Europe controls a meager 5% of global AI computing capacity. The United States controls about 75%. That is less of a gap, and more of a very expensive canyon, and Europe has just noticed it needs to take a leap it’s not currently equipped for.
An independent coalition of economists, scientists, former policymakers, and AI experts has now published A Transformative AI Strategy for Europe. Its warning is painfully blunt: without urgent action, Europe could become dependent on foreign models, foreign infrastructure, and decisions made elsewhere about technology that can reshape economies, institutions, and security.
More compute will increase Europe’s capabilities. Without equally mature access governance, however, it will also increase the potential blast radius.
What the transformative AI strategy says Europe lacks
The proposed transformative AI strategy rests on three pillars: securing access to frontier AI, building economic strength, and ensuring safety and security. Its five urgent objectives include an alliance for AI supply-chain security, stronger AI capability inside European institutions, 15% of global AI compute by 2030, resilience against AI crises, and European leadership in assurance technology.
Published numbers from other sources support the same concern. The European Central Bank’s 2026 analysis puts Europe at 5% of global AI compute, and says that rapid adoption could raise European productivity by as much as 4% over a decade. This is both a sovereignty problem and an opportunity, with a rather unforgiving clock.
Adoption is erratic and uneven. Eurostat’s 2026 digitalization report found that 20% of EU businesses used AI in 2025. The rate was 55% among large enterprises and 19% among small and midsize organizations. Meanwhile, 53% bought cloud services. AI is, alarmingly, arriving through cloud infrastructure faster than most governance programs can react.
That makes multi-cloud security, identity risk, and AI cybersecurity standards part of Europe’s strategic readiness, not just the basics of internal housekeeping.
AI capability and AI control aren’t the same thing
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of respondents expected AI to be the largest driver of cybersecurity change in 2026. Eighty-seven percent identified AI-related vulnerabilities as the fastest-growing cyber risk during 2025.
Still, we should separate today’s documented risks from more extreme, uncertain scenarios; there’s already enough myth around AI. The International AI Safety Report 2026 says current systems mainly accelerate existing attack methods. It also says present systems don’t yet possess the sustained capabilities required for catastrophic loss of control.
Crucially, the report identifies three factors that shape deployment risk: the environment's criticality, the resources an AI can access, and its permissions. An agent summarizing public documents isn’t the same proposition as one holding production credentials and the ability to call AWS (Amazon Web Services), Microsoft Azure, or Google Cloud APIs.
That is why AI agent security, service account security, and every unmanaged machine identity belong in the same conversation as model evaluations and data centers. And we need to have this conversation now, not tomorrow.
The mathematics of European expansion
To bring itself up to a future-ready standard, Europe would need to think not in terms of individual data centers but in gigawatts of computing capacity, plus the institutions capable of turning that capacity into useful intelligence. One gigawatt running continuously consumes 8.76 terawatt-hours of electricity a year and, after allowing for cooling and other overheads, could support roughly half a million of today’s advanced AI accelerators. A ten-gigawatt European program would therefore imply around five million chips and annual electricity consumption approaching 90 terawatt-hours.
The physical footprint of the data centers would be manageable, and their direct water demand could be greatly reduced through closed-loop liquid and dry cooling. The real constraint would be finding sites where dependable electricity, substations, transmission capacity, and multiple fiber connections are available together. Promising examples might include former industrial and power-generation sites in France’s Seine-et-Marne and Moselle regions, alongside well-connected renewable-energy hubs in Finland, Sweden, and Norway.
Europe would also have to reserve accelerators years in advance, along with the high-bandwidth memory, advanced packaging, networking equipment, transformers, and cooling systems needed to operate them, while building enough new generation to ensure that AI did not merely divert power from households and existing industry.
This expansion would take place amid intense global competition for the same equipment and a semiconductor supply chain already exposed to geopolitical shocks. Instability around the Strait of Hormuz, for example, threatens not only energy prices but the LNG-dependent electricity systems, industrial gases and petrochemical inputs on which Asian chip manufacturing relies.
Yet infrastructure alone would not create an AI industry. Europe is not starting from zero: France’s Mistral AI has emerged as its most credible general-purpose model company, while Germany’s Aleph Alpha and DeepL, France’s LightOn and numerous specialist laboratories demonstrate that the continent possesses considerable technical talent. The EU is also building a network of AI Factories, proposing up to five larger gigafactories backed by €20 billion of public and private finance, supporting OpenEuroLLM to develop transparent multilingual foundation models, and drawing on an ELLIS research network of more than 2,000 researchers across 47 sites.
The weakness is not a lack of intelligence but the difficulty of turning it into enduring institutions and competitive models. Doing so would require dependable computing allocations, competitive salaries and long-term research careers, easier movement for specialists and their families, growth capital that allows start-ups to remain independent, and public procurement that gives European models demanding customers in science, defense, healthcare, education and government.
The limiting mathematics, then, is not simply how many processors Europe can afford, but how many it can source, power and connect, and whether it can assemble the talent, data, capital and sustained demand needed to turn those machines into foundation models whose expertise, intellectual property and economic value remain in Europe.
N'oubliez pas la Grande-Bretagne
As an Englishman, I feel it’s worth noting that the UK’s standing in the broader European landscape is both critical and nuanced/complicated. Influenced by Brexit, this position stems from the reality that much of Britain’s advanced AI ecosystem relies on foreign ownership, depends on US-based infrastructure, or remains disconnected from the EU’s collective investment frameworks. It has perhaps Europe’s strongest concentration of AI research, venture capital, and leading universities, while London and Cambridge have produced companies and laboratories including Google DeepMind, Wayve, Synthesia, ElevenLabs and Stability AI. Yet Britain still lacks an independently controlled general-purpose model company with the strategic importance of France’s Mistral.
The UK government is trying to close the infrastructure gap through the Isambard-AI and Dawn supercomputers, a planned twentyfold expansion of the public AI Research Resource, and AI Growth Zones intended to raise AI-capable data-center capacity to at least six gigawatts by 2030. Britain has also rejoined Horizon Europe and entered the EuroHPC partnership, although it remains outside much of the EU’s industrial funding and decision-making.
For me, I feel the UKs most productive role would be to neither stand apart from Europe nor to surrender its strategy to Brussels, but to combine British strengths in research, finance, and company formation with European compute, energy, language data, and industrial demand. Without such cooperation, both sides still risk perpetuating the same weakness: Researchers creating valuable technology on American infrastructure for companies ultimately owned elsewhere.
Secure access is part of European AI assurance
A future strategy calls for secure access to advanced models and leadership in AI assurance. Assurance, however, needs more than hardened chips and physically secure data centers. A sovereign data center with permanent administrator access is still a data center full of permanent administrator access. Geography doesn’t magically revoke credentials.
The practical control layer should inventory every human, workload, service account, and agent; map effective permissions; assign accountable owners; and separate model access from infrastructure administration. AI access controls should be scoped to a task, resource, and duration. AI least privilege should be measurable, not just an encouraging paragraph that ticks a box in a policy document.
For sensitive systems, we should replace standing privilege with zero standing privileges, use access automation to remove permissions when work ends, and preserve identity provenance showing where access came from, who approved it, and whether it was used.
What security needs to do now
The European Commission’s 2026 Action Plan on Cybersecurity and Artificial Intelligence already proposes a blueprint for secure access to advanced AI and a testing platform for critical sectors. We don’t need to wait for every policy detail before improving the architecture underneath it; we need to act ASAP.
Organizations can start by identifying AI agents across cloud and SaaS, eliminating shared credentials, limiting external tool and API access, and requiring human approval for consequential actions. Incident plans should include immediate token revocation, agent isolation, and evidence preservation. Access reviews should cover non-human actors continuously, because quarterly certification and machine-speed autonomy may as well be decades apart.
Most importantly, identity governance must become part of AI architecture from the beginning. Europe needs more compute, investment, talent, and access to frontier systems. It also needs a reliable answer when someone asks what those systems can touch.
Europe doesn’t have to choose between moving quickly and maintaining control. Governable access is what makes speed defensible.
Get control of AI access before it gets interesting
If you want to discover human and non-human identities across cloud environments, expose excessive permissions, and replace standing privilege with time-bound, auditable access, give our Trustle free trial a spin in as little as 30 minutes. Europe’s AI transformation needs ambition. Our production accounts would also appreciate guardrails.




