Artificial intelligence and EU securitythe false promise of digital sovereignty

Andrea Calderaro, Stella BlumfeldeView original
OverviewBalancedharry voice
Europe calls itself a digital sovereignty leader. Andrea Calderaro and Stella Blumfelde argue it is more accurately described as a digital sovereignty regulator. Those are not the same thing, and that distinction is the foundation of their entire argument. Their paper, published in European Security, poses a deceptively simple question: what does it actually take to be sovereign in artificial intelligence, and does the European Union have any of it? The uncomfortable answer they arrive at reveals that the European Union has genuine power in one area and serious gaps in the other two. Understanding which is which requires breaking artificial intelligence down into its components. Calderaro and Blumfelde treat artificial intelligence not as a single technology but as the functional combination of three elements: data, algorithms, and hardware, meaning computational capacity. For each aspect, you can ask a clear question. Can the European Union control the data that trains artificial intelligence systems? Can it govern the algorithms that run them? Can it produce or secure the chips and infrastructure they depend on? That three-part framework serves as the paper's analytical engine and makes the argument precise rather than impressionistic. Regarding data, the European Union's record is the strongest. The trajectory runs from the 2012 "right to be forgotten" debate through the Snowden revelations to the General Data Protection Regulation, also known as GDPR, of 2016. GDPR is the clearest example of what scholars call the Brussels Effect: the European Union's ability to export regulatory standards simply through the gravitational pull of its internal market. Any company, anywhere in the world, accessed by European Union citizens must comply. That is real power. But notice what GDPR does and does not do. It constrains how data is handled. It does not create the sovereign datasets, the data infrastructure, or the artificial intelligence training pipelines that underpin competitive artificial intelligence development. On algorithms, the European Union's control is more limited. Calderaro and Blumfelde point to a sequence of alarming episodes — ISIS exploiting algorithmic filter bubbles in the early 2010s, the Cambridge Analytica scandal exposing the manipulative potential of social media platforms — as moments that sharpened European awareness of algorithmic governance. The European Union has responded with ethical guidelines, parliamentary resolutions, and non-binding frameworks. However, awareness and governance capacity are not the same. The European Union does not own the dominant algorithmic platforms. It cannot directly shape how they function; it can only regulate what they are permitted to do. On hardware, the gaps are most pronounced. A 2017 report from the European Union Agency for Cybersecurity, also known as ENISA, warned of critical dependence on foreign technology. Parliamentary debates surrounding Huawei and ZTE raised fears about backdoors in fifth generation infrastructure. Ursula von der Leyen called in 2019 for European capacity in quantum computing, fifth generation, and artificial intelligence. These are signals of ambition, but they are not evidence of delivery. This is where the security argument becomes urgent. Calderaro and Blumfelde remind us that artificial intelligence and military competition have been intertwined since Alan Turing's wartime work decoding Enigma — the computational race has always had a strategic motive. What is new is the breadth and speed of artificial intelligence's military applications today. The authors identify three converging fronts. In the cyber domain, artificial intelligence can discover and exploit vulnerabilities in real time while defending against them simultaneously. In information operations, machine learning multiplies the scale and credibility of disinformation — deepfakes, targeted propaganda, automated influence campaigns. And on the kinetic battlefield, Lethal Autonomous Weapon Systems, also known as LAWS, are being developed with the capacity to identify and destroy targets without human interaction. Major powers are responding with urgency. The United States has embedded artificial intelligence into defense at the institutional level. Project Maven partnered the Pentagon with Google to analyze drone footage, and the Department of Defense created an Office of Digital and Artificial Intelligence in February 2022. China's 2017 Next Generation Artificial Intelligence Development Plan explicitly links civilian innovation with military use, targeting global artificial intelligence leadership by 2030. Russia has invested in military roboticization through unmanned ground vehicles capable of carrying weapons and plans for autonomous swarming systems, even though it lacked an official national artificial intelligence strategy until 2019. The investment numbers tell the competitive story plainly. Between 2013 and 2021, United States private investment in artificial intelligence companies totaled 52 billion dollars. China's total was 17 billion. The European Union's total reached 6 billion. American private firms invested 70 billion euros in artificial intelligence research and development, compared to 9 billion euros by European firms. In 2019, the European Union spent almost 9 billion euros on artificial intelligence overall — approximately half of that focused on skills and capacity building, not on developing industrial or computational capacity. These are not rounding errors; they represent a structural gap. That gap shows up within European Union defense institutions as well. Of sixty projects under Permanent Structured Cooperation, also known as PESCO, which is the European Union's main framework for defense collaboration, only one, the Maritime Unmanned Anti-Submarine System, explicitly mentions artificial intelligence. Nine involve unmanned systems without specifying degrees of autonomy. The European Defence Agency reports that just 16.9 percent of total defense investments fund collaborative research and development — its lowest measured level. The European Union's Strategic Compass, a sixty-four-page strategic document published in 2022, mentions artificial intelligence exactly four times. Only France has released a specific artificial intelligence military strategy among European Union member states. The fragmentation is not incidental; it reflects the absence of a coherent pan-European defense posture that places artificial intelligence at its center. This is where the Normative Power Europe framework — coined by Ian Manners in 2002 — becomes both an explanation and a limit. Manners defined normative power as the European Union's ability to shape what constitutes normal in international relations. Combined with the Brussels Effect, this describes how the European Union exports standards through market size and regulatory ambition rather than through military or industrial strength. The General Data Protection Regulation reshaped global data practices. The European Union's ethical artificial intelligence guidelines, its 2018 call to ban Lethal Autonomous Weapon Systems, and the European Defence Fund's 2019 budget condition prohibiting research funding for autonomous lethal weapons are markers of genuine normative influence. However, Calderaro and Blumfelde are precise about what this power cannot accomplish. Regulation shapes the rules of the game but does not build the chips, fill the data centers, or produce the training datasets that underpin dominant artificial intelligence capability. The European Union can instruct other players on how to behave. It cannot yet field a competitive team. That is the central paradox the paper highlights, and it is not a temporary issue. The investments required to build real industrial capacity across data, algorithms, and hardware are long-term. In the short and medium term, the European Union can mostly rely on regulatory tools. The legitimacy question compounds the strategic one. The European Union's identity as a largely civilian, normative, and "benevolent" actor conflicts with military artificial intelligence development. It is precisely that self-definition that lends the Brussels Effect its credibility — other actors accept European Union standards partly because the European Union is not perceived as a military threat. But that same identity limits the European Union's authority in the domain where artificial intelligence competition is now most consequential. The chief executive of the European Defence Agency, Jiří Šedivý, warned in 2021 that for the European Union to be a credible security provider, artificial intelligence must be central to capability development. The warning signals intent but does not close the gap. The paths forward that Calderaro and Blumfelde identify are real but constrained. International partnerships — a digital economy dialogue with Brazil in 2021, closer cooperation with Singapore in 2022, a formalized digital partnership with Japan at the EU-Japan Summit in May 2022 — expand the European Union's network of influence. Cyber diplomacy and ethical standard-setting remain active levers. These are not insignificant efforts, but they operate within the same framework as the Brussels Effect: projecting norms and building coalitions rather than generating sovereign industrial capacity. The paper's final, sobering point is this: the European Union's greatest strength in artificial intelligence is also its ceiling. Regulatory power is what gives Europe global influence in this domain. And it is regulatory power alone that the European Union can reliably deploy. Everything beyond that — the algorithms, the computational capacity, the integrated defense strategy — remains aspirational. Calderaro and Blumfelde do not argue that the European Union should abandon its normative ambitions. Instead, they suggest Europe should stop confusing those ambitions with sovereignty. Shaping the rules is not the same as controlling the game. This lecture was created by ennepō. Go to https://ennepo.ai to Discover, Create and Follow the latest research in your field. Read when you can. Listen when you want to.

Europe calls itself a digital sovereignty leader. Andrea Calderaro and Stella Blumfelde argue it is more accurately described as a digital sovereignty regulator. Those are not the same thing, and that distinction is the foundation of their entire argument. Their paper, published in European Security, poses a deceptively simple question: what does it actually take to be sovereign in artificial intelligence, and does the European Union have any of it? The uncomfortable answer they arrive at reveals that the European Union has genuine power in one area and serious gaps in the other two. Understanding which is which requires breaking artificial intelligence down into its components. Calderaro and Blumfelde treat artificial intelligence not as a single technology but as the functional combination of three elements: data, algorithms, and hardware, meaning computational capacity. For each aspect, you can ask a clear question. Can the European Union control the data that trains artificial intelligence systems? Can it govern the algorithms that run them? Can it produce or secure the chips and infrastructure they depend on? That three-part framework serves as the paper's analytical engine and makes the argument precise rather than impressionistic.

Regarding data, the European Union's record is the strongest. The trajectory runs from the 2012 "right to be forgotten" debate through the Snowden revelations to the General Data Protection Regulation, also known as GDPR, of 2016. GDPR is the clearest example of what scholars call the Brussels Effect: the European Union's ability to export regulatory standards simply through the gravitational pull of its internal market. Any company, anywhere in the world, accessed by European Union citizens must comply. That is real power. But notice what GDPR does and does not do. It constrains how data is handled. It does not create the sovereign datasets, the data infrastructure, or the artificial intelligence training pipelines that underpin competitive artificial intelligence development. On algorithms, the European Union's control is more limited. Calderaro and Blumfelde point to a sequence of alarming episodes — ISIS exploiting algorithmic filter bubbles in the early 2010s, the Cambridge Analytica scandal exposing the manipulative potential of social media platforms — as moments that sharpened European awareness of algorithmic governance. The European Union has responded with ethical guidelines, parliamentary resolutions, and non-binding frameworks. However, awareness and governance capacity are not the same. The European Union does not own the dominant algorithmic platforms. It cannot directly shape how they function; it can only regulate what they are permitted to do.

On hardware, the gaps are most pronounced. A 2017 report from the European Union Agency for Cybersecurity, also known as ENISA, warned of critical dependence on foreign technology. Parliamentary debates surrounding Huawei and ZTE raised fears about backdoors in fifth generation infrastructure. Ursula von der Leyen called in 2019 for European capacity in quantum computing, fifth generation, and artificial intelligence. These are signals of ambition, but they are not evidence of delivery. This is where the security argument becomes urgent. Calderaro and Blumfelde remind us that artificial intelligence and military competition have been intertwined since Alan Turing's wartime work decoding Enigma — the computational race has always had a strategic motive. What is new is the breadth and speed of artificial intelligence's military applications today. The authors identify three converging fronts. In the cyber domain, artificial intelligence can discover and exploit vulnerabilities in real time while defending against them simultaneously. In information operations, machine learning multiplies the scale and credibility of disinformation — deepfakes, targeted propaganda, automated influence campaigns. And on the kinetic battlefield, Lethal Autonomous Weapon Systems, also known as LAWS, are being developed with the capacity to identify and destroy targets without human interaction.

Major powers are responding with urgency. The United States has embedded artificial intelligence into defense at the institutional level. Project Maven partnered the Pentagon with Google to analyze drone footage, and the Department of Defense created an Office of Digital and Artificial Intelligence in February 2022. China's 2017 Next Generation Artificial Intelligence Development Plan explicitly links civilian innovation with military use, targeting global artificial intelligence leadership by 2030. Russia has invested in military roboticization through unmanned ground vehicles capable of carrying weapons and plans for autonomous swarming systems, even though it lacked an official national artificial intelligence strategy until 2019. The investment numbers tell the competitive story plainly. Between 2013 and 2021, United States private investment in artificial intelligence companies totaled 52 billion dollars. China's total was 17 billion. The European Union's total reached 6 billion. American private firms invested 70 billion euros in artificial intelligence research and development, compared to 9 billion euros by European firms. In 2019, the European Union spent almost 9 billion euros on artificial intelligence overall — approximately half of that focused on skills and capacity building, not on developing industrial or computational capacity. These are not rounding errors; they represent a structural gap.

That gap shows up within European Union defense institutions as well. Of sixty projects under Permanent Structured Cooperation, also known as PESCO, which is the European Union's main framework for defense collaboration, only one, the Maritime Unmanned Anti-Submarine System, explicitly mentions artificial intelligence. Nine involve unmanned systems without specifying degrees of autonomy. The European Defence Agency reports that just 16.9 percent of total defense investments fund collaborative research and development — its lowest measured level. The European Union's Strategic Compass, a sixty-four-page strategic document published in 2022, mentions artificial intelligence exactly four times. Only France has released a specific artificial intelligence military strategy among European Union member states. The fragmentation is not incidental; it reflects the absence of a coherent pan-European defense posture that places artificial intelligence at its center. This is where the Normative Power Europe framework — coined by Ian Manners in 2002 — becomes both an explanation and a limit. Manners defined normative power as the European Union's ability to shape what constitutes normal in international relations. Combined with the Brussels Effect, this describes how the European Union exports standards through market size and regulatory ambition rather than through military or industrial strength.

The General Data Protection Regulation reshaped global data practices. The European Union's ethical artificial intelligence guidelines, its 2018 call to ban Lethal Autonomous Weapon Systems, and the European Defence Fund's 2019 budget condition prohibiting research funding for autonomous lethal weapons are markers of genuine normative influence. However, Calderaro and Blumfelde are precise about what this power cannot accomplish. Regulation shapes the rules of the game but does not build the chips, fill the data centers, or produce the training datasets that underpin dominant artificial intelligence capability. The European Union can instruct other players on how to behave. It cannot yet field a competitive team. That is the central paradox the paper highlights, and it is not a temporary issue. The investments required to build real industrial capacity across data, algorithms, and hardware are long-term. In the short and medium term, the European Union can mostly rely on regulatory tools. The legitimacy question compounds the strategic one. The European Union's identity as a largely civilian, normative, and "benevolent" actor conflicts with military artificial intelligence development. It is precisely that self-definition that lends the Brussels Effect its credibility — other actors accept European Union standards partly because the European Union is not perceived as a military threat.

But that same identity limits the European Union's authority in the domain where artificial intelligence competition is now most consequential. The chief executive of the European Defence Agency, Jiří Šedivý, warned in 2021 that for the European Union to be a credible security provider, artificial intelligence must be central to capability development. The warning signals intent but does not close the gap. The paths forward that Calderaro and Blumfelde identify are real but constrained. International partnerships — a digital economy dialogue with Brazil in 2021, closer cooperation with Singapore in 2022, a formalized digital partnership with Japan at the EU-Japan Summit in May 2022 — expand the European Union's network of influence. Cyber diplomacy and ethical standard-setting remain active levers. These are not insignificant efforts, but they operate within the same framework as the Brussels Effect: projecting norms and building coalitions rather than generating sovereign industrial capacity. The paper's final, sobering point is this: the European Union's greatest strength in artificial intelligence is also its ceiling. Regulatory power is what gives Europe global influence in this domain. And it is regulatory power alone that the European Union can reliably deploy.

Everything beyond that — the algorithms, the computational capacity, the integrated defense strategy — remains aspirational. Calderaro and Blumfelde do not argue that the European Union should abandon its normative ambitions. Instead, they suggest Europe should stop confusing those ambitions with sovereignty. Shaping the rules is not the same as controlling the game. This lecture was created by ennepō. Go to https://ennepo.ai to Discover, Create and Follow the latest research in your field. Read when you can. Listen when you want to.

More in Social Sciences