On June 3, 2026, the European Commission adopted its Tech Sovereignty Package. Four components: the Cloud and AI Development Act (CADA), Chips Act 2.0, an EU Open Source Strategy, and a strategic roadmap for digitalization and AI.
The headline that matters for community infrastructure is buried in CADA's explanatory memorandum. It names "autonomy across the cloud stack" as one of four core strategic objectives. The Act introduces a single EU-wide sovereignty framework to assess cloud and AI sovereignty, and it explicitly targets hyperscaler dependency as a concentration risk.
This is the EU saying out loud what sovereign infrastructure practitioners have been saying for years: if your cloud runs on three American companies, you don't have a cloud. You have a subscription.
The Tools Shipped The Same Quarter
What's notable isn't just the policy. The FOSS infrastructure stack that actually delivers sovereignty got measurably better in the same quarter:
Proxmox VE 9.2 (May 21, 2026) shipped a Dynamic Load Balancer integrated directly into the cluster resource scheduler. More relevant for community deployments: native WireGuard and BGP support in the SDN stack. WireGuard as a first-class SDN fabric means a 3-node community cluster can build encrypted inter-node networking without an overlay VPN on top. Debian 13.5 base, Linux 7.0 kernel. This is the platform we deploy for communities, and it just got better at the thing it's for.
Keycloak 26.7 (July 9, 2026) delivered version 2 of the Identity Brokering API. Applications can now retrieve tokens obtained from external identity providers during federated login. For community federations — where one community's Keycloak trusts another's — this is the plumbing that makes cross-community SSO less painful to wire up. Keycloak 26.6 (April) already added Identity Provider mappers that auto-assign federated users to organization groups based on external claims. The federation story is getting concrete.
Nextcloud Hub 26 Spring (June 9, 2026) introduced a governance tool and a new office experience. The governance piece matters for community co-ops: member-controlled governance baked into the platform, not bolted on. The office option (your choice of Collabora or ONLYOFFICE) is a practical necessity for communities replacing Google Workspace.
Policy Doesn't Deploy Infrastructure
Here's the gap the Tech Sovereignty Package doesn't close: policy creates mandates, budgets, and risk frameworks. It doesn't deploy servers. It doesn't configure SDN. It doesn't explain to a fire hall treasurer why Proxmox on three refurbed mini PCs beats a Microsoft 365 Business subscription.
CADA introduces a sovereignty framework to assess cloud sovereignty. Assessment isn't deployment. The EU Open Source Strategy creates preferences for open source in public procurement. Preferences aren't infrastructure.
The people who will actually build sovereign cloud are not in Brussels. They're in community centers, fire halls, libraries, and town offices. They need someone who's done it before to show up, deploy the stack, document it, and leave them with the skills to run it.
That's the work. The policy makes the conversation easier — "the EU says we should" is a useful argument in a town council meeting. But the hard part is still the hard part: metal, configs, training, and sustainability planning.
What Actually Changed
For the communities we work with, the practical takeaway from this quarter is:
- Proxmox 9.2's WireGuard SDN simplifies encrypted cluster networking. If you're running a 3-node community cluster, upgrade and stop maintaining a separate overlay.
- Keycloak's improved federation APIs make cross-community identity trust less custom-code and more configuration. This is the piece that lets your community's SSO talk to the next community's SSO without a consulting engagement to write the glue.
- Nextcloud's governance tool gives co-ops a first-class mechanism for member governance inside the platform. Less governance theater, more actual control.
- The EU policy environment is now an argument you can use. If your town council is skeptical of "not Microsoft," the Tech Sovereignty Package and its Open Source Strategy are citations, not opinions.
The Honest Part
The Tech Sovereignty Package is a proposal, not a law. CADA has to go through the EU legislative process. The Open Source Strategy is a Commission strategy, not a directive with force. Chips Act 2.0 is about semiconductors, not your community cloud.
But the direction is right, and more importantly, the tools are ready. The gap between "policy says sovereignty matters" and "your community actually owns its infrastructure" is the gap we exist to close.
The infrastructure is buildable today. The policy just made it easier to justify building it.