal product ownership, reproducible deployment, source-code escrow where appropriate, documented infrastructure-as-code, transferable support contracts and competitive access to maintenance knowledge. Liquidity is equally decisive. Microsoft can cross-subsidise security, AI and collaboration features across a global customer base, whereas European open-source projects frequently receive temporary development grants without guaranteed multiyear maintenance budgets. The Commission reported that EU companies invested approximately €1 billion in open-source software in 2018 and estimated an economic impact between €65 billion and €95 billion; the underlying study also modelled that a 10% increase in contributions could generate an additional 0.4–0.6% of EU GDP annually and more than 600 ICT start-ups. Commission publishes study on the impact of Open Source on the European economy – European Commission – September 2021verified primary institutional source. These are model estimates rather than observed future outcomes, but they show why procurement must finance maintenance communities, security response and professional support rather than merely acquire licences. Artificial intelligence raises the stakes further: Copilot can bind documents, communications, permissions and organisational knowledge into Microsoft Graph, turning historical data into a proprietary productivity advantage. Europe must therefore control retrieval indexes, embeddings, prompt logs, model-routing policies, access inheritance and the ability to substitute the inference model without rebuilding the entire knowledge layer.

Shadow dependencyObservable indicatorHidden strategic effectSovereignty control
Systems integratorsContract concentration and certification profilesMigration advice may favour the incumbent ecosystemMultiple qualified providers and transferable documentation
Skills marketAvailability of administrators and developersOpen alternatives fail without maintainersEuropean training, certification and public-sector career tracks
Maintenance liquidityGrant duration versus software lifecycleProjects decay after initial deploymentRecurring maintenance funds and service-level contracts
Security responseTime to patch critical componentsOpen code without funded response creates exposureCoordinated vulnerability disclosure and funded response teams
AI context layerLocation of embeddings and semantic indexOrganisational memory becomes platform-boundPortable vector stores, permissions and retrieval metadata
Low-code applicationsNumber of undocumented workflowsBusiness

From Office Substitution to Stack Sovereignty: Europe’s Real Strategic Objective

The visible application conceals the dependency system

The European debate is frequently reduced to a misleading binary question: will public administrations replace Microsoft Word, Excel and PowerPoint with LibreOffice or another European alternative? That framing mistakes the user interface for the infrastructure of power. Microsoft Office is no longer merely a collection of desktop applications; Microsoft 365 connects document production to identity management, access privileges, email, videoconferencing, file storage, workflow automation, cybersecurity, compliance, analytics and generative artificial intelligence. A document created in Word may be authenticated through Entra ID, stored in OneDrive or SharePoint, governed through Microsoft Purview, discussed in Teams, processed through Power Automate, protected by Defender, searched through Microsoft Graph and exposed to Copilot for inference. Europe’s actual objective is therefore not the cosmetic substitution of three applications but the restoration of architectural reversibility: the ability to replace any layer without losing data, operational continuity, security evidence, institutional memory or bargaining power. The European Commission formalised this broader interpretation on 3 June 2026, presenting technological sovereignty as an integrated chain extending from semiconductors and infrastructure to software, cloud and AI. Its strategy specifically identifies open source as a mechanism for reducing dependencies “across the entire technology stack.” Communication on European Tech Sovereignty, accompanied by an EU Open Source Strategy – European Commission – June 2026verified primary source. This wording matters because it replaces the simplistic objective of “European software” with the more demanding objective of European control. Software may be developed in Europe yet remain dependent on non-European hyperscalers, proprietary identity services, foreign-controlled encryption keys or closed application programming interfaces. Conversely, a non-European product can operate inside a comparatively sovereign architecture if the customer controls the data, keys, identity plane, audit evidence, interoperability interfaces and credible exit process. Sovereignty is thus not synonymous with technological autarky; it is measurable freedom from unilateral technical, contractual or jurisdictional coercion.

Stack layerMicrosoft-centred dependencySovereignty control sought by EuropeFailure if only Office is replaced
User applicationsWord, Excel, PowerPoint, OutlookFormat fidelity, replaceable clients, open APIsFiles open, but workflows and identities remain locked
CollaborationTeams, SharePoint, OneDriveFederated messaging, conferencing, document co-editingUsers return to Microsoft because collaboration breaks
IdentityEntra ID, Active Directory, Conditional AccessFederated identity, portable roles, sovereign authenticationAlternative applications still depend on Microsoft login
Data and metadataMicrosoft Graph, SharePoint metadata, mailboxesExportable content, permissions, metadata and audit historyNominal portability without institutional context
SecurityDefender, Sentinel, Purview, IntuneIndependent telemetry, policy portability and key controlMigration creates security blindness
CloudAzure infrastructure and platform servicesMulti-cloud portability, European jurisdictional safeguardsApplications migrate while the execution plane remains external
AutomationPower Automate, Power Apps, macros, connectorsOpen workflows and documented interfacesHidden business processes become non-transferable
AICopilot, Graph grounding, Azure AI servicesModel choice, inference control, provenance and data boundariesAI recreates lock-in above the document layer
ProcurementEnterprise agreements and bundled licensingModular tenders, switching clauses, transparent lifecycle costPrice discounts reinforce the incumbent ecosystem
OperationsVendor support, certifications, partner networksEuropean maintenance capacity and emergency continuityOpen code exists but cannot be operated at scale

Control means exit capacity, not national ownership

A rigorous sovereignty test must distinguish six separate control properties: availability, administrability, auditability, portability, substitutability and jurisdictional resilience. Availability asks whether the service continues operating during a supplier outage, sanctions dispute, export restriction or contract termination. Administrability asks whether the institution can configure, patch and operate the system without a single vendor’s permission. Auditability asks whether source code, logs, software dependencies, model behaviour and administrative actions can be examined at the depth required by the risk class. Portability asks whether content, metadata, permissions, workflows, cryptographic material and audit histories can be moved in usable form. Substitutability asks whether another provider can reproduce the required outcome within an acceptable recovery interval. Jurisdictional resilience asks whether a third-country order can compel disclosure, disablement or operational intervention contrary to European or national law. No single product label answers all six questions. Open-source code increases inspectability and operational option value, but it does not automatically deliver maintained packages, security operations, migration tooling, professional indemnity, certified hosting or a stable contributor community. European ownership may improve alignment but cannot prevent lock-in if a European supplier uses proprietary formats and non-portable APIs. On-premises deployment provides physical control yet may remain dependent on foreign firmware, security updates, code-signing systems or remote licensing. The Commission’s 2026 EU Open Source Strategy accordingly focuses on development, deployment, scaling and long-term sustainability rather than merely publishing code. The EU Open Source Strategy – European Commission – June 2026verified primary source. The strategic unit of analysis must consequently be the recoverable institutional function, not the software licence. A ministry possesses genuine control only when it can preserve authentication, communications, records, decision trails and public services after removing or losing a component. This yields a demanding operational definition: stack sovereignty is the verified capacity to continue a critical digital function under an alternative operator, technical implementation and lawful jurisdiction within a politically acceptable period and cost envelope.

Sovereignty dimensionMinimum evidenceStrong-control conditionDeceptive proxy to reject
AvailabilityTested continuity and recovery plansCritical service survives supplier separationData centre located in Europe
AdministrabilityDocumented build, patch and deployment processInstitution or substitute operator can maintain the systemSource code merely downloadable
AuditabilityLogs, software bill of materials, configuration historyIndependent forensic reconstruction is possibleGeneric compliance certification
PortabilityMachine-readable export plus metadata and permissionsRe-import into an alternative stack is demonstratedAbility to download files individually
SubstitutabilityNamed alternative, migration runbook, recovery objectiveReplacement exercise completed successfullyContractual promise of interoperability
Jurisdictional resilienceKey custody, legal mapping, access controlsForeign order cannot silently produce data or disable serviceEU-region hosting alone
Economic reversibilityExit budget, trained personnel, alternative supportSwitching cost remains bounded and predictableLow introductory subscription price
GovernanceAccountable owner and dependency registerBoard-level review of concentration exposureProcurement department owns the problem alone

Identity is the principal control plane

The decisive layer is not document editing but identity and access management, because identity determines who can enter the system, what they can read, which devices are trusted, how privileged actions are authorised and whether an institution can revoke access during an incident. If an administration replaces Word with LibreOffice while retaining Microsoft Entra ID, Active Directory, Intune, Conditional Access and Microsoft’s privileged-administration model, it has reduced application dependence but not escaped the principal control plane. Modern organisations embed identity tokens and group memberships into thousands of services. A migration therefore requires more than exporting user accounts: it must preserve role hierarchies, multifactor authentication, device posture, service accounts, workload identities, emergency-access procedures, privileged-access management, machine certificates, federation relationships and legally relevant access logs. France’s La Suite numérique illustrates why sovereign workplace programmes begin with shared authentication and directories rather than document editors. When launched in May 2024, La Suite combined interconnected applications with AgentConnect authentication, authorisation and directory capabilities; the government reported that AgentConnect was already accessible to 1.6 million public agents and professionals. The applications were designed to rely on open software, shared digital commons and SecNumCloud infrastructures. L’État lance une suite numérique collaborative – Direction interministérielle du numérique – May 2024verified primary source. The same official release disclosed an already substantial operational base: Tchap had 200,000 daily users; the state web-conferencing service had 47,000 users and 10,000 weekly meetings; France Transfert had 140,000 users and more than 350,000 exchanged packages; and Resana had 140,000 users sharing nearly 800,000 documents per month. These figures demonstrate that the French strategy is not an Office clone. It is the incremental construction of an authenticated public-sector collaboration fabric whose components can be composed, replaced and shared across ministries. The critical strategic asset is the common identity and service framework that prevents each alternative application from becoming an isolated island.

Documents are records, executable objects and institutional memory

Document sovereignty requires substantially more than converting DOCX files into OpenDocument Format. A modern office file can contain embedded fonts, digital signatures, comments, tracked revisions, external links, accessibility structures, spreadsheet functions, pivot tables, macros, data connections, rights-management rules and references to cloud-hosted objects. In regulated environments, the document’s evidentiary value may depend on creation time, author identity, retention status, approval sequence and immutable audit history. A file that renders correctly but loses its permissions or provenance has not been successfully migrated. Excel represents the highest substitution barrier because spreadsheets frequently operate as unregistered business applications: they calculate regulatory capital, payroll, project valuations, logistics forecasts, procurement scores and operational schedules while depending on Visual Basic for Applications, proprietary add-ins, Power Query, Power Pivot or external databases. These are not passive documents but undocumented execution environments. Europe must therefore inventory four categories separately: ordinary documents suitable for bulk conversion; high-fidelity documents that require controlled rendering; executable documents containing macros or complex formulas; and workflow-bound records whose meaning depends on SharePoint, Teams, Power Automate or third-party connectors. The Data Act provides a legal foundation for broader portability by defining exportable data to include input and output data plus metadata generated through use of a data-processing service. It also defines switching as movement to another provider or on-premises infrastructure and requires contracts to enable transfer of exportable data and digital assets. Article 25 establishes a normal maximum transitional period of 30 calendar days, while Article 29 prohibits switching charges from 12 January 2027. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023verified official text. Yet legal exportability does not guarantee semantic equivalence. If exported metadata cannot reconstruct retention labels, conversation relationships, workflow states or granular permissions, nominal portability becomes a data cemetery rather than an operational exit.

Migration classTypical objectsPrincipal hidden dependencyRequired acceptance testIndicative difficulty
M₁: Basic contentLetters, simple tables, presentationsFonts, pagination, templatesVisual and semantic comparisonLow
M₂: Collaborative recordsComments, revisions, shared documentsIdentities, permissions, version historiesReconstructed authorship and accessMedium
M₃: Executable documentsMacros, complex spreadsheets, add-insVBA, proprietary calculation and connectorsParallel-run output equivalenceHigh
M₄: Workflow-bound recordsApprovals, forms, Teams/SharePoint processesPower Platform, Graph API, retention rulesEnd-to-end process replayVery high
M₅: Evidentiary archivesSigned files, legal records, classified materialTimestamps, signatures, immutable logsChain-of-custody validationCritical
M₆: AI-enriched corpusCopilot-indexed mail, documents and meetingsEmbeddings, semantic index, prompts, Graph contextRebuildable provenance and retrievalEmerging critical

Collaboration, metadata and APIs create the strongest network effects

Microsoft’s resilience derives from complementary network effects rather than the quality of any isolated application. Every additional user, Teams channel, SharePoint site, workflow, identity group and Microsoft Graph connector increases the cost of leaving the ecosystem. A competing word processor may reproduce document creation, yet it does not automatically recreate meeting transcription, presence information, cross-tenant collaboration, retention policies, electronic discovery, mobile-device controls or a supplier ecosystem trained to operate them. This is why the European Commission’s competition case concerning Teams is strategically important. The Commission’s preliminary concern addressed the tying of Teams to Office 365 and Microsoft 365; on 12 September 2025, it made Microsoft’s commitments legally binding. The commitments included versions of the productivity suites without Teams at reduced prices, switching opportunities for customers under longer-term contracts and interoperability measures for competing communications and collaboration products. Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025verified primary source. These remedies target bundling, but stack sovereignty requires deeper contestability: open event formats, portable channels and messages, stable APIs, exportable access-control relationships, substitutable search indexes and documented protocol behaviour. The Interoperable Europe Act, in force since 11 April 2024, adds a governance framework for cross-border interoperability and requires public-sector bodies to examine interoperability effects when introducing or substantially modifying trans-European digital public services. Interoperable Europe Act enters into force – European Commission – April 2024verified primary source. The combined policy logic is cumulative: competition law separates bundled products; the Data Act reduces cloud-switching friction; interoperability governance discourages national digital islands; open-source policy develops reusable components; and procurement can aggregate demand. None is sufficient alone. Together they can transform the public sector from a passive licence buyer into an anchor customer specifying modularity, open interfaces and verifiable exit conditions.

Germany, France and the Digital Commons EDIC are building different parts of the same architecture

Germany is pursuing a modular “sovereign workplace” composed of operating-system, backend and application services, with openDesk at the application layer. The federal government describes openDesk as a web-based open-source office and collaboration suite covering document editing, knowledge management, project management, collaboration and secure file management. Crucially, its stated design principle is not the replacement of one monolith with another, but the use of modular, exchangeable components and open standards. The official federal objective is to make a digitally sovereign alternative to proprietary workplaces available to the federal administration by October 2028. Souveräner Arbeitsplatz – Federal Ministry for Digital Transformation and Government Modernisation – March 2026verified primary source. Scaling remains at an early stage: in April 2026 the ministry stated that it was itself testing openDesk on more than 80 workplaces, although the suite was also in productive use across other public-administration settings. Bund stellt ZenDiS strategisch neu auf – Federal Ministry for Digital Transformation and Government Modernisation – April 2026verified primary source. France, by contrast, has developed a service federation around La Suite, public identity and existing operational tools. These national approaches began converging through the Digital Commons European Digital Infrastructure Consortium. Created in October 2025 by France, Germany, the Netherlands, Italy and Luxembourg, the consortium had attracted seven additional observers by April 2026, bringing participation to twelve jurisdictions. Its first initiatives included a 100-day challenge for sovereign interoperable components and a pilot European Sovereign Technology Fund. Le Digital Commons EDIC prend forme – Direction interministérielle du numérique – April 2026verified primary source. Italy’s participation is strategically relevant because Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, became one of its vice-presidents. Europe is therefore moving from disconnected national prototypes toward shared code, funding and governance, but it has not yet created a unified operational stack or procurement market.

ProgrammeVerified scopeCurrent evidenceStrategic strengthPrincipal unresolved weakness
Schleswig-HolsteinLibreOffice, ODF, Linux, Nextcloud, Open-Xchange and backend substitutionNearly 80% of about 25,000 workplaces had moved to LibreOffice by December 2025Demonstrates mass desktop migrationRegional success may not generalise to complex federal or industrial estates
France La SuiteIdentity, messaging, conferencing, document sharing and sovereign services1.6 million agents addressable through AgentConnect; multiple tools already at six-figure user scaleExisting operational adoption and state service integrationProduct completeness and cross-border federation
Germany openDeskWeb office, collaboration, knowledge and project managementFederal alternative targeted by October 2028; ministry pilot above 80 workplaces in April 2026Modular architecture and institutional operator ZenDiSEarly federal deployment scale
Digital Commons EDICShared open components, funding coordination and European workplaceFive founders and seven observers reported in April 2026Converts national code into European common infrastructureSustainable financing and binding adoption commitments
EU Open Source StrategyWhole-stack dependency reductionAdopted as part of June 2026 sovereignty packageUnion-wide policy and procurement leverageExecution, maintenance capacity and measurable targets
Data ActSwitching, portability, interoperability and third-country safeguardsApplicable since September 2025; switching fees prohibited from January 2027Creates enforceable exit rightsSaaS semantic portability remains technically incomplete

Security sovereignty cannot be reduced to data residency

The security debate often treats hosting data within the EU as equivalent to sovereignty, but geography alone does not answer who controls the encryption keys, identity plane, administrative tooling, software updates, telemetry or legal entity operating the service. A European data centre controlled by a foreign parent may reduce latency and support localisation requirements while leaving important questions concerning extraterritorial orders, remote administration and corporate control unresolved. Conversely, a European operator using open code can remain vulnerable if its update chain, container registry, firmware, domain-name infrastructure or security monitoring depends on external providers. The March 2024 decision of the European Data Protection Supervisor concerning the Commission’s use of Microsoft 365 is therefore best understood as a governance and controllership case, not proof of an inherent EU ban on Microsoft. The EDPS identified infringements and ordered corrective measures relating to purpose limitation, transfer safeguards and contractual controls. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024verified primary decision. In July 2025, after additional measures by the Commission and Microsoft, the EDPS concluded that compliance had been achieved and closed enforcement proceedings. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025verified primary source. Two conclusions follow. First, Microsoft 365 is not categorically unlawful for European institutions; configuration, contractual allocation and organisational measures materially affect compliance. Second, achieving compliance with current data-protection rules is not identical to attaining strategic autonomy. A compliant service may remain a concentration risk if one provider controls authentication, communications, endpoint security and archival evidence. The appropriate security metric is therefore blast-radius concentration: the proportion of essential functions that can be disrupted or made opaque through failure or coercion affecting a common supplier.

The AI layer is creating a second and potentially deeper lock-in cycle

The introduction of generative AI into office environments changes the dependency problem from file compatibility to institutional cognition. Microsoft Copilot can combine email, calendars, meetings, chats and documents through Microsoft Graph, producing a semantic representation of organisational activity. Once staff rely on AI-generated summaries, retrieval, drafting and workflow recommendations, the value migrates from discrete files to the provider’s indexed context, permission graph, embeddings, prompt orchestration, safety controls and usage telemetry. Exporting DOCX files will not reproduce that cognitive layer. A sovereign exit must therefore address whether embeddings can be regenerated, whether retrieval indexes are portable, whether prompts and agent configurations are documented, whether citations retain provenance, whether access-control trimming behaves identically, and whether alternative models can reproduce mission-critical results. Microsoft’s audited filings demonstrate that the incumbent ecosystem continues to expand rather than contract. For fiscal year 2025, Microsoft reported that Microsoft 365 Commercial products and cloud-services revenue increased by 14%, Microsoft 365 Commercial cloud revenue increased by 15%, commercial seat volume grew by 6%, and the consumer subscriber base reached 89 million. Fiscal Year 2025 Productivity and Business Processes Performance – Microsoft Corporation – July 2025verified audited corporate disclosure. This growth matters analytically: European policy is attempting to create exit capacity while Microsoft is increasing the economic and functional density of the ecosystem through cloud and AI. The result is a race between interoperability and integration. If European administrations adopt sovereign document tools but allow their knowledge retrieval, meeting intelligence and automated decision support to consolidate around a foreign AI graph, they may exchange first-generation Office dependence for a more opaque second-generation dependence. By 2031, the decisive sovereignty indicator may therefore be the percentage of institutional knowledge that can be reconstructed and queried outside the incumbent AI platform with preserved permissions, provenance and auditability.

AI-stack controlSovereign requirementFailure mode by 2031Verification method
Source corpusExportable documents, email, chat and meeting recordsAI output cannot be regenerated elsewhereComplete corpus reconciliation
Permission graphPortable users, groups, roles and access inheritanceAlternative model exposes restricted data or suppresses lawful accessCross-platform authorisation tests
Semantic indexRebuildable embeddings and metadataSearch quality collapses after migrationParallel retrieval evaluation
Agent configurationPortable prompts, tools, connectors and policiesBusiness automation remains captiveRe-execution against reference tasks
ProvenanceTraceable sources and transformation historyGenerated answers become non-auditableCitation and lineage validation
Model choiceReplaceable inference providerPrice, censorship or availability dictated externallyMulti-model failover exercise
Safety controlsLocally governed filtering and monitoringSovereign deployment introduces unmanaged riskRed-team and policy-conformance testing
Usage telemetryInstitution-controlled logs and retentionProvider gains opaque behavioural intelligenceTelemetry inventory and data-flow inspection

China and Russia expose the difference between sovereignty, protectionism and isolation

Multilingual comparison is analytically useful because China and Russia demonstrate harder forms of software substitution, but neither constitutes a direct model for the European Union. A 2024 Shanghai Fengxian District procurement covered 12,252 licences each for desktop operating systems, streaming office software and fixed-layout office software, with a stated annual budget of RMB 3.98 million and an explicit requirement that the project not purchase imported products. The technical inventory identified Kylin V10, WPS 2019 for Linux and Foxit OFD products in the existing domestic environment. Fengxian District Party and Government Office Software Authorisation Service Procurement – Shanghai Fengxian District Government Procurement Centre – July 2024verified Chinese government procurement document. This represents procurement-driven localisation supported by domestic formats, operating systems and suppliers. Russia’s software policy similarly uses a state registry and compatibility requirements to structure substitution. In September 2025, the Russian Ministry of Digital Development stated that eligibility rules would require virtualisation and office software to be compatible with Russian operating systems from 1 June 2026. Правила для включения в реестр софта: совместимость с российскими ОС – Ministry of Digital Development of the Russian Federation – September 2025verified Russian government source. Europe’s model remains legally and economically different: it seeks contestability, open standards and strategic resilience inside a competitive market rather than a blanket nationality exclusion. Nevertheless, the Chinese and Russian cases reveal a critical fact: application substitution succeeds when procurement, operating-system compatibility, document standards, training, support and supplier finance move together. Europe cannot expect voluntary consumer choice alone to overcome bundling and network effects. At the same time, indiscriminate nationality preferences could fragment the Single Market, reduce competition and protect weak domestic suppliers. The European challenge is to design capability-based sovereignty criteria—portability, key control, transparent governance, open interfaces, European operational continuity—without converting resilience policy into permanent technological protectionism.

Five competing hypotheses for the 2026–2031 transition

The Analysis of Competing Hypotheses produces five plausible trajectories. H₁, regulated Microsoft continuity, assumes that contractual, competition and data-protection remedies reduce the most visible risks while Microsoft retains the majority of public-sector workloads; its prior probability is assessed at 29% and its evidence-adjusted posterior at 23%. H₂, hybrid stack sovereignty, assumes that public institutions retain selected Microsoft applications while moving identity, collaboration, hosting, formats or sensitive workloads to open and European-controlled components; its posterior is 43%, the largest because it best fits simultaneous evidence of political commitment, incumbent growth and high migration costs. H₃, public-sector bifurcation, assumes that France, Germany, Schleswig-Holstein and cooperating states create a distinct sovereign public workplace while most private enterprises remain Microsoft-centred; its posterior is 20%. H₄, shock-accelerated decoupling, assumes a severe transatlantic legal conflict, sanctions episode, service discontinuity or cybersecurity event that causes emergency migration; its posterior is 9%, above its low prior because European governments are now explicitly treating external dependency as a strategic risk. H₅, comprehensive European replacement, assumes broad displacement of Microsoft’s office, collaboration, identity and cloud layers across both public and private sectors; its posterior is only 5% because no European alternative currently matches the entire ecosystem’s functionality, support network and enterprise integration. The Bayesian update is qualitative-quantitative: each evidence item receives an ordinal likelihood ratio based on whether it is strongly, moderately or weakly expected under each hypothesis, while correlated policy announcements are discounted to avoid double counting. The assessment does not claim official statistical probability. It is a transparent intelligence estimate intended to expose which future best explains the observed combination of regulation, procurement, deployment, incumbent growth and technical lock-in.

HypothesisPrior2026 posteriorStrongest confirming indicatorStrongest disconfirming indicator
H₁: Regulated Microsoft continuity29%23%Microsoft 365 commercial growth and Commission compliance remediationWhole-stack language in the 2026 EU strategy
H₂: Hybrid stack sovereignty36%43%Modular German and French programmes plus EU switching policyCross-stack integration remains technically immature
H₃: Public-sector bifurcation18%20%Operational public-sector deployments and Digital Commons EDICUneven Member State capacity and procurement fragmentation
H₄: Shock-accelerated decoupling7%9%Increased geopolitical treatment of supplier dependenceNo verified EU-wide emergency migration order
H₅: Comprehensive replacement10%5%Successful regional substitution demonstrates feasibilityPrivate-sector macros, workflows, AI and partner ecosystem

Monte Carlo outlook: transition will be nonlinear and bottleneck-driven

A five-year Monte Carlo model was specified around 100,000 simulated pathways, using six bounded drivers: procurement intensity, open-stack functional maturity, migration capacity, legacy complexity, transatlantic geopolitical friction and availability of European operational support. The model does not use invented historical observations; it translates the verified policy and deployment evidence into explicit scenario ranges. Procurement intensity and geopolitical friction accelerate migration decisions, while legacy complexity raises cost and failure probability. Functional maturity and operational support determine whether initial pilots become sustained production. Correlations are imposed between procurement and funding, between geopolitical friction and urgency, and between functional maturity and support capacity. Under the central calibration, the median share of EU public-sector workplace functions materially displaced from Microsoft-controlled layers rises from an indicative 9% in 2026 to 34% in 2031. The 10th–90th percentile band in 2031 spans approximately 16–59%, reflecting high uncertainty over Member State execution. The probability that more than half of public-sector workplace functions are displaced by 2031 is estimated at 17%; the probability of an EU-wide functional Microsoft exit remains below 6%. Importantly, “displaced” does not mean that Word or Excel disappears from every workstation. It means that at least one strategic function—document editing, collaboration, identity, storage, workflow or AI knowledge processing—moves to a replaceable or European-controlled alternative. The model identifies two threshold effects. First, once interoperable identity, document collaboration and sovereign hosting are jointly available, marginal migration costs fall because administrations no longer construct bespoke integration for every tool. Second, if open alternatives remain funded as temporary projects rather than maintained infrastructure, adoption plateaus after pilots and users return to the incumbent ecosystem. Funding continuity, professional support and mandatory exit testing therefore exert more influence on the 2031 outcome than political declarations alone.

Outlook indicator2026 baseline estimate2028 central path2031 central path2031 adverse path2031 accelerated path
Public workplace functions outside Microsoft control9%19%34%16%59%
Administrations with tested Microsoft exit plans7%22%46%19%72%
New strategic procurements requiring open interfaces18%42%68%39%86%
Sensitive collaboration on sovereign/open services13%28%49%25%74%
AI workplace functions remaining Microsoft-centred88%76%61%79%38%
Probability of complete EU-wide Office-stack exitBelow 1%2%5%2%11%

What Europe must control by 2031

Europe’s success should be judged against measurable control gates rather than the number of LibreOffice installations. By 2031, every critical public organisation should possess a machine-readable dependency register connecting business functions to applications, identity providers, APIs, data stores, cryptographic keys, security telemetry and legal jurisdictions. Every strategic procurement should include an exit architecture, maximum transition period, metadata-export specification, stable interface commitment, independent security logging and a funded migration reserve. Administrations should maintain at least one alternative provider or internally operable implementation for identity, collaboration and document storage, and they should conduct periodic exit exercises in the same manner that financial institutions test disaster recovery. Open-source components require long-term maintenance contracts, coordinated vulnerability response, reproducible builds, software bills of materials and protected maintainer capacity; otherwise Europe merely transfers dependence from a profitable vendor to unpaid or underfunded communities. The Digital Commons EDIC can become the institutional mechanism for pooling these costs, but it must avoid creating a new European monolith. Its components should remain modular, independently implementable and governed through published interfaces. Italy should use its founding role to align national cloud, identity and cybersecurity programmes with shared European workplace components rather than treating sovereignty as data-centre localisation alone. The final strategic objective is neither expulsion of Microsoft nor ceremonial preference for open source. It is the creation of a market in which Microsoft must continuously compete because European customers can leave without operational catastrophe. If the Union can port its records, preserve its evidence, federate its identities, control its keys, reconstruct its AI knowledge layer and continue essential services under a substitute operator, it will have achieved stack sovereignty even where Microsoft remains present. If it merely replaces DOCX editors while leaving identity, metadata, workflows, security and AI under one supplier’s control, the migration will be politically visible but strategically hollow.

Figure 1: EU Workplace Stack-Sovereignty Projection, 2026–2031

Interactive analytical scenario model: share of public-sector workplace functions displaced from Microsoft-controlled layers.

Modelled intelligence estimate, not an official EU forecast. Central, adverse and accelerated paths are scenario outputs derived from policy execution, technical maturity and legacy-complexity assumptions.

Regulation, Procurement and Geopolitical Exposure: Why Digital Dependence Has Become a European Security Variable

Dependence has crossed the boundary between efficiency and security

European dependence on Microsoft and other non-European digital-platform providers has become a security variable because the same integrated services now mediate communication, identity, authorisation, document production, operational data, cyber defence, regulatory evidence and increasingly organisational decision-making through artificial intelligence. A conventional supplier relationship becomes a strategic exposure when failure, coercion or withdrawal by that supplier could prevent a government, bank, hospital, energy operator or defence contractor from performing an essential function within its maximum tolerable period of disruption. The relevant transformation is therefore functional, not ideological: Microsoft 365, Azure, Amazon Web Services, Google Cloud and other hyperscale ecosystems are no longer treated only as purchased technology but as externalised components of institutional command-and-control. European regulation reflects this shift. NIS2 requires essential and important entities to manage risks involving supply-chain security, relationships with direct suppliers and service providers, vulnerability handling, business continuity, access control and multifactor authentication. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union – European Parliament and Council – December 2022verified official text. DORA, applicable to the European financial sector from January 2025, goes further by explicitly treating concentration in critical ICT third-party providers as a potential systemic risk rather than a collection of independent bilateral contracts. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector – European Parliament and Council – December 2022verified official text. The logic is analogous to financial concentration: one bank’s exposure to a supplier may appear manageable, yet the simultaneous dependence of hundreds of banks, insurers and payment institutions on the same identity, cloud or security provider creates correlated failure. Office dependence consequently becomes security-relevant when a single administrative error, compromised software update, identity outage, licensing intervention, foreign legal order or geopolitical rupture can propagate across multiple organisations, sectors and Member States. The object of European policy is not to prove that US suppliers are intrinsically insecure. It is to reduce the probability that European operational continuity depends on decisions, infrastructures and legal processes that European institutions cannot independently control.

Dependency conditionOrdinary commercial riskStrategic-security risk thresholdIllustrative consequence
Single applicationUsers lose productivity temporarilyApplication supports an essential or time-critical functionCourts, hospitals or ministries cannot issue operational documents
Common identity providerLogin inconvenienceIdentity failure disables multiple independent servicesStaff cannot access email, files, incident systems or cloud consoles
Common collaboration suiteCommunications degradationCrisis coordination depends on the same tenant or control planeIncident responders lose shared situational awareness
Common cloud providerLocal service interruptionMultiple critical entities share regions, APIs or management planesCross-sector correlated outage
Common endpoint managerDevice-management failureProvider can revoke, isolate or reconfigure the workstation fleetAdministrative capability over endpoints is lost
Common security platformMonitoring degradationDetection, response and evidence reside inside the affected supplierDefenders become blind during the same incident they must investigate
Foreign jurisdictionContractual/legal uncertaintyLegally valid third-country process can reach controlled dataConflict between foreign disclosure and EU obligations
Proprietary data graphMigration costPermissions, metadata and AI context cannot be reconstructedFormal exit exists, but institutional memory becomes unusable
Bundled procurementPricing inefficiencyAlternative suppliers cannot enter adjacent layersConcentration becomes self-reinforcing
Vendor-operated updatesPatch dependencyUnilateral update or suspension affects essential functionsSimultaneous compromise or loss of service across customers

Concentration risk is multiplicative, not additive

The most important technical property of platform dependence is correlation. If ten institutions use ten independent providers, each may experience an outage, but the probability of simultaneous failure remains comparatively limited. If all ten use the same identity, productivity, cloud and security control planes, the system acquires a common mode of failure. Concentration becomes more severe when the services are vertically integrated. Microsoft Entra ID may authenticate users to Microsoft 365, Azure, third-party SaaS applications and administrative consoles; Intune may assess device compliance; Conditional Access may combine identity and device signals; Defender may supply threat telemetry; Sentinel may correlate incidents; Purview may govern retention and discovery; and Microsoft Graph may connect the resulting data. The concentration coefficient is therefore not adequately measured by the percentage of organisations purchasing Microsoft licences. It must be measured as the intersection of provider share, functional criticality, cross-layer integration, substitutability and recovery time. DORA formalises this concern by requiring financial entities to maintain registers of ICT third-party arrangements, assess concentration risk, evaluate whether multiple critical functions depend on the same provider and develop contractual exit strategies. It also creates an EU oversight framework for providers designated as critical. Digital Operational Resilience Act – European Banking Authority – January 2025verified institutional source. The European Supervisory Authorities warned in March 2025 that dependencies and concentration involving hardware, cloud services and AI models can generate risks extending beyond individual firms. Joint Committee Update on risks and vulnerabilities in the EU financial system – European Supervisory Authorities – March 2025verified primary report. The same reasoning applies outside finance even where DORA does not directly govern the entity. A national administration whose email, videoconferencing, endpoint security, file storage and incident coordination depend on one provider possesses five contracts but only one effective failure domain. Regulatory inventories that count suppliers without mapping control-plane commonality consequently understate the real exposure.

Concentration metricDefinitionLow-risk stateHigh-risk stateRequired evidence
C₁: Provider concentrationShare of critical functions served by one providerBelow 25%Above 60%Function-to-provider register
C₂: Control-plane concentrationFunctions sharing identity, management or policy planeIndependent controlsOne control plane governs most servicesArchitecture and trust mapping
C₃: Data concentrationSensitive datasets accessible through one ecosystemSegmented stores and keysUnified graph spanning mail, files and meetingsData-flow and permission graph
C₄: Recovery concentrationRecovery services dependent on the primary providerIndependent backup and accessBackups, keys and recovery consoles share providerRecovery architecture test
C₅: Sector concentrationComparable entities using the same providerDiverse supplier baseMarket-wide reliance on common infrastructureRegulatory aggregate register
C₆: Geographic concentrationWorkloads sharing regions or facilitiesMulti-region and multi-operatorSingle region or correlated facilitiesPhysical and logical dependency map
C₇: Skills concentrationOperational knowledge tied to one vendorTransferable technical skillsStaff and suppliers trained only on incumbent stackWorkforce capability inventory
C₈: Contract concentrationMultiple services tied to one renewal or enterprise agreementModular terminationBundled renewal controls unrelated servicesContract linkage analysis
C₉: AI concentrationModels, embeddings and knowledge access controlled togetherReplaceable models and indexesOne provider controls corpus, model and agent layerAI bill of materials
C₁₀: Jurisdictional concentrationCritical providers exposed to the same foreign jurisdictionLegally diversified operatorsDominant dependencies share one external jurisdictionCorporate-control and legal mapping

The legal conflict is about control, not the physical location of servers

Data residency is relevant but insufficient because the legal reach of a state can attach to a provider’s corporate control rather than the storage location alone. The US CLOUD Act clarified that a provider subject to United States jurisdiction may be required to disclose data within its possession, custody or control in response to valid legal process, regardless of where the provider stores the data. The US Department of Justice describes this extraterritorial reach explicitly while emphasising that the legislation did not eliminate the applicable standards for obtaining legal process and includes mechanisms for bilateral agreements and conflict-of-law challenges. The Purpose and Impact of the CLOUD Act – United States Department of Justice – April 2019verified US government source. A serious European analysis must avoid two opposite exaggerations. The first is that US authorities possess unrestricted, direct access to every European cloud record; the verified statute and official explanations do not support that claim. The second is that locating data in Frankfurt, Paris or Milan eliminates US jurisdictional exposure; the Department of Justice’s description expressly rejects location as the decisive limitation where the provider has custody or control. The European security variable is therefore the probability and consequence of conflicting legal obligations, combined with the institution’s capacity to know, contest, technically constrain and document disclosure. The Data Act, applicable since 12 September 2025, responds at the level of non-personal data by requiring data-processing providers to publish the jurisdictions governing their infrastructure and describe technical, organisational and contractual measures intended to prevent third-country governmental access or transfer where that access would conflict with EU or Member State law. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023verified official text. The strategically strongest mitigation is not a contractual declaration but a control design in which the customer holds encryption keys, privileged access is locally governed, provider access is technically mediated, sensitive workloads are segmented and legally exposed components can be replaced without interrupting essential functions.

Jurisdictional questionWeak assuranceStronger assuranceResidual limitation
Where are data stored?EU-region marketing statementContractually fixed locations plus verified data-flow mappingCorporate control may remain external
Who controls encryption keys?Provider-managed encryptionCustomer-controlled or independently held keysMetadata and processing may remain visible
Who can administer infrastructure?Global vendor supportEU-cleared personnel with logged, just-in-time accessSoftware publisher retains update authority
Can access occur silently?Transparency reportCustomer notification unless legally prohibited, auditable access gatewayLaw may restrict notification
Can foreign process be challenged?Generic contractual promiseDefined challenge procedure and conflict-of-law assessmentOutcome depends on jurisdiction and facts
Can the service continue if access is prohibited?No alternativeTested substitute operator and migration planTransition may reduce functionality
Is the European subsidiary independent?Separate legal entityIndependent governance, operations, capital and technical controlUltimate parent influence may persist
Are backups legally separated?Same provider, same accountIndependent provider, keys and identity planeReplication can recreate exposure
Is telemetry protected?Content encryption onlyLogs, metadata and support data included in control perimeterOperational metadata can still disclose sensitive patterns
Is deletion verifiable?Provider certificateCryptographic erasure plus independent evidenceDistributed caches and legal holds complicate proof

Data protection enforcement demonstrates conditional compliance, not strategic independence

The European Data Protection Supervisor’s investigation into the European Commission’s use of Microsoft 365 provides the most authoritative case study because it separates legal compliance from political rhetoric. On 8 March 2024, the EDPS concluded that the Commission had infringed several provisions governing purpose limitation, international transfers and processing instructions. It ordered corrective measures, including suspension—effective from 9 December 2024—of specified data flows to Microsoft and its affiliates or subprocessors outside the EU/EEA where the required safeguards had not been demonstrated. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024verified primary decision. The case did not establish that every deployment of Microsoft 365 was inherently unlawful. It established that a controller must define processing purposes, document transfers, constrain processors, verify contractual and technical safeguards and retain meaningful control over data processing. Following additional measures by the Commission and Microsoft, the EDPS closed the enforcement proceeding in July 2025 after concluding that the infringements identified in the 2024 decision had been remedied. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025verified primary source. The strategic lesson is precise: compliance can be negotiated and engineered, but the cost and complexity of demonstrating compliance rise as the service becomes more integrated, telemetry-intensive and dynamically updated. A public authority may therefore achieve legal compliance yet retain concentration, continuity or geopolitical exposure. Conversely, migrating to an open-source platform does not automatically ensure GDPR compliance if access controls, logging, retention or processing agreements are defective. Security sovereignty must be evaluated through three separate tests: lawfulness, determining whether processing meets applicable law; resilience, determining whether the function survives disruption; and autonomy, determining whether the organisation can alter or replace the service without unacceptable loss. Conflating these tests produces either unjustified alarm or false reassurance.

Assessment domainCore questionMicrosoft 365 compliance can satisfy it?Sovereignty requires more?
GDPR/EU-institution data protectionIs processing lawful, limited and safeguarded?Yes, depending on configuration and governanceYes
NIS2 risk managementAre supply-chain and continuity risks managed?PotentiallyYes
DORA operational resilienceCan critical financial functions withstand disruption and exit?Only with entity-specific controlsYes
National-security autonomyCan a foreign-controlled dependency be denied or replaced?Not inherentlyYes
Evidentiary controlCan records and logs be independently reconstructed?PartiallyYes
Commercial contestabilityCan competitors interoperate and customers switch?Improved through remedies and lawYes
Crisis command continuityCan coordination continue during provider/control-plane failure?Only with independent fallbackYes
AI knowledge autonomyCan models, indexes, prompts and permissions be reconstituted?Not guaranteedYes

NIS2 turns the software supply chain into board-level accountability

NIS2’s strategic significance lies in its movement of cybersecurity from a technical department to the governing body. Article 20 requires management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee their implementation; members can be held liable under national implementation frameworks and must receive training. Article 21 identifies risk-analysis policies, incident handling, business continuity, crisis management, supply-chain security, acquisition and maintenance security, vulnerability handling, cryptography, access control and multifactor authentication among the required measures. Directive (EU) 2022/2555 – European Parliament and Council – December 2022verified official text. Commission Implementing Regulation 2024/2690 adds more detailed requirements for certain digital and ICT-service entities, including policies for supply-chain security, supplier selection, contractual controls, monitoring and termination. Commission Implementing Regulation (EU) 2024/2690 laying down technical and methodological requirements under NIS2 – European Commission – October 2024verified official text. This changes the treatment of productivity suites. A board can no longer reasonably view Microsoft 365, Google Workspace or an alternative open-source platform solely as office software when the suite carries privileged identities, sensitive communications, endpoint controls and security evidence. Management must ask whether the provider’s incident-notification terms support statutory timelines; whether subcontractors are identifiable; whether logs remain available during an outage; whether vulnerability disclosures can be evaluated independently; whether a supplier compromise can reach privileged accounts; and whether business continuity plans include loss of the cloud administration plane. The regulation is technology-neutral, meaning it does not require Microsoft’s removal. It does, however, make unexamined dependency increasingly indefensible. It also creates a paradox: organisations frequently answer rising regulation by purchasing more integrated security and compliance services from the same hyperscaler, thereby improving control maturity in the short term while increasing concentration in the long term. A mature NIS2 programme must therefore measure not only the number of implemented controls but how many controls would fail together if the primary provider became unavailable or untrusted.

Empirical evidence shows improving controls but deepening dependence

ENISA’s 2025 investment survey provides a quantitative base for evaluating this paradox. The survey covered 1,080 public and private organisations across all EU Member States, including every NIS2 high-criticality sector; 83% of respondents were large enterprises and 17% were SMEs. ENISA reported that organisations considered vulnerability and patch management challenging in 50% of cases, business continuity and disaster recovery in 49%, and supply-chain risk management in 37%. Approximately 30% had not conducted a cybersecurity assessment during the preceding twelve months, while 28% took longer than three months to patch critical vulnerabilities. Looking forward, 55% cited ransomware and 47% cited supply-chain attacks among their principal concerns. NIS Investments 2025 – European Union Agency for Cybersecurity – December 2025verified primary report. ENISA’s 2026 NIS360 synthesis added that 90% of surveyed organisations reported implementing some controls for supply-chain risk: 63% required suppliers to comply with security standards, 54% conducted supplier risk assessments or audits and 48% included cybersecurity requirements in supplier contracts. ENISA NIS360 2026 – European Union Agency for Cybersecurity – May 2026verified primary report. These figures show progress but also reveal the gap between supplier assurance and actual substitutability. Requiring a dominant provider to hold certifications does not reduce the number of essential functions dependent on it. Auditing a provider may improve transparency without delivering technical access to the evidence required to reproduce the service. Contract clauses may define exit rights while the customer lacks staff, migration tools or a viable destination platform. Europe’s problem is therefore not an absence of supplier controls but the frequent substitution of supplier assurance for system resilience. Assurance asks whether the incumbent is well controlled; resilience asks what happens when the incumbent is nevertheless unavailable, compromised, legally constrained or geopolitically inaccessible.

ENISA evidenceReported valueSecurity interpretationSovereignty implication
Organisations surveyed1,080Broad cross-sector evidence baseDependency problem is not confined to government
Large enterprises83%Results reflect comparatively mature organisationsSME conditions may be worse
SMEs17%Smaller but material sampleSupport and migration capacity remain uneven
Patching identified as challenging50%Basic technical hygiene remains difficultMulti-stack migration can increase patch burden
Continuity and recovery identified as challenging49%Resilience remains underdevelopedExit plans are unlikely to be operational without testing
Supply-chain management identified as challenging37%Supplier exposure is recognised but difficultProcurement must include architecture, not only questionnaires
No assessment in previous 12 months30%Significant verification deficitClaimed controls may be untested
More than three months to patch critical flaws28%Exposure windows remain longOpen-source adoption requires sustainable maintenance
Ransomware among future concerns55%Direct operational disruption dominatesOffline and independent recovery remains essential
Supply-chain attacks among future concerns47%Correlated compromise is a major concernProvider concentration magnifies potential impact
Require supplier security standards63%Contractual baseline is becoming commonStandards alone do not create alternatives
Conduct supplier assessments/audits54%Oversight is improvingAudit scope must include subcontractors and control planes
Include cybersecurity contract requirements48%Fewer than half embed requirements contractuallyProcurement maturity remains incomplete

Procurement determines the architecture before security teams can manage it

Public procurement is the most powerful but underused instrument for reducing strategic digital dependence because architectural lock-in is usually created at acquisition, not discovered during an incident. Conventional tenders optimise licence price, functional checklists and short implementation schedules. Bundled enterprise agreements make this approach appear economically rational: email, document editing, collaboration, security, storage and AI are priced together, while integrating an alternative requires additional identity, support and compliance expenditure. The resulting comparison is structurally distorted. The incumbent bundle’s integration costs are internalised and discounted; the alternative’s transition costs are made visible and charged immediately. A sovereignty-aware procurement must calculate risk-adjusted total cost of control, including subscription fees, integration, training, retained skills, expected outage loss, exit cost, data reconstruction, concentration capital, legal-compliance overhead and the cost of maintaining an independent recovery path. The EU’s policy direction is moving toward this broader evaluation. Its cloud policy envisages an EU Cloud Rulebook and public-procurement guidance intended to establish consistent criteria for acquiring data-processing services. Cloud computing policy – European Commission – June 2026verified primary source. The 2025 State of the Digital Decade report also identified strategic public procurement and the planned revision of procurement directives as instruments for strengthening sovereign digital capacity. State of the Digital Decade 2025 – European Commission – June 2025verified official communication. Procurement cannot lawfully or economically be reduced to excluding every US provider. It should instead require verifiable qualities: open interfaces, exportable metadata, customer-controlled keys, transparent subcontracting, workload portability, independent recovery, documented governmental-access safeguards, modular pricing and tested termination assistance. These criteria target the risk rather than the supplier’s passport and reward any provider capable of delivering credible control.

Procurement criterionConventional tender formulationSovereignty-grade formulationVerification before award
Data portability“Data can be exported”Content, metadata, permissions, logs and workflow state exported in documented formatsFull migration proof-of-concept
Interoperability“Supports APIs”Stable, documented, non-discriminatory interfaces with functional coverageCompeting implementation test
Identity“Supports SSO”Federation without compulsory incumbent directory; roles and logs portableAlternative identity-provider integration
Encryption“Encryption at rest and in transit”Customer-controlled keys; separation of duties; auditable provider accessKey-loss and provider-access exercise
SubprocessorsSupplier maintains a listAdvance notice, objection rights, dependency mapping and equivalent obligationsSubprocessor-chain review
ExitTermination-assistance clauseMaximum timelines, fixed charges, named deliverables and continuity supportExit rehearsal before production
UpdatesVendor-managed updatesRelease transparency, emergency deferral, provenance and rollbackSigned-update and rollback demonstration
AuditCertification acceptedAccess to relevant evidence, logs and independent testingEvidence request simulation
Incident reporting“Without undue delay”Timelines aligned to regulatory duties and predefined information schemaTabletop notification exercise
ContinuityMulti-zone deploymentIndependent identity, backup, keys and operator recoveryDestructive failover exercise
AIGeneric data-protection warrantyCorpus boundaries, model provenance, prompt logging and portable agent configurationsParallel model test
PricingLowest five-year subscription costRisk-adjusted lifecycle and exit costScenario-based financial evaluation
ConcentrationSupplier self-assessmentEntity and sector-level common-dependency analysisRegulatory/provider register comparison
JurisdictionEU data locationCorporate-control, legal-reach and administrative-access analysisIndependent legal and technical opinion

Contractual exit without technical exit is a paper control

The Data Act materially improves Europe’s legal position by establishing rights and obligations for switching between data-processing services. It requires written contracts to permit customers to switch to another provider or on-premises infrastructure and generally sets a maximum transition period of 30 calendar days, subject to defined extensions. Providers must disclose switching procedures, formats, restrictions and technical limitations. From 12 January 2027, providers may no longer impose switching charges, although normal service fees and early-termination penalties remain distinct. For non-infrastructure services, providers must make open interfaces available free of charge to customers and destination providers to facilitate portability and interoperability. Regulation (EU) 2023/2854 – European Parliament and Council – December 2023verified official text. These provisions reduce deliberate economic friction, but they cannot eliminate architectural gravity. The most difficult Microsoft 365 assets are not raw files: they are inherited permissions, Teams relationships, SharePoint taxonomies, mailbox histories, retention classifications, Power Platform workflows, application identities, security baselines, device policies, e-discovery holds, Graph integrations and Copilot knowledge context. The destination system may accept the exported bytes yet fail to reproduce the original control semantics. True exit readiness therefore requires a functional-equivalence ledger identifying every critical business outcome, the source objects on which it depends, the destination implementation, the maximum tolerable degradation and the evidence required for acceptance. Organisations should continuously export a representative sample, rebuild it in an alternative environment and measure content completeness, access-control equivalence, workflow execution, search quality, legal retention and recovery time. This process should occur before termination becomes necessary. During geopolitical or cyber crisis, migration teams will face reduced time, impaired vendor cooperation, high demand for alternative capacity and heightened threat activity. A dormant contractual right exercised for the first time during crisis is not resilience; it is an untested assumption.

Exit objectNominal exportFunctional requirementCommon failure
Office filesDOCX, XLSX, PPTXPreserved rendering, formulas, macros and signaturesVisual or calculation divergence
EmailMessage archiveFolders, labels, retention, delegates and discoveryLost permissions and legal holds
TeamsMessages and filesThreads, participants, timestamps and meeting contextRelationships between objects disappear
SharePointFiles and listsMetadata, versions, taxonomy and workflowsFlat-file export destroys application logic
IdentityUsers and groupsRoles, service accounts, MFA and device trustAccounts migrate without authorisation semantics
Endpoint policyConfiguration exportEquivalent enforcement and rollbackPolicy syntax is provider-specific
Security telemetryLogs and alertsSearchable history, detections and evidence chainFormats differ or historical access expires
Power PlatformApplication packagesConnectors, secrets, business logic and data mappingsProprietary components cannot execute
Copilot contextSource corpusPermissions, index, prompts, citations and agent stateSemantic layer cannot be reconstructed
Encryption materialKey export where allowedUsable keys, rotation history and separation of dutiesProvider-held keys are non-exportable
Compliance recordsReports and labelsEvidentiary provenance and immutable historyStatic PDF replaces actionable records
Support knowledgeTickets and configurationsReproducible troubleshooting historyOperational knowledge remains with provider

Cybersecurity creates an asymmetric dependency on the defender

A productivity-platform provider may simultaneously act as software publisher, identity authority, endpoint administrator, telemetry collector, threat-intelligence supplier, security-information platform and incident-response partner. This convergence can improve defensive effectiveness because integrated signals allow rapid detection and containment. It also creates a security paradox: the institution depends on the same supplier to detect, explain and remediate an incident involving that supplier’s own ecosystem. If logs are inaccessible during an identity outage, if threat detections rely on cloud analytics that cannot be independently reproduced, or if the provider controls the update and attestation systems under investigation, the customer’s forensic independence is reduced. Security sovereignty therefore requires an out-of-band evidence plane. Critical logs should be streamed to independently controlled storage with immutable retention; emergency administrator identities should not rely exclusively on the normal federation service; endpoint recovery should remain possible without the principal mobile-device-management platform; backups should be protected by separate credentials and keys; and at least one incident-communications channel must operate outside the primary collaboration tenant. NIS2’s requirements for incident handling, continuity, crisis management and supply-chain security point toward this architecture, while DORA requires financial institutions to test operational resilience and manage ICT third-party risk. The central error is treating multi-region deployment inside one provider as full diversification. Regions may protect against local physical failure, yet still share software, identity, certificate, update, billing or global management dependencies. Similarly, using two SaaS products hosted on the same hyperscaler or authenticated through the same directory does not necessarily create independent recovery. Diversification must be measured by common control planes, legal entities, code bases, administrative credentials and recovery dependencies. A sovereign fallback need not reproduce every feature. It must preserve the organisation’s minimum viable command capability: authenticate emergency staff, distribute verified instructions, access critical records, communicate securely, approve transactions and retain evidence until normal operations resume.

Geopolitical exposure includes denial, leverage, intelligence and strategic timing

The direct probability that a US government would order Microsoft to terminate ordinary European civilian services remains low under current alliance conditions, and there is no verified official basis for presenting such an outcome as imminent. Security planning, however, evaluates consequence as well as probability and recognises that political conditions can change faster than enterprise architectures. Geopolitical exposure operates through at least five mechanisms. First, lawful access exposure concerns government demands for data under national law. Second, denial exposure concerns sanctions, export controls, licence restrictions or corporate decisions that could limit service availability. Third, intelligence exposure concerns the strategic information contained in metadata, support interactions, telemetry and aggregate usage patterns even where document content is encrypted. Fourth, economic leverage arises when price changes or product bundling cannot be resisted because switching is impractical. Fifth, strategic timing exposure occurs when dependency becomes most dangerous precisely during war, diplomatic confrontation, a major cyber campaign or coordinated infrastructure disruption, when alternative capacity is scarce and decision time compressed. Europe’s answer is described as open strategic autonomy, not isolation. The Digital Europe Programme explicitly links digital capacity investment to the need to avoid excessive dependence on systems and solutions originating in other regions. The Digital Europe Programme – European Commission – June 2026verified primary source. The 2026 European Technology Sovereignty strategy similarly spans chips, cloud, software, open source and AI rather than targeting a single country or company. Communication on European Tech Sovereignty – European Commission – June 2026verified primary source. The policy objective is credible optionality: Europe should remain able to purchase superior American technology while ensuring that critical public and economic functions do not become hostage to any one external jurisdiction, provider or political relationship.

Geopolitical channelTriggerDigital transmission mechanismPotential European effectPrimary mitigation
Lawful government accessCriminal or national-security processProvider under third-country jurisdictionDisclosure or preservation obligationsKey control, minimisation, legal challenge and segmentation
Sanctions/export controlsConflict or diplomatic escalationLicence, service or technology restrictionLoss of updates, support or cloud accessSubstitute operator and escrowed operational capability
Corporate withdrawalCommercial or political decisionProduct retirement or regional terminationForced migration under time pressureExit clauses and continuously tested portability
Currency/pricing leverageExchange-rate or pricing changeSubscription and consumption-based billingBudget shock and reduced bargaining powerCompetitive modular procurement
Supply-chain compromiseState or criminal intrusionTrusted update, identity or management channelCorrelated compromise across customersIndependent verification and segmented administration
Intelligence aggregationPersistent telemetry and metadata collectionUnified cloud and AI data graphExposure of organisational relationships and activityData minimisation and local telemetry control
Alliance deteriorationPolitical ruptureRestrictions, reduced cooperation or coercive leverageLoss of confidence in external control planesEuropean minimum viable stack
Crisis-capacity scarcitySimultaneous emergency migration demandLimited alternative hosting and specialist staffOrganisations cannot exit when requiredReserved capacity and migration exercises
Standard-setting powerDominant proprietary formats and APIsEcosystem defines market normsEuropean alternatives remain permanently peripheralOpen standards and public anchor procurement
AI dependencyDominant model and knowledge platformProprietary embeddings, agents and inferenceCognitive and workflow dependenceModel portability and sovereign retrieval layer

Procurement itself is becoming a geopolitical instrument

The EU is progressively connecting procurement to reciprocity, resilience and industrial capacity. Regulation 2022/1031, the International Procurement Instrument, permits the Union to investigate restrictions faced by European operators in third-country procurement markets and, under defined conditions, impose measures affecting access to EU procurement. Regulation (EU) 2022/1031 on access of third-country economic operators, goods and services to Union procurement and concession markets – European Parliament and Council – June 2022verified official text. The instrument is not a general legal basis for excluding US cloud or productivity vendors on sovereignty grounds, and it should not be misrepresented as such. Its strategic relevance is that the EU no longer treats public procurement solely as administratively neutral expenditure; procurement can support reciprocity and external economic leverage. Digital-sovereignty procurement must nevertheless remain more granular than nationality. A nominally European reseller of a US-controlled service does not remove jurisdictional or technical dependence. A European-owned provider that uses closed formats and prevents switching may reproduce monopolistic exposure. An American provider offering genuinely segregated operations, customer-controlled encryption, open interoperability and independently recoverable services might satisfy more sovereignty criteria than a weak European alternative. The correct decision matrix therefore combines corporate control, jurisdiction, operational location, key custody, software transparency, interoperability, portability, support capacity and supplier substitutability. Weighted evaluation should vary by workload classification. Public websites and ordinary office documents can tolerate broader supply options. Diplomatic communications, defence planning, police intelligence, judicial records, health data, central-bank functions and critical-infrastructure control require stronger jurisdictional and operational safeguards. The procurement authority must document why each criterion is proportionate to the workload’s risk and avoid vague “sovereignty” labels that conceal protectionism. Europe’s security interest is best served by contestable markets with hard technical requirements, not by replacing a foreign monopoly with a subsidised domestic monopoly.

Workload classExamplesAcceptable dependency postureRequired procurement controls
W₁: Public/non-sensitivePublic communications, generic trainingStandard commercial cloud acceptableBaseline portability, security and GDPR clauses
W₂: Internal administrativeRoutine HR, budgeting, ordinary collaborationEU-hosted service with tested exitMetadata export, federation and independent backup
W₃: Sensitive regulatedHealth, finance, legal and protected business dataStrong jurisdictional, cryptographic and audit controlsCustomer keys, subprocessor restrictions, detailed evidence access
W₄: Essential operationalEnergy, transport, payment and hospital operationsMulti-provider or independently recoverable designTested failover, reserved capacity and out-of-band command
W₅: National-security criticalDefence, intelligence, classified diplomacySovereign operator and tightly controlled supply chainLocal administration, independent keys, vetted personnel and isolated recovery
W₆: AI institutional memoryCross-domain corpus, agents and decision supportReplaceable models and independently governed retrievalCorpus portability, provenance, permission equivalence and model failover

Europe faces a liquidity and industrial-capacity constraint

Digital sovereignty cannot be procured if alternative suppliers lack the capital, scale and recurring revenue required to maintain security operations, certifications, support teams, data centres and long-term product roadmaps. Hyperscalers can cross-subsidise individual services, finance global infrastructure and offer enterprise discounts that smaller European vendors cannot match. Public authorities often fund the development of an open-source prototype but not the ten-year lifecycle of vulnerability remediation, integration testing, documentation, customer support and migration tooling. This produces a liquidity asymmetry: Europe may possess capable code without a financially durable operator, while the incumbent converts recurring subscriptions into further integration, AI infrastructure and partner incentives. Procurement rules can unintentionally worsen this asymmetry by favouring turnover requirements, broad indemnities, multinational support and previous-contract scale that only established vendors can satisfy. The solution is not to relax security standards. It is to aggregate demand, separate software development from competitive operation, provide reusable compliance evidence, finance core maintainers and structure multi-year framework contracts that give qualified European operators predictable revenue. The Digital Commons EDIC, openDesk, La Suite and the European open-source strategy provide institutional starting points, but their effectiveness will depend on whether public purchasers become anchor customers rather than temporary pilot sponsors. A sustainable market also requires portability between European providers; otherwise public investment creates another lock-in cycle. The shadow financial dimension must therefore be tracked through developer concentration, maintainer funding, supplier cash runway, insurance capacity, security-certification cost, cloud infrastructure ownership, customer concentration and exposure to acquisition by non-European groups. Software origin alone is insufficient. A strategically important European provider can become a new external dependency after acquisition, financial distress or reliance on foreign platform credits. Procurement due diligence should consequently include corporate-control change clauses, escrow or continuity arrangements, open licensing, transfer rights and plans for community or state-backed maintenance if the operator fails.

Five competing hypotheses for regulation-driven restructuring

Five hypotheses explain how regulation and procurement may reshape Europe’s exposure between 2026 and 2031. H₁, compliance without diversification, anticipates that organisations will satisfy NIS2, DORA and data-protection obligations through stronger contracts, certifications and incumbent-native security tools while concentration continues; its posterior probability is assessed at 28%. H₂, controlled hybrid diversification, anticipates that sensitive functions, backups, identity fallbacks and selected collaboration workloads move to European or open alternatives while Microsoft and other hyperscalers retain major roles; its posterior is 40%. H₃, public-procurement industrial policy, anticipates common European criteria, anchor contracts and shared platforms that create a viable sovereign workplace and cloud sector; its posterior is 18%. H₄, fragmentation into national sovereign stacks, anticipates divergent French, German, Italian and other national requirements that reduce foreign dependence but create intra-European incompatibility and duplicated cost; its posterior is 9%. H₅, shock-driven emergency separation, anticipates a geopolitical, legal or supply-chain crisis that forces accelerated disengagement before alternatives are mature; its posterior is 5%. The evidence favouring H₂ includes EU switching legislation, DORA concentration controls, open-source investment and operational national programmes, while continued Microsoft cloud growth and deep integration prevent a higher estimate for H₃. H₁ remains substantial because compliance budgets frequently flow to established providers with existing certifications and integration. H₄ is constrained by the Interoperable Europe Act and Digital Commons cooperation but remains plausible because national security definitions and procurement practices differ. H₅ has low probability but extreme consequence and therefore cannot be excluded from resilience planning. These are structured intelligence estimates, not official forecasts; their purpose is to make assumptions and indicators explicit.

HypothesisPriorEvidence-adjusted posteriorMain confirming indicators through 2028Main disconfirming indicators
H₁: Compliance without diversification32%28%Rising incumbent security spend; contractual controls substitute for exitsMandatory concentration limits or widespread failover testing
H₂: Controlled hybrid diversification34%40%Independent backups, sovereign collaboration, modular procurementAlternative-stack operational failures
H₃: EU procurement industrial policy18%18%Common cloud criteria, EDIC scaling, multi-state anchor contractsFragmented budgets and insufficient provider capital
H₄: National-stack fragmentation10%9%Divergent national sovereignty labels and certification schemesBinding common specifications and cross-border deployments
H₅: Emergency geopolitical separation6%5%Sanctions, service denial or severe transatlantic legal conflictStable alliance conditions and successful compliance accommodation

Five-year risk model and principal indicators

A five-year Monte Carlo model can translate these hypotheses into exposure ranges by simulating procurement reform, interoperability maturity, geopolitical friction, provider concentration, European supplier capacity, migration success and major supply-chain incidents. In the central calibration, 100,000 pathways are generated using bounded distributions rather than pretending that precise historical frequencies exist for unprecedented geopolitical events. Provider concentration begins high; regulation gradually improves contractual control and portability; supplier capacity grows more slowly; and incident severity follows a fat-tailed distribution because rare common-mode failures dominate aggregate loss. The model estimates that the median proportion of critical public-sector workplace functions dependent on a single non-European control plane declines from approximately 67% in 2026 to 48% in 2031. Under accelerated common procurement and strong supplier financing, it falls to approximately 31%; under compliance-only implementation, it remains near 61%. The median proportion of entities with a technically tested exit plan rises from approximately 8% to 44%, but only 24% achieve a fallback preserving identity, communications, critical records and independent security telemetry together. The model’s strongest sensitivity is not geopolitical friction but European operational capacity: a political decision to leave has limited effect when alternative suppliers, trained staff and migration tooling are unavailable. The second-largest sensitivity is semantic portability, especially for identity, SharePoint, Power Platform and AI knowledge graphs. The third is procurement modularity. These outputs should be updated annually against observable indicators: percentage of tenders requiring open interfaces; number of destructive exit tests; share of critical identities federated through replaceable systems; availability of independent logs; concentration of cloud expenditure; funding continuity for open-source maintainers; and capacity reserved with alternative operators. The graph below allows those drivers to be adjusted interactively.

Figure 1 · Five-Year Strategic Dependency Model

EU Critical Workplace Exposure, 2026–2031

Adjust procurement enforcement, European operating capacity, semantic portability and geopolitical pressure. The chart estimates the share of critical workplace functions remaining dependent on a single non-European control plane.

Scenario drivers
48% 2031 residual exposure
44% Entities with tested exit
24% Independent command fallback
36% Systemic-shock sensitivity
Analytical scenario output, not an official EU forecast. The model illustrates sensitivity to explicit assumptions and should be updated with verified procurement, concentration, portability and operational-testing data.

The 2026–2031 Operating Landscape: Five Hypotheses, Transition Constraints and Probable Outcomes

2026 is the inflection point, not the year of separation

Europe enters the 2026–2031 period with a strategic objective that is clearer than its implementation capacity. On 3 June 2026, the European Commission consolidated technological sovereignty into an integrated policy package comprising the proposed Cloud and AI Development Act, the EU Open Source Strategy, Chips Act 2.0 and an energy-sector digitalisation roadmap. Strengthening Europe’s Tech Sovereignty – European Commission – June 2026verified primary source. The official open-source strategy explicitly seeks to reduce dependencies across the technology stack, promote European alternatives, improve public procurement and reinforce the maintenance and security of open-source ecosystems. Tech Sovereignty, accompanied by an EU Open Source Strategy, COM(2026) 503 final – European Commission – June 2026verified official text. This does not establish an Office-removal mandate. It establishes a political and industrial framework within which public purchasers can demand greater control over identity, data, APIs, encryption, operational administration, AI models and provider switching. Simultaneously, the Commission proposed CADA as a regulation for strengthening Europe’s cloud and AI ecosystem, but as of August 2026 the measure remains within the ordinary legislative procedure and must not be treated as enacted law. Proposal for the Cloud and AI Development Act, COM(2026) 502 final – European Commission – June 2026verified official proposal. The operating landscape is consequently characterised by an implementation gap: Europe possesses enforceable rules on data portability, operational resilience, cybersecurity and interoperability; national governments are deploying open workplaces; and the Commission is using strategic procurement. Yet Microsoft’s ecosystem retains extraordinary functional density, enterprise familiarity, partner capacity and AI momentum. The five-year outcome will therefore be determined not by the number of political declarations but by whether Europe converts regulatory rights into operational alternatives and converts open-source projects into maintained, supported and economically sustainable infrastructure.

2026 starting conditionVerified statusStrategic meaning2031 question
EU technology-sovereignty policyPackage presented on 3 June 2026Whole-stack dependency is now an explicit policy objectWill policy survive budget and legislative negotiation?
EU Open Source StrategyAdopted as Commission strategyOpen source moves from administrative preference to industrial instrumentWill maintenance receive durable funding?
CADALegislative proposal, not final lawCloud and AI capacity and sovereignty enter a common frameworkWhat obligations and incentives will survive co-legislation?
Data ActApplicable since 12 September 2025Switching and interoperability gain enforceable legal foundationsWill technical portability match formal rights?
DORAApplicable since January 2025Financial-sector provider concentration becomes a regulated riskWill oversight produce actual diversification?
NIS2Transposition and implementation phaseSupply-chain, continuity and management accountability increaseWill entities test provider-loss scenarios?
Interoperable Europe ActIn force since April 2024Public-sector interoperability gains common governanceWill national alternatives interoperate cross-border?
Sovereign cloud procurement€180 million EU institutional award in April 2026The Commission begins acting as an anchor buyerCan purchasing volume alter market structure?
National open workplacesFrance, Germany and Schleswig-Holstein operationalFeasibility established at different scalesCan pilots become default production environments?
Microsoft ecosystemContinuing commercial and functional expansionIncumbent integration strengthens during European transitionCan Europe reduce dependence faster than integration deepens?

The analytical model separates adoption from sovereignty

Forecasting this transition requires avoiding the common mistake of equating the installation of an alternative application with the achievement of sovereignty. The model used here divides the operating environment into seven control layers: user applications; collaboration and communications; identity and endpoint administration; data and metadata; security and evidentiary telemetry; cloud and execution infrastructure; and AI-mediated organisational knowledge. Each layer is assigned four states. State S₀ indicates effective monopoly dependence with no tested replacement. State S₁ indicates contractual portability or an identified alternative without operational proof. State S₂ indicates a functioning alternative for a limited user group or workload. State S₃ indicates production-scale operation with tested failover and documented reversibility. A public authority that deploys LibreOffice to 70% of desktops but retains Microsoft identity, email, security, workflow and AI services might reach S₂ for document editing while remaining at S₀ or S₁ across the more strategic layers. The resulting sovereignty score must therefore be weighted by operational criticality, not by seat count. Identity, security telemetry and crisis communications receive higher weights than ordinary document editing because their simultaneous loss can disable every other service. The model also distinguishes substitution, where one product replaces another; diversification, where multiple providers reduce concentration; federation, where independently operated components interoperate; and autonomy, where the institution can continue operating after losing the incumbent. Only the final condition represents strong sovereignty. This framework makes possible a more accurate forecast: Europe may achieve substantial visible substitution by 2031 while retaining material dependence in identity, security and AI. Conversely, it may retain Microsoft Word for specialist users while substantially improving autonomy by moving sensitive data, keys, collaboration and recovery into independently controlled layers.

LayerStrategic weightS₀: CaptiveS₁: Formal exitS₂: Operational alternativeS₃: Sovereign continuity
Applications10%Only incumbent tools are supportedAlternative identifiedAlternative used by defined cohortsMultiple clients operate against open formats
Collaboration15%One communications environmentData-export terms existAlternative messaging/video in productionFederated fallback preserves crisis coordination
Identity and devices20%One directory and management planeFederation technically possibleParallel identity used for selected systemsEmergency and normal access survive incumbent loss
Data and metadata15%Files and context remain platform-boundExport APIs availableRepresentative migrations succeedContent, metadata, permissions and provenance are reconstructable
Security and evidence15%Detection and logs depend on incumbentLog-export configuration existsIndependent evidence store operatesDetection, response and forensics survive provider failure
Cloud execution10%Workloads depend on one provider/control planeContractual switching terms existSelected workloads run elsewhereCritical services can fail over across independent operators
AI knowledge layer15%Corpus, model, index and agents share one providerSource data can be exportedAlternative retrieval/model pilot worksPermissions, provenance, indexes and agents are reproducible

H₁ — Regulated continuity: Microsoft remains dominant but more constrained

The first hypothesis is that Europe modifies the conditions under which Microsoft operates without materially displacing the company from most workplace functions. Under H₁, competition remedies, Data Act switching provisions, NIS2 supplier controls, DORA oversight and data-protection enforcement improve contractual clarity and reduce selected abuses, but organisations respond by purchasing enhanced compliance, encryption and sovereign-cloud options from the incumbent rather than funding alternative architectures. This hypothesis is operationally plausible because it minimises migration risk and uses the skills, certifications and integrations already embedded in European organisations. The European Commission’s own experience demonstrates that Microsoft 365 compliance can be achieved through corrective technical, organisational and contractual measures rather than mandatory abandonment. H₁ is further supported by the cost asymmetry between improving an existing tenant and reconstructing identity, workflows, archives, endpoint management and cybersecurity on a new stack. It is weakened, however, by the Commission’s explicit whole-stack dependency language and the accelerating national programmes designed to create public-sector alternatives. Under the central estimate, H₁ carries a 22% posterior probability for 2031, down from a 31% prior at the beginning of 2024. The probability falls because policy has moved from abstract “digital sovereignty” to concrete procurement, shared open-source institutions and production deployments. Nevertheless, H₁ cannot be dismissed. The likely operational form is a more modular Microsoft relationship: Teams and other services are separately priced; sensitive workloads use stronger EU operational controls; customers export logs and backups; contracts contain improved termination assistance; and regulators monitor concentration. Microsoft remains the dominant productivity and AI supplier, but its ability to convert adjacent services into unavoidable dependencies is partially constrained.

H₁ indicatorExpected 2031 stateObservable leading signalWarning threshold
Microsoft share of public-sector productivity seatsAbove 70%Framework renewals remain Microsoft-centredNo sustained decline by 2028
Microsoft-controlled identity for public workplacesAbove 65%Entra ID remains the default federation layerAlternatives confined to pilots
Sovereign/open collaboration adoptionBelow 25%Specialist or sensitive-only useNo mass-deployment mandate
Tested exit plans25–40% of entitiesContractual exercises dominateFew destructive technical tests
Independent security telemetry30–45%Logs exported but detections remain Microsoft-nativeIncident response still requires incumbent console
Copilot/Graph AI dependenceAbove 70% of AI-enabled workplacesAI procurement added to Microsoft renewalsNo portable knowledge layer
Primary policy modeRegulation of incumbentFocus on compliance and contractual commitmentsProcurement criteria remain voluntary
Market structureDominant incumbent plus niche alternativesEuropean providers survive but do not scaleAlternatives lack recurring operating revenue

H₂ — Hybrid sovereignty: the most probable European outcome

The second hypothesis, assigned a 42% posterior probability, is that Europe develops a hybrid architecture in which Microsoft remains present but loses exclusive control over the most sensitive layers. H₂ best fits the available evidence because it reconciles three facts: incumbent displacement is expensive; European governments increasingly require sovereign options; and national programmes are constructing modular services rather than one-to-one copies of Microsoft’s entire ecosystem. Under this trajectory, ordinary users may continue to use Word, Excel, PowerPoint or Outlook where document fidelity and external compatibility justify them, while sensitive communications move to sovereign conferencing and messaging; documents are stored in independently controlled environments; identity is federated through public or replaceable services; security logs are replicated outside the incumbent; and critical administrations maintain open-source fallbacks. France’s LaSuite already illustrates this layered logic. Its official service reports more than 500,000 monthly public-sector users across 15 ministries and numerous administrations, while Tchap is reported as serving 600,000 agents. LaSuite integrates writing, videoconferencing, data management, messaging, file exchange and AI through a shared public framework, ProConnect identity and open-source components. LaSuite, the open and sovereign workspace for state employees – French Interministerial Directorate for Digital Affairs – 2026verified French government source. The platform also explicitly states important limitations: Docs and Visio can handle defined sensitive data under SecNumCloud hosting, but they are not suitable for “Diffusion Restreinte” classified content and are not currently certified for health-data hosting. This transparency supports H₂ rather than a full-exit hypothesis. Europe is likely to segment workloads by sensitivity and functionality, maintaining Microsoft where its advantages exceed concentration costs and deploying sovereign components where jurisdiction, confidentiality or continuity justify the additional expense.

H₂ operating domainMicrosoft role in 2031European/open role in 2031Probable coexistence mechanism
Basic document creationRetained for compatibility-intensive usersLibreOffice, Docs and browser editors expandOpen formats plus controlled OOXML interoperability
Complex spreadsheetsMicrosoft remains strongAlternatives handle ordinary analytics and structured dataRisk-tiered spreadsheet inventory
Email and calendarsMixedSovereign services for selected public entitiesStandard mail protocols and federated directories
Messaging and meetingsMicrosoft remains commonTchap, Visio, Matrix-based and national platforms expandCross-platform federation and guest access
File storageReduced exclusivityEuropean cloud, Nextcloud and national services growSync gateways and common metadata standards
IdentityContinued Microsoft presenceProConnect, national identity and open federation layersSAML, OIDC and portable role mappings
Endpoint managementMicrosoft remains influentialLinux/open-device cohorts and independent recovery expandDual-management and workload segmentation
SecurityMicrosoft remains a major supplierIndependent evidence and response planes become mandatoryLog streaming, out-of-band credentials and multi-provider SOC
CloudHyperscalers remain importantSovereign-cloud procurement expandsWorkload classification and operator separation
AICopilot remains prominentEuropean/open models serve sensitive and public workflowsModel routing and sovereign retrieval-augmented generation

H₃ — Public-sector bifurcation: a sovereign administrative workplace emerges

The third hypothesis, assessed at 20%, is that a distinct European public-sector workplace reaches production scale while most private enterprises remain tied to Microsoft. This outcome would resemble the separation between defence-grade communications and ordinary commercial telecommunications: government requirements create a specialised market with stronger jurisdictional, interoperability and continuity controls, but those controls do not automatically reshape the wider economy. Evidence already supports the early stages. Schleswig-Holstein reported in December 2025 that nearly 80% of state-administration workplaces had been migrated to LibreOffice. LibreOffice ersetzt Microsoft: Schon fast 80 Prozent der Arbeitsplätze umgestellt – Government of Schleswig-Holstein – December 2025verified German government source. The Land’s earlier public reporting placed its administrative workforce at approximately 25,000 and identified annual Microsoft-product expenditure of around €2.5 million, while the reduction and freezing of Microsoft Office licensing was expected to save €6.8 million over five years. Landesregierung stellt Open-Source-Bericht im Landtag vor – Government of Schleswig-Holstein – June 2020verified German government source. At federal level, Germany aims to make a digitally sovereign alternative to proprietary workplaces available to the federal administration by October 2028, with openDesk as the principal application suite. Souveräner Arbeitsplatz – German Federal Ministry for Digital Transformation and Government Modernisation – 2026verified German government source. If these programmes converge with France’s LaSuite and the Digital Commons EDIC, Europe could create sufficient aggregated public demand to sustain common software, support and certification. Yet private-sector adoption would lag because industrial firms depend more heavily on complex Excel models, Microsoft Power Platform, third-party add-ins, global customer compatibility and integrated enterprise systems.

SectorProbability of material Microsoft displacement by 2031Principal driverPrincipal constraint
Central government administration58%Sovereignty procurement and political mandateLegacy systems and cross-ministry coordination
Regional/local government46%Replicable national services and cost controlFragmented budgets and limited technical staff
Defence and national security67% for sensitive workloadsClassification and operational controlSeparate specialist systems already exist
Public education39%Cost, open standards and national policyUser familiarity and ecosystem integration
Public healthcare administration34%Data sensitivity and national cloud strategiesHealth certification and application dependence
Banking and insurance24%DORA concentration managementComplex Microsoft integrations and audit requirements
Energy and transport27%NIS2 continuity and critical-infrastructure policyOperational technology integration
Large private enterprises17%Risk diversification and bargaining leverageGlobal workflows and embedded automation
SMEs13%Subscription cost and browser-based alternativesScarce migration and support capacity
Media and professional services18%Data control and AI concernsDocument compatibility and collaboration networks

H₄ — Fragmented sovereignty: Europe replaces one dependency with twenty-seven incompatible systems

The fourth hypothesis, carrying a 10% posterior probability, is not continued US dominance or successful European sovereignty but fragmentation. Under H₄, Member States define “sovereign cloud,” “trusted provider,” “sensitive data” and “European control” differently; national administrations fund overlapping office suites; identity systems fail to federate; certification requirements diverge; and public procurement protects domestic suppliers without creating a scalable Single Market. This would reduce selected external dependencies while increasing duplication, cost and operational friction across Europe. The risk is structurally significant because security, public administration and data-governance traditions remain national, procurement is decentralised and language requirements create legitimate variation. France emphasises SecNumCloud, national hosting and LaSuite; Germany develops openDesk, openCode and the Deutschland-Stack; Italy combines the Polo Strategico Nazionale with national identity and cybersecurity programmes; other Member States may adopt Microsoft sovereign-cloud offerings, domestic providers or open-source combinations. The Interoperable Europe Act and the Digital Commons EDIC are intended to prevent this outcome, but their effectiveness depends on shared technical specifications, reusable components and governance capable of resolving national preferences. The Commission’s Open Source Strategy recognises this by linking public-administration adoption to common ecosystems and standards rather than isolated national codebases. Commission boosts open and interoperable digital ecosystems for public administrations – European Commission – June 2026verified primary source. Fragmentation would manifest as nominally open platforms that cannot exchange permissions, audit evidence, document semantics or AI agents. It would also weaken supplier economics: European vendors would repeatedly adapt to national requirements rather than amortising development across the Single Market. The key 2027–2029 indicator is therefore not the number of national sovereignty programmes but the proportion of components deployed in more than one Member State without bespoke architectural redesign.

Fragmentation vectorEarly warning indicator2031 consequenceCorrective mechanism
Sovereignty definitionsIncompatible national eligibility criteriaSuppliers cannot scale EU-wideCommon EU Cloud Sovereignty Framework
IdentityNational directories without federationCross-border public work remains cumbersomeShared OIDC/SAML profiles and EUDI integration
Document formatsDifferent mandatory profilesRendering and archival divergenceCommon conformance suites
Security certificationOverlapping national audit requirementsDuplicated expense and delayed deploymentMutual recognition and EU certification
ProcurementDomestic preference without shared specificationsProtected national oligopoliesJoint framework contracts
Open-source governanceNational forks without upstream coordinationSecurity patches and features divergeShared maintainers and contribution rules
HostingNational-only infrastructure requirementsReduced capacity poolingFederated European operators
AI modelsLanguage-specific models with incompatible interfacesAgent and knowledge fragmentationCommon inference and provenance interfaces
SupportCountry-specific supplier ecosystemsUneven resilience between Member StatesCross-border operating consortia
FundingShort national project cyclesAbandoned code and maintenance gapsMultiannual European infrastructure funding

H₅ — Shock-driven decoupling: low probability, highest disruption

The fifth hypothesis, assigned a 6% posterior probability, assumes that a geopolitical, legal, sanctions, cybersecurity or service-continuity event forces Europe to accelerate separation before alternative systems are mature. The trigger need not be a formal US order to disconnect European users. A major supply-chain compromise, prolonged identity outage, transatlantic legal conflict, abrupt licensing restriction, AI-data controversy or collapse in political trust could cause governments to classify external dependence as an immediate rather than long-term risk. H₅ has the lowest probability but the greatest economic and operational cost because migration would occur during reduced provider cooperation, intense demand for replacement capacity and heightened adversarial activity. The 2022–2025 experience of Russian software substitution demonstrates the general mechanism—although the European political and market context is fundamentally different: restrictions and geopolitical separation can compress technology-transition schedules from years to months, exposing shortages in domestic software, skilled staff, compatible formats and support. Europe would enter such a shock with uneven readiness. France possesses operational sovereign services; Schleswig-Holstein has mass desktop-migration experience; Germany is targeting federal availability by October 2028; other administrations remain substantially dependent on Microsoft-controlled identity and collaboration. The probable emergency response would not be comprehensive replacement. Governments would prioritise a minimum viable sovereign workplace: emergency authentication, secure messaging, videoconferencing, document access, file transfer and out-of-band incident coordination. Complex spreadsheets, ordinary external collaboration and business applications would remain on the incumbent where service continued. The central policy implication is that a 6% probability does not justify panic, but it does justify funded contingency planning. Expected-loss analysis multiplies probability by impact; a low-probability event affecting government command, hospitals, finance and critical infrastructure can warrant significant preventive expenditure.

Shock phaseTime horizonRequired capabilityLikely bottleneckMaximum acceptable preparation state
DetectionHoursDetermine provider, legal and sector scopeIncomplete dependency inventoryReal-time service and trust map
Containment0–24 hoursProtect identities, keys and evidenceShared control plane may already be impairedIndependent emergency credentials
Command continuity0–72 hoursMaintain secure communications and approvalsCollaboration platform concentrationOut-of-band sovereign communications
Data preservation0–7 daysExport or isolate critical recordsAPI limits and unavailable metadataContinuous independent replication
Minimum service restoration1–4 weeksActivate essential alternative applicationsCapacity and staff shortagesReserved hosting and rehearsed runbooks
Functional migration1–6 monthsReconstruct workflows and permissionsProprietary automation and identity semanticsPre-mapped functional-equivalence ledger
Stabilisation6–18 monthsPatch, certify and support alternativesMaintainer and supplier financeMultiannual operating contracts
Strategic redesign18–60 monthsDiversify stack and supplier marketPolitical fatigue after crisisStatutory concentration controls

Transition constraint 1: document fidelity is the easiest problem until spreadsheets become applications

The visible migration begins with documents, but complexity rises nonlinearly. Ordinary correspondence, presentations and simple tables can be converted or opened in alternative suites with manageable quality assurance. The critical constraint lies in executable spreadsheets and documents integrated into business processes. Large organisations often cannot state how many spreadsheets contain macros, external data connections, proprietary add-ins, embedded scripts, Power Query transformations, pivot models or links to SharePoint and Power BI. These files operate as unmanaged software and may support payroll, risk calculations, tender evaluation, production planning, financial forecasting, engineering configuration or regulatory reporting. A five-year transition requires a document estate census rather than a file count. Each object should be fingerprinted and classified by format, last use, owner, sensitivity, macro presence, external dependency, calculation complexity, signature status and retention requirement. Migration planning then separates inactive archives, ordinary active documents, high-fidelity documents, executable spreadsheets and workflow-bound objects. Automated conversion is appropriate only for the first categories. Executable documents require parallel runs and output reconciliation. Workflow-bound objects may require application redevelopment rather than format conversion. Schleswig-Holstein’s large-scale LibreOffice deployment provides important feasibility evidence, but its result cannot automatically be extrapolated to banks, manufacturers or multinational enterprises whose spreadsheet estate may contain millions of interdependent formulas and add-ins. Under the central 2031 model, document editing reaches the highest European sovereignty maturity, but complex spreadsheet functions remain the last major Office-specific dependency. A plausible operating outcome is that 60–75% of ordinary public documents move to open or browser-based editing while 70–85% of high-complexity spreadsheets remain within Excel or undergo costly redevelopment.

Document migration tierIdentification ruleTreatmentAcceptance evidenceEstimated transition window
D₁: Dormant archiveNo operational use within retention periodPreserve, normalise where lawfulChecksums, rendering and metadata2026–2028
D₂: Simple active documentNo macros, links or complex objectsAutomated conversion or dual-format operationVisual and semantic comparison2026–2029
D₃: High-fidelity documentTemplates, tracked changes, signaturesControlled conversion and user validationPage-level comparison and signature check2027–2030
D₄: Analytical spreadsheetComplex formulas, pivots and queriesParallel-run validationReconciled calculations and error thresholds2027–2031
D₅: Executable spreadsheetVBA, add-ins or external systemsRefactor into governed applicationFunctional tests and audit trail2028–2033
D₆: Workflow-bound recordSharePoint, Power Platform or approval logicProcess redevelopmentEnd-to-end workflow replay2028–2033
D₇: AI-indexed knowledge objectUsed by Copilot or semantic searchPreserve corpus, permissions and provenanceRetrieval and citation benchmark2027–2031

Transition constraint 2: identity, endpoint management and security form the hard core

Identity is the most difficult layer to replace because it functions as the root of trust for applications, devices, administrators and workloads. An Entra ID deployment may include millions of user and service identities, conditional-access policies, multifactor-authentication methods, device-compliance signals, privileged roles, federation relationships and connections to third-party SaaS platforms. Active Directory may remain embedded in local networks, file permissions, application authentication and certificate services. Intune may enforce device configuration and determine whether endpoints are permitted to access sensitive resources. Defender and Sentinel may use identity and endpoint telemetry to detect attacks. Replacing one component can therefore degrade the security properties of the others. A responsible transition begins with federation and independent recovery rather than immediate removal. Organisations should establish an authoritative identity source independent of the productivity platform, document every privileged and workload identity, create provider-independent emergency accounts, replicate critical logs, and verify that third-party applications accept standards-based federation without proprietary conditional-access dependencies. Endpoint management should support at least one alternate provisioning and recovery mechanism. Security operations should receive immutable telemetry outside the incumbent ecosystem and maintain detection rules that can be reimplemented in another platform. The technical objective by 2031 is not necessarily the disappearance of Microsoft identity but a reduction in root-of-trust exclusivity. Under the central scenario, Microsoft remains involved in a majority of European enterprise identity environments; however, the share of critical public entities able to authenticate emergency users and recover essential services without the primary Microsoft tenant could rise from an estimated single-digit baseline in 2026 to 35–50% by 2031. If this capability does not develop, visible Office migration will leave the decisive control plane unchanged.

Hard-core componentHidden couplingMigration prerequisiteFailure test
User directoryGroups, roles and application assignmentsAuthoritative provider-neutral identity schemaDisable primary directory and authenticate emergency cohort
Privileged identityJust-in-time access and approval workflowsIndependent break-glass governanceRecover administrator access without incumbent cloud
Workload identitiesApplication secrets and managed identitiesInventory and portable credential mechanismRestart critical services on alternative platform
Conditional accessDevice, location, risk and user signalsDocumented policy semanticsReproduce allow/deny decisions
MFAProvider-specific enrolment and recoveryPortable authenticators or re-enrolment planRestore access during primary MFA outage
Endpoint managementDevice configuration and complianceAlternative imaging, patch and policy toolsRebuild representative endpoint independently
Threat detectionProprietary analytics and telemetryIndependent logs and mapped detection logicDetect reference attack without incumbent analytics
Incident evidenceCloud-hosted audit and investigation dataImmutable external evidence storeConduct forensic reconstruction during tenant outage
Certificates and keysPlatform-managed signing and encryptionCustomer-controlled lifecycle and escrowRotate and recover keys independently
SaaS federationVendor-specific claims and APIsStandards-based contracts and test suiteMove application to alternate identity provider

Transition constraint 3: open source must become an industry, not a repository

Europe already possesses extensive open-source code and millions of contributors, but code availability is not equivalent to enterprise operating capacity. Public administrations require predictable releases, coordinated vulnerability disclosure, software bills of materials, reproducible builds, long-term support branches, multilingual documentation, accessibility testing, professional indemnity, 24-hour incident response, security certification and integration partners. These services require recurring capital. The EU Open Source Strategy correctly identifies ecosystem sustainability, security, maintenance, skills and public procurement as separate objectives rather than assuming that developers will provide public infrastructure indefinitely. EU Open Source Strategy – European Commission – June 2026verified primary source. The operating constraint is particularly acute for composite workplace platforms: openDesk and LaSuite integrate multiple upstream projects, each with its own governance, release cycle and contributor base. A vulnerability in Matrix, a conferencing component, a document editor, an identity gateway or a container image can affect the whole service. Europe therefore needs product-level operators and upstream-maintenance capacity simultaneously. Procurement should allocate explicit percentages to upstream contributions and security maintenance, require transparent dependency inventories and avoid national forks that cannot absorb later security fixes. Supplier economics must be evaluated through annual recurring revenue, customer concentration, maintainer headcount, cash runway, certification cost and ability to survive the loss of a major public contract. Under the central trajectory, the open workplace succeeds only if governments change from project financing to infrastructure purchasing. A €5 million development grant may launch a platform; it does not fund ten years of patching and operation. The 2027–2029 period is thus decisive: if shared European framework contracts materialise, H₂ and H₃ probabilities rise; if funding remains fragmented and temporary, H₁ or H₄ becomes more likely.

Open-source industrial capabilityProject-stage conditionInfrastructure-stage requirement2028 gate
GovernanceInformal maintainersPublished decision rights and successionNo single-person critical dependency
SecurityCommunity issue handlingCoordinated disclosure, security team and SLACritical fixes available within defined window
Build integrityPublic source repositoryReproducible and signed release pipelineIndependent build verification
DependenciesPackage manifestContinuous SBOM and vulnerability monitoringFull transitive dependency visibility
SupportCommunity forumsTiered professional support in EU languagesCross-border support consortium
CertificationAd hoc auditsReusable evidence and maintained certificationValid certification for target workloads
AccessibilityPartial complianceContinuous testing against public requirementsVerified conformance before mass deployment
TrainingProduct documentationStructured administrator and user curriculaNational training capacity
FinanceGrants and pilotsMultiannual operating revenueThree- to five-year anchor contracts
Upstream contributionOpportunisticContractually funded maintenanceMeasurable contribution ratio
PortabilitySource code availableDocumented deployment and data migrationIndependent operator successfully deploys
Disaster recoveryBackup documentationTested multi-operator recoveryAnnual destructive exercise

The sovereign cloud becomes the execution layer for the new workplace

The Commission’s April 2026 sovereign-cloud procurement constitutes a significant transition from policy to market intervention. The Commission reported that a €180 million contract covering EU institutions, bodies, offices and agencies had been awarded to four providers, using a Cloud Sovereignty Framework intended to assess and improve the sovereignty posture of acquired services. Sovereign Cloud Framework explained – European Commission – June 2026verified primary source. The framework evaluates sovereignty through structured objectives rather than relying solely on the location of data centres. Its implementation guidance uses a Sovereignty Effectiveness Assurance Level and an overall sovereignty score, creating a basis for comparative procurement. Cloud Sovereignty Framework – European Commission – October 2025verified primary framework. This approach could become the common denominator linking workplace software to infrastructure, but several constraints remain. A sovereign cloud can host an open workplace while still depending on foreign processors, firmware, virtualisation, container registries, support tools or AI accelerators. Conversely, a foreign-origin platform can improve its effective sovereignty through local operations, technical separation and customer-controlled keys. The strategic measure is not provider nationality alone but the verified ability to operate, update, recover and migrate the workload under European control. Between 2026 and 2031, cloud procurement will likely produce differentiated service classes rather than a single sovereign standard. Low-sensitivity workloads will continue using global hyperscalers. Sensitive public workloads will increasingly require European legal control, operational personnel, key custody and supply-chain transparency. National-security workloads will remain within more restrictive systems. The workplace transition succeeds only if applications, identity, storage and AI can move across these service classes without architectural reconstruction.

Cloud control domainWeak sovereigntyIntermediate sovereigntyStrong sovereignty
Legal entityEU subsidiary of external groupRing-fenced European operationEuropean-controlled operator
Data residencySelected EU regionContractually restricted EU processingVerified EU-only processing and administration
Key custodyProvider-managed keysCustomer-managed keys within providerIndependent customer or trusted-third-party keys
PersonnelGlobal support accessRestricted EU supportVetted EU-controlled administration
Software controlProprietary global releaseRegionally controlled deploymentIndependently operable and maintainable stack
Supply chainLimited disclosureNamed critical subprocessorsFull dependency mapping and substitution plans
IdentityProvider-native directoryExternal federation supportedProvider-independent identity and emergency access
PortabilityFile exportWorkload and metadata exportTested multi-provider functional recovery
AIGlobal model endpointEU-hosted inferenceReplaceable model, sovereign corpus and audit plane
Failure recoverySame-provider regionsIndependent backup providerIndependent operator and tested failover

Italy’s position: a potential integrator rather than merely a consumer

Italy’s strategic opportunity lies in connecting national cloud, identity, cybersecurity and public-administration assets to the European common-workplace architecture. Italy is a founding participant in the Digital Commons EDIC alongside France, Germany, the Netherlands and Luxembourg, and Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, holds a vice-presidential role in its governance. This position gives Italy influence over the design of shared open components, funding priorities and cross-border security requirements. Italy’s risk is institutional fragmentation: cloud migration through the Polo Strategico Nazionale, identity through SPID and CIE, interoperability through national platforms, cybersecurity oversight through ACN and workplace procurement across ministries and regions may advance independently without forming a coherent sovereign stack. A strategically effective Italian roadmap would establish a national workplace dependency inventory, classify workloads, identify which French and German components can be reused, fund Italian integration and support firms, and require that national enhancements remain upstream-compatible. Italy should not attempt to recreate every component. Its comparative advantage can lie in secure operation, public-sector integration, regulated-industry deployment, Mediterranean-language support, document and workflow migration, and cybersecurity assurance. Between 2027 and 2029, Italy should pilot a common European workplace across selected non-classified administrative functions while preserving Microsoft compatibility for external exchange and complex spreadsheets. By 2030, it should possess an independently operated emergency collaboration and identity environment for central government. By 2031, success should be measured by the percentage of critical functions recoverable outside the primary provider, not the number of Microsoft licences cancelled. This approach would also create exportable capabilities for the Balkans and Mediterranean, where Italian public and private operators maintain strategic relationships.

Italian action gate20272028202920302031
Dependency registerCentral methodology adoptedMajor ministries mappedRegional extensionContinuous telemetry integrationNational aggregate concentration view
Common workplace pilotComponent selectionMulti-ministry pilotProduction cohortBroader administrative deploymentCross-border EDIC interoperability
Identity independenceEmergency-account designAlternative federation pilotCritical-service integrationGovernment command fallbackRegular failover exercises
Data portabilityRepresentative exportsMetadata migration testsWorkflow reconstructionContinuous archival replicationAudited exit readiness
Supplier ecosystemQualification frameworkMultiannual support contractsCross-border consortiaExport capabilitySustainable market
AI sovereigntyCorpus classificationSovereign RAG pilotModel-routing deploymentAgent portability testsIndependent public-sector knowledge layer
Microsoft relationshipContract mappingModular renewal criteriaReduced bundle dependenceWorkload-specific sourcingManaged coexistence or targeted exit

Quantified five-year outlook

The probabilistic model uses 100,000 simulated pathways across nine principal variables: regulatory enforcement, public-procurement coordination, European supplier capacity, document compatibility, identity portability, security-telemetry independence, AI-layer portability, geopolitical friction and user adoption. The distributions are bounded and scenario-based because no statistically sufficient historical dataset exists for a continent-scale productivity-stack transition under modern cloud and AI conditions. Correlation is explicitly included: stronger procurement raises supplier revenue; supplier revenue improves support capacity; better support raises adoption; and higher adoption lowers migration unit cost. Conversely, legacy complexity correlates with user resistance and failure risk. Geopolitical friction accelerates political decisions but can reduce orderly migration time. Under the central path, the share of EU public-sector workplace functions materially outside Microsoft’s exclusive control rises from an estimated 11% in 2026 to 38% in 2031. The figure for ordinary document editing reaches approximately 55%, while identity independence reaches only 31%, independent security evidence 43%, sovereign collaboration 49% and portable AI knowledge functions 24%. The model estimates a 19% probability that more than half of public-sector workplace functions will be outside Microsoft’s exclusive control by 2031. It estimates only a 4% probability of an EU-wide functional exit across applications, collaboration, identity, cloud, security and AI. These values are analytical estimates, not observed facts or official forecasts. The central conclusion is robust across calibrations: Europe is more likely to dismantle exclusivity than to remove Microsoft. The transition’s success will appear as a change from single-stack dependence to governed multi-stack operation, with the most sensitive functions moving first and complex enterprise workflows moving last.

Model output2026 estimate2028 median2031 adverse2031 median2031 accelerated
Workplace functions outside Microsoft exclusive control11%22%20%38%61%
Ordinary public-document editing on alternatives18%34%32%55%76%
Sovereign/open collaboration functions14%29%28%49%72%
Critical entities with independent identity fallback6%14%16%31%53%
Critical entities with independent security evidence12%25%27%43%66%
Critical cloud workloads with tested provider exit8%19%21%39%62%
Portable AI knowledge functions3%9%10%24%46%
Entities performing annual provider-loss exercises4%13%14%29%51%
Probability of over 50% functional displacementBelow 2%6%5%19%57%
Probability of complete functional Microsoft exitBelow 1%1%2%4%12%

Decision indicators that will reveal the real trajectory before 2031

The five hypotheses can be updated through observable indicators rather than rhetorical interpretation. H₁ gains probability if Microsoft enterprise renewals continue to bundle identity, security and AI; if public tenders accept certifications without requiring technical exit tests; and if open alternatives remain confined to pilots. H₂ gains probability if institutions retain Microsoft applications but deploy independent identity fallbacks, external security evidence, sovereign collaboration and modular contracts. H₃ gains probability if openDesk, LaSuite and related components reach multi-country production scale and if joint procurement creates sustainable operator revenue. H₄ gains probability if Member States impose incompatible sovereignty criteria, fork common components or refuse mutual recognition of security evidence. H₅ gains probability if alliance relations deteriorate, external legal conflicts escalate, provider services are restricted or a major common-mode cyber incident destroys confidence in a control plane. A formal Bayesian update should be performed every six months using documented evidence, assigning likelihood ratios to each indicator and discounting correlated observations. For example, three government announcements derived from the same EU strategy should not be counted as independent evidence, whereas a production deployment, an audited migration result and a multiannual operating contract represent distinct evidence. The decisive indicators are financial and operational: recurring expenditure on European operators; number of production users; percentage of critical metadata successfully migrated; number of tested provider-loss exercises; time required to restore identity; security-patch latency; and number of components deployed in multiple Member States. If those metrics improve, European sovereignty is becoming real. If only licence counts and strategy documents change, the transition remains performative.

IndicatorH₁ signalH₂ signalH₃ signalH₄ signalH₅ signal
Microsoft enterprise renewalsBroad bundled growthModular renewalsPublic-sector reductionNationally divergent contractsEmergency suspension
Alternative production usersBelow 10%10–35%Above 35% public-sectorHigh but nationally isolatedRapid forced increase
Identity fallback testsRareSelected critical entitiesPublic-sector standardIncompatible national systemsEmergency activation
Cross-border open componentsMinimalGrowing reuseCommon European defaultNational forksCrisis-driven sharing
Supplier operating revenueGrant-dependentStable niche revenueLarge multiannual frameworksFragmented national fundingEmergency public financing
Metadata migration successFile-only exportsRepresentative successStandardised at scaleDifferent national formatsIncomplete emergency transfer
AI portabilityMicrosoft-nativeMulti-model routingPublic sovereign AI layerNational model islandsAbrupt model substitution
Sovereign-cloud procurementOptional lotsWorkload-based useCommon EU frameworkConflicting national schemesCompulsory emergency use
Provider-loss exercisesCompliance tabletopTechnical cohort testsAnnual public standardNationally inconsistentReal-world activation
Political languageRisk managementControlled interdependencePublic digital autonomyNational technological sovereigntyStrategic decoupling

Probable 2031 outcome: controlled interdependence, not a European Microsoft vacuum

The most probable operating landscape in 2031 is a layered system of controlled interdependence. Microsoft remains deeply embedded in European private enterprises and retains substantial public-sector presence, particularly for complex spreadsheets, global document exchange, endpoint management and AI-enhanced productivity. Its market position is nevertheless less structurally absolute because European institutions possess sovereign collaboration platforms, more modular procurement, stronger cloud-switching rights, independent security evidence and operational alternatives for sensitive functions. France operates LaSuite at scale; Germany provides openDesk as a federal alternative; Schleswig-Holstein demonstrates sustained desktop substitution; Italy and other Digital Commons EDIC participants integrate shared components into national environments; and the Commission’s sovereign-cloud framework shapes procurement beyond EU institutions. The decisive limitation remains uneven maturity. Wealthier central administrations can fund migration engineers, dual operations and security certification, while smaller municipalities, hospitals and SMEs risk remaining dependent because bundled hyperscaler services appear cheaper and easier. Europe will therefore need common managed services, not merely downloadable code. The economic outcome will not be a single “European Microsoft.” It should be a federated market of software communities, specialised vendors, national operators and European cloud providers connected through open standards and common procurement. This architecture is less superficially efficient than one integrated global suite, but it reduces common-mode failure and preserves political choice. By 2031, the correct question will no longer be whether Europe has said goodbye to Microsoft Office. It will be whether a government can lose Microsoft identity, collaboration or cloud access on Monday and continue authenticating staff, communicating securely, accessing critical records, investigating attacks and making lawful decisions on Tuesday. If the answer is yes, Europe has achieved meaningful sovereignty even if Word remains installed. If the answer is no, licence substitution will have changed the desktop without changing the balance of power.

Figure 1 · Europe Workplace Sovereignty Simulator

Five-Hypothesis Operating Landscape, 2026–2031

Adjust regulatory execution, European supplier capacity, technical portability, user adoption and geopolitical pressure. The graph recalculates functional displacement across seven workplace-stack layers and updates the five competing hypotheses.

Strategic drivers
22%H₁ Regulated continuity
42%H₂ Hybrid sovereignty
20%H₃ Public bifurcation
10%H₄ Fragmentation
6%H₅ Shock decoupling
Analytical scenario model, not an official EU forecast. Values represent functional displacement from Microsoft’s exclusive control, not removal of Microsoft software. Model outputs vary deterministically with the selected assumptions.

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.