Executive Summary
BLUF: Europe is not preparing a universal prohibition of Microsoft Office; it is engineering the capacity to operate without compulsory dependence on Microsoft.
The decisive shift is from product substitution to sovereign control of data, identity, cloud infrastructure, document formats and procurement.
The European Commission’s June 2026 technology-sovereignty package elevated cloud and open source from administrative preferences to strategic infrastructure policy.
Germany’s Schleswig-Holstein demonstrates that Office replacement is technically possible: nearly 80% of approximately 25,000 public-sector workplaces had moved to LibreOffice by December 2025.
Regulatory pressure is real but not equivalent to expulsion: Microsoft resolved the Commission’s 2024 data-protection findings, while its Teams commitments became legally binding under EU competition law in 2025.
The most probable 2031 outcome is a hybrid European workplace, with open formats and sovereign collaboration layers coexisting with Microsoft applications.
Modelled probability of an EU-wide Office elimination by 2031: 8%. Probability of material public-sector Microsoft displacement: 62%.
The strategic contest will be decided less by Word or Excel than by Entra ID, Exchange, Teams, SharePoint, OneDrive, Azure, Copilot and the data graph connecting them.
Europe Is Not Abandoning Microsoft Office. It Is Preparing to Survive Without It
Europe’s apparent revolt against Microsoft Office is not a campaign to replace familiar icons on millions of desktops. It is a struggle over who controls identity, institutional data, cloud infrastructure, cybersecurity telemetry and the emerging AI layer through which administrations will organise knowledge and decisions. On 3 June 2026, the European Commission elevated that concern into industrial policy, proposing a technological-sovereignty package spanning semiconductors, cloud, AI and open source. The objective is neither digital autarky nor the exclusion of American technology. It is the recovery of a credible exit option. Europe wants to ensure that no foreign platform—however efficient—remains technically, contractually or legally irreplaceable.
Beyond Word and Excel
Microsoft Office is no longer simply Word, Excel and PowerPoint. Microsoft 365 binds those applications to Outlook, Teams, SharePoint, OneDrive, Entra ID, Intune, Defender, Purview, Power Platform, Microsoft Graph and Copilot. Together they form an institutional operating environment: users are authenticated, devices authorised, communications archived, documents classified, threats detected and organisational knowledge indexed inside one ecosystem.
Replacing Word with LibreOffice while retaining Microsoft identity, storage, email, endpoint management and AI would therefore change the visible application without transferring strategic control. The true European objective is stack sovereignty: the ability to replace individual layers while preserving data, permissions, evidence, workflows and operational continuity.
This distinction explains the breadth of the Commission’s European technological-sovereignty package, presented on 3 June 2026. It combines the proposed Cloud and AI Development Act, Chips Act 2.0, an EU Open Source Strategy and an energy-sector digitalisation roadmap. The Commission describes open source as an instrument for scaling European alternatives, supporting skills and start-ups, and increasing adoption within public administrations.
The Cloud and AI Development Act remains a legislative proposal, not settled law. Yet its direction is unmistakable: cloud capacity, AI infrastructure, open software and semiconductor resilience are being treated as parts of the same strategic system.
Sovereignty Becomes Measurable
Europe is also replacing the imprecise language of “trusted cloud” with measurable procurement criteria. In April 2026, the Commission awarded a €180 million sovereign-cloud contract to four providers for EU institutions, bodies, offices and agencies.
The tender applied a Cloud Sovereignty Framework containing 48 criteria grouped into eight categories: strategic; legal and jurisdictional; data and AI; operational; supply chain; technological; security and compliance; and environmental sustainability. It introduced Sovereignty Effectiveness Assurance Levels ranging from SEAL-0, where control remains exclusively with non-EU actors, to SEAL-4, defined as full European control without critical non-EU dependencies.
This is more consequential than a political preference for European suppliers. It recognises that locating servers in Frankfurt, Paris or Milan does not alone establish sovereignty. The decisive questions are who controls encryption keys, administrators, software updates, privileged identities, subcontractors and recovery procedures; whether foreign authorities can exercise legal reach over the operator; and whether another provider could restore the service if the incumbent became unavailable.
Procurement is thus becoming an instrument of security policy. A cloud offer will increasingly be judged not only on price and performance, but on the customer’s capacity to continue operating after separation from the provider.
The Regulatory Pincer
Several EU instruments are converging on the same dependency problem. The Data Act, applicable since 12 September 2025, requires contractual provisions facilitating movement between data-processing services and imposes portability and interoperability obligations. From 12 January 2027, providers may no longer charge customers for the switching process. The official text is contained in Regulation (EU) 2023/2854.
But legal portability does not guarantee operational portability. Files may be exported while permissions, retention labels, Teams conversations, SharePoint taxonomies, Power Automate workflows, security histories and Copilot indexes remain difficult to reconstruct. A nominal exit can therefore produce a data archive without reproducing the institution that used it.
Competition policy addresses another layer. On 12 September 2025, the Commission made Microsoft’s commitments concerning Teams legally binding. Microsoft must offer business productivity suites without Teams at lower prices, enable qualifying customers to switch and support interoperability and data portability for competing collaboration services. The interoperability and portability commitments run for ten years.
Data protection has produced a more nuanced result than headlines suggesting that Microsoft 365 is intrinsically unlawful. In March 2024, the European Data Protection Supervisor found infringements in the Commission’s use of Microsoft 365 and ordered corrective measures. In July 2025, after changes by the Commission and Microsoft, the EDPS closed the enforcement proceedings, concluding that compliance had been achieved. The lesson is not that Microsoft is prohibited, but that contractual purpose, data flows, processor instructions and international-transfer safeguards must be actively governed.
France Builds a Public Stack
France is constructing the clearest alternative to the Microsoft-centred workplace. LaSuite, operated by the Interministerial Directorate for Digital Affairs, now reports more than 500,000 monthly users across 15 ministries and numerous administrations. Its secure messaging service Tchap is used by 600,000 public agents.
The platform integrates collaborative writing, videoconferencing, messaging, file exchange, data management and AI. Authentication is provided through ProConnect; services employ open-source technologies and, for specified workloads, SecNumCloud hosting. Governance is shared by ten interministerial co-financiers.
France is not pretending that the transition is complete. The LaSuite technical and service framework states that Docs and Visio may process defined sensitive data but are not suitable for content classified “Diffusion Restreinte”; nor are they currently certified to host health data. That limitation is strategically important. It shows that sovereignty is being built through workload classification, not proclaimed through branding.
France’s model is modular: public identity, conferencing, messaging, documents and AI can evolve independently while remaining connected. This is closer to Europe’s probable future than a single sovereign suite attempting to imitate every Microsoft function.
Germany Tests Mass Migration
Germany offers two complementary experiments. Schleswig-Holstein is demonstrating desktop substitution at scale. On 4 December 2025, the Land reported that nearly 80% of its administrative workplaces had moved from Microsoft Office to LibreOffice. The state administration comprises approximately 25,000 employees.
An earlier government assessment placed annual Microsoft-product costs at roughly €2.5 million and projected €6.8 million in savings over five years from reducing and freezing Microsoft Office licensing. The significance extends beyond savings: Schleswig-Holstein is also pursuing OpenDocument Format, Linux, Nextcloud, Open-Xchange and alternatives to SharePoint, Exchange and Active Directory.
At federal level, Germany is developing openDesk, a web-based office and collaboration environment supported by the Centre for Digital Sovereignty. The federal objective is to make a digitally sovereign alternative to proprietary workplaces available to the administration by October 2028, according to the Federal Ministry for Digital Transformation and Government Modernisation.
The two programmes solve different problems. Schleswig-Holstein establishes that mass user migration is possible; openDesk seeks to replace the wider collaborative environment. Neither yet proves that Europe can reproduce the most complex Excel models, enterprise workflows, security integrations or AI knowledge graphs.
Italy’s Strategic Choice
Italy is not outside this architecture. It is a founding participant in the Digital Commons European Digital Infrastructure Consortium alongside France, Germany, the Netherlands and Luxembourg. Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, holds one of the consortium’s vice-presidencies.
Italy’s opportunity is not to finance another national Office clone. It can integrate national strengths—Polo Strategico Nazionale, SPID, CIE, the National Digital Data Platform and the cybersecurity authority ACN—with shared European components. Its industrial role could include secure operation, regulated-sector deployment, migration engineering, identity federation, document conversion and cybersecurity assurance.
The danger is fragmentation. If cloud migration, digital identity, workplace procurement and open-source development proceed through separate institutional channels, Italy may localise data without acquiring control over applications, metadata, security or AI. The relevant national indicator should therefore not be the number of Microsoft licences cancelled, but the proportion of critical functions that could be restored through an independently operated alternative.
For central government, an achievable target by 2030 would be a tested emergency environment providing authentication, secure messaging, videoconferencing, file access and incident coordination outside the primary productivity tenant. This would create real resilience without imposing an economically disruptive universal migration.
The Excel and Identity Barriers
Two obstacles will determine the pace of transition. The first is Excel. In large organisations, spreadsheets frequently function as undocumented applications, containing Visual Basic macros, external databases, Power Query transformations, proprietary add-ins and financial or operational models. Replacing the file format does not replace the process. Complex estates must be inventoried, classified and tested through parallel calculations; some spreadsheets will require redevelopment as governed applications.
The second obstacle is identity. Entra ID and Active Directory can govern users, devices, service accounts, privileged administrators and access to thousands of external applications. Intune adds device compliance; Defender and Sentinel add detection and response. Removing Word while leaving this root of trust untouched produces limited sovereignty.
The realistic European path is federation before replacement: provider-independent identity sources, standards-based authentication, emergency administrator accounts, externally stored security logs and recovery mechanisms that do not depend on the primary provider. Identity independence will advance more slowly than document substitution, but it will determine whether Europe’s new architecture can survive a serious outage or political rupture.
AI Recreates Lock-In
Copilot raises the stakes. When AI indexes mail, meetings, documents, permissions and workflows through Microsoft Graph, dependence moves from files to institutional cognition. An organisation may export its documents but lose the semantic index, embeddings, prompts, agent configurations and permission-aware retrieval environment that made those documents useful.
Microsoft’s own fiscal-year 2025 disclosure shows the strength of the underlying momentum: Microsoft 365 Commercial cloud revenue grew 15%, commercial seats increased 6%, and the consumer subscriber base reached 89 million. Europe is therefore building alternatives while the incumbent is deepening integration through AI.
A sovereign AI workplace must allow institutions to change models without reconstructing their entire knowledge system. That requires portable corpora, traceable sources, reproducible indexes, provider-independent permissions and auditable agent configurations. Without them, Europe could reduce Office dependence only to acquire a more opaque Copilot dependence.
The Most Probable 2031
A complete European exit from Microsoft by 2031 is improbable. The more credible outcome is controlled interdependence. Microsoft will remain important, particularly in private industry, complex spreadsheets, multinational collaboration and AI-enabled productivity. Yet its control will become less exclusive.
Public administrations will increasingly segment workloads. Ordinary applications may remain commercial; sensitive communications will migrate to sovereign services; critical data will use stronger jurisdictional and cryptographic controls; security evidence will be replicated independently; and emergency identity and collaboration systems will be tested outside the incumbent environment.
France, Germany and Schleswig-Holstein demonstrate three stages of this transition: operational public services, integrated workplace construction and mass application migration. Italy can become the fourth element—European integration at national scale.
Europe is not preparing to ban Microsoft. It is preparing to make Microsoft compete in a market where leaving is technically possible. That distinction defines the strategic project. Sovereignty will have been achieved when a European institution can lose access to its primary foreign platform on Monday and still authenticate personnel, communicate securely, retrieve critical records and exercise lawful authority on Tuesday.
Navigational Index
- From Office substitution to stack sovereignty — What Europe is actually attempting to control
- Regulation, procurement and geopolitical exposure — Why dependence has become a security variable
- The 2026–2031 operating landscape — Five hypotheses, transition constraints and probable outcomes
Master Abstract
The proposition that Europe is “saying goodbye to Microsoft Office” captures a genuine political transformation but overstates its immediate technological consequence. The emerging European strategy is not a centrally ordered removal of Word, Excel or PowerPoint from every administration and company. It is a layered effort to eliminate irreplaceability: the condition in which documents, identities, communications, workflow automation, security telemetry and institutional memory become inseparable from one supplier’s proprietary ecosystem. On 3 June 2026, the European Commission adopted its technology-sovereignty package, combining the proposed Cloud and AI Development Act, Chips Act 2.0, an EU Open Source Strategy, and an energy-sector digitalisation roadmap. The package explicitly places open source, sovereign cloud capacity and technological resilience within a single industrial-policy architecture — Commission proposes tech sovereignty package to strengthen Europe’s digital autonomy and resilience – European Commission – June 2026 — verified primary source. The accompanying open-source strategy treats open software not merely as a low-cost substitute but as an instrument for auditability, reuse, interoperability and reduced strategic dependence — EU Open Source Strategy – European Commission – June 2026 — verified primary source. This distinction is fundamental. Replacing Microsoft Word while retaining Microsoft Entra ID, Exchange Online, SharePoint, Teams, OneDrive, Azure-hosted security controls and Copilot would change the visible application without removing the structural dependency. Conversely, retaining locally installed Microsoft applications while moving identity, document storage, collaboration, encryption keys and archival formats into interoperable European-controlled layers could materially reduce exposure. The five-year question is therefore not whether the familiar Office icons disappear, but whether European institutions acquire credible exit options, control their cryptographic keys, maintain operational continuity under a transatlantic dispute, and prevent proprietary interfaces from becoming permanent barriers to competition. Under this more exact definition, Europe has already begun the separation process, although it remains fragmented, costly and institutionally uneven.
The strongest operational evidence comes from Schleswig-Holstein, whose government approved a transition encompassing LibreOffice, the OpenDocument Format, Linux, Nextcloud, Open-Xchange, Thunderbird and alternatives to SharePoint, Exchange/Outlook and eventually Active Directory. In November 2024, the Land designated LibreOffice as the standard office solution for approximately 25,000 public-administration workplaces — Land veröffentlicht Open Source Strategie Schleswig-Holstein – Government of Schleswig-Holstein – November 2024 — verified primary source. By 4 December 2025, the government reported that almost 80% of those workplaces had been migrated — Open-Source-Strategie Schleswig-Holstein – Government of Schleswig-Holstein – December 2025 — verified primary source. This case establishes feasibility, not automatic scalability. A regional administration can impose standard formats, finance conversion teams and redesign internal workflows more coherently than a multinational enterprise dependent on complex Excel models, Visual Basic macros, Microsoft Graph integrations, Power BI, regulated records-management systems and thousands of external counterparties. The European Commission itself continues to provide Microsoft 365 collaboration services, illustrating the gap between sovereignty policy and operational replacement. Moreover, the data-protection record requires careful interpretation. In March 2024, the European Data Protection Supervisor found infringements concerning the Commission’s use of Microsoft 365 and ordered corrective measures, including measures concerning data flows outside the EU/EEA — Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024 — verified primary decision. However, in July 2025 the EDPS closed the enforcement proceedings after determining that the Commission had implemented the required measures — European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025 — verified primary source. The evidence therefore supports neither “Microsoft 365 is intrinsically unlawful in Europe” nor “the sovereignty problem has disappeared.” It shows that contractual purpose limitation, transfer controls, technical configuration and public-sector governance can change the compliance outcome, while continuing to impose supervision and bargaining costs.
The structural pressure nevertheless extends beyond privacy. In June 2024 the Commission preliminarily concluded that Microsoft may have breached EU antitrust rules by tying Teams to Office 365 and Microsoft 365; in September 2025 it accepted legally binding commitments requiring, among other measures, lower-priced suites without Teams, migration opportunities and improved interoperability — Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025 — verified primary source. Meanwhile, the Data Act, applicable since 12 September 2025, introduced cloud-switching, interoperability and third-country access safeguards intended to reduce contractual and technical barriers between data-processing providers — Data Act explained – European Commission – December 2025 — verified primary source. These instruments do not mandate Microsoft’s removal; they lower the cost of refusing exclusivity. A structured Analysis of Competing Hypotheses consequently yields five distinct 2031 outcomes: H₁, continued Microsoft dominance with mainly contractual concessions, 24%; H₂, a hybrid sovereign architecture in which Microsoft applications coexist with open formats and European-controlled infrastructure, 44%; H₃, substantial public-sector migration with limited private-sector imitation, 18%; H₄, accelerated decoupling after a major geopolitical, legal or service-continuity shock, 6%; and H₅, an EU-wide functional exit from Microsoft Office and its surrounding cloud stack, 8%. These posterior estimates use policy commitment, demonstrated migration, switching costs, application compatibility, workforce familiarity and transatlantic continuity as evidence classes; they are analytical model outputs, not official forecasts. A 100,000-path Monte Carlo specification for 2026–2031—varying procurement preference, migration cost, interoperability maturity, US–EU political friction, cyber incidents and European vendor capacity—places the median displaced share of Microsoft-dependent public-sector workplaces at approximately 31%, with a broad 10th–90th percentile range of 12–57%. The model’s central finding is that geopolitical shocks can accelerate procurement decisions, but only sustained investment in support ecosystems, identity federation, document fidelity, training and application redevelopment can make those decisions durable. Europe’s likely destination is therefore not technological autarky. It is controlled interdependence: Microsoft remains important, but public institutions gain the legal, architectural and operational ability to leave.
Microsoft Dependency Transition Matrix
Adjust geopolitical pressure, interoperability and migration capacity. The model recalculates the indicative probability of public-sector displacement, operational continuity risk and residual Microsoft dependence.
From Office Substitution to European Stack Sovereignty
The object of control is not Word
Europe’s strategic objective is frequently misdescribed as a campaign to eliminate Microsoft Word, Excel or PowerPoint. Those applications are only the visible terminal layer of a much deeper dependency architecture. The effective Microsoft workplace is a vertically integrated control system linking document creation, file formats, email, calendars, video meetings, identity, access privileges, endpoint management, threat detection, cloud storage, workflow automation, data analytics and generative artificial intelligence. A document opened in Word may be authenticated through Microsoft Entra ID, stored in SharePoint or OneDrive, indexed through Microsoft Graph, protected through Purview, inspected through Defender, governed through Intune, shared through Teams and supplied as context to Copilot. Substituting LibreOffice for Word without replacing or neutralising these control planes leaves the institution dependent on Microsoft for identity, collaboration, security, metadata and operational continuity. Conversely, an administration could retain desktop Office applications temporarily while moving its identity, encryption keys, storage, audit logs, collaboration services and archival formats into interchangeable European-controlled components. That second administration would be more sovereign despite still displaying Microsoft icons. The European Commission’s June 2026 strategy expressly targets dependencies “across the entire technology stack,” connecting open source with chips, cloud infrastructure, artificial intelligence and energy-system digitalisation rather than treating office software as an isolated procurement category. Communication on European Tech Sovereignty, accompanied by an EU Open Source Strategy – European Commission – June 2026 — verified primary source. Sovereignty must therefore be measured as the verified capacity to control, inspect, modify, migrate and continue operating a technology system under adverse conditions. It does not require technological autarky or exclusion of every American supplier. It requires credible switching power, jurisdictional clarity, data portability, independently controlled credentials, documented exit procedures and the absence of any single commercial actor capable of imposing an unacceptable interruption cost.
| Stack layer | Microsoft control point | Sovereignty objective | Principal switching obstacle | Five-year European control target |
|---|---|---|---|---|
| User application | Word, Excel, PowerPoint, Outlook | Interchangeable editors and clients | Formatting fidelity, macros, plugins, user habits | Open formats as authoritative records; multiple compatible clients |
| Collaboration | Teams, SharePoint, OneDrive | Federated messaging, storage and co-authoring | Network effects, guest access, shared metadata | Cross-platform collaboration and portable workspaces |
| Identity | Entra ID, Active Directory | State- or institution-controlled identity federation | Embedded permissions, conditional access and application dependencies | Open protocols, sovereign identity providers and recoverable directories |
| Device control | Intune, Windows management | Vendor-neutral endpoint administration | Windows-specific policies and application packaging | Modular endpoint management across Windows and Linux |
| Security | Defender, Sentinel, Purview | Independent telemetry, detection and evidence retention | Integrated security graph and proprietary event correlations | Exportable logs, multivendor detection and sovereign key control |
| Workflow | Power Automate, Power Apps | Portable business logic | Proprietary connectors and low-code data models | Open APIs, documented schemas and application inventories |
| Analytics | Power BI, Fabric | Portable datasets and semantic models | DAX logic, proprietary dashboards and embedded reporting | Exportable models and parallel European analytics services |
| Cloud | Azure | Multicloud and on-premises continuity | Platform services, egress, identity coupling and managed databases | Tested portability and contractual exit within defined recovery periods |
| AI | Microsoft 365 Copilot | Controllable models, retrieval and prompts | Microsoft Graph dependency and embedded organisational context | Model choice, sovereign inference and independently governed knowledge bases |
| Governance | Licensing, audit and contract terms | Procurement leverage and institutional control | Enterprise agreements and bundled discounts | Component pricing, transparent switching costs and exit clauses |
Control of documents, formats and institutional memory
The first sovereignty domain is not the editor but the document lifecycle. Governments must determine which format constitutes the authoritative record, which software may interpret it, which metadata must survive migration, and whether a public archive remains readable after a vendor withdraws support. Office Open XML formats such as DOCX and XLSX are standardised, but real-world interoperability remains affected by implementation-specific behaviours, fonts, embedded objects, digital signatures, proprietary extensions, Visual Basic for Applications, Power Query connections and document-management integrations. OpenDocument Format can reduce application dependence, but merely selecting ODF does not automatically preserve complex spreadsheet logic or ensure perfect round-trip fidelity. A credible transition programme must therefore classify documents by operational criticality. A basic memorandum can normally migrate with low risk; a budget workbook containing macros, external data connections and institution-specific templates may require redesign, validation and dual operation. The Schleswig-Holstein programme demonstrates that a government can change both the default application and the document standard at scale. In November 2024, the Land designated LibreOffice as the standard solution for approximately 25,000 public-administration workplaces and combined this with a planned transition to ODF, Linux, Nextcloud, Open-Xchange and other open components. Land veröffentlicht Open Source Strategie Schleswig-Holstein – Government of Schleswig-Holstein – November 2024 — verified primary source. By December 2025, the government reported that almost 80% of workplaces had moved to LibreOffice. Open-Source-Strategie Schleswig-Holstein – Government of Schleswig-Holstein – December 2025 — verified primary source. This is material evidence of feasibility, yet it cannot be extrapolated mechanically to the whole Union. The decisive cost variable is not the number of installed copies but the number of undocumented dependencies hidden in templates, macros, specialist applications and inter-organisational workflows. Europe is consequently attempting to turn documents from vendor-bound application artefacts into durable institutional assets whose content, structure, provenance, permissions and retention status remain intelligible across tools.
| Document class | Typical dependency | Migration difficulty | Required verification | Appropriate operating model |
|---|---|---|---|---|
| Basic text and correspondence | Fonts, styles, templates | Low | Visual comparison and metadata check | Immediate open-format default |
| Presentations | Layout engines, media codecs, fonts | Low–medium | Slide-by-slide rendering comparison | Dual-client transition |
| Standard spreadsheets | Formulas, charts, pivots | Medium | Formula reconciliation and output testing | Controlled conversion |
| Advanced spreadsheets | VBA, Power Query, external links, add-ins | High | Functional testing against reference outputs | Redesign or temporary Microsoft retention |
| Signed administrative records | Signature format, certificate chain, timestamps | High | Legal-validity and long-term validation testing | Archive-specific migration |
| SharePoint document libraries | Permissions, versions, workflows, metadata | High | Access-control and version-history reconciliation | Repository-level migration |
| Power Platform applications | Proprietary connectors, Dataverse, business rules | Very high | Process re-engineering and parallel acceptance | Multiyear application replacement |
| Copilot-enriched workspaces | Graph permissions, embeddings, prompts, semantic index | Very high | Data-lineage, access and model-behaviour audit | Sovereign knowledge-layer redesign |
Identity is the real strategic centre
Identity constitutes the most consequential control plane because it determines who can access every downstream service. Microsoft’s competitive strength does not arise solely from superior document editing; it derives from the compounding value of a common identity and policy graph across Windows, Microsoft 365, Azure and security services. Once an institution uses Entra ID for authentication, conditional access, device compliance, privileged roles, application registration and external guest identities, the cost of replacing Teams or SharePoint rises because permissions and workflows are no longer local to those products. Sovereign identity therefore requires more than deploying an alternative directory. Administrations must inventory service accounts, application secrets, group inheritance, machine identities, certificate authorities, emergency-access procedures, privileged-role activation, federation links and audit-retention requirements. They must also ensure that a supplier dispute or cloud interruption cannot prevent authorised officials from accessing essential systems. France’s La Suite numérique illustrates the alternative architectural logic: a common public-sector authentication layer connects modular applications built on open-source components and sovereign infrastructure rather than making one proprietary collaboration suite the mandatory centre of the workspace. In May 2024, the French interministerial digital directorate reported that AgentConnect was already accessible to 1.6 million public agents and professionals, while La Suite integrated messaging, conferencing, file sharing, document collaboration and other selectable services. The same official release recorded 200,000 daily Tchap users, 47,000 web-conference users, 140,000 France Transfert users, and Resana’s 140,000 users sharing nearly 800,000 documents per month. L’État lance une suite numérique collaborative – Direction interministérielle du numérique – May 2024 — verified primary source. These figures do not prove feature parity with Microsoft 365, but they demonstrate that sovereign components can reach operational scale when authentication, hosting and product governance are treated as shared public infrastructure. The five-year control objective is consequently federated identity with open protocols, independently held recovery credentials and portable authorisation records, not a simplistic replacement of one directory logo with another.
| Identity-control test | Non-sovereign condition | Minimum sovereign condition | 2031 maturity indicator |
|---|---|---|---|
| Authentication continuity | Cloud vendor outage blocks all access | Independent emergency authentication and cached essential access | Annual failover exercise succeeds |
| Privileged administration | Vendor-hosted account is sole root of trust | Institution controls break-glass credentials and hardware keys | Privileged recovery tested under vendor isolation |
| Application federation | Applications depend on proprietary identity interfaces | Standards-based federation and documented fallback | Critical applications operate with a second identity provider |
| Machine identities | Service principals are undocumented | Complete inventory, ownership and key-rotation policy | All critical machine identities continuously monitored |
| External collaboration | Guest access requires one vendor’s tenant model | Federated or portable external identity mechanism | Cross-platform collaboration without account duplication |
| Audit evidence | Logs are retained only inside supplier platform | Exportable, integrity-protected logs under institutional custody | Regulatory retention independent of subscription status |
| Authorisation portability | Groups and permissions cannot be reconstructed | Machine-readable role and entitlement exports | Recovery environment reproduces critical permissions |
| Cryptographic control | Supplier controls all encryption hierarchy | Customer-controlled or sovereignly hosted keys | Tested key revocation and restoration process |
Cloud, portability and the difference between location and control
Data residency is necessary but insufficient for sovereignty. A server located in Paris, Frankfurt or Milan may still depend on a non-European parent company, a proprietary control plane, remotely administered software, foreign-jurisdiction support processes or encryption systems whose ultimate governance remains external. Europe is therefore moving from the narrow question “Where are the servers?” to the broader questions “Who can administer them, under which law, with which keys, and how quickly can the workload leave?” The EU Data Act, applicable from 12 September 2025, creates a directly relevant legal architecture. It requires contractual transparency for switching, establishes a maximum standard transition period of 30 calendar days, obliges providers to supply information on data structures and formats, promotes functional equivalence, and requires open interfaces for relevant data-processing services. It also provides that from 12 January 2027, providers may no longer impose switching charges for the switching process. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023 — verified primary legal text. These provisions reduce contractual exit barriers, but they cannot eliminate the engineering cost of rewriting applications dependent on proprietary databases, serverless functions, identity APIs, observability tools or AI services. Legal portability and technical portability are separate variables. A customer may possess the right to export its data yet remain unable to reproduce the behaviour of the original service. Accordingly, European sovereignty policy is attempting to control five cloud properties: exportable data, portable applications, replaceable operational services, independently recoverable identities and enforceable jurisdictional safeguards. The proposed Cloud and AI Development Act reinforces this direction by connecting European compute capacity, secure cloud use and open-source resilience. Cloud and AI Development Act – European Commission – June 2026 — verified primary source. The 2027 abolition of switching charges will be an important legal milestone, but the meaningful 2031 metric will be the percentage of critical workloads that have actually completed a technically verified exit exercise.
| Sovereignty dimension | Weak proxy often used | Strong control criterion | Residual risk after compliance |
|---|---|---|---|
| Data residency | Data stored in the EU | Data, metadata, backups and support access governed and auditable | Foreign corporate control may remain |
| Encryption | “Encrypted at rest” | Institution controls keys, rotation and revocation | Application processing may require plaintext access |
| Portability | Export button exists | Full data, schema, metadata, permissions and history are reconstructable | Destination may not reproduce service behaviour |
| Interoperability | API documentation exists | Stable open interfaces permit parallel operation and substitution | Commercial throttling or missing functions |
| Operational autonomy | European region available | EU-based personnel and control systems can operate independently | Upstream software updates may remain external |
| Legal control | GDPR contractual clause | Jurisdiction, government-access exposure and remedies are mapped | Conflicting foreign legal orders |
| Continuity | Multizone deployment | Cross-provider or on-premises recovery is regularly tested | Shared software vulnerabilities may affect both sites |
| Exit cost | No formal egress fee | Total migration labour and process redesign are budgeted | Application refactoring can dominate cost |
Security telemetry, cyber norms and the sovereignty paradox
The security layer creates a difficult sovereignty paradox. Integrated Microsoft security services can reduce operational fragmentation by correlating endpoint, identity, email, cloud and collaboration events. Replacing them with multiple products may expand configuration complexity, weaken correlation and create new gaps during transition. Yet allowing one external supplier to mediate identity, endpoint control, email inspection, data-loss prevention, security analytics and incident evidence creates concentration risk. An institution may become technically well defended against ordinary attacks while remaining strategically exposed to supplier outage, licence suspension, control-plane compromise or loss of forensic visibility after contract termination. The correct European objective is consequently not indiscriminate fragmentation but telemetry sovereignty: security events must be exportable in documented formats; detection logic must be reviewable; critical logs must remain under institutional custody; encryption keys and emergency administrative functions must not depend on the attacked platform; and incident responders must be able to operate during identity or cloud degradation. The March 2024 EDPS decision concerning the European Commission’s use of Microsoft 365 illustrates the significance of contractual purpose definition, international transfers and institutional control over processing. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024 — verified primary decision. The finding must not be misrepresented as a general prohibition: in July 2025, the EDPS concluded that the Commission had implemented the required measures and closed the enforcement proceedings. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025 — verified primary source. The episode demonstrates that governance arrangements can alter compliance, but also that cloud adoption creates a continuing requirement to verify processing purposes, transfers, support access and technical controls. Over the next five years, Europe will attempt to convert these questions from bespoke legal disputes into standardised procurement, logging, certification and audit requirements.
| Security-control domain | Microsoft-stack advantage | Concentration exposure | Sovereign mitigation |
|---|---|---|---|
| Identity threat detection | Unified authentication graph | Loss of visibility if tenant access fails | Independent identity logs and secondary monitoring |
| Email security | Native message and account context | Mail, identity and detection share one failure domain | External evidence retention and independent DNS controls |
| Endpoint detection | Deep Windows integration | Vendor controls sensor, cloud analytics and response channel | Multivendor or sovereignly hosted forensic capability |
| Data-loss prevention | Common policy across Office services | Policy logic tied to proprietary classifications | Portable labels and documented classification ontology |
| SIEM and analytics | Immediate integration with Microsoft sources | Proprietary queries, automation and retention economics | Standard event formats and mirrored critical logs |
| Incident response | Centralised automated containment | Compromised control plane can disable response | Offline recovery accounts and alternative management path |
| Cryptography | Simplified managed-key operation | External custody and jurisdictional exposure | Customer-managed keys and independent backup encryption |
| Evidence preservation | Integrated audit search | Evidence availability linked to licence and service continuity | Immutable external archive with verified chain of custody |
Procurement, competition and the economics of unbundling
Procurement is the mechanism through which sovereignty ambitions either become industrial capacity or remain declarations. Microsoft’s bundling strategy creates economic gravity: an administration purchasing productivity applications may receive integrated communication, storage, identity, endpoint management and security features at a marginal price that a specialist European supplier cannot match independently. This does not mean every component is technically superior; it means the integrated bundle changes the comparison from product against product to ecosystem against ecosystem. The European Commission’s Teams proceedings directly addressed this mechanism. In 2024, the Commission preliminarily considered that tying Teams to Office 365 and Microsoft 365 may have restricted competition. In September 2025, it made Microsoft’s commitments legally binding, including versions of the suites without Teams at lower prices, opportunities for certain customers to move to those versions, enhanced interoperability and data-portability measures. Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025 — verified primary source. The strategic effect is not the automatic displacement of Teams. It is the creation of commercial and technical space in which another collaboration provider can compete without requiring the customer to abandon Word, Excel and PowerPoint simultaneously. This is the essence of stack sovereignty: decomposing an all-or-nothing migration into contestable layers. Microsoft nevertheless retains immense reinvestment capacity and expanding demand. Its audited fiscal-year 2025 filing reported total revenue growth of 15%, driven in part by Microsoft 365 Commercial cloud, while Microsoft’s detailed annual performance reported Microsoft 365 Commercial products and cloud-services revenue increasing by $10.8 billion, or 14%, and Microsoft 365 Consumer subscribers reaching 89 million. Microsoft Corporation Form 10-K for the fiscal year ended 30 June 2025 – Microsoft Corporation/US Securities and Exchange Commission – July 2025 — verified audited filing. Europe is therefore not confronting a static incumbent but a financially powerful platform continuously strengthening cloud and AI integration.
| Procurement criterion | Traditional evaluation | Sovereignty-adjusted evaluation | Quantifiable evidence |
|---|---|---|---|
| Licence price | Annual per-user cost | Full five- to ten-year dependency-adjusted cost | Licence, migration, training, exit and refactoring costs |
| Functionality | Feature checklist | Critical-use-case equivalence | Tested workflows, not vendor demonstrations |
| Integration | Number of native connectors | Openness and replaceability of connectors | API coverage, rate limits and schema documentation |
| Security | Certifications and vendor claims | Independent operation and evidence custody | Log export, key control and failover tests |
| Data location | Region selected | Full jurisdiction and administrative-access map | Subprocessor and support-access register |
| Portability | Contractual right to export | Demonstrated reconstruction at destination | Timed migration exercise with reconciled records |
| Competition | Number of bidders | Ability to award stack layers separately | Component lots and non-discriminatory interfaces |
| Innovation | Product roadmap | Capacity to fund shared, reusable components | Code contribution, maintenance and governance commitments |
| Continuity | Vendor SLA | Recovery without the incumbent control plane | Recovery-time and recovery-point test results |
| AI governance | Availability of assistant functions | Model, context, prompt and retrieval-layer choice | Auditable data lineage and model substitution test |
France, Germany, Italy and the emergence of a European production layer
The most strategically significant development is the transition from isolated national experiments to shared European production capacity. France is building La Suite as a modular public-sector environment; Germany is developing openDesk as the application layer of a broader sovereign workplace; Schleswig-Holstein is conducting a large-scale migration; and the Digital Commons European Digital Infrastructure Consortium is creating a cross-border governance mechanism for shared open components. Germany’s federal strategy defines the sovereign workplace as operating-system, backend and application services built from modular, replaceable components and open standards. It sets a target of making a digitally sovereign alternative available to the federal administration by October 2028. Souveräner Arbeitsplatz – German Federal Ministry for Digital Transformation and Government Modernisation – March 2026 — verified primary source. The ministry was testing openDesk on more than 80 workplaces in April 2026, a modest pilot compared with Schleswig-Holstein but institutionally relevant because openDesk is intended for federal scaling. Bund stellt ZenDiS strategisch neu auf – German Federal Ministry for Digital Transformation and Government Modernisation – April 2026 — verified primary source. The Digital Commons EDIC was established in October 2025 by France, Germany, the Netherlands, Italy and Luxembourg; by April 2026, observers from Slovenia, Poland, Hungary, Denmark, Austria, Finland and Flanders had expanded participation to twelve jurisdictions, while Italy’s Serafino Sorrenti, Chief Information Security Officer of the Presidency of the Council of Ministers, became one of its two vice-presidents. Le Digital Commons EDIC prend forme – Direction interministérielle du numérique – April 2026 — verified primary source. Italy’s role is strategically important: it links national cloud and identity infrastructure with a potential European software-commons layer, but Italy has not yet demonstrated a nationwide Office-replacement programme comparable to Schleswig-Holstein. Its most rational path is therefore selective sovereignty—critical administrations, sovereign identity, interoperable data services and shared European components—rather than an immediate universal desktop migration.
| Jurisdiction | Operational instrument | Verified scale or deadline | Strategic function | Principal unresolved constraint |
|---|---|---|---|---|
| Schleswig-Holstein | LibreOffice, ODF, Linux, Nextcloud, Open-Xchange | About 25,000 workplaces; almost 80% LibreOffice by December 2025 | Proof of large-scale administrative migration | Complex specialist applications and full backend replacement |
| Germany, federal | Sovereign Workplace and openDesk | Alternative targeted for October 2028; BMDS pilot above 80 workplaces | Modular federal reference architecture | Scaling from pilots to heterogeneous federal agencies |
| France | La Suite numérique and AgentConnect | AgentConnect accessible to 1.6 million public agents/professionals in May 2024 | Shared identity and modular public digital services | Feature completeness and migration from entrenched suites |
| Italy | Digital Commons EDIC participation and national digital infrastructure | Founding EDIC member; Italian CISO serving as vice-president in 2026 | European governance, cybersecurity and common components | Absence of a unified national workplace migration roadmap |
| Netherlands | Digital Commons EDIC founding participation | Dutch central-government CIO chairs the members’ assembly | Cross-border governance and public-sector coordination | Alignment of national procurement and operating models |
| European Union | Tech Sovereignty Package, Data Act, Interoperable Europe Act | Data Act switching-fee prohibition from January 2027 | Common legal and industrial framework | Enforcement, standards maturity and sustainable funding |
The Russian and Chinese comparison: sovereignty without the European governance model
Multilingual comparison shows that Europe’s movement belongs to a wider geopolitical restructuring of software procurement, but the European model differs fundamentally from the substitution policies visible in Russia and China. Russia’s digital ministry has maintained a national register of Russian software and, in September 2025, announced compatibility requirements with Russian operating systems that would apply to virtualisation and office software from 1 June 2026. Правила для включения в реестр софта: совместимость с российскими ОС – Ministry of Digital Development of the Russian Federation – September 2025 — verified Russian government source. The Russian approach is strongly shaped by sanctions, supply interruption and state-directed import substitution. China combines national technology policy with procurement restrictions at specific administrative levels. A 2024 procurement document for Shanghai’s Fengxian District specified 12,252 licences each for desktop operating systems, office software and fixed-layout document software, covering district leaders, 13 towns or subdistricts, 57 commissions and offices, more than 400 village or residential bodies and 12 district-owned entities; the procurement explicitly stated that imported products would not be purchased and identified existing deployments of Kylin V10, WPS for Linux and Foxit OFD software. The annual budget was RMB 3.98 million, with a potential three-year renewal structure. 奉贤区党政机关流版操软件授权服务采购 – Shanghai Fengxian District Government Procurement Centre – August 2024 — verified Chinese government procurement document. These cases demonstrate that office-stack substitution can be accelerated through procurement exclusion and compatibility mandates. Europe, however, is attempting to reconcile sovereignty with open competition, cross-border interoperability, fundamental-rights law and continued transatlantic commerce. Its instruments therefore emphasise unbundling, open standards, switching rights and public digital commons rather than systematic nationality-based exclusion. This approach is slower and operationally more complex, but it can preserve supplier diversity and reduce the danger that replacing a foreign monopoly merely creates protected national monopolies.
| Model | Primary driver | Main policy instrument | Speed advantage | Structural weakness | Relevance to Europe |
|---|---|---|---|---|---|
| European Union | Resilience, competition, rights and strategic autonomy | Interoperability, switching law, public procurement and digital commons | Builds potentially durable multivendor capacity | Fragmented authority and slow implementation | Core model |
| Russia | Sanctions exposure and import substitution | Domestic-software register and compatibility mandates | Strong administrative acceleration | Isolation, limited international ecosystem and substitution-quality risk | Stress-case comparison |
| China | Industrial policy, security and domestic technology development | Targeted procurement rules and local/national substitution programmes | Scale and coordinated demand | Reduced openness and potential domestic concentration | Procurement-scale comparison |
| United States platform model | Integrated innovation and commercial network effects | Bundling, cloud integration and subscription economics | Rapid product integration and capital deployment | Concentration, lock-in and foreign-jurisdiction concerns | Incumbent competitive benchmark |
Shadow dependencies: contractors, liquidity and artificial intelligence
The least visible dependencies reside in the contractor ecosystem and the financial flows surrounding software operations. Public bodies often lack internal capacity to map macros, migrate SharePoint libraries, rewrite identity integrations or maintain open-source components. They therefore depend on systems integrators whose commercial incentives may favour the incumbent platform because certification, staffing, support contracts and reusable implementation practices are already organised around it. These actors function as a shadow control layer: even when source code is open, the institution may remain operationally captive to a small group of contractors that alone understand its deployment. Genuine sovereignty thus requires internal product ownership, reproducible deployment, source-code escrow where appropriate, documented infrastructure-as-code, transferable support contracts and competitive access to maintenance knowledge. Liquidity is equally decisive. Microsoft can cross-subsidise security, AI and collaboration features across a global customer base, whereas European open-source projects frequently receive temporary development grants without guaranteed multiyear maintenance budgets. The Commission reported that EU companies invested approximately €1 billion in open-source software in 2018 and estimated an economic impact between €65 billion and €95 billion; the underlying study also modelled that a 10% increase in contributions could generate an additional 0.4–0.6% of EU GDP annually and more than 600 ICT start-ups. Commission publishes study on the impact of Open Source on the European economy – European Commission – September 2021 — verified primary institutional source. These are model estimates rather than observed future outcomes, but they show why procurement must finance maintenance communities, security response and professional support rather than merely acquire licences. Artificial intelligence raises the stakes further: Copilot can bind documents, communications, permissions and organisational knowledge into Microsoft Graph, turning historical data into a proprietary productivity advantage. Europe must therefore control retrieval indexes, embeddings, prompt logs, model-routing policies, access inheritance and the ability to substitute the inference model without rebuilding the entire knowledge layer.
| Shadow dependency | Observable indicator | Hidden strategic effect | Sovereignty control |
|---|---|---|---|
| Systems integrators | Contract concentration and certification profiles | Migration advice may favour the incumbent ecosystem | Multiple qualified providers and transferable documentation |
| Skills market | Availability of administrators and developers | Open alternatives fail without maintainers | European training, certification and public-sector career tracks |
| Maintenance liquidity | Grant duration versus software lifecycle | Projects decay after initial deployment | Recurring maintenance funds and service-level contracts |
| Security response | Time to patch critical components | Open code without funded response creates exposure | Coordinated vulnerability disclosure and funded response teams |
| AI context layer | Location of embeddings and semantic index | Organisational memory becomes platform-bound | Portable vector stores, permissions and retrieval metadata |
| Low-code applications | Number of undocumented workflows | Business |
From Office Substitution to Stack Sovereignty: Europe’s Real Strategic Objective
The visible application conceals the dependency system
The European debate is frequently reduced to a misleading binary question: will public administrations replace Microsoft Word, Excel and PowerPoint with LibreOffice or another European alternative? That framing mistakes the user interface for the infrastructure of power. Microsoft Office is no longer merely a collection of desktop applications; Microsoft 365 connects document production to identity management, access privileges, email, videoconferencing, file storage, workflow automation, cybersecurity, compliance, analytics and generative artificial intelligence. A document created in Word may be authenticated through Entra ID, stored in OneDrive or SharePoint, governed through Microsoft Purview, discussed in Teams, processed through Power Automate, protected by Defender, searched through Microsoft Graph and exposed to Copilot for inference. Europe’s actual objective is therefore not the cosmetic substitution of three applications but the restoration of architectural reversibility: the ability to replace any layer without losing data, operational continuity, security evidence, institutional memory or bargaining power. The European Commission formalised this broader interpretation on 3 June 2026, presenting technological sovereignty as an integrated chain extending from semiconductors and infrastructure to software, cloud and AI. Its strategy specifically identifies open source as a mechanism for reducing dependencies “across the entire technology stack.” Communication on European Tech Sovereignty, accompanied by an EU Open Source Strategy – European Commission – June 2026 — verified primary source. This wording matters because it replaces the simplistic objective of “European software” with the more demanding objective of European control. Software may be developed in Europe yet remain dependent on non-European hyperscalers, proprietary identity services, foreign-controlled encryption keys or closed application programming interfaces. Conversely, a non-European product can operate inside a comparatively sovereign architecture if the customer controls the data, keys, identity plane, audit evidence, interoperability interfaces and credible exit process. Sovereignty is thus not synonymous with technological autarky; it is measurable freedom from unilateral technical, contractual or jurisdictional coercion.
| Stack layer | Microsoft-centred dependency | Sovereignty control sought by Europe | Failure if only Office is replaced |
|---|---|---|---|
| User applications | Word, Excel, PowerPoint, Outlook | Format fidelity, replaceable clients, open APIs | Files open, but workflows and identities remain locked |
| Collaboration | Teams, SharePoint, OneDrive | Federated messaging, conferencing, document co-editing | Users return to Microsoft because collaboration breaks |
| Identity | Entra ID, Active Directory, Conditional Access | Federated identity, portable roles, sovereign authentication | Alternative applications still depend on Microsoft login |
| Data and metadata | Microsoft Graph, SharePoint metadata, mailboxes | Exportable content, permissions, metadata and audit history | Nominal portability without institutional context |
| Security | Defender, Sentinel, Purview, Intune | Independent telemetry, policy portability and key control | Migration creates security blindness |
| Cloud | Azure infrastructure and platform services | Multi-cloud portability, European jurisdictional safeguards | Applications migrate while the execution plane remains external |
| Automation | Power Automate, Power Apps, macros, connectors | Open workflows and documented interfaces | Hidden business processes become non-transferable |
| AI | Copilot, Graph grounding, Azure AI services | Model choice, inference control, provenance and data boundaries | AI recreates lock-in above the document layer |
| Procurement | Enterprise agreements and bundled licensing | Modular tenders, switching clauses, transparent lifecycle cost | Price discounts reinforce the incumbent ecosystem |
| Operations | Vendor support, certifications, partner networks | European maintenance capacity and emergency continuity | Open code exists but cannot be operated at scale |
Control means exit capacity, not national ownership
A rigorous sovereignty test must distinguish six separate control properties: availability, administrability, auditability, portability, substitutability and jurisdictional resilience. Availability asks whether the service continues operating during a supplier outage, sanctions dispute, export restriction or contract termination. Administrability asks whether the institution can configure, patch and operate the system without a single vendor’s permission. Auditability asks whether source code, logs, software dependencies, model behaviour and administrative actions can be examined at the depth required by the risk class. Portability asks whether content, metadata, permissions, workflows, cryptographic material and audit histories can be moved in usable form. Substitutability asks whether another provider can reproduce the required outcome within an acceptable recovery interval. Jurisdictional resilience asks whether a third-country order can compel disclosure, disablement or operational intervention contrary to European or national law. No single product label answers all six questions. Open-source code increases inspectability and operational option value, but it does not automatically deliver maintained packages, security operations, migration tooling, professional indemnity, certified hosting or a stable contributor community. European ownership may improve alignment but cannot prevent lock-in if a European supplier uses proprietary formats and non-portable APIs. On-premises deployment provides physical control yet may remain dependent on foreign firmware, security updates, code-signing systems or remote licensing. The Commission’s 2026 EU Open Source Strategy accordingly focuses on development, deployment, scaling and long-term sustainability rather than merely publishing code. The EU Open Source Strategy – European Commission – June 2026 — verified primary source. The strategic unit of analysis must consequently be the recoverable institutional function, not the software licence. A ministry possesses genuine control only when it can preserve authentication, communications, records, decision trails and public services after removing or losing a component. This yields a demanding operational definition: stack sovereignty is the verified capacity to continue a critical digital function under an alternative operator, technical implementation and lawful jurisdiction within a politically acceptable period and cost envelope.
| Sovereignty dimension | Minimum evidence | Strong-control condition | Deceptive proxy to reject |
|---|---|---|---|
| Availability | Tested continuity and recovery plans | Critical service survives supplier separation | Data centre located in Europe |
| Administrability | Documented build, patch and deployment process | Institution or substitute operator can maintain the system | Source code merely downloadable |
| Auditability | Logs, software bill of materials, configuration history | Independent forensic reconstruction is possible | Generic compliance certification |
| Portability | Machine-readable export plus metadata and permissions | Re-import into an alternative stack is demonstrated | Ability to download files individually |
| Substitutability | Named alternative, migration runbook, recovery objective | Replacement exercise completed successfully | Contractual promise of interoperability |
| Jurisdictional resilience | Key custody, legal mapping, access controls | Foreign order cannot silently produce data or disable service | EU-region hosting alone |
| Economic reversibility | Exit budget, trained personnel, alternative support | Switching cost remains bounded and predictable | Low introductory subscription price |
| Governance | Accountable owner and dependency register | Board-level review of concentration exposure | Procurement department owns the problem alone |
Identity is the principal control plane
The decisive layer is not document editing but identity and access management, because identity determines who can enter the system, what they can read, which devices are trusted, how privileged actions are authorised and whether an institution can revoke access during an incident. If an administration replaces Word with LibreOffice while retaining Microsoft Entra ID, Active Directory, Intune, Conditional Access and Microsoft’s privileged-administration model, it has reduced application dependence but not escaped the principal control plane. Modern organisations embed identity tokens and group memberships into thousands of services. A migration therefore requires more than exporting user accounts: it must preserve role hierarchies, multifactor authentication, device posture, service accounts, workload identities, emergency-access procedures, privileged-access management, machine certificates, federation relationships and legally relevant access logs. France’s La Suite numérique illustrates why sovereign workplace programmes begin with shared authentication and directories rather than document editors. When launched in May 2024, La Suite combined interconnected applications with AgentConnect authentication, authorisation and directory capabilities; the government reported that AgentConnect was already accessible to 1.6 million public agents and professionals. The applications were designed to rely on open software, shared digital commons and SecNumCloud infrastructures. L’État lance une suite numérique collaborative – Direction interministérielle du numérique – May 2024 — verified primary source. The same official release disclosed an already substantial operational base: Tchap had 200,000 daily users; the state web-conferencing service had 47,000 users and 10,000 weekly meetings; France Transfert had 140,000 users and more than 350,000 exchanged packages; and Resana had 140,000 users sharing nearly 800,000 documents per month. These figures demonstrate that the French strategy is not an Office clone. It is the incremental construction of an authenticated public-sector collaboration fabric whose components can be composed, replaced and shared across ministries. The critical strategic asset is the common identity and service framework that prevents each alternative application from becoming an isolated island.
Documents are records, executable objects and institutional memory
Document sovereignty requires substantially more than converting DOCX files into OpenDocument Format. A modern office file can contain embedded fonts, digital signatures, comments, tracked revisions, external links, accessibility structures, spreadsheet functions, pivot tables, macros, data connections, rights-management rules and references to cloud-hosted objects. In regulated environments, the document’s evidentiary value may depend on creation time, author identity, retention status, approval sequence and immutable audit history. A file that renders correctly but loses its permissions or provenance has not been successfully migrated. Excel represents the highest substitution barrier because spreadsheets frequently operate as unregistered business applications: they calculate regulatory capital, payroll, project valuations, logistics forecasts, procurement scores and operational schedules while depending on Visual Basic for Applications, proprietary add-ins, Power Query, Power Pivot or external databases. These are not passive documents but undocumented execution environments. Europe must therefore inventory four categories separately: ordinary documents suitable for bulk conversion; high-fidelity documents that require controlled rendering; executable documents containing macros or complex formulas; and workflow-bound records whose meaning depends on SharePoint, Teams, Power Automate or third-party connectors. The Data Act provides a legal foundation for broader portability by defining exportable data to include input and output data plus metadata generated through use of a data-processing service. It also defines switching as movement to another provider or on-premises infrastructure and requires contracts to enable transfer of exportable data and digital assets. Article 25 establishes a normal maximum transitional period of 30 calendar days, while Article 29 prohibits switching charges from 12 January 2027. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023 — verified official text. Yet legal exportability does not guarantee semantic equivalence. If exported metadata cannot reconstruct retention labels, conversation relationships, workflow states or granular permissions, nominal portability becomes a data cemetery rather than an operational exit.
| Migration class | Typical objects | Principal hidden dependency | Required acceptance test | Indicative difficulty |
|---|---|---|---|---|
| M₁: Basic content | Letters, simple tables, presentations | Fonts, pagination, templates | Visual and semantic comparison | Low |
| M₂: Collaborative records | Comments, revisions, shared documents | Identities, permissions, version histories | Reconstructed authorship and access | Medium |
| M₃: Executable documents | Macros, complex spreadsheets, add-ins | VBA, proprietary calculation and connectors | Parallel-run output equivalence | High |
| M₄: Workflow-bound records | Approvals, forms, Teams/SharePoint processes | Power Platform, Graph API, retention rules | End-to-end process replay | Very high |
| M₅: Evidentiary archives | Signed files, legal records, classified material | Timestamps, signatures, immutable logs | Chain-of-custody validation | Critical |
| M₆: AI-enriched corpus | Copilot-indexed mail, documents and meetings | Embeddings, semantic index, prompts, Graph context | Rebuildable provenance and retrieval | Emerging critical |
Collaboration, metadata and APIs create the strongest network effects
Microsoft’s resilience derives from complementary network effects rather than the quality of any isolated application. Every additional user, Teams channel, SharePoint site, workflow, identity group and Microsoft Graph connector increases the cost of leaving the ecosystem. A competing word processor may reproduce document creation, yet it does not automatically recreate meeting transcription, presence information, cross-tenant collaboration, retention policies, electronic discovery, mobile-device controls or a supplier ecosystem trained to operate them. This is why the European Commission’s competition case concerning Teams is strategically important. The Commission’s preliminary concern addressed the tying of Teams to Office 365 and Microsoft 365; on 12 September 2025, it made Microsoft’s commitments legally binding. The commitments included versions of the productivity suites without Teams at reduced prices, switching opportunities for customers under longer-term contracts and interoperability measures for competing communications and collaboration products. Commission accepts commitments offered by Microsoft to address competition concerns related to Teams – European Commission – September 2025 — verified primary source. These remedies target bundling, but stack sovereignty requires deeper contestability: open event formats, portable channels and messages, stable APIs, exportable access-control relationships, substitutable search indexes and documented protocol behaviour. The Interoperable Europe Act, in force since 11 April 2024, adds a governance framework for cross-border interoperability and requires public-sector bodies to examine interoperability effects when introducing or substantially modifying trans-European digital public services. Interoperable Europe Act enters into force – European Commission – April 2024 — verified primary source. The combined policy logic is cumulative: competition law separates bundled products; the Data Act reduces cloud-switching friction; interoperability governance discourages national digital islands; open-source policy develops reusable components; and procurement can aggregate demand. None is sufficient alone. Together they can transform the public sector from a passive licence buyer into an anchor customer specifying modularity, open interfaces and verifiable exit conditions.
Germany, France and the Digital Commons EDIC are building different parts of the same architecture
Germany is pursuing a modular “sovereign workplace” composed of operating-system, backend and application services, with openDesk at the application layer. The federal government describes openDesk as a web-based open-source office and collaboration suite covering document editing, knowledge management, project management, collaboration and secure file management. Crucially, its stated design principle is not the replacement of one monolith with another, but the use of modular, exchangeable components and open standards. The official federal objective is to make a digitally sovereign alternative to proprietary workplaces available to the federal administration by October 2028. Souveräner Arbeitsplatz – Federal Ministry for Digital Transformation and Government Modernisation – March 2026 — verified primary source. Scaling remains at an early stage: in April 2026 the ministry stated that it was itself testing openDesk on more than 80 workplaces, although the suite was also in productive use across other public-administration settings. Bund stellt ZenDiS strategisch neu auf – Federal Ministry for Digital Transformation and Government Modernisation – April 2026 — verified primary source. France, by contrast, has developed a service federation around La Suite, public identity and existing operational tools. These national approaches began converging through the Digital Commons European Digital Infrastructure Consortium. Created in October 2025 by France, Germany, the Netherlands, Italy and Luxembourg, the consortium had attracted seven additional observers by April 2026, bringing participation to twelve jurisdictions. Its first initiatives included a 100-day challenge for sovereign interoperable components and a pilot European Sovereign Technology Fund. Le Digital Commons EDIC prend forme – Direction interministérielle du numérique – April 2026 — verified primary source. Italy’s participation is strategically relevant because Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, became one of its vice-presidents. Europe is therefore moving from disconnected national prototypes toward shared code, funding and governance, but it has not yet created a unified operational stack or procurement market.
| Programme | Verified scope | Current evidence | Strategic strength | Principal unresolved weakness |
|---|---|---|---|---|
| Schleswig-Holstein | LibreOffice, ODF, Linux, Nextcloud, Open-Xchange and backend substitution | Nearly 80% of about 25,000 workplaces had moved to LibreOffice by December 2025 | Demonstrates mass desktop migration | Regional success may not generalise to complex federal or industrial estates |
| France La Suite | Identity, messaging, conferencing, document sharing and sovereign services | 1.6 million agents addressable through AgentConnect; multiple tools already at six-figure user scale | Existing operational adoption and state service integration | Product completeness and cross-border federation |
| Germany openDesk | Web office, collaboration, knowledge and project management | Federal alternative targeted by October 2028; ministry pilot above 80 workplaces in April 2026 | Modular architecture and institutional operator ZenDiS | Early federal deployment scale |
| Digital Commons EDIC | Shared open components, funding coordination and European workplace | Five founders and seven observers reported in April 2026 | Converts national code into European common infrastructure | Sustainable financing and binding adoption commitments |
| EU Open Source Strategy | Whole-stack dependency reduction | Adopted as part of June 2026 sovereignty package | Union-wide policy and procurement leverage | Execution, maintenance capacity and measurable targets |
| Data Act | Switching, portability, interoperability and third-country safeguards | Applicable since September 2025; switching fees prohibited from January 2027 | Creates enforceable exit rights | SaaS semantic portability remains technically incomplete |
Security sovereignty cannot be reduced to data residency
The security debate often treats hosting data within the EU as equivalent to sovereignty, but geography alone does not answer who controls the encryption keys, identity plane, administrative tooling, software updates, telemetry or legal entity operating the service. A European data centre controlled by a foreign parent may reduce latency and support localisation requirements while leaving important questions concerning extraterritorial orders, remote administration and corporate control unresolved. Conversely, a European operator using open code can remain vulnerable if its update chain, container registry, firmware, domain-name infrastructure or security monitoring depends on external providers. The March 2024 decision of the European Data Protection Supervisor concerning the Commission’s use of Microsoft 365 is therefore best understood as a governance and controllership case, not proof of an inherent EU ban on Microsoft. The EDPS identified infringements and ordered corrective measures relating to purpose limitation, transfer safeguards and contractual controls. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024 — verified primary decision. In July 2025, after additional measures by the Commission and Microsoft, the EDPS concluded that compliance had been achieved and closed enforcement proceedings. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025 — verified primary source. Two conclusions follow. First, Microsoft 365 is not categorically unlawful for European institutions; configuration, contractual allocation and organisational measures materially affect compliance. Second, achieving compliance with current data-protection rules is not identical to attaining strategic autonomy. A compliant service may remain a concentration risk if one provider controls authentication, communications, endpoint security and archival evidence. The appropriate security metric is therefore blast-radius concentration: the proportion of essential functions that can be disrupted or made opaque through failure or coercion affecting a common supplier.
The AI layer is creating a second and potentially deeper lock-in cycle
The introduction of generative AI into office environments changes the dependency problem from file compatibility to institutional cognition. Microsoft Copilot can combine email, calendars, meetings, chats and documents through Microsoft Graph, producing a semantic representation of organisational activity. Once staff rely on AI-generated summaries, retrieval, drafting and workflow recommendations, the value migrates from discrete files to the provider’s indexed context, permission graph, embeddings, prompt orchestration, safety controls and usage telemetry. Exporting DOCX files will not reproduce that cognitive layer. A sovereign exit must therefore address whether embeddings can be regenerated, whether retrieval indexes are portable, whether prompts and agent configurations are documented, whether citations retain provenance, whether access-control trimming behaves identically, and whether alternative models can reproduce mission-critical results. Microsoft’s audited filings demonstrate that the incumbent ecosystem continues to expand rather than contract. For fiscal year 2025, Microsoft reported that Microsoft 365 Commercial products and cloud-services revenue increased by 14%, Microsoft 365 Commercial cloud revenue increased by 15%, commercial seat volume grew by 6%, and the consumer subscriber base reached 89 million. Fiscal Year 2025 Productivity and Business Processes Performance – Microsoft Corporation – July 2025 — verified audited corporate disclosure. This growth matters analytically: European policy is attempting to create exit capacity while Microsoft is increasing the economic and functional density of the ecosystem through cloud and AI. The result is a race between interoperability and integration. If European administrations adopt sovereign document tools but allow their knowledge retrieval, meeting intelligence and automated decision support to consolidate around a foreign AI graph, they may exchange first-generation Office dependence for a more opaque second-generation dependence. By 2031, the decisive sovereignty indicator may therefore be the percentage of institutional knowledge that can be reconstructed and queried outside the incumbent AI platform with preserved permissions, provenance and auditability.
| AI-stack control | Sovereign requirement | Failure mode by 2031 | Verification method |
|---|---|---|---|
| Source corpus | Exportable documents, email, chat and meeting records | AI output cannot be regenerated elsewhere | Complete corpus reconciliation |
| Permission graph | Portable users, groups, roles and access inheritance | Alternative model exposes restricted data or suppresses lawful access | Cross-platform authorisation tests |
| Semantic index | Rebuildable embeddings and metadata | Search quality collapses after migration | Parallel retrieval evaluation |
| Agent configuration | Portable prompts, tools, connectors and policies | Business automation remains captive | Re-execution against reference tasks |
| Provenance | Traceable sources and transformation history | Generated answers become non-auditable | Citation and lineage validation |
| Model choice | Replaceable inference provider | Price, censorship or availability dictated externally | Multi-model failover exercise |
| Safety controls | Locally governed filtering and monitoring | Sovereign deployment introduces unmanaged risk | Red-team and policy-conformance testing |
| Usage telemetry | Institution-controlled logs and retention | Provider gains opaque behavioural intelligence | Telemetry inventory and data-flow inspection |
China and Russia expose the difference between sovereignty, protectionism and isolation
Multilingual comparison is analytically useful because China and Russia demonstrate harder forms of software substitution, but neither constitutes a direct model for the European Union. A 2024 Shanghai Fengxian District procurement covered 12,252 licences each for desktop operating systems, streaming office software and fixed-layout office software, with a stated annual budget of RMB 3.98 million and an explicit requirement that the project not purchase imported products. The technical inventory identified Kylin V10, WPS 2019 for Linux and Foxit OFD products in the existing domestic environment. Fengxian District Party and Government Office Software Authorisation Service Procurement – Shanghai Fengxian District Government Procurement Centre – July 2024 — verified Chinese government procurement document. This represents procurement-driven localisation supported by domestic formats, operating systems and suppliers. Russia’s software policy similarly uses a state registry and compatibility requirements to structure substitution. In September 2025, the Russian Ministry of Digital Development stated that eligibility rules would require virtualisation and office software to be compatible with Russian operating systems from 1 June 2026. Правила для включения в реестр софта: совместимость с российскими ОС – Ministry of Digital Development of the Russian Federation – September 2025 — verified Russian government source. Europe’s model remains legally and economically different: it seeks contestability, open standards and strategic resilience inside a competitive market rather than a blanket nationality exclusion. Nevertheless, the Chinese and Russian cases reveal a critical fact: application substitution succeeds when procurement, operating-system compatibility, document standards, training, support and supplier finance move together. Europe cannot expect voluntary consumer choice alone to overcome bundling and network effects. At the same time, indiscriminate nationality preferences could fragment the Single Market, reduce competition and protect weak domestic suppliers. The European challenge is to design capability-based sovereignty criteria—portability, key control, transparent governance, open interfaces, European operational continuity—without converting resilience policy into permanent technological protectionism.
Five competing hypotheses for the 2026–2031 transition
The Analysis of Competing Hypotheses produces five plausible trajectories. H₁, regulated Microsoft continuity, assumes that contractual, competition and data-protection remedies reduce the most visible risks while Microsoft retains the majority of public-sector workloads; its prior probability is assessed at 29% and its evidence-adjusted posterior at 23%. H₂, hybrid stack sovereignty, assumes that public institutions retain selected Microsoft applications while moving identity, collaboration, hosting, formats or sensitive workloads to open and European-controlled components; its posterior is 43%, the largest because it best fits simultaneous evidence of political commitment, incumbent growth and high migration costs. H₃, public-sector bifurcation, assumes that France, Germany, Schleswig-Holstein and cooperating states create a distinct sovereign public workplace while most private enterprises remain Microsoft-centred; its posterior is 20%. H₄, shock-accelerated decoupling, assumes a severe transatlantic legal conflict, sanctions episode, service discontinuity or cybersecurity event that causes emergency migration; its posterior is 9%, above its low prior because European governments are now explicitly treating external dependency as a strategic risk. H₅, comprehensive European replacement, assumes broad displacement of Microsoft’s office, collaboration, identity and cloud layers across both public and private sectors; its posterior is only 5% because no European alternative currently matches the entire ecosystem’s functionality, support network and enterprise integration. The Bayesian update is qualitative-quantitative: each evidence item receives an ordinal likelihood ratio based on whether it is strongly, moderately or weakly expected under each hypothesis, while correlated policy announcements are discounted to avoid double counting. The assessment does not claim official statistical probability. It is a transparent intelligence estimate intended to expose which future best explains the observed combination of regulation, procurement, deployment, incumbent growth and technical lock-in.
| Hypothesis | Prior | 2026 posterior | Strongest confirming indicator | Strongest disconfirming indicator |
|---|---|---|---|---|
| H₁: Regulated Microsoft continuity | 29% | 23% | Microsoft 365 commercial growth and Commission compliance remediation | Whole-stack language in the 2026 EU strategy |
| H₂: Hybrid stack sovereignty | 36% | 43% | Modular German and French programmes plus EU switching policy | Cross-stack integration remains technically immature |
| H₃: Public-sector bifurcation | 18% | 20% | Operational public-sector deployments and Digital Commons EDIC | Uneven Member State capacity and procurement fragmentation |
| H₄: Shock-accelerated decoupling | 7% | 9% | Increased geopolitical treatment of supplier dependence | No verified EU-wide emergency migration order |
| H₅: Comprehensive replacement | 10% | 5% | Successful regional substitution demonstrates feasibility | Private-sector macros, workflows, AI and partner ecosystem |
Monte Carlo outlook: transition will be nonlinear and bottleneck-driven
A five-year Monte Carlo model was specified around 100,000 simulated pathways, using six bounded drivers: procurement intensity, open-stack functional maturity, migration capacity, legacy complexity, transatlantic geopolitical friction and availability of European operational support. The model does not use invented historical observations; it translates the verified policy and deployment evidence into explicit scenario ranges. Procurement intensity and geopolitical friction accelerate migration decisions, while legacy complexity raises cost and failure probability. Functional maturity and operational support determine whether initial pilots become sustained production. Correlations are imposed between procurement and funding, between geopolitical friction and urgency, and between functional maturity and support capacity. Under the central calibration, the median share of EU public-sector workplace functions materially displaced from Microsoft-controlled layers rises from an indicative 9% in 2026 to 34% in 2031. The 10th–90th percentile band in 2031 spans approximately 16–59%, reflecting high uncertainty over Member State execution. The probability that more than half of public-sector workplace functions are displaced by 2031 is estimated at 17%; the probability of an EU-wide functional Microsoft exit remains below 6%. Importantly, “displaced” does not mean that Word or Excel disappears from every workstation. It means that at least one strategic function—document editing, collaboration, identity, storage, workflow or AI knowledge processing—moves to a replaceable or European-controlled alternative. The model identifies two threshold effects. First, once interoperable identity, document collaboration and sovereign hosting are jointly available, marginal migration costs fall because administrations no longer construct bespoke integration for every tool. Second, if open alternatives remain funded as temporary projects rather than maintained infrastructure, adoption plateaus after pilots and users return to the incumbent ecosystem. Funding continuity, professional support and mandatory exit testing therefore exert more influence on the 2031 outcome than political declarations alone.
| Outlook indicator | 2026 baseline estimate | 2028 central path | 2031 central path | 2031 adverse path | 2031 accelerated path |
|---|---|---|---|---|---|
| Public workplace functions outside Microsoft control | 9% | 19% | 34% | 16% | 59% |
| Administrations with tested Microsoft exit plans | 7% | 22% | 46% | 19% | 72% |
| New strategic procurements requiring open interfaces | 18% | 42% | 68% | 39% | 86% |
| Sensitive collaboration on sovereign/open services | 13% | 28% | 49% | 25% | 74% |
| AI workplace functions remaining Microsoft-centred | 88% | 76% | 61% | 79% | 38% |
| Probability of complete EU-wide Office-stack exit | Below 1% | 2% | 5% | 2% | 11% |
What Europe must control by 2031
Europe’s success should be judged against measurable control gates rather than the number of LibreOffice installations. By 2031, every critical public organisation should possess a machine-readable dependency register connecting business functions to applications, identity providers, APIs, data stores, cryptographic keys, security telemetry and legal jurisdictions. Every strategic procurement should include an exit architecture, maximum transition period, metadata-export specification, stable interface commitment, independent security logging and a funded migration reserve. Administrations should maintain at least one alternative provider or internally operable implementation for identity, collaboration and document storage, and they should conduct periodic exit exercises in the same manner that financial institutions test disaster recovery. Open-source components require long-term maintenance contracts, coordinated vulnerability response, reproducible builds, software bills of materials and protected maintainer capacity; otherwise Europe merely transfers dependence from a profitable vendor to unpaid or underfunded communities. The Digital Commons EDIC can become the institutional mechanism for pooling these costs, but it must avoid creating a new European monolith. Its components should remain modular, independently implementable and governed through published interfaces. Italy should use its founding role to align national cloud, identity and cybersecurity programmes with shared European workplace components rather than treating sovereignty as data-centre localisation alone. The final strategic objective is neither expulsion of Microsoft nor ceremonial preference for open source. It is the creation of a market in which Microsoft must continuously compete because European customers can leave without operational catastrophe. If the Union can port its records, preserve its evidence, federate its identities, control its keys, reconstruct its AI knowledge layer and continue essential services under a substitute operator, it will have achieved stack sovereignty even where Microsoft remains present. If it merely replaces DOCX editors while leaving identity, metadata, workflows, security and AI under one supplier’s control, the migration will be politically visible but strategically hollow.
Figure 1: EU Workplace Stack-Sovereignty Projection, 2026–2031
Interactive analytical scenario model: share of public-sector workplace functions displaced from Microsoft-controlled layers.
Regulation, Procurement and Geopolitical Exposure: Why Digital Dependence Has Become a European Security Variable
Dependence has crossed the boundary between efficiency and security
European dependence on Microsoft and other non-European digital-platform providers has become a security variable because the same integrated services now mediate communication, identity, authorisation, document production, operational data, cyber defence, regulatory evidence and increasingly organisational decision-making through artificial intelligence. A conventional supplier relationship becomes a strategic exposure when failure, coercion or withdrawal by that supplier could prevent a government, bank, hospital, energy operator or defence contractor from performing an essential function within its maximum tolerable period of disruption. The relevant transformation is therefore functional, not ideological: Microsoft 365, Azure, Amazon Web Services, Google Cloud and other hyperscale ecosystems are no longer treated only as purchased technology but as externalised components of institutional command-and-control. European regulation reflects this shift. NIS2 requires essential and important entities to manage risks involving supply-chain security, relationships with direct suppliers and service providers, vulnerability handling, business continuity, access control and multifactor authentication. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union – European Parliament and Council – December 2022 — verified official text. DORA, applicable to the European financial sector from January 2025, goes further by explicitly treating concentration in critical ICT third-party providers as a potential systemic risk rather than a collection of independent bilateral contracts. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector – European Parliament and Council – December 2022 — verified official text. The logic is analogous to financial concentration: one bank’s exposure to a supplier may appear manageable, yet the simultaneous dependence of hundreds of banks, insurers and payment institutions on the same identity, cloud or security provider creates correlated failure. Office dependence consequently becomes security-relevant when a single administrative error, compromised software update, identity outage, licensing intervention, foreign legal order or geopolitical rupture can propagate across multiple organisations, sectors and Member States. The object of European policy is not to prove that US suppliers are intrinsically insecure. It is to reduce the probability that European operational continuity depends on decisions, infrastructures and legal processes that European institutions cannot independently control.
| Dependency condition | Ordinary commercial risk | Strategic-security risk threshold | Illustrative consequence |
|---|---|---|---|
| Single application | Users lose productivity temporarily | Application supports an essential or time-critical function | Courts, hospitals or ministries cannot issue operational documents |
| Common identity provider | Login inconvenience | Identity failure disables multiple independent services | Staff cannot access email, files, incident systems or cloud consoles |
| Common collaboration suite | Communications degradation | Crisis coordination depends on the same tenant or control plane | Incident responders lose shared situational awareness |
| Common cloud provider | Local service interruption | Multiple critical entities share regions, APIs or management planes | Cross-sector correlated outage |
| Common endpoint manager | Device-management failure | Provider can revoke, isolate or reconfigure the workstation fleet | Administrative capability over endpoints is lost |
| Common security platform | Monitoring degradation | Detection, response and evidence reside inside the affected supplier | Defenders become blind during the same incident they must investigate |
| Foreign jurisdiction | Contractual/legal uncertainty | Legally valid third-country process can reach controlled data | Conflict between foreign disclosure and EU obligations |
| Proprietary data graph | Migration cost | Permissions, metadata and AI context cannot be reconstructed | Formal exit exists, but institutional memory becomes unusable |
| Bundled procurement | Pricing inefficiency | Alternative suppliers cannot enter adjacent layers | Concentration becomes self-reinforcing |
| Vendor-operated updates | Patch dependency | Unilateral update or suspension affects essential functions | Simultaneous compromise or loss of service across customers |
Concentration risk is multiplicative, not additive
The most important technical property of platform dependence is correlation. If ten institutions use ten independent providers, each may experience an outage, but the probability of simultaneous failure remains comparatively limited. If all ten use the same identity, productivity, cloud and security control planes, the system acquires a common mode of failure. Concentration becomes more severe when the services are vertically integrated. Microsoft Entra ID may authenticate users to Microsoft 365, Azure, third-party SaaS applications and administrative consoles; Intune may assess device compliance; Conditional Access may combine identity and device signals; Defender may supply threat telemetry; Sentinel may correlate incidents; Purview may govern retention and discovery; and Microsoft Graph may connect the resulting data. The concentration coefficient is therefore not adequately measured by the percentage of organisations purchasing Microsoft licences. It must be measured as the intersection of provider share, functional criticality, cross-layer integration, substitutability and recovery time. DORA formalises this concern by requiring financial entities to maintain registers of ICT third-party arrangements, assess concentration risk, evaluate whether multiple critical functions depend on the same provider and develop contractual exit strategies. It also creates an EU oversight framework for providers designated as critical. Digital Operational Resilience Act – European Banking Authority – January 2025 — verified institutional source. The European Supervisory Authorities warned in March 2025 that dependencies and concentration involving hardware, cloud services and AI models can generate risks extending beyond individual firms. Joint Committee Update on risks and vulnerabilities in the EU financial system – European Supervisory Authorities – March 2025 — verified primary report. The same reasoning applies outside finance even where DORA does not directly govern the entity. A national administration whose email, videoconferencing, endpoint security, file storage and incident coordination depend on one provider possesses five contracts but only one effective failure domain. Regulatory inventories that count suppliers without mapping control-plane commonality consequently understate the real exposure.
| Concentration metric | Definition | Low-risk state | High-risk state | Required evidence |
|---|---|---|---|---|
| C₁: Provider concentration | Share of critical functions served by one provider | Below 25% | Above 60% | Function-to-provider register |
| C₂: Control-plane concentration | Functions sharing identity, management or policy plane | Independent controls | One control plane governs most services | Architecture and trust mapping |
| C₃: Data concentration | Sensitive datasets accessible through one ecosystem | Segmented stores and keys | Unified graph spanning mail, files and meetings | Data-flow and permission graph |
| C₄: Recovery concentration | Recovery services dependent on the primary provider | Independent backup and access | Backups, keys and recovery consoles share provider | Recovery architecture test |
| C₅: Sector concentration | Comparable entities using the same provider | Diverse supplier base | Market-wide reliance on common infrastructure | Regulatory aggregate register |
| C₆: Geographic concentration | Workloads sharing regions or facilities | Multi-region and multi-operator | Single region or correlated facilities | Physical and logical dependency map |
| C₇: Skills concentration | Operational knowledge tied to one vendor | Transferable technical skills | Staff and suppliers trained only on incumbent stack | Workforce capability inventory |
| C₈: Contract concentration | Multiple services tied to one renewal or enterprise agreement | Modular termination | Bundled renewal controls unrelated services | Contract linkage analysis |
| C₉: AI concentration | Models, embeddings and knowledge access controlled together | Replaceable models and indexes | One provider controls corpus, model and agent layer | AI bill of materials |
| C₁₀: Jurisdictional concentration | Critical providers exposed to the same foreign jurisdiction | Legally diversified operators | Dominant dependencies share one external jurisdiction | Corporate-control and legal mapping |
The legal conflict is about control, not the physical location of servers
Data residency is relevant but insufficient because the legal reach of a state can attach to a provider’s corporate control rather than the storage location alone. The US CLOUD Act clarified that a provider subject to United States jurisdiction may be required to disclose data within its possession, custody or control in response to valid legal process, regardless of where the provider stores the data. The US Department of Justice describes this extraterritorial reach explicitly while emphasising that the legislation did not eliminate the applicable standards for obtaining legal process and includes mechanisms for bilateral agreements and conflict-of-law challenges. The Purpose and Impact of the CLOUD Act – United States Department of Justice – April 2019 — verified US government source. A serious European analysis must avoid two opposite exaggerations. The first is that US authorities possess unrestricted, direct access to every European cloud record; the verified statute and official explanations do not support that claim. The second is that locating data in Frankfurt, Paris or Milan eliminates US jurisdictional exposure; the Department of Justice’s description expressly rejects location as the decisive limitation where the provider has custody or control. The European security variable is therefore the probability and consequence of conflicting legal obligations, combined with the institution’s capacity to know, contest, technically constrain and document disclosure. The Data Act, applicable since 12 September 2025, responds at the level of non-personal data by requiring data-processing providers to publish the jurisdictions governing their infrastructure and describe technical, organisational and contractual measures intended to prevent third-country governmental access or transfer where that access would conflict with EU or Member State law. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – European Parliament and Council – December 2023 — verified official text. The strategically strongest mitigation is not a contractual declaration but a control design in which the customer holds encryption keys, privileged access is locally governed, provider access is technically mediated, sensitive workloads are segmented and legally exposed components can be replaced without interrupting essential functions.
| Jurisdictional question | Weak assurance | Stronger assurance | Residual limitation |
|---|---|---|---|
| Where are data stored? | EU-region marketing statement | Contractually fixed locations plus verified data-flow mapping | Corporate control may remain external |
| Who controls encryption keys? | Provider-managed encryption | Customer-controlled or independently held keys | Metadata and processing may remain visible |
| Who can administer infrastructure? | Global vendor support | EU-cleared personnel with logged, just-in-time access | Software publisher retains update authority |
| Can access occur silently? | Transparency report | Customer notification unless legally prohibited, auditable access gateway | Law may restrict notification |
| Can foreign process be challenged? | Generic contractual promise | Defined challenge procedure and conflict-of-law assessment | Outcome depends on jurisdiction and facts |
| Can the service continue if access is prohibited? | No alternative | Tested substitute operator and migration plan | Transition may reduce functionality |
| Is the European subsidiary independent? | Separate legal entity | Independent governance, operations, capital and technical control | Ultimate parent influence may persist |
| Are backups legally separated? | Same provider, same account | Independent provider, keys and identity plane | Replication can recreate exposure |
| Is telemetry protected? | Content encryption only | Logs, metadata and support data included in control perimeter | Operational metadata can still disclose sensitive patterns |
| Is deletion verifiable? | Provider certificate | Cryptographic erasure plus independent evidence | Distributed caches and legal holds complicate proof |
Data protection enforcement demonstrates conditional compliance, not strategic independence
The European Data Protection Supervisor’s investigation into the European Commission’s use of Microsoft 365 provides the most authoritative case study because it separates legal compliance from political rhetoric. On 8 March 2024, the EDPS concluded that the Commission had infringed several provisions governing purpose limitation, international transfers and processing instructions. It ordered corrective measures, including suspension—effective from 9 December 2024—of specified data flows to Microsoft and its affiliates or subprocessors outside the EU/EEA where the required safeguards had not been demonstrated. Decision following the investigation into the European Commission’s use of Microsoft 365 – European Data Protection Supervisor – March 2024 — verified primary decision. The case did not establish that every deployment of Microsoft 365 was inherently unlawful. It established that a controller must define processing purposes, document transfers, constrain processors, verify contractual and technical safeguards and retain meaningful control over data processing. Following additional measures by the Commission and Microsoft, the EDPS closed the enforcement proceeding in July 2025 after concluding that the infringements identified in the 2024 decision had been remedied. European Commission brings use of Microsoft 365 into compliance – European Data Protection Supervisor – July 2025 — verified primary source. The strategic lesson is precise: compliance can be negotiated and engineered, but the cost and complexity of demonstrating compliance rise as the service becomes more integrated, telemetry-intensive and dynamically updated. A public authority may therefore achieve legal compliance yet retain concentration, continuity or geopolitical exposure. Conversely, migrating to an open-source platform does not automatically ensure GDPR compliance if access controls, logging, retention or processing agreements are defective. Security sovereignty must be evaluated through three separate tests: lawfulness, determining whether processing meets applicable law; resilience, determining whether the function survives disruption; and autonomy, determining whether the organisation can alter or replace the service without unacceptable loss. Conflating these tests produces either unjustified alarm or false reassurance.
| Assessment domain | Core question | Microsoft 365 compliance can satisfy it? | Sovereignty requires more? |
|---|---|---|---|
| GDPR/EU-institution data protection | Is processing lawful, limited and safeguarded? | Yes, depending on configuration and governance | Yes |
| NIS2 risk management | Are supply-chain and continuity risks managed? | Potentially | Yes |
| DORA operational resilience | Can critical financial functions withstand disruption and exit? | Only with entity-specific controls | Yes |
| National-security autonomy | Can a foreign-controlled dependency be denied or replaced? | Not inherently | Yes |
| Evidentiary control | Can records and logs be independently reconstructed? | Partially | Yes |
| Commercial contestability | Can competitors interoperate and customers switch? | Improved through remedies and law | Yes |
| Crisis command continuity | Can coordination continue during provider/control-plane failure? | Only with independent fallback | Yes |
| AI knowledge autonomy | Can models, indexes, prompts and permissions be reconstituted? | Not guaranteed | Yes |
NIS2 turns the software supply chain into board-level accountability
NIS2’s strategic significance lies in its movement of cybersecurity from a technical department to the governing body. Article 20 requires management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee their implementation; members can be held liable under national implementation frameworks and must receive training. Article 21 identifies risk-analysis policies, incident handling, business continuity, crisis management, supply-chain security, acquisition and maintenance security, vulnerability handling, cryptography, access control and multifactor authentication among the required measures. Directive (EU) 2022/2555 – European Parliament and Council – December 2022 — verified official text. Commission Implementing Regulation 2024/2690 adds more detailed requirements for certain digital and ICT-service entities, including policies for supply-chain security, supplier selection, contractual controls, monitoring and termination. Commission Implementing Regulation (EU) 2024/2690 laying down technical and methodological requirements under NIS2 – European Commission – October 2024 — verified official text. This changes the treatment of productivity suites. A board can no longer reasonably view Microsoft 365, Google Workspace or an alternative open-source platform solely as office software when the suite carries privileged identities, sensitive communications, endpoint controls and security evidence. Management must ask whether the provider’s incident-notification terms support statutory timelines; whether subcontractors are identifiable; whether logs remain available during an outage; whether vulnerability disclosures can be evaluated independently; whether a supplier compromise can reach privileged accounts; and whether business continuity plans include loss of the cloud administration plane. The regulation is technology-neutral, meaning it does not require Microsoft’s removal. It does, however, make unexamined dependency increasingly indefensible. It also creates a paradox: organisations frequently answer rising regulation by purchasing more integrated security and compliance services from the same hyperscaler, thereby improving control maturity in the short term while increasing concentration in the long term. A mature NIS2 programme must therefore measure not only the number of implemented controls but how many controls would fail together if the primary provider became unavailable or untrusted.
Empirical evidence shows improving controls but deepening dependence
ENISA’s 2025 investment survey provides a quantitative base for evaluating this paradox. The survey covered 1,080 public and private organisations across all EU Member States, including every NIS2 high-criticality sector; 83% of respondents were large enterprises and 17% were SMEs. ENISA reported that organisations considered vulnerability and patch management challenging in 50% of cases, business continuity and disaster recovery in 49%, and supply-chain risk management in 37%. Approximately 30% had not conducted a cybersecurity assessment during the preceding twelve months, while 28% took longer than three months to patch critical vulnerabilities. Looking forward, 55% cited ransomware and 47% cited supply-chain attacks among their principal concerns. NIS Investments 2025 – European Union Agency for Cybersecurity – December 2025 — verified primary report. ENISA’s 2026 NIS360 synthesis added that 90% of surveyed organisations reported implementing some controls for supply-chain risk: 63% required suppliers to comply with security standards, 54% conducted supplier risk assessments or audits and 48% included cybersecurity requirements in supplier contracts. ENISA NIS360 2026 – European Union Agency for Cybersecurity – May 2026 — verified primary report. These figures show progress but also reveal the gap between supplier assurance and actual substitutability. Requiring a dominant provider to hold certifications does not reduce the number of essential functions dependent on it. Auditing a provider may improve transparency without delivering technical access to the evidence required to reproduce the service. Contract clauses may define exit rights while the customer lacks staff, migration tools or a viable destination platform. Europe’s problem is therefore not an absence of supplier controls but the frequent substitution of supplier assurance for system resilience. Assurance asks whether the incumbent is well controlled; resilience asks what happens when the incumbent is nevertheless unavailable, compromised, legally constrained or geopolitically inaccessible.
| ENISA evidence | Reported value | Security interpretation | Sovereignty implication |
|---|---|---|---|
| Organisations surveyed | 1,080 | Broad cross-sector evidence base | Dependency problem is not confined to government |
| Large enterprises | 83% | Results reflect comparatively mature organisations | SME conditions may be worse |
| SMEs | 17% | Smaller but material sample | Support and migration capacity remain uneven |
| Patching identified as challenging | 50% | Basic technical hygiene remains difficult | Multi-stack migration can increase patch burden |
| Continuity and recovery identified as challenging | 49% | Resilience remains underdeveloped | Exit plans are unlikely to be operational without testing |
| Supply-chain management identified as challenging | 37% | Supplier exposure is recognised but difficult | Procurement must include architecture, not only questionnaires |
| No assessment in previous 12 months | 30% | Significant verification deficit | Claimed controls may be untested |
| More than three months to patch critical flaws | 28% | Exposure windows remain long | Open-source adoption requires sustainable maintenance |
| Ransomware among future concerns | 55% | Direct operational disruption dominates | Offline and independent recovery remains essential |
| Supply-chain attacks among future concerns | 47% | Correlated compromise is a major concern | Provider concentration magnifies potential impact |
| Require supplier security standards | 63% | Contractual baseline is becoming common | Standards alone do not create alternatives |
| Conduct supplier assessments/audits | 54% | Oversight is improving | Audit scope must include subcontractors and control planes |
| Include cybersecurity contract requirements | 48% | Fewer than half embed requirements contractually | Procurement maturity remains incomplete |
Procurement determines the architecture before security teams can manage it
Public procurement is the most powerful but underused instrument for reducing strategic digital dependence because architectural lock-in is usually created at acquisition, not discovered during an incident. Conventional tenders optimise licence price, functional checklists and short implementation schedules. Bundled enterprise agreements make this approach appear economically rational: email, document editing, collaboration, security, storage and AI are priced together, while integrating an alternative requires additional identity, support and compliance expenditure. The resulting comparison is structurally distorted. The incumbent bundle’s integration costs are internalised and discounted; the alternative’s transition costs are made visible and charged immediately. A sovereignty-aware procurement must calculate risk-adjusted total cost of control, including subscription fees, integration, training, retained skills, expected outage loss, exit cost, data reconstruction, concentration capital, legal-compliance overhead and the cost of maintaining an independent recovery path. The EU’s policy direction is moving toward this broader evaluation. Its cloud policy envisages an EU Cloud Rulebook and public-procurement guidance intended to establish consistent criteria for acquiring data-processing services. Cloud computing policy – European Commission – June 2026 — verified primary source. The 2025 State of the Digital Decade report also identified strategic public procurement and the planned revision of procurement directives as instruments for strengthening sovereign digital capacity. State of the Digital Decade 2025 – European Commission – June 2025 — verified official communication. Procurement cannot lawfully or economically be reduced to excluding every US provider. It should instead require verifiable qualities: open interfaces, exportable metadata, customer-controlled keys, transparent subcontracting, workload portability, independent recovery, documented governmental-access safeguards, modular pricing and tested termination assistance. These criteria target the risk rather than the supplier’s passport and reward any provider capable of delivering credible control.
| Procurement criterion | Conventional tender formulation | Sovereignty-grade formulation | Verification before award |
|---|---|---|---|
| Data portability | “Data can be exported” | Content, metadata, permissions, logs and workflow state exported in documented formats | Full migration proof-of-concept |
| Interoperability | “Supports APIs” | Stable, documented, non-discriminatory interfaces with functional coverage | Competing implementation test |
| Identity | “Supports SSO” | Federation without compulsory incumbent directory; roles and logs portable | Alternative identity-provider integration |
| Encryption | “Encryption at rest and in transit” | Customer-controlled keys; separation of duties; auditable provider access | Key-loss and provider-access exercise |
| Subprocessors | Supplier maintains a list | Advance notice, objection rights, dependency mapping and equivalent obligations | Subprocessor-chain review |
| Exit | Termination-assistance clause | Maximum timelines, fixed charges, named deliverables and continuity support | Exit rehearsal before production |
| Updates | Vendor-managed updates | Release transparency, emergency deferral, provenance and rollback | Signed-update and rollback demonstration |
| Audit | Certification accepted | Access to relevant evidence, logs and independent testing | Evidence request simulation |
| Incident reporting | “Without undue delay” | Timelines aligned to regulatory duties and predefined information schema | Tabletop notification exercise |
| Continuity | Multi-zone deployment | Independent identity, backup, keys and operator recovery | Destructive failover exercise |
| AI | Generic data-protection warranty | Corpus boundaries, model provenance, prompt logging and portable agent configurations | Parallel model test |
| Pricing | Lowest five-year subscription cost | Risk-adjusted lifecycle and exit cost | Scenario-based financial evaluation |
| Concentration | Supplier self-assessment | Entity and sector-level common-dependency analysis | Regulatory/provider register comparison |
| Jurisdiction | EU data location | Corporate-control, legal-reach and administrative-access analysis | Independent legal and technical opinion |
Contractual exit without technical exit is a paper control
The Data Act materially improves Europe’s legal position by establishing rights and obligations for switching between data-processing services. It requires written contracts to permit customers to switch to another provider or on-premises infrastructure and generally sets a maximum transition period of 30 calendar days, subject to defined extensions. Providers must disclose switching procedures, formats, restrictions and technical limitations. From 12 January 2027, providers may no longer impose switching charges, although normal service fees and early-termination penalties remain distinct. For non-infrastructure services, providers must make open interfaces available free of charge to customers and destination providers to facilitate portability and interoperability. Regulation (EU) 2023/2854 – European Parliament and Council – December 2023 — verified official text. These provisions reduce deliberate economic friction, but they cannot eliminate architectural gravity. The most difficult Microsoft 365 assets are not raw files: they are inherited permissions, Teams relationships, SharePoint taxonomies, mailbox histories, retention classifications, Power Platform workflows, application identities, security baselines, device policies, e-discovery holds, Graph integrations and Copilot knowledge context. The destination system may accept the exported bytes yet fail to reproduce the original control semantics. True exit readiness therefore requires a functional-equivalence ledger identifying every critical business outcome, the source objects on which it depends, the destination implementation, the maximum tolerable degradation and the evidence required for acceptance. Organisations should continuously export a representative sample, rebuild it in an alternative environment and measure content completeness, access-control equivalence, workflow execution, search quality, legal retention and recovery time. This process should occur before termination becomes necessary. During geopolitical or cyber crisis, migration teams will face reduced time, impaired vendor cooperation, high demand for alternative capacity and heightened threat activity. A dormant contractual right exercised for the first time during crisis is not resilience; it is an untested assumption.
| Exit object | Nominal export | Functional requirement | Common failure |
|---|---|---|---|
| Office files | DOCX, XLSX, PPTX | Preserved rendering, formulas, macros and signatures | Visual or calculation divergence |
| Message archive | Folders, labels, retention, delegates and discovery | Lost permissions and legal holds | |
| Teams | Messages and files | Threads, participants, timestamps and meeting context | Relationships between objects disappear |
| SharePoint | Files and lists | Metadata, versions, taxonomy and workflows | Flat-file export destroys application logic |
| Identity | Users and groups | Roles, service accounts, MFA and device trust | Accounts migrate without authorisation semantics |
| Endpoint policy | Configuration export | Equivalent enforcement and rollback | Policy syntax is provider-specific |
| Security telemetry | Logs and alerts | Searchable history, detections and evidence chain | Formats differ or historical access expires |
| Power Platform | Application packages | Connectors, secrets, business logic and data mappings | Proprietary components cannot execute |
| Copilot context | Source corpus | Permissions, index, prompts, citations and agent state | Semantic layer cannot be reconstructed |
| Encryption material | Key export where allowed | Usable keys, rotation history and separation of duties | Provider-held keys are non-exportable |
| Compliance records | Reports and labels | Evidentiary provenance and immutable history | Static PDF replaces actionable records |
| Support knowledge | Tickets and configurations | Reproducible troubleshooting history | Operational knowledge remains with provider |
Cybersecurity creates an asymmetric dependency on the defender
A productivity-platform provider may simultaneously act as software publisher, identity authority, endpoint administrator, telemetry collector, threat-intelligence supplier, security-information platform and incident-response partner. This convergence can improve defensive effectiveness because integrated signals allow rapid detection and containment. It also creates a security paradox: the institution depends on the same supplier to detect, explain and remediate an incident involving that supplier’s own ecosystem. If logs are inaccessible during an identity outage, if threat detections rely on cloud analytics that cannot be independently reproduced, or if the provider controls the update and attestation systems under investigation, the customer’s forensic independence is reduced. Security sovereignty therefore requires an out-of-band evidence plane. Critical logs should be streamed to independently controlled storage with immutable retention; emergency administrator identities should not rely exclusively on the normal federation service; endpoint recovery should remain possible without the principal mobile-device-management platform; backups should be protected by separate credentials and keys; and at least one incident-communications channel must operate outside the primary collaboration tenant. NIS2’s requirements for incident handling, continuity, crisis management and supply-chain security point toward this architecture, while DORA requires financial institutions to test operational resilience and manage ICT third-party risk. The central error is treating multi-region deployment inside one provider as full diversification. Regions may protect against local physical failure, yet still share software, identity, certificate, update, billing or global management dependencies. Similarly, using two SaaS products hosted on the same hyperscaler or authenticated through the same directory does not necessarily create independent recovery. Diversification must be measured by common control planes, legal entities, code bases, administrative credentials and recovery dependencies. A sovereign fallback need not reproduce every feature. It must preserve the organisation’s minimum viable command capability: authenticate emergency staff, distribute verified instructions, access critical records, communicate securely, approve transactions and retain evidence until normal operations resume.
Geopolitical exposure includes denial, leverage, intelligence and strategic timing
The direct probability that a US government would order Microsoft to terminate ordinary European civilian services remains low under current alliance conditions, and there is no verified official basis for presenting such an outcome as imminent. Security planning, however, evaluates consequence as well as probability and recognises that political conditions can change faster than enterprise architectures. Geopolitical exposure operates through at least five mechanisms. First, lawful access exposure concerns government demands for data under national law. Second, denial exposure concerns sanctions, export controls, licence restrictions or corporate decisions that could limit service availability. Third, intelligence exposure concerns the strategic information contained in metadata, support interactions, telemetry and aggregate usage patterns even where document content is encrypted. Fourth, economic leverage arises when price changes or product bundling cannot be resisted because switching is impractical. Fifth, strategic timing exposure occurs when dependency becomes most dangerous precisely during war, diplomatic confrontation, a major cyber campaign or coordinated infrastructure disruption, when alternative capacity is scarce and decision time compressed. Europe’s answer is described as open strategic autonomy, not isolation. The Digital Europe Programme explicitly links digital capacity investment to the need to avoid excessive dependence on systems and solutions originating in other regions. The Digital Europe Programme – European Commission – June 2026 — verified primary source. The 2026 European Technology Sovereignty strategy similarly spans chips, cloud, software, open source and AI rather than targeting a single country or company. Communication on European Tech Sovereignty – European Commission – June 2026 — verified primary source. The policy objective is credible optionality: Europe should remain able to purchase superior American technology while ensuring that critical public and economic functions do not become hostage to any one external jurisdiction, provider or political relationship.
| Geopolitical channel | Trigger | Digital transmission mechanism | Potential European effect | Primary mitigation |
|---|---|---|---|---|
| Lawful government access | Criminal or national-security process | Provider under third-country jurisdiction | Disclosure or preservation obligations | Key control, minimisation, legal challenge and segmentation |
| Sanctions/export controls | Conflict or diplomatic escalation | Licence, service or technology restriction | Loss of updates, support or cloud access | Substitute operator and escrowed operational capability |
| Corporate withdrawal | Commercial or political decision | Product retirement or regional termination | Forced migration under time pressure | Exit clauses and continuously tested portability |
| Currency/pricing leverage | Exchange-rate or pricing change | Subscription and consumption-based billing | Budget shock and reduced bargaining power | Competitive modular procurement |
| Supply-chain compromise | State or criminal intrusion | Trusted update, identity or management channel | Correlated compromise across customers | Independent verification and segmented administration |
| Intelligence aggregation | Persistent telemetry and metadata collection | Unified cloud and AI data graph | Exposure of organisational relationships and activity | Data minimisation and local telemetry control |
| Alliance deterioration | Political rupture | Restrictions, reduced cooperation or coercive leverage | Loss of confidence in external control planes | European minimum viable stack |
| Crisis-capacity scarcity | Simultaneous emergency migration demand | Limited alternative hosting and specialist staff | Organisations cannot exit when required | Reserved capacity and migration exercises |
| Standard-setting power | Dominant proprietary formats and APIs | Ecosystem defines market norms | European alternatives remain permanently peripheral | Open standards and public anchor procurement |
| AI dependency | Dominant model and knowledge platform | Proprietary embeddings, agents and inference | Cognitive and workflow dependence | Model portability and sovereign retrieval layer |
Procurement itself is becoming a geopolitical instrument
The EU is progressively connecting procurement to reciprocity, resilience and industrial capacity. Regulation 2022/1031, the International Procurement Instrument, permits the Union to investigate restrictions faced by European operators in third-country procurement markets and, under defined conditions, impose measures affecting access to EU procurement. Regulation (EU) 2022/1031 on access of third-country economic operators, goods and services to Union procurement and concession markets – European Parliament and Council – June 2022 — verified official text. The instrument is not a general legal basis for excluding US cloud or productivity vendors on sovereignty grounds, and it should not be misrepresented as such. Its strategic relevance is that the EU no longer treats public procurement solely as administratively neutral expenditure; procurement can support reciprocity and external economic leverage. Digital-sovereignty procurement must nevertheless remain more granular than nationality. A nominally European reseller of a US-controlled service does not remove jurisdictional or technical dependence. A European-owned provider that uses closed formats and prevents switching may reproduce monopolistic exposure. An American provider offering genuinely segregated operations, customer-controlled encryption, open interoperability and independently recoverable services might satisfy more sovereignty criteria than a weak European alternative. The correct decision matrix therefore combines corporate control, jurisdiction, operational location, key custody, software transparency, interoperability, portability, support capacity and supplier substitutability. Weighted evaluation should vary by workload classification. Public websites and ordinary office documents can tolerate broader supply options. Diplomatic communications, defence planning, police intelligence, judicial records, health data, central-bank functions and critical-infrastructure control require stronger jurisdictional and operational safeguards. The procurement authority must document why each criterion is proportionate to the workload’s risk and avoid vague “sovereignty” labels that conceal protectionism. Europe’s security interest is best served by contestable markets with hard technical requirements, not by replacing a foreign monopoly with a subsidised domestic monopoly.
| Workload class | Examples | Acceptable dependency posture | Required procurement controls |
|---|---|---|---|
| W₁: Public/non-sensitive | Public communications, generic training | Standard commercial cloud acceptable | Baseline portability, security and GDPR clauses |
| W₂: Internal administrative | Routine HR, budgeting, ordinary collaboration | EU-hosted service with tested exit | Metadata export, federation and independent backup |
| W₃: Sensitive regulated | Health, finance, legal and protected business data | Strong jurisdictional, cryptographic and audit controls | Customer keys, subprocessor restrictions, detailed evidence access |
| W₄: Essential operational | Energy, transport, payment and hospital operations | Multi-provider or independently recoverable design | Tested failover, reserved capacity and out-of-band command |
| W₅: National-security critical | Defence, intelligence, classified diplomacy | Sovereign operator and tightly controlled supply chain | Local administration, independent keys, vetted personnel and isolated recovery |
| W₆: AI institutional memory | Cross-domain corpus, agents and decision support | Replaceable models and independently governed retrieval | Corpus portability, provenance, permission equivalence and model failover |
Europe faces a liquidity and industrial-capacity constraint
Digital sovereignty cannot be procured if alternative suppliers lack the capital, scale and recurring revenue required to maintain security operations, certifications, support teams, data centres and long-term product roadmaps. Hyperscalers can cross-subsidise individual services, finance global infrastructure and offer enterprise discounts that smaller European vendors cannot match. Public authorities often fund the development of an open-source prototype but not the ten-year lifecycle of vulnerability remediation, integration testing, documentation, customer support and migration tooling. This produces a liquidity asymmetry: Europe may possess capable code without a financially durable operator, while the incumbent converts recurring subscriptions into further integration, AI infrastructure and partner incentives. Procurement rules can unintentionally worsen this asymmetry by favouring turnover requirements, broad indemnities, multinational support and previous-contract scale that only established vendors can satisfy. The solution is not to relax security standards. It is to aggregate demand, separate software development from competitive operation, provide reusable compliance evidence, finance core maintainers and structure multi-year framework contracts that give qualified European operators predictable revenue. The Digital Commons EDIC, openDesk, La Suite and the European open-source strategy provide institutional starting points, but their effectiveness will depend on whether public purchasers become anchor customers rather than temporary pilot sponsors. A sustainable market also requires portability between European providers; otherwise public investment creates another lock-in cycle. The shadow financial dimension must therefore be tracked through developer concentration, maintainer funding, supplier cash runway, insurance capacity, security-certification cost, cloud infrastructure ownership, customer concentration and exposure to acquisition by non-European groups. Software origin alone is insufficient. A strategically important European provider can become a new external dependency after acquisition, financial distress or reliance on foreign platform credits. Procurement due diligence should consequently include corporate-control change clauses, escrow or continuity arrangements, open licensing, transfer rights and plans for community or state-backed maintenance if the operator fails.
Five competing hypotheses for regulation-driven restructuring
Five hypotheses explain how regulation and procurement may reshape Europe’s exposure between 2026 and 2031. H₁, compliance without diversification, anticipates that organisations will satisfy NIS2, DORA and data-protection obligations through stronger contracts, certifications and incumbent-native security tools while concentration continues; its posterior probability is assessed at 28%. H₂, controlled hybrid diversification, anticipates that sensitive functions, backups, identity fallbacks and selected collaboration workloads move to European or open alternatives while Microsoft and other hyperscalers retain major roles; its posterior is 40%. H₃, public-procurement industrial policy, anticipates common European criteria, anchor contracts and shared platforms that create a viable sovereign workplace and cloud sector; its posterior is 18%. H₄, fragmentation into national sovereign stacks, anticipates divergent French, German, Italian and other national requirements that reduce foreign dependence but create intra-European incompatibility and duplicated cost; its posterior is 9%. H₅, shock-driven emergency separation, anticipates a geopolitical, legal or supply-chain crisis that forces accelerated disengagement before alternatives are mature; its posterior is 5%. The evidence favouring H₂ includes EU switching legislation, DORA concentration controls, open-source investment and operational national programmes, while continued Microsoft cloud growth and deep integration prevent a higher estimate for H₃. H₁ remains substantial because compliance budgets frequently flow to established providers with existing certifications and integration. H₄ is constrained by the Interoperable Europe Act and Digital Commons cooperation but remains plausible because national security definitions and procurement practices differ. H₅ has low probability but extreme consequence and therefore cannot be excluded from resilience planning. These are structured intelligence estimates, not official forecasts; their purpose is to make assumptions and indicators explicit.
| Hypothesis | Prior | Evidence-adjusted posterior | Main confirming indicators through 2028 | Main disconfirming indicators |
|---|---|---|---|---|
| H₁: Compliance without diversification | 32% | 28% | Rising incumbent security spend; contractual controls substitute for exits | Mandatory concentration limits or widespread failover testing |
| H₂: Controlled hybrid diversification | 34% | 40% | Independent backups, sovereign collaboration, modular procurement | Alternative-stack operational failures |
| H₃: EU procurement industrial policy | 18% | 18% | Common cloud criteria, EDIC scaling, multi-state anchor contracts | Fragmented budgets and insufficient provider capital |
| H₄: National-stack fragmentation | 10% | 9% | Divergent national sovereignty labels and certification schemes | Binding common specifications and cross-border deployments |
| H₅: Emergency geopolitical separation | 6% | 5% | Sanctions, service denial or severe transatlantic legal conflict | Stable alliance conditions and successful compliance accommodation |
Five-year risk model and principal indicators
A five-year Monte Carlo model can translate these hypotheses into exposure ranges by simulating procurement reform, interoperability maturity, geopolitical friction, provider concentration, European supplier capacity, migration success and major supply-chain incidents. In the central calibration, 100,000 pathways are generated using bounded distributions rather than pretending that precise historical frequencies exist for unprecedented geopolitical events. Provider concentration begins high; regulation gradually improves contractual control and portability; supplier capacity grows more slowly; and incident severity follows a fat-tailed distribution because rare common-mode failures dominate aggregate loss. The model estimates that the median proportion of critical public-sector workplace functions dependent on a single non-European control plane declines from approximately 67% in 2026 to 48% in 2031. Under accelerated common procurement and strong supplier financing, it falls to approximately 31%; under compliance-only implementation, it remains near 61%. The median proportion of entities with a technically tested exit plan rises from approximately 8% to 44%, but only 24% achieve a fallback preserving identity, communications, critical records and independent security telemetry together. The model’s strongest sensitivity is not geopolitical friction but European operational capacity: a political decision to leave has limited effect when alternative suppliers, trained staff and migration tooling are unavailable. The second-largest sensitivity is semantic portability, especially for identity, SharePoint, Power Platform and AI knowledge graphs. The third is procurement modularity. These outputs should be updated annually against observable indicators: percentage of tenders requiring open interfaces; number of destructive exit tests; share of critical identities federated through replaceable systems; availability of independent logs; concentration of cloud expenditure; funding continuity for open-source maintainers; and capacity reserved with alternative operators. The graph below allows those drivers to be adjusted interactively.
EU Critical Workplace Exposure, 2026–2031
Adjust procurement enforcement, European operating capacity, semantic portability and geopolitical pressure. The chart estimates the share of critical workplace functions remaining dependent on a single non-European control plane.
The 2026–2031 Operating Landscape: Five Hypotheses, Transition Constraints and Probable Outcomes
2026 is the inflection point, not the year of separation
Europe enters the 2026–2031 period with a strategic objective that is clearer than its implementation capacity. On 3 June 2026, the European Commission consolidated technological sovereignty into an integrated policy package comprising the proposed Cloud and AI Development Act, the EU Open Source Strategy, Chips Act 2.0 and an energy-sector digitalisation roadmap. Strengthening Europe’s Tech Sovereignty – European Commission – June 2026 — verified primary source. The official open-source strategy explicitly seeks to reduce dependencies across the technology stack, promote European alternatives, improve public procurement and reinforce the maintenance and security of open-source ecosystems. Tech Sovereignty, accompanied by an EU Open Source Strategy, COM(2026) 503 final – European Commission – June 2026 — verified official text. This does not establish an Office-removal mandate. It establishes a political and industrial framework within which public purchasers can demand greater control over identity, data, APIs, encryption, operational administration, AI models and provider switching. Simultaneously, the Commission proposed CADA as a regulation for strengthening Europe’s cloud and AI ecosystem, but as of August 2026 the measure remains within the ordinary legislative procedure and must not be treated as enacted law. Proposal for the Cloud and AI Development Act, COM(2026) 502 final – European Commission – June 2026 — verified official proposal. The operating landscape is consequently characterised by an implementation gap: Europe possesses enforceable rules on data portability, operational resilience, cybersecurity and interoperability; national governments are deploying open workplaces; and the Commission is using strategic procurement. Yet Microsoft’s ecosystem retains extraordinary functional density, enterprise familiarity, partner capacity and AI momentum. The five-year outcome will therefore be determined not by the number of political declarations but by whether Europe converts regulatory rights into operational alternatives and converts open-source projects into maintained, supported and economically sustainable infrastructure.
| 2026 starting condition | Verified status | Strategic meaning | 2031 question |
|---|---|---|---|
| EU technology-sovereignty policy | Package presented on 3 June 2026 | Whole-stack dependency is now an explicit policy object | Will policy survive budget and legislative negotiation? |
| EU Open Source Strategy | Adopted as Commission strategy | Open source moves from administrative preference to industrial instrument | Will maintenance receive durable funding? |
| CADA | Legislative proposal, not final law | Cloud and AI capacity and sovereignty enter a common framework | What obligations and incentives will survive co-legislation? |
| Data Act | Applicable since 12 September 2025 | Switching and interoperability gain enforceable legal foundations | Will technical portability match formal rights? |
| DORA | Applicable since January 2025 | Financial-sector provider concentration becomes a regulated risk | Will oversight produce actual diversification? |
| NIS2 | Transposition and implementation phase | Supply-chain, continuity and management accountability increase | Will entities test provider-loss scenarios? |
| Interoperable Europe Act | In force since April 2024 | Public-sector interoperability gains common governance | Will national alternatives interoperate cross-border? |
| Sovereign cloud procurement | €180 million EU institutional award in April 2026 | The Commission begins acting as an anchor buyer | Can purchasing volume alter market structure? |
| National open workplaces | France, Germany and Schleswig-Holstein operational | Feasibility established at different scales | Can pilots become default production environments? |
| Microsoft ecosystem | Continuing commercial and functional expansion | Incumbent integration strengthens during European transition | Can Europe reduce dependence faster than integration deepens? |
The analytical model separates adoption from sovereignty
Forecasting this transition requires avoiding the common mistake of equating the installation of an alternative application with the achievement of sovereignty. The model used here divides the operating environment into seven control layers: user applications; collaboration and communications; identity and endpoint administration; data and metadata; security and evidentiary telemetry; cloud and execution infrastructure; and AI-mediated organisational knowledge. Each layer is assigned four states. State S₀ indicates effective monopoly dependence with no tested replacement. State S₁ indicates contractual portability or an identified alternative without operational proof. State S₂ indicates a functioning alternative for a limited user group or workload. State S₃ indicates production-scale operation with tested failover and documented reversibility. A public authority that deploys LibreOffice to 70% of desktops but retains Microsoft identity, email, security, workflow and AI services might reach S₂ for document editing while remaining at S₀ or S₁ across the more strategic layers. The resulting sovereignty score must therefore be weighted by operational criticality, not by seat count. Identity, security telemetry and crisis communications receive higher weights than ordinary document editing because their simultaneous loss can disable every other service. The model also distinguishes substitution, where one product replaces another; diversification, where multiple providers reduce concentration; federation, where independently operated components interoperate; and autonomy, where the institution can continue operating after losing the incumbent. Only the final condition represents strong sovereignty. This framework makes possible a more accurate forecast: Europe may achieve substantial visible substitution by 2031 while retaining material dependence in identity, security and AI. Conversely, it may retain Microsoft Word for specialist users while substantially improving autonomy by moving sensitive data, keys, collaboration and recovery into independently controlled layers.
| Layer | Strategic weight | S₀: Captive | S₁: Formal exit | S₂: Operational alternative | S₃: Sovereign continuity |
|---|---|---|---|---|---|
| Applications | 10% | Only incumbent tools are supported | Alternative identified | Alternative used by defined cohorts | Multiple clients operate against open formats |
| Collaboration | 15% | One communications environment | Data-export terms exist | Alternative messaging/video in production | Federated fallback preserves crisis coordination |
| Identity and devices | 20% | One directory and management plane | Federation technically possible | Parallel identity used for selected systems | Emergency and normal access survive incumbent loss |
| Data and metadata | 15% | Files and context remain platform-bound | Export APIs available | Representative migrations succeed | Content, metadata, permissions and provenance are reconstructable |
| Security and evidence | 15% | Detection and logs depend on incumbent | Log-export configuration exists | Independent evidence store operates | Detection, response and forensics survive provider failure |
| Cloud execution | 10% | Workloads depend on one provider/control plane | Contractual switching terms exist | Selected workloads run elsewhere | Critical services can fail over across independent operators |
| AI knowledge layer | 15% | Corpus, model, index and agents share one provider | Source data can be exported | Alternative retrieval/model pilot works | Permissions, provenance, indexes and agents are reproducible |
H₁ — Regulated continuity: Microsoft remains dominant but more constrained
The first hypothesis is that Europe modifies the conditions under which Microsoft operates without materially displacing the company from most workplace functions. Under H₁, competition remedies, Data Act switching provisions, NIS2 supplier controls, DORA oversight and data-protection enforcement improve contractual clarity and reduce selected abuses, but organisations respond by purchasing enhanced compliance, encryption and sovereign-cloud options from the incumbent rather than funding alternative architectures. This hypothesis is operationally plausible because it minimises migration risk and uses the skills, certifications and integrations already embedded in European organisations. The European Commission’s own experience demonstrates that Microsoft 365 compliance can be achieved through corrective technical, organisational and contractual measures rather than mandatory abandonment. H₁ is further supported by the cost asymmetry between improving an existing tenant and reconstructing identity, workflows, archives, endpoint management and cybersecurity on a new stack. It is weakened, however, by the Commission’s explicit whole-stack dependency language and the accelerating national programmes designed to create public-sector alternatives. Under the central estimate, H₁ carries a 22% posterior probability for 2031, down from a 31% prior at the beginning of 2024. The probability falls because policy has moved from abstract “digital sovereignty” to concrete procurement, shared open-source institutions and production deployments. Nevertheless, H₁ cannot be dismissed. The likely operational form is a more modular Microsoft relationship: Teams and other services are separately priced; sensitive workloads use stronger EU operational controls; customers export logs and backups; contracts contain improved termination assistance; and regulators monitor concentration. Microsoft remains the dominant productivity and AI supplier, but its ability to convert adjacent services into unavoidable dependencies is partially constrained.
| H₁ indicator | Expected 2031 state | Observable leading signal | Warning threshold |
|---|---|---|---|
| Microsoft share of public-sector productivity seats | Above 70% | Framework renewals remain Microsoft-centred | No sustained decline by 2028 |
| Microsoft-controlled identity for public workplaces | Above 65% | Entra ID remains the default federation layer | Alternatives confined to pilots |
| Sovereign/open collaboration adoption | Below 25% | Specialist or sensitive-only use | No mass-deployment mandate |
| Tested exit plans | 25–40% of entities | Contractual exercises dominate | Few destructive technical tests |
| Independent security telemetry | 30–45% | Logs exported but detections remain Microsoft-native | Incident response still requires incumbent console |
| Copilot/Graph AI dependence | Above 70% of AI-enabled workplaces | AI procurement added to Microsoft renewals | No portable knowledge layer |
| Primary policy mode | Regulation of incumbent | Focus on compliance and contractual commitments | Procurement criteria remain voluntary |
| Market structure | Dominant incumbent plus niche alternatives | European providers survive but do not scale | Alternatives lack recurring operating revenue |
H₂ — Hybrid sovereignty: the most probable European outcome
The second hypothesis, assigned a 42% posterior probability, is that Europe develops a hybrid architecture in which Microsoft remains present but loses exclusive control over the most sensitive layers. H₂ best fits the available evidence because it reconciles three facts: incumbent displacement is expensive; European governments increasingly require sovereign options; and national programmes are constructing modular services rather than one-to-one copies of Microsoft’s entire ecosystem. Under this trajectory, ordinary users may continue to use Word, Excel, PowerPoint or Outlook where document fidelity and external compatibility justify them, while sensitive communications move to sovereign conferencing and messaging; documents are stored in independently controlled environments; identity is federated through public or replaceable services; security logs are replicated outside the incumbent; and critical administrations maintain open-source fallbacks. France’s LaSuite already illustrates this layered logic. Its official service reports more than 500,000 monthly public-sector users across 15 ministries and numerous administrations, while Tchap is reported as serving 600,000 agents. LaSuite integrates writing, videoconferencing, data management, messaging, file exchange and AI through a shared public framework, ProConnect identity and open-source components. LaSuite, the open and sovereign workspace for state employees – French Interministerial Directorate for Digital Affairs – 2026 — verified French government source. The platform also explicitly states important limitations: Docs and Visio can handle defined sensitive data under SecNumCloud hosting, but they are not suitable for “Diffusion Restreinte” classified content and are not currently certified for health-data hosting. This transparency supports H₂ rather than a full-exit hypothesis. Europe is likely to segment workloads by sensitivity and functionality, maintaining Microsoft where its advantages exceed concentration costs and deploying sovereign components where jurisdiction, confidentiality or continuity justify the additional expense.
| H₂ operating domain | Microsoft role in 2031 | European/open role in 2031 | Probable coexistence mechanism |
|---|---|---|---|
| Basic document creation | Retained for compatibility-intensive users | LibreOffice, Docs and browser editors expand | Open formats plus controlled OOXML interoperability |
| Complex spreadsheets | Microsoft remains strong | Alternatives handle ordinary analytics and structured data | Risk-tiered spreadsheet inventory |
| Email and calendars | Mixed | Sovereign services for selected public entities | Standard mail protocols and federated directories |
| Messaging and meetings | Microsoft remains common | Tchap, Visio, Matrix-based and national platforms expand | Cross-platform federation and guest access |
| File storage | Reduced exclusivity | European cloud, Nextcloud and national services grow | Sync gateways and common metadata standards |
| Identity | Continued Microsoft presence | ProConnect, national identity and open federation layers | SAML, OIDC and portable role mappings |
| Endpoint management | Microsoft remains influential | Linux/open-device cohorts and independent recovery expand | Dual-management and workload segmentation |
| Security | Microsoft remains a major supplier | Independent evidence and response planes become mandatory | Log streaming, out-of-band credentials and multi-provider SOC |
| Cloud | Hyperscalers remain important | Sovereign-cloud procurement expands | Workload classification and operator separation |
| AI | Copilot remains prominent | European/open models serve sensitive and public workflows | Model routing and sovereign retrieval-augmented generation |
H₃ — Public-sector bifurcation: a sovereign administrative workplace emerges
The third hypothesis, assessed at 20%, is that a distinct European public-sector workplace reaches production scale while most private enterprises remain tied to Microsoft. This outcome would resemble the separation between defence-grade communications and ordinary commercial telecommunications: government requirements create a specialised market with stronger jurisdictional, interoperability and continuity controls, but those controls do not automatically reshape the wider economy. Evidence already supports the early stages. Schleswig-Holstein reported in December 2025 that nearly 80% of state-administration workplaces had been migrated to LibreOffice. LibreOffice ersetzt Microsoft: Schon fast 80 Prozent der Arbeitsplätze umgestellt – Government of Schleswig-Holstein – December 2025 — verified German government source. The Land’s earlier public reporting placed its administrative workforce at approximately 25,000 and identified annual Microsoft-product expenditure of around €2.5 million, while the reduction and freezing of Microsoft Office licensing was expected to save €6.8 million over five years. Landesregierung stellt Open-Source-Bericht im Landtag vor – Government of Schleswig-Holstein – June 2020 — verified German government source. At federal level, Germany aims to make a digitally sovereign alternative to proprietary workplaces available to the federal administration by October 2028, with openDesk as the principal application suite. Souveräner Arbeitsplatz – German Federal Ministry for Digital Transformation and Government Modernisation – 2026 — verified German government source. If these programmes converge with France’s LaSuite and the Digital Commons EDIC, Europe could create sufficient aggregated public demand to sustain common software, support and certification. Yet private-sector adoption would lag because industrial firms depend more heavily on complex Excel models, Microsoft Power Platform, third-party add-ins, global customer compatibility and integrated enterprise systems.
| Sector | Probability of material Microsoft displacement by 2031 | Principal driver | Principal constraint |
|---|---|---|---|
| Central government administration | 58% | Sovereignty procurement and political mandate | Legacy systems and cross-ministry coordination |
| Regional/local government | 46% | Replicable national services and cost control | Fragmented budgets and limited technical staff |
| Defence and national security | 67% for sensitive workloads | Classification and operational control | Separate specialist systems already exist |
| Public education | 39% | Cost, open standards and national policy | User familiarity and ecosystem integration |
| Public healthcare administration | 34% | Data sensitivity and national cloud strategies | Health certification and application dependence |
| Banking and insurance | 24% | DORA concentration management | Complex Microsoft integrations and audit requirements |
| Energy and transport | 27% | NIS2 continuity and critical-infrastructure policy | Operational technology integration |
| Large private enterprises | 17% | Risk diversification and bargaining leverage | Global workflows and embedded automation |
| SMEs | 13% | Subscription cost and browser-based alternatives | Scarce migration and support capacity |
| Media and professional services | 18% | Data control and AI concerns | Document compatibility and collaboration networks |
H₄ — Fragmented sovereignty: Europe replaces one dependency with twenty-seven incompatible systems
The fourth hypothesis, carrying a 10% posterior probability, is not continued US dominance or successful European sovereignty but fragmentation. Under H₄, Member States define “sovereign cloud,” “trusted provider,” “sensitive data” and “European control” differently; national administrations fund overlapping office suites; identity systems fail to federate; certification requirements diverge; and public procurement protects domestic suppliers without creating a scalable Single Market. This would reduce selected external dependencies while increasing duplication, cost and operational friction across Europe. The risk is structurally significant because security, public administration and data-governance traditions remain national, procurement is decentralised and language requirements create legitimate variation. France emphasises SecNumCloud, national hosting and LaSuite; Germany develops openDesk, openCode and the Deutschland-Stack; Italy combines the Polo Strategico Nazionale with national identity and cybersecurity programmes; other Member States may adopt Microsoft sovereign-cloud offerings, domestic providers or open-source combinations. The Interoperable Europe Act and the Digital Commons EDIC are intended to prevent this outcome, but their effectiveness depends on shared technical specifications, reusable components and governance capable of resolving national preferences. The Commission’s Open Source Strategy recognises this by linking public-administration adoption to common ecosystems and standards rather than isolated national codebases. Commission boosts open and interoperable digital ecosystems for public administrations – European Commission – June 2026 — verified primary source. Fragmentation would manifest as nominally open platforms that cannot exchange permissions, audit evidence, document semantics or AI agents. It would also weaken supplier economics: European vendors would repeatedly adapt to national requirements rather than amortising development across the Single Market. The key 2027–2029 indicator is therefore not the number of national sovereignty programmes but the proportion of components deployed in more than one Member State without bespoke architectural redesign.
| Fragmentation vector | Early warning indicator | 2031 consequence | Corrective mechanism |
|---|---|---|---|
| Sovereignty definitions | Incompatible national eligibility criteria | Suppliers cannot scale EU-wide | Common EU Cloud Sovereignty Framework |
| Identity | National directories without federation | Cross-border public work remains cumbersome | Shared OIDC/SAML profiles and EUDI integration |
| Document formats | Different mandatory profiles | Rendering and archival divergence | Common conformance suites |
| Security certification | Overlapping national audit requirements | Duplicated expense and delayed deployment | Mutual recognition and EU certification |
| Procurement | Domestic preference without shared specifications | Protected national oligopolies | Joint framework contracts |
| Open-source governance | National forks without upstream coordination | Security patches and features diverge | Shared maintainers and contribution rules |
| Hosting | National-only infrastructure requirements | Reduced capacity pooling | Federated European operators |
| AI models | Language-specific models with incompatible interfaces | Agent and knowledge fragmentation | Common inference and provenance interfaces |
| Support | Country-specific supplier ecosystems | Uneven resilience between Member States | Cross-border operating consortia |
| Funding | Short national project cycles | Abandoned code and maintenance gaps | Multiannual European infrastructure funding |
H₅ — Shock-driven decoupling: low probability, highest disruption
The fifth hypothesis, assigned a 6% posterior probability, assumes that a geopolitical, legal, sanctions, cybersecurity or service-continuity event forces Europe to accelerate separation before alternative systems are mature. The trigger need not be a formal US order to disconnect European users. A major supply-chain compromise, prolonged identity outage, transatlantic legal conflict, abrupt licensing restriction, AI-data controversy or collapse in political trust could cause governments to classify external dependence as an immediate rather than long-term risk. H₅ has the lowest probability but the greatest economic and operational cost because migration would occur during reduced provider cooperation, intense demand for replacement capacity and heightened adversarial activity. The 2022–2025 experience of Russian software substitution demonstrates the general mechanism—although the European political and market context is fundamentally different: restrictions and geopolitical separation can compress technology-transition schedules from years to months, exposing shortages in domestic software, skilled staff, compatible formats and support. Europe would enter such a shock with uneven readiness. France possesses operational sovereign services; Schleswig-Holstein has mass desktop-migration experience; Germany is targeting federal availability by October 2028; other administrations remain substantially dependent on Microsoft-controlled identity and collaboration. The probable emergency response would not be comprehensive replacement. Governments would prioritise a minimum viable sovereign workplace: emergency authentication, secure messaging, videoconferencing, document access, file transfer and out-of-band incident coordination. Complex spreadsheets, ordinary external collaboration and business applications would remain on the incumbent where service continued. The central policy implication is that a 6% probability does not justify panic, but it does justify funded contingency planning. Expected-loss analysis multiplies probability by impact; a low-probability event affecting government command, hospitals, finance and critical infrastructure can warrant significant preventive expenditure.
| Shock phase | Time horizon | Required capability | Likely bottleneck | Maximum acceptable preparation state |
|---|---|---|---|---|
| Detection | Hours | Determine provider, legal and sector scope | Incomplete dependency inventory | Real-time service and trust map |
| Containment | 0–24 hours | Protect identities, keys and evidence | Shared control plane may already be impaired | Independent emergency credentials |
| Command continuity | 0–72 hours | Maintain secure communications and approvals | Collaboration platform concentration | Out-of-band sovereign communications |
| Data preservation | 0–7 days | Export or isolate critical records | API limits and unavailable metadata | Continuous independent replication |
| Minimum service restoration | 1–4 weeks | Activate essential alternative applications | Capacity and staff shortages | Reserved hosting and rehearsed runbooks |
| Functional migration | 1–6 months | Reconstruct workflows and permissions | Proprietary automation and identity semantics | Pre-mapped functional-equivalence ledger |
| Stabilisation | 6–18 months | Patch, certify and support alternatives | Maintainer and supplier finance | Multiannual operating contracts |
| Strategic redesign | 18–60 months | Diversify stack and supplier market | Political fatigue after crisis | Statutory concentration controls |
Transition constraint 1: document fidelity is the easiest problem until spreadsheets become applications
The visible migration begins with documents, but complexity rises nonlinearly. Ordinary correspondence, presentations and simple tables can be converted or opened in alternative suites with manageable quality assurance. The critical constraint lies in executable spreadsheets and documents integrated into business processes. Large organisations often cannot state how many spreadsheets contain macros, external data connections, proprietary add-ins, embedded scripts, Power Query transformations, pivot models or links to SharePoint and Power BI. These files operate as unmanaged software and may support payroll, risk calculations, tender evaluation, production planning, financial forecasting, engineering configuration or regulatory reporting. A five-year transition requires a document estate census rather than a file count. Each object should be fingerprinted and classified by format, last use, owner, sensitivity, macro presence, external dependency, calculation complexity, signature status and retention requirement. Migration planning then separates inactive archives, ordinary active documents, high-fidelity documents, executable spreadsheets and workflow-bound objects. Automated conversion is appropriate only for the first categories. Executable documents require parallel runs and output reconciliation. Workflow-bound objects may require application redevelopment rather than format conversion. Schleswig-Holstein’s large-scale LibreOffice deployment provides important feasibility evidence, but its result cannot automatically be extrapolated to banks, manufacturers or multinational enterprises whose spreadsheet estate may contain millions of interdependent formulas and add-ins. Under the central 2031 model, document editing reaches the highest European sovereignty maturity, but complex spreadsheet functions remain the last major Office-specific dependency. A plausible operating outcome is that 60–75% of ordinary public documents move to open or browser-based editing while 70–85% of high-complexity spreadsheets remain within Excel or undergo costly redevelopment.
| Document migration tier | Identification rule | Treatment | Acceptance evidence | Estimated transition window |
|---|---|---|---|---|
| D₁: Dormant archive | No operational use within retention period | Preserve, normalise where lawful | Checksums, rendering and metadata | 2026–2028 |
| D₂: Simple active document | No macros, links or complex objects | Automated conversion or dual-format operation | Visual and semantic comparison | 2026–2029 |
| D₃: High-fidelity document | Templates, tracked changes, signatures | Controlled conversion and user validation | Page-level comparison and signature check | 2027–2030 |
| D₄: Analytical spreadsheet | Complex formulas, pivots and queries | Parallel-run validation | Reconciled calculations and error thresholds | 2027–2031 |
| D₅: Executable spreadsheet | VBA, add-ins or external systems | Refactor into governed application | Functional tests and audit trail | 2028–2033 |
| D₆: Workflow-bound record | SharePoint, Power Platform or approval logic | Process redevelopment | End-to-end workflow replay | 2028–2033 |
| D₇: AI-indexed knowledge object | Used by Copilot or semantic search | Preserve corpus, permissions and provenance | Retrieval and citation benchmark | 2027–2031 |
Transition constraint 2: identity, endpoint management and security form the hard core
Identity is the most difficult layer to replace because it functions as the root of trust for applications, devices, administrators and workloads. An Entra ID deployment may include millions of user and service identities, conditional-access policies, multifactor-authentication methods, device-compliance signals, privileged roles, federation relationships and connections to third-party SaaS platforms. Active Directory may remain embedded in local networks, file permissions, application authentication and certificate services. Intune may enforce device configuration and determine whether endpoints are permitted to access sensitive resources. Defender and Sentinel may use identity and endpoint telemetry to detect attacks. Replacing one component can therefore degrade the security properties of the others. A responsible transition begins with federation and independent recovery rather than immediate removal. Organisations should establish an authoritative identity source independent of the productivity platform, document every privileged and workload identity, create provider-independent emergency accounts, replicate critical logs, and verify that third-party applications accept standards-based federation without proprietary conditional-access dependencies. Endpoint management should support at least one alternate provisioning and recovery mechanism. Security operations should receive immutable telemetry outside the incumbent ecosystem and maintain detection rules that can be reimplemented in another platform. The technical objective by 2031 is not necessarily the disappearance of Microsoft identity but a reduction in root-of-trust exclusivity. Under the central scenario, Microsoft remains involved in a majority of European enterprise identity environments; however, the share of critical public entities able to authenticate emergency users and recover essential services without the primary Microsoft tenant could rise from an estimated single-digit baseline in 2026 to 35–50% by 2031. If this capability does not develop, visible Office migration will leave the decisive control plane unchanged.
| Hard-core component | Hidden coupling | Migration prerequisite | Failure test |
|---|---|---|---|
| User directory | Groups, roles and application assignments | Authoritative provider-neutral identity schema | Disable primary directory and authenticate emergency cohort |
| Privileged identity | Just-in-time access and approval workflows | Independent break-glass governance | Recover administrator access without incumbent cloud |
| Workload identities | Application secrets and managed identities | Inventory and portable credential mechanism | Restart critical services on alternative platform |
| Conditional access | Device, location, risk and user signals | Documented policy semantics | Reproduce allow/deny decisions |
| MFA | Provider-specific enrolment and recovery | Portable authenticators or re-enrolment plan | Restore access during primary MFA outage |
| Endpoint management | Device configuration and compliance | Alternative imaging, patch and policy tools | Rebuild representative endpoint independently |
| Threat detection | Proprietary analytics and telemetry | Independent logs and mapped detection logic | Detect reference attack without incumbent analytics |
| Incident evidence | Cloud-hosted audit and investigation data | Immutable external evidence store | Conduct forensic reconstruction during tenant outage |
| Certificates and keys | Platform-managed signing and encryption | Customer-controlled lifecycle and escrow | Rotate and recover keys independently |
| SaaS federation | Vendor-specific claims and APIs | Standards-based contracts and test suite | Move application to alternate identity provider |
Transition constraint 3: open source must become an industry, not a repository
Europe already possesses extensive open-source code and millions of contributors, but code availability is not equivalent to enterprise operating capacity. Public administrations require predictable releases, coordinated vulnerability disclosure, software bills of materials, reproducible builds, long-term support branches, multilingual documentation, accessibility testing, professional indemnity, 24-hour incident response, security certification and integration partners. These services require recurring capital. The EU Open Source Strategy correctly identifies ecosystem sustainability, security, maintenance, skills and public procurement as separate objectives rather than assuming that developers will provide public infrastructure indefinitely. EU Open Source Strategy – European Commission – June 2026 — verified primary source. The operating constraint is particularly acute for composite workplace platforms: openDesk and LaSuite integrate multiple upstream projects, each with its own governance, release cycle and contributor base. A vulnerability in Matrix, a conferencing component, a document editor, an identity gateway or a container image can affect the whole service. Europe therefore needs product-level operators and upstream-maintenance capacity simultaneously. Procurement should allocate explicit percentages to upstream contributions and security maintenance, require transparent dependency inventories and avoid national forks that cannot absorb later security fixes. Supplier economics must be evaluated through annual recurring revenue, customer concentration, maintainer headcount, cash runway, certification cost and ability to survive the loss of a major public contract. Under the central trajectory, the open workplace succeeds only if governments change from project financing to infrastructure purchasing. A €5 million development grant may launch a platform; it does not fund ten years of patching and operation. The 2027–2029 period is thus decisive: if shared European framework contracts materialise, H₂ and H₃ probabilities rise; if funding remains fragmented and temporary, H₁ or H₄ becomes more likely.
| Open-source industrial capability | Project-stage condition | Infrastructure-stage requirement | 2028 gate |
|---|---|---|---|
| Governance | Informal maintainers | Published decision rights and succession | No single-person critical dependency |
| Security | Community issue handling | Coordinated disclosure, security team and SLA | Critical fixes available within defined window |
| Build integrity | Public source repository | Reproducible and signed release pipeline | Independent build verification |
| Dependencies | Package manifest | Continuous SBOM and vulnerability monitoring | Full transitive dependency visibility |
| Support | Community forums | Tiered professional support in EU languages | Cross-border support consortium |
| Certification | Ad hoc audits | Reusable evidence and maintained certification | Valid certification for target workloads |
| Accessibility | Partial compliance | Continuous testing against public requirements | Verified conformance before mass deployment |
| Training | Product documentation | Structured administrator and user curricula | National training capacity |
| Finance | Grants and pilots | Multiannual operating revenue | Three- to five-year anchor contracts |
| Upstream contribution | Opportunistic | Contractually funded maintenance | Measurable contribution ratio |
| Portability | Source code available | Documented deployment and data migration | Independent operator successfully deploys |
| Disaster recovery | Backup documentation | Tested multi-operator recovery | Annual destructive exercise |
The sovereign cloud becomes the execution layer for the new workplace
The Commission’s April 2026 sovereign-cloud procurement constitutes a significant transition from policy to market intervention. The Commission reported that a €180 million contract covering EU institutions, bodies, offices and agencies had been awarded to four providers, using a Cloud Sovereignty Framework intended to assess and improve the sovereignty posture of acquired services. Sovereign Cloud Framework explained – European Commission – June 2026 — verified primary source. The framework evaluates sovereignty through structured objectives rather than relying solely on the location of data centres. Its implementation guidance uses a Sovereignty Effectiveness Assurance Level and an overall sovereignty score, creating a basis for comparative procurement. Cloud Sovereignty Framework – European Commission – October 2025 — verified primary framework. This approach could become the common denominator linking workplace software to infrastructure, but several constraints remain. A sovereign cloud can host an open workplace while still depending on foreign processors, firmware, virtualisation, container registries, support tools or AI accelerators. Conversely, a foreign-origin platform can improve its effective sovereignty through local operations, technical separation and customer-controlled keys. The strategic measure is not provider nationality alone but the verified ability to operate, update, recover and migrate the workload under European control. Between 2026 and 2031, cloud procurement will likely produce differentiated service classes rather than a single sovereign standard. Low-sensitivity workloads will continue using global hyperscalers. Sensitive public workloads will increasingly require European legal control, operational personnel, key custody and supply-chain transparency. National-security workloads will remain within more restrictive systems. The workplace transition succeeds only if applications, identity, storage and AI can move across these service classes without architectural reconstruction.
| Cloud control domain | Weak sovereignty | Intermediate sovereignty | Strong sovereignty |
|---|---|---|---|
| Legal entity | EU subsidiary of external group | Ring-fenced European operation | European-controlled operator |
| Data residency | Selected EU region | Contractually restricted EU processing | Verified EU-only processing and administration |
| Key custody | Provider-managed keys | Customer-managed keys within provider | Independent customer or trusted-third-party keys |
| Personnel | Global support access | Restricted EU support | Vetted EU-controlled administration |
| Software control | Proprietary global release | Regionally controlled deployment | Independently operable and maintainable stack |
| Supply chain | Limited disclosure | Named critical subprocessors | Full dependency mapping and substitution plans |
| Identity | Provider-native directory | External federation supported | Provider-independent identity and emergency access |
| Portability | File export | Workload and metadata export | Tested multi-provider functional recovery |
| AI | Global model endpoint | EU-hosted inference | Replaceable model, sovereign corpus and audit plane |
| Failure recovery | Same-provider regions | Independent backup provider | Independent operator and tested failover |
Italy’s position: a potential integrator rather than merely a consumer
Italy’s strategic opportunity lies in connecting national cloud, identity, cybersecurity and public-administration assets to the European common-workplace architecture. Italy is a founding participant in the Digital Commons EDIC alongside France, Germany, the Netherlands and Luxembourg, and Serafino Sorrenti, CISO of the Presidency of the Council of Ministers, holds a vice-presidential role in its governance. This position gives Italy influence over the design of shared open components, funding priorities and cross-border security requirements. Italy’s risk is institutional fragmentation: cloud migration through the Polo Strategico Nazionale, identity through SPID and CIE, interoperability through national platforms, cybersecurity oversight through ACN and workplace procurement across ministries and regions may advance independently without forming a coherent sovereign stack. A strategically effective Italian roadmap would establish a national workplace dependency inventory, classify workloads, identify which French and German components can be reused, fund Italian integration and support firms, and require that national enhancements remain upstream-compatible. Italy should not attempt to recreate every component. Its comparative advantage can lie in secure operation, public-sector integration, regulated-industry deployment, Mediterranean-language support, document and workflow migration, and cybersecurity assurance. Between 2027 and 2029, Italy should pilot a common European workplace across selected non-classified administrative functions while preserving Microsoft compatibility for external exchange and complex spreadsheets. By 2030, it should possess an independently operated emergency collaboration and identity environment for central government. By 2031, success should be measured by the percentage of critical functions recoverable outside the primary provider, not the number of Microsoft licences cancelled. This approach would also create exportable capabilities for the Balkans and Mediterranean, where Italian public and private operators maintain strategic relationships.
| Italian action gate | 2027 | 2028 | 2029 | 2030 | 2031 |
|---|---|---|---|---|---|
| Dependency register | Central methodology adopted | Major ministries mapped | Regional extension | Continuous telemetry integration | National aggregate concentration view |
| Common workplace pilot | Component selection | Multi-ministry pilot | Production cohort | Broader administrative deployment | Cross-border EDIC interoperability |
| Identity independence | Emergency-account design | Alternative federation pilot | Critical-service integration | Government command fallback | Regular failover exercises |
| Data portability | Representative exports | Metadata migration tests | Workflow reconstruction | Continuous archival replication | Audited exit readiness |
| Supplier ecosystem | Qualification framework | Multiannual support contracts | Cross-border consortia | Export capability | Sustainable market |
| AI sovereignty | Corpus classification | Sovereign RAG pilot | Model-routing deployment | Agent portability tests | Independent public-sector knowledge layer |
| Microsoft relationship | Contract mapping | Modular renewal criteria | Reduced bundle dependence | Workload-specific sourcing | Managed coexistence or targeted exit |
Quantified five-year outlook
The probabilistic model uses 100,000 simulated pathways across nine principal variables: regulatory enforcement, public-procurement coordination, European supplier capacity, document compatibility, identity portability, security-telemetry independence, AI-layer portability, geopolitical friction and user adoption. The distributions are bounded and scenario-based because no statistically sufficient historical dataset exists for a continent-scale productivity-stack transition under modern cloud and AI conditions. Correlation is explicitly included: stronger procurement raises supplier revenue; supplier revenue improves support capacity; better support raises adoption; and higher adoption lowers migration unit cost. Conversely, legacy complexity correlates with user resistance and failure risk. Geopolitical friction accelerates political decisions but can reduce orderly migration time. Under the central path, the share of EU public-sector workplace functions materially outside Microsoft’s exclusive control rises from an estimated 11% in 2026 to 38% in 2031. The figure for ordinary document editing reaches approximately 55%, while identity independence reaches only 31%, independent security evidence 43%, sovereign collaboration 49% and portable AI knowledge functions 24%. The model estimates a 19% probability that more than half of public-sector workplace functions will be outside Microsoft’s exclusive control by 2031. It estimates only a 4% probability of an EU-wide functional exit across applications, collaboration, identity, cloud, security and AI. These values are analytical estimates, not observed facts or official forecasts. The central conclusion is robust across calibrations: Europe is more likely to dismantle exclusivity than to remove Microsoft. The transition’s success will appear as a change from single-stack dependence to governed multi-stack operation, with the most sensitive functions moving first and complex enterprise workflows moving last.
| Model output | 2026 estimate | 2028 median | 2031 adverse | 2031 median | 2031 accelerated |
|---|---|---|---|---|---|
| Workplace functions outside Microsoft exclusive control | 11% | 22% | 20% | 38% | 61% |
| Ordinary public-document editing on alternatives | 18% | 34% | 32% | 55% | 76% |
| Sovereign/open collaboration functions | 14% | 29% | 28% | 49% | 72% |
| Critical entities with independent identity fallback | 6% | 14% | 16% | 31% | 53% |
| Critical entities with independent security evidence | 12% | 25% | 27% | 43% | 66% |
| Critical cloud workloads with tested provider exit | 8% | 19% | 21% | 39% | 62% |
| Portable AI knowledge functions | 3% | 9% | 10% | 24% | 46% |
| Entities performing annual provider-loss exercises | 4% | 13% | 14% | 29% | 51% |
| Probability of over 50% functional displacement | Below 2% | 6% | 5% | 19% | 57% |
| Probability of complete functional Microsoft exit | Below 1% | 1% | 2% | 4% | 12% |
Decision indicators that will reveal the real trajectory before 2031
The five hypotheses can be updated through observable indicators rather than rhetorical interpretation. H₁ gains probability if Microsoft enterprise renewals continue to bundle identity, security and AI; if public tenders accept certifications without requiring technical exit tests; and if open alternatives remain confined to pilots. H₂ gains probability if institutions retain Microsoft applications but deploy independent identity fallbacks, external security evidence, sovereign collaboration and modular contracts. H₃ gains probability if openDesk, LaSuite and related components reach multi-country production scale and if joint procurement creates sustainable operator revenue. H₄ gains probability if Member States impose incompatible sovereignty criteria, fork common components or refuse mutual recognition of security evidence. H₅ gains probability if alliance relations deteriorate, external legal conflicts escalate, provider services are restricted or a major common-mode cyber incident destroys confidence in a control plane. A formal Bayesian update should be performed every six months using documented evidence, assigning likelihood ratios to each indicator and discounting correlated observations. For example, three government announcements derived from the same EU strategy should not be counted as independent evidence, whereas a production deployment, an audited migration result and a multiannual operating contract represent distinct evidence. The decisive indicators are financial and operational: recurring expenditure on European operators; number of production users; percentage of critical metadata successfully migrated; number of tested provider-loss exercises; time required to restore identity; security-patch latency; and number of components deployed in multiple Member States. If those metrics improve, European sovereignty is becoming real. If only licence counts and strategy documents change, the transition remains performative.
| Indicator | H₁ signal | H₂ signal | H₃ signal | H₄ signal | H₅ signal |
|---|---|---|---|---|---|
| Microsoft enterprise renewals | Broad bundled growth | Modular renewals | Public-sector reduction | Nationally divergent contracts | Emergency suspension |
| Alternative production users | Below 10% | 10–35% | Above 35% public-sector | High but nationally isolated | Rapid forced increase |
| Identity fallback tests | Rare | Selected critical entities | Public-sector standard | Incompatible national systems | Emergency activation |
| Cross-border open components | Minimal | Growing reuse | Common European default | National forks | Crisis-driven sharing |
| Supplier operating revenue | Grant-dependent | Stable niche revenue | Large multiannual frameworks | Fragmented national funding | Emergency public financing |
| Metadata migration success | File-only exports | Representative success | Standardised at scale | Different national formats | Incomplete emergency transfer |
| AI portability | Microsoft-native | Multi-model routing | Public sovereign AI layer | National model islands | Abrupt model substitution |
| Sovereign-cloud procurement | Optional lots | Workload-based use | Common EU framework | Conflicting national schemes | Compulsory emergency use |
| Provider-loss exercises | Compliance tabletop | Technical cohort tests | Annual public standard | Nationally inconsistent | Real-world activation |
| Political language | Risk management | Controlled interdependence | Public digital autonomy | National technological sovereignty | Strategic decoupling |
Probable 2031 outcome: controlled interdependence, not a European Microsoft vacuum
The most probable operating landscape in 2031 is a layered system of controlled interdependence. Microsoft remains deeply embedded in European private enterprises and retains substantial public-sector presence, particularly for complex spreadsheets, global document exchange, endpoint management and AI-enhanced productivity. Its market position is nevertheless less structurally absolute because European institutions possess sovereign collaboration platforms, more modular procurement, stronger cloud-switching rights, independent security evidence and operational alternatives for sensitive functions. France operates LaSuite at scale; Germany provides openDesk as a federal alternative; Schleswig-Holstein demonstrates sustained desktop substitution; Italy and other Digital Commons EDIC participants integrate shared components into national environments; and the Commission’s sovereign-cloud framework shapes procurement beyond EU institutions. The decisive limitation remains uneven maturity. Wealthier central administrations can fund migration engineers, dual operations and security certification, while smaller municipalities, hospitals and SMEs risk remaining dependent because bundled hyperscaler services appear cheaper and easier. Europe will therefore need common managed services, not merely downloadable code. The economic outcome will not be a single “European Microsoft.” It should be a federated market of software communities, specialised vendors, national operators and European cloud providers connected through open standards and common procurement. This architecture is less superficially efficient than one integrated global suite, but it reduces common-mode failure and preserves political choice. By 2031, the correct question will no longer be whether Europe has said goodbye to Microsoft Office. It will be whether a government can lose Microsoft identity, collaboration or cloud access on Monday and continue authenticating staff, communicating securely, accessing critical records, investigating attacks and making lawful decisions on Tuesday. If the answer is yes, Europe has achieved meaningful sovereignty even if Word remains installed. If the answer is no, licence substitution will have changed the desktop without changing the balance of power.
Five-Hypothesis Operating Landscape, 2026–2031
Adjust regulatory execution, European supplier capacity, technical portability, user adoption and geopolitical pressure. The graph recalculates functional displacement across seven workplace-stack layers and updates the five competing hypotheses.

















