Digital sovereignty has been understood, until recently, as a question of where data is stored and which laws apply to its storage. That understanding is now incomplete. A second layer has emerged. The state's exposure is no longer about storage and communication. It is about how information is generated, interpreted, and acted on. That layer is artificial intelligence, and I want to set out why it is reshaping what sovereignty means for European public administration.
The baseline established in the first piece - that US legal authority over technology providers is now being applied as an instrument of state power against European allies - extends to this layer too. The exposure is the same. The mechanism is different.
The global frontier AI landscape is, at present, bipolar. The leading models are developed and operated within the United States. OpenAI, Anthropic, Google, Microsoft, Meta, and a small number of others. A parallel Chinese ecosystem now operates at a competitive scale, led by DeepSeek and others. Neither jurisdiction has strategic interests aligned with Europe's. Whether the Chinese state would act in comparable terms against European entities is not on the public record. The structural exposure, in either direction, is the same.
The European Union is a late entrant. The most advanced European efforts - Mistral foremost among them, with Aleph Alpha and a small number of others - are credible but not yet at frontier scale. The Mistral-SAP partnership announced at the Berlin summit in November 2025 to build a sovereign European AI stack, as Politico reported in "Germany wakes up to US tech dominance" (19 November 2025), is the most significant institutional commitment to date. It is necessary. It is also late. Closing the gap to the US and Chinese frontier requires investment and consolidation at a scale that no individual Member State can deliver alone. It requires a pace that the Union has not historically operated at.
I want to set out why this matters in plain terms. AI tools do not simply store information or move it from one place to another. They draft. They summarise. They classify. They recommend. They increasingly decide. When a public-sector officer uses an AI tool to handle a case, the tool shapes which words are used, which information is emphasised, which category the case falls into, and which outcome is recommended. The interpretation of information is not a neutral background activity. It is the part of governance that produces results.
For the citizen on the other side, the consequence is direct. A Maltese citizen applies for a permit. Contests a tax assessment. Accesses a health service. Increasingly, their case is processed by a model. The model's training, parameters, and operational behaviour are determined by a company operating under foreign jurisdiction. The decisions that follow are partly shaped by systems that the state does not operate and cannot independently inspect. The citizen is dealing with a Maltese public service. The interpretation of their case, in part, is happening elsewhere.
The dependency runs deeper than it appears. The data sits on external infrastructure. The models that interpret the data sit on external systems too. And the interpretations those models produce - what the information is taken to mean - are produced elsewhere as well. Storage and communication can be moved. Data can be brought home. The interpretations cannot, until Europe builds its own.
I want to draw a further distinction, because it is the most important one in this argument. Infrastructure failure is visible. A state knows when its email is down, when its cloud is unreachable, and when its data centre is offline. The disruption presents itself. AI failure does not. A model that subtly weights its outputs toward the priorities of its trainer - emphasising certain categories of risk, recommending certain kinds of outcome, framing information in particular terms - produces results that look ordinary. The Maltese officer using the tool sees a draft, a summary, and a recommendation. The citizen sees a decision. Neither sees the model's priors. Neither has a way to compare the recommendation against what an alternative model would have produced. AI exposure is not just deeper than infrastructure exposure. It is harder to detect. Harder to attribute. Harder to defend against. The state can only manage what it can see. A dependency that operates invisibly is a dependency the state cannot, in the ordinary course, govern.
The implications for public-sector AI procurement are direct. Public administrations across Europe are adopting AI tools. Drafting, analysis, decision support, and citizen services. Each contract, in the present landscape, is a decision to interpret information using a model that operates outside European control. The choice is not between using AI and not using it. AI tools are now part of how public administrations work. The choice is between procuring within the US or Chinese ecosystems, or contributing to the European one as it is built.
Europe must come together. Europe must invest. Malta should be part of that work. Investing in the European capability. Shaping the European framework. Acting on the European timetable.
The strategic and policy framework that follows from this - for both the infrastructure and the AI dimensions of the sovereignty question - is the subject of the third and final piece in this series.
David Spiteri Gingell is a Governance, Institutional, and Digital Transformation Consultant