On 4 August 2026, Executive Vice-President Henna Virkkunen, answering a parliamentary question from The Left MEPs Jonas Sjöstedt and Hanna Gedin, acknowledged that dependencies on digital solutions from non-EU-controlled companies can threaten security, data sovereignty, and EU-law compliance, and create vendor lock-in. She stressed that addressing these concerns is central to the Tech Sovereignty Package, which includes the proposed Cloud and AI Development Act and the EU Open Source Strategy. Virkkunen declined to comment on individual companies or national procurement decisions, but reaffirmed the Commission's commitment to ensuring digital solutions respect fundamental rights, including non-discrimination, and pointed to the AI Act's rules for high-risk AI systems in law enforcement.
The question, prompted by concerns over Palantir's role in Swedish policing and its alleged complicity in violations of international law in Gaza, highlighted risks of sensitive EU data leaking to US authorities and the lack of transparency in proprietary algorithms. Virkkunen's answer, while not naming Palantir, outlined a broader EU strategy to reduce such dependencies. The Tech Sovereignty Package, announced on 3 June 2026, aims to strengthen Europe's technological independence. The proposed Cloud and AI Development Act would establish a framework for assessing sovereignty credentials of cloud and AI services, helping public administrations choose providers that meet EU standards for critical services. The Open Source Strategy promotes secure, transparent alternatives for public administrations.
Virkkunen also referenced the Commission's support for sovereign defence solutions through the European Defence Fund, the European Defence Industry Programme, and the Security Action for Europe (SAFE), indicating a cross-sectoral approach to reducing reliance on non-EU technology. The answer, however, contained no new concrete proposals or numerical targets, instead reiterating existing commitments and frameworks. It did not address the specific concerns about Palantir's investments by Swedish pension funds or the company's manifesto, which UK MPs have cited as evidence of unsuitability to handle citizens' data.
The response signals that the Commission views the issue primarily through the lens of its ongoing tech sovereignty agenda, rather than through case-by-case scrutiny of individual vendors. The practical impact will depend on the implementation of the Cloud and AI Development Act and the enforcement of the AI Act, which the European AI Office is tasked with overseeing alongside national authorities. For EU public administrations, the proposed framework could lead to more rigorous vetting of digital tools, potentially limiting the use of non-EU software in critical services. For non-EU tech companies, the measures could create new compliance burdens and market access barriers, while EU-based providers may benefit from increased demand for sovereign alternatives. The answer leaves open how quickly these frameworks will materialise and whether they will effectively address the data sovereignty risks highlighted by the MEPs.