
In 2013, Edward Snowden revealed just how deeply US intelligence agencies could reach into the world's digital infrastructure. The response in Europe was predictable: outrage, committee hearings, strongly worded statements and promises to build alternatives.
Then everyone carried on buying US software.
More than a decade later, Europe faces a much bigger question than data privacy. It is confronting the possibility that it has outsourced not just its infrastructure, but its cognition and intelligence.
The rise of generative AI has concentrated enormous power in a handful of US companies. OpenAI, Anthropic, Microsoft, Google and Amazon increasingly provide the models, cloud infrastructure and training environments on which businesses and public institutions depend. In many cases, they also influence the frameworks governing how these AI systems operate.
For European businesses, governments and critical infrastructure operators, that creates an uncomfortable dependency.
The issue is not whether US technology is good. Clearly, much of it is exceptional. The question is whether Europe should place its future decision-making capabilities inside systems it does not control.
Across Europe, concerns about digital sovereignty have accelerated investment in homegrown AI infrastructure, sovereign clouds and locally controlled intelligence platforms. France's ChapsVision has become one of the most prominent examples, positioning itself as a European alternative to companies such as Palantir.
The company has secured major government contracts and built a business approaching €200 million in annual revenue around trusted data intelligence, AI and sovereign decision-making systems.
Its Argonos platform is designed to turn fragmented information into actionable intelligence while maintaining European control over data and operations.
But a new generation of companies is pushing the sovereignty argument further.
One of them is Veldris. The company's Midgard platform is built around open-source architecture, local inference, post-quantum encryption and self-hosted deployment. Unlike many AI providers that still depend on external cloud services, Veldris is designed to operate within a customer's own environment, including air-gapped systems.
Founded by cybersecurity entrepreneur JB Benjamin, Veldris takes a position that is almost unfashionably blunt in today's AI market: if you cannot inspect it, control it or run it yourself, then it is not truly sovereign. As Benjamin puts it:
“Our personal, corporate, individual and institutional data sovereignty and privacy are non-negotiable assets of our humanity. The data exposed by virtue of our very existence belongs to no one, other than ourselves.
“True sovereign AI can only be achieved if you personally own the entire stack, the model, the weights and tuning, the hardware and the power to run the compute. We are working with more than 56 countries to achieve this; with their own datacenters and commonwealth models.
“We work differently from most of our competitors. We believe in intelligence for diplomacy and sovereignty. Parity for all. We are not leaving anyone behind.”
European organisations are increasingly discovering that moving from one vendor to another does not necessarily create sovereignty. A French AI running on a US hyperscale Cloud is still exposed to external jurisdictions, supply chains and commercial priorities. A European model that relies on foreign infrastructure remains vulnerable to decisions made elsewhere.
Veldris argues that sovereignty starts with visibility. Algorithms should be inspectable, models should be traceable and security mechanisms should be verifiable. Its philosophy, described as "the anti-black-box", challenges a growing tendency in AI to ask organisations to trust systems they cannot fully understand.
This is where the comparison with ChapsVision becomes interesting. ChapsVision represents the industrial-scale vision of European sovereignty. It has built a broad ecosystem covering intelligence, compliance, defence, translation, investigation and enterprise AI.
The company has partnered with European cloud provider Scaleway to create what it describes as a fully European technology stack, designed to avoid exposure to extraterritorial legislation such as the US Cloud Act.
Its Chaps Agents platform provides governance, orchestration and enterprise deployment of AI agents while allowing organisations to work across different models and infrastructure. Argonos, meanwhile, has become an important part of the company's work in sensitive intelligence and security environments.
Veldris approaches the same problem from the other end.
Where ChapsVision is building a European technology champion capable of competing with global incumbents, Veldris is attempting to reduce dependency through open-source software, reproducible builds and infrastructure controlled by the customer.
ChapsVision is pursuing strategic autonomy through scale. Veldris is pursuing it through transparency. Europe probably needs both.
The important point is that sovereignty is not a single product category. It is a stack. At the top sits AI. Beneath that is software. Beneath software comes infrastructure, and beneath infrastructure sits cryptography. Every layer introduces another potential dependency.
If one of those layers remains outside European control, questions remain about how sovereign the final system really is.
That becomes particularly important as AI moves beyond productivity tools and into decision-making.
Banks are using AI to assess risk. Healthcare providers are using it to analyse medical information. Governments are deploying AI to support investigations and public services. Energy companies are using it to optimise critical infrastructure.
In all these environments, trust becomes a strategic asset and trust cannot be outsourced.
The geopolitical environment makes the issue more urgent. Trade disputes, regulatory divergence and shifting alliances have highlighted the risks of relying on technology ecosystems controlled by foreign governments or corporations.
The concern is not necessarily hostility; it is uncertainty. A company can plan around a price increase. It can plan around a new competitor. It is much harder to plan around a change in access, regulation or foreign policy that could affect the technology on which its operations depend.
European organisations are therefore beginning to ask a more fundamental question. It is no longer simply whether they should use AI. They need to know whose AI they are using, where it runs, who controls it and what happens if access changes tomorrow.
The answer is unlikely to come from one company. It will come from an ecosystem of European builders creating alternatives at every layer of the stack. Companies such as ChapsVision are demonstrating that Europe can build at scale while others such as Veldris are making the case that transparency, security and control need to be designed into the foundations rather than bolted on afterwards.
For decades, Europe outsourced much of its digital infrastructure. It now faces a choice about whether it wants to outsource its intelligence as well.
The next phase of the AI race may not be about who builds the smartest models.It may be about who controls them. Or as Veldris’s JB Benjamin concludes:
“At Veldris we will never compromise on our responsibility to our users, in providing individual sovereignty, security and privacy. Midgard unlocks the power and intelligence of your data, for you, by you.”

