Europe 2031: The Non-Fiction Edition
On 11 June 2026, eight authors from the European AI-governance scene published Europe 2031, a 65-page fictional scenario of European irrelevance in AI. Two invented characters live through six invented years while a sidebar tracks American and European compute in gigawatts. The plot centers on an American export control against Claude Mythos.
Reality needed just one day to catch up. On 12 June 2026, Washington restricted exports of Anthropic's real Mythos and Fable models by private letter; on 26 June it exempted "trusted partners," for Mythos only; by 30 June the controls were withdrawn, eighteen days after imposition. The public learned any of this when the law firm Mayer Brown published a client alert, written by a former US Assistant Secretary of Commerce for Export Administration. The scenario authors had to invent their export control. The real one was imposed, adjusted and switched off again before most of Europe had finished reading the Europe 2031 scenario.
One week after that, on 7 July 2026, Reuters reported that Beijing is deliberating restrictions on overseas access to Chinese frontier models, including models not yet released. The same day, Armin Ronacher, the Austrian who created Flask, quote-tweeted the story with four words: "Europeans please wake up."
Europeans please wake up. https://t.co/JUQ0Hgv2C4
— Armin Ronacher ⇌ (@mitsuhiko) July 7, 2026
Since then events like this happen almost on a day to day basis. All of them lead to the same diagnosis: Europe does not control the AI it now starts depending on. Where Europe 2031 loses me is the spirit. Its message is courage, build like a country at war! Courage doesn't pour concrete, and it doesn't shorten a queue for buying transformers or GPUs.
So I decided to create a non-fiction version of "waking up". My intent is not to show how to fail, but to show how it can be done. And I'm going to put you - dear reader - in charge of the strongest consortium Europe can assemble, hand you the EU's own data-centre package, and build chain node by node until you either hold a sovereign frontier model or know exactly why you don't.
The EU's strategy allows someone else to have the hand on the off switch
Europe's de-facto model-access strategy is easier to read from behavior than from policy papers: subscribe to the frontier through closed US APIs, or download it as open weights, and add European sparkle on top by post-training. It is a reasonable strategy. It is also a strategy whose off-switch sits on other continents, and 2026 is the year both switch-holders - Trump and Xi Jinping - verified that their switches worked.
The US subscriptions are already discretionary. In January 2025 the US put unpublished frontier model weights under export control; that rule was rescinded in May 2025. It got replaced by private "is-informed" letters that gate named models, demonstrated on Mythos and Fable in June 2026. A letter most Europeans will never see can change what European businesses run on.
The download side is wide open today. Moonshot shipped four open-weight releases between July 2025 and April 2026, DeepSeek released V4 under an MIT license in April 2026, Mistral put Large 3 under Apache 2.0 in December 2025. On Epoch AI's capability index, the most capable open-weight models run about four months behind the closed frontier. But notice what happened: Meta has gone quiet at the top, with Behemoth (Llama 4) unreleased. And the Reuters story above is Beijing deliberating whether overseas access to Chinese frontier models should be filed, reviewed, or entirely banned. Reuters itself says it is not clear when or even if rules would come into force.
Europe's strategy rests on concentrated external supply risk: several foreign labs, and in China's case one government, can remove the next generation (even if none can remove the weights the EU already holds). The critical decision is still someone else's to make.
There is a mechanism shaping this external supply risk:reciprocity. OpenAI told the US Congress it has evidence that DeepSeek-linked accounts harvested model outputs through third-party routers for distillation, the practice of training your model on another model's answers. The US now gates access in response: terms-of-service enforcement, account elimination, origin screening, and the named-model letters. Beijing is deliberating the mirror image. My opinion: Beijing will start gating some of their models because reciprocity is the pattern of this decade. However, nothing I write here depends on it. Whether the US and China reciprocate next quarter or never, Europe has no plan B written down.
But isn't the EU doing something: On 13 July 2026, a German consortium, Fraunhofer, DFKI and TU Darmstadt among the partners, federal money behind it, released Soofi S, a 30B open-weight model trained on Deutsche Telekom's Munich cloud. Two days later a widely shared post celebrated "one of the world's best open-source AI models… fully trained in Europe". The same afternoon, a single researcher took it apart: the architecture is NVIDIA's Nemotron 3 Nano reference design, unmodified, with roughly 80 percent of the training mixture in common, and the headline benchmark advantage rested on a training dataset containing paraphrases of the complete test set, about 70 percent of the measured edge over the architecture-identical American baseline. The team conceded the "contamination" in the X replies.
The compute was European, the training run was real, the German-language gains survived. What was borrowed was the recipe, and what was missing was the verification: the audit came from one person with an off-the-shelf coding agent in an afternoon.
So here is my proposal: the EU needs a firm response to the external supply risk.
- The prerequisites are having our own model resources, permanent rights to operate and test them, and sufficient capacity for workloads that cannot tolerate any downtime.
- Ensuring that such a capability stays evergreen is even more important: a permanent European laboratory capable of training and certifying the next generation of a model without having to wait for approval from third parties.
- Having a frontier position is even harder - maybe even impossible: full-stack autarky, down to fabs and memory, is not realistic.
The build: let's go!
From here on the post runs in second person. A well-capitalized private consortium with member-state backing, deliberately the strongest actor the European system can produce and the exact shape the gigafactory program imagines, is about to hire you as its fractional CTO. If you hit a wall, every weaker actor hits it even harder. The clock is set in your very favor: everything that can go right goes right, at record speed. Sort of "operation warp speed."
The consortium, its decisions and its outcomes are invented; so are you and your advisor. Your advisor is a frontier-lab veteran who has shipped the kind of training run and now answers your messages at any time of the day. Every constraint, lead time, benchmark and precedent comes from a sourced real project. Projections remain projections, and the scenes run on a charitable clock.
Each scene ends the same way: with a summary of what is done, what is still open, and who can push it forward. The month count runs across the top, so you can always see where you are. Let's get started.
July 2026. Your mandate.
The call comes the week the Reuters story runs. The consortium wants a CTO, and its charter fits on one page, which is the first thing you ask to see. Two clauses.
- First: within a decade, Europe's strategic workloads, defense, intelligence, critical infrastructure, foundational science, run on AI that no foreign letter, rule or release decision can degrade.
- Second: Europe holds a seat at the frontier as a builder, not a subscriber, because the first clause has no sustainable answer without the second. Nothing in the charter says chatbots, and nothing says out-shipping OpenAI.
You notice what the wording quietly admits: sovereignty is being specified as a guarantee against a threat model.
You have watched enough European flagship programs to name one condition before you talk compensation. FCAS, the Franco-German fighter program, is postponed indefinitely, with Dassault's CEO telling Reuters in December 2025 he was unsure the fighter would go ahead at all, and the two governments reportedly no longer wanting the same aircraft. It is the same juste-retour pathology that drove France out of the Eurofighter program in 1985, toward the Rafale. The only counter-example your remember is Airbus itself, which spent thirty years as a consortium of national champions and only became Airbus in January 2001, when workshare became a management decision instead of a political formula. You know that AI already has the pathology in miniature: OpenEuroLLM, twenty partners and €37.4M, zero flagship checkpoints as of July 2026. So you voice your condition: one company, one balance sheet, member states as shareholders, no workshare formula, no national veto. Otherwise you stay a consultant. Because ink does not bind the next parliament, the charter also needs ten-year validity and offtake commitments, an independent board and pre-agreed exit rules for any state that changes its mind. The backers agree in writing, and you sign. It is the first gate, but not a proof that European politics has been cured.
Month 0
Done: one company, one balance sheet, no national veto. Signed.
Open: ten years of budgets that no signature today can guarantee.
Who can move it: the founding shareholders, and the parliaments that backs them.
August 2026. The package.
Your first week in office starts with the EU's own paperwork. On your desk sits the Cloud and AI Development Act, published as a Commission proposal on 3 June 2026, no lead committee assigned yet, adoption targeted for late 2027. You read it the way an operator reads a contract: what do you get, when, from whom. What a strategic-project designation grants, once the Act exists. Your member state has designated an acceleration zone, is a single information point, a permit capped at twelve months, an aggregated baseline permit, and priority grid connection. What it does not grant is money. The headline figure of roughly €200bn is an investment-need estimate, "mostly private," which is a polite way of saying: you are going to figure it out.
You remember the €20bn AI-gigafactory program - the capital arm, and check its status. It moved three days before you took the job. On 30 July 2026 the Commission opened the call: up to seven AI Gigafactories, up to €10bn in EU and national funding, at least €20bn more hoped for from private investors. Eighteen member states signed the joint procurement agreement.
Then you read the tender specifications the way you read the Act, and the €30bn falls apart in your hands. The Union's share is not €10bn but up to €5bn, the other half being money member states have yet to commit. Of that €5bn, up to €1bn is available under the current budget. The remaining €4bn "may be awarded after 31 December 2027," subject to the next budget being adopted, to a successor to the EuroHPC JU being established, to a financing decision, and to appropriations existing. All appropriations as of 2028, the document says, are indicative. So the real number is exactly €1bn: four projects at €100m, three at €200m.
And that €1bn is not construction capital. The Union's role is written down as a strategic anchor customer, pre-purchasing compute access time over about five years at an agreed price, capped at 17% of IT capital expenditure, a definition covering accelerators, interconnect, racks and cooling, and explicitly excluding the building, the utilities, the site preparation and every euro of operating cost. Those belong to the consortium, along with the rest of a facility the Commission itself puts at €4bn to €5bn each. The €20bn of private investment is not a pledge from anyone. It is the ask for privat capital deployment.
The call closes 12 November 2026, awards land in early 2027, construction begins in 2027, and winners have up to eighteen months from signature to switch anything on. The earlier informal call had already drawn 76 proposals across 60 sites in 16 member states, offering more than €230bn of private investment. The demand side was never the problem.
One clause is interessting and stays with you. To make sure the winners can actually get hardware, the Commission signed three letters of intent with AMD, NVIDIA and Qualcomm, as a follow-up to the EU-US trade deal. Europe's sovereign compute program secures its silicon with letters from three American vendors. You have spent your first month reading about American letters.
So you make the first real decision: you don't wait for the package. SoftBank didn't wait when it committed 5 GW across three French sites in May 2026. If the Act arrives on its schedule it will arrive as an accelerator. What arrives when you eventually file is a faster permit and a queue ticket, not capital.
Month 1
Done: the package is read and priced. It buys a permit and a queue ticket, not a build.
Open: €4bn that depends on a budget nobody has agreed.
Who can move it: Brussels, and the member states that have yet to commit their half.
September 2026. A data centre is not a data centre.
Your first architecture meeting establishes the term everyone else in Brussels skips. Three different species hide under "AI data centre."
- Inference: Serving a finished model to users, can be built almost anywhere.
- Adaptation: tuning an existing model to a task, runs on hardware an ordinary enterprise can procure without waiting.
- Frontier pretraining: training a new model from scratch, currently needs a tightly coordinated low-latency fabric running for months.
The physics are unfortunately unforgiving. Thousands of GPUs exchange gradients and activations through hierarchical collectives; every extra hop turns synchronization into waiting. Meta built two 24,576-GPU clusters for its Llama 3-era work. Methods for training across distant sites are improving; a federation of separately scheduled machines still fails to form one coherent training fabric. This is why the EU's nineteen "AI Factories" cannot simply be networked into a frontier machine: they are a federated one-stop-shop, not one fabric. The new Gigafactories call repeats the pattern: a site may be one location, several locations, or cross-border distributed facilities. Distribution is a concession to the EU's federated nature and a fabric problem at the same time.
Your board asks you the question every European board asks next: why not train on the public machines, JUPITER, Leonardo? Because they are shared science instruments, and the math doesnt math, you answer. Leonardo in Bologna runs 13,824 A100 GPUs, a 2020-generation chip two architectures behind what frontier labs rack today; JUPITER runs more than 24,000 GH200 superchips. Access comes as allocations: the industrial fast lane tops out at 50,000 GPU-hours over three months, the largest access class at a few million GPU-hours across a year. Leonardo is closed to new large-scale requests for excess demand as you need. The industrial fast lane is fast only if you are traveling somewhere else than the frontier. A frontier pretrain wants a hundred thousand current-generation GPUs, exclusively, for months, on the order of two hundred million GPU-hours.
The board does what boards always do: Challenge. You argue that this is not hypothetical: TrustLLM, the Union's flagship trustworthy-LLM project, won 500,000 node-hours on Leonardo's A100s under it, about two million GPU-hours, for AI-Act-compliant dataset and training work across the Union's languages. That is one percent we need you explain. The most compute European public infrastructure has ever granted a single project is Apertus's ten-million-plus GPU-hours on the Swiss Alps machine, and that bought a capable 70B and its 8B sibling. No EuroHPC machine has ever been handed to one private project for half a year.
Then your CFO does the arithmetic on the new gigafactory call. Its top lot requires, in phase two, four times the advanced processors installed in Europe's most powerful AI factory. JUPITER is about 24,000 GH200s. Somebody is being asked to rack something near a hundred thousand accelerators, which is the right order of magnitude, and the first time a European document has asked for it. Then you check what the number is attached to: phase two depends on a budget that begins in 2028 and has - again - not been agreed. The ambition is finally the right size. It is scheduled to start in the wrong year, if at all.
You realize that ninety percent of what the EU debates building is Inference and Adoption. "Sovereign frontier" means something different, and finally your board believes you.
You write the program as the charter's two clauses, two tracks. Track A takes the second clause, the frontier seat: one coherent cluster and a training run of Europe's own, which is the rest of this story. Track B takes the first clause, the workloads that cannot wait, and it is small enough to be a footnote: two racks in a Vienna colocation hall before Christmas, near-frontier weights the consortium owns or licenses, a registry that mirrors every open release the program depends on, and the evaluation and assurance work that turns held weights into something a ministry can certify. The lettering is the order of ambition, not of delivery: Track B is live before Christmas; Track A is years from its first token. The board minutes call it a publicity hedge. The rest of this post will call it the baseline.
Month 2
Done: the program splits in two: Track A for the frontier cluster, Track B for the workloads that cannot wait.
Open: one coherent training fabric. A federation of machines is not one.
Who can move it: physics.
October 2026. Sizing.
The sizing meeting in October reorganizes the program. The largest training run known as of mid-2026 is xAI's Grok 4 at roughly 5×10²⁶ floating-point operations. The clusters under construction for the next runs are gigawatt-class: Colossus 2 in Memphis had about 460 MW installed by August 2025 on a path past 1.5 GW; Stargate Abilene is headed for 1.2 GW on analyst estimates. Epoch's central projection is that a frontier run wants about 2×10²⁹ operations and roughly 6 GW of power, on a cluster costing over $100bn. Keep two numbers apart in your head: the cluster, one coherent fabric, plausibly gigawatt-class by the time you arrive; and the fleet, the tens of gigawatts a country may run behind sustained frontier presence. Your 300 MW first phase is sized to the frontier of 2024. According to the forecast, the gap will widen as the expansion progresses; should the number of algorithms increase tenfold, the gap will widen more slowly, but the expansion will still lag behind.
And the 300 MW is rarely available. In the legacy hubs, Frankfurt, London, Amsterdam, Paris, Dublin, grid-connection queues run seven to thirteen years. The Netherlands restricts new hyperscale projects to two designated zones. Denmark paused new connections in March 2026. Frankfurt is effectively closed until 2030. A twelve-month permit cap the EU guarantees is cosmetic next to a seven-year queue, and your request is no longer 300 MW, it is a gigawatt. A permit can be accelerated by law; copper not so much. Even the country with spare generation fails operationally: Germany's wind sits in the north and its industrial demand in the south, and the transmission lines meant to join them, SuedLink and SuedOstLink, have slipped from 2025–26 targets to 2028, part of roughly 16,800 km of legally mandated grid expansion. In the meantime, paying power plants to ramp up and down around the bottleneck cost Germany €3.07bn in 2025 alone. Gigawatts at the wrong end of the wire.
So power becomes your next full-time job. You give it a dedicated month and a single instruction: find a gigawatt.
Month 3
Done: the cluster is sized against the frontier.
Open: the grid connection - seven to thirteen years in the legacy hubs.
Who can move it: the transmission operator and the transformer order books.
November 2026. Shopping for gigawatts.
The month turns into a tour of everything Europe has already tried. Brownfield comes first, because it genuinely works: reuse a retired power plant's existing grid interconnection and you connect in under a year instead of more than five. Europe is mid coal phase-out, so the inventory of dead plants with live connections is real, and the EU's own acceleration-zone criteria hint at it. But a retired coal plant hands you hundreds of megawatts, and your problem is a gigawatt fabric. You file brownfield where it belongs.
Bring-your-own-power is the American answer: on-site gas generation, roughly 50 GW of it announced in the US in 2025 alone, at 24 to 36 months to power instead of five-plus years in the queue. But the EU does is watering down that approach twice. First, any gas installation above 20 megawatts thermal becomes an emissions-trading installation and buys CO₂ allowances at the carbon price, and the Industrial Emissions Directive adds permits and abatement on top. Large new connections there now require on-site dispatchable generation. Second, even where the law is favorable, the turbines are already sold. GE Vernova's heavy turbines are sold out through 2029 and Siemens Energy quotes similar; Europe's own power-equipment champions are backlogged by the same AI demand you have. Reciprocating engines, including INNIO's Jenbacher line from Austria, bridge at one to three years, at engine scale, but not gigawatt scale.
The elegant answers sit a decade out. No operational small modular reactor powers a data centre anywhere on Earth, and the EU's own target for first units is the early 2030s. Fusion is further still, though this year it stopped being a punchline: Proxima Fusion, Munich's stellarator startup and Europe's best-funded fusion company, raised €411M in July 2026 at a €2.4bn valuation, with more than 90% of its investors European, and plans Stellaris, its first commercial plant, on the site of the decommissioned Gundremmingen reactor in Bavaria. Germany shut its last reactors in 2023; its best-funded fusion company plans to build on the same site. You cannot invent this. You wish them speed and read the date again: power for the 2030s, not for your required timeline.
What remains before 2030 is low-carbon power at a handful of Nordic hydro and French nuclear nodes, all of them already courted by hydrogen plants, battery factories and other data centres. That elimination is how you end the month on the coast at Loon-Plage, the industrial port zone west of Dunkirk, twenty kilometres from the six 900-megawatt reactors of Gravelines, Western Europe's largest nuclear plant. France is the only EU country actively marketing firm carbon-free power for AI data centres: 35 pre-identified sites, about 1,200 hectares, announced in February 2025 under the slogan "plug, baby, plug". Reality voted for this coastline before you did: SoftBank's 5 GW commitment named Dunkirk first. One entry for the risk register: the site list grew from 35 to 63 by November 2025, and only 26 precise locations are public; the fullest map of the program is maintained by an NGO that opposes it - well, it's the EU. You have seen that pattern before, in the gigafactory tender. You take the option anyway and open the connection file with RTE (Réseau de Transport d'Électricité - the French transmission system operator) the same week.

If you doubt this hunt stops serious people, it stopped the most serious: OpenAI paused Stargate UK in April 2026 over British energy costs and regulatory conditions. Energy - or the lack thereof - stops the best-funded actor on Earth. Proximity to a nuclear plant is not a grid connection. An RTE connection offer, capacity reservation and reinforcement date become the program's first go/no-go gate. This story grants all three on the fastest plausible schedule. Godspeed.
Month 4
Done: every route around the queue checked - brownfield, on-site gas, SMR, fusion. A site option taken at Loon-Plage.
Open: the RTE connection offer, the capacity reservation and the reinforcement date.
Who can move it: RTE. The carbon price and the turbine order books close the alternatives.
Early December 2026. The cap table.
The capital raise closes this month; it has been your CFO's whole autumn. The money the program needs through the first training run sits in the tens of billions. Someone has to write the cheques. Your CFO's term-sheet is where you learn who in Europe can. It is a short file. Most of its sections are variations of "not this asset class."
The institutions that hold Europe's money do not do much of this asset class. European pension funds ended 2023 with €2.7 trillion under management and put €0.6 billion of new money into venture funds that year, 0.02 percent of assets. Insurers face a different rulebook: under Solvency II, ordinary unlisted equity carries a 49 percent solvency stress, although qualifying long-term equity can receive a 22 percent treatment. Although this is a capital test (not cash placed in a reserve) it makes assets like your consortium structurally expensive. The one European vehicle actually designed for large private tickets is Bpifrance's Blue Sea fund, announced in June 2026 at a €4 to 5 billion target, writing €200 to 500 million per deal. Bpifrance's executives described filling it with Middle Eastern, North American and Asian institutions, because European ones would not chip in. For scale: CoreWeave, a single American GPU cloud, raised $3.5 billion in one convertible-note offering in April 2026. France's flagship fund is one and a half CoreWeave tranches.
The file also shows where Europe's money actually sits. Norway's oil fund closed 2025 holding NOK 574 billion of NVIDIA, its largest position in anything, and that single line outweighs the fund's entire allocation to German equities, still the largest economy in Europe. Households across the Union hold roughly €37 trillion in savings, and they put some €300 billion of the annual flow into markets abroad, mostly American.
The frontier rounds those savings help finance were open for inspection this spring: OpenAI closed $122 billion in March 2026 at an $852 billion valuation; Anthropic closed $65 billion in May at $965 billion. Read down both investor lists and you find Singapore twice and Abu Dhabi once, GIC, Temasek, MGX, and not one European public or institutional fund. A French trade journal wrote the sentence that belongs in your notebook: the continent that aggregated $109 billion of capital around Paris in February 2025 placed no public capital in the round that created the world's most valuable private AI company.
Fundraising therefore takes place in the only way permitted by the term sheets. The member states form the foundation, strategic industrial companies join in, and the remainder comes from the same region from which Blue Sea draws its investors - MEA. Equity capital alone is not enough: the states also sign ten-year capacity and off-take commitments, because a state-subsidized cluster without guaranteed capacity utilization is an expensive white elephant. Three points remain open as conditions to close.
- Member-state capital must clear the state-aid route. State-backed non-European money can trigger the EU's Foreign Subsidies Regulation.
- Foreign equity in an AI and critical-infrastructure supplier enters national review under the EU's strengthened foreign-investment screening framework.
- The defence and intelligence shareholders impose the final condition: foreign capital stays passive and non-controlling, without board or information rights over classified workloads.
The story's charitable clock grants the approvals and security clearances. Your consortium is the strongest actor Europe can produce. By construction of the European capital market, part of its capital is not European. One more thought you have: nobody publishes a European AI-infrastructure capex total. The analysts tally the four American hyperscalers at roughly $725 billion for 2026.
Month 5
Done: the money is raised and the demand is contracted for ten years.
Open: state-aid clearance, foreign-subsidy review and investment screening.
Who can move it: the limited partners Europe did not provide, the state customers, and regulators.
December 2026. Everything is a queue.
The final investment decision is signed, and you spend December learning the procurement reality: a frontier cluster is queued for, not bought. The construction itself is the easy part, which surprises your board: proven European contractors deliver a data center with mechanical and electrical fit-out in 18 to 24 months. Of a six-to-ten-year default path, only about two and a half to three and a half years is actual building. Water is an engineering problem you can solve with waterless direct-to-chip cooling, and German law even turns your waste heat into a district-heating asset - maybe France will do the same. The remaining blockages are all order books.
High-voltage transformers: three to five years, from an OEM set you can count on one hand. Switchgear: fourteen-plus months. You sign the transformer order in the same week as the investment decision, because no other signature in the program is this unforgiving. Then the cluster itself. At 100,000 GPUs you do not order cards; you negotiate allocation with NVIDIA, whose priorities favor its largest American customers, and whose interconnect fabric, NVLink, InfiniBand, Spectrum-X, is the part of the machine you cannot buy from anyone else. Your procurement plan comes back with the same finding on every line of the bill of materials: Micron declared its AI-class memory sold out for 2026, and nearline hard drives are fully allocated under long-term agreements running into 2028. Capacity is allocated, not sold. A consortium starting now queues behind contracts signed in 2024, for every component.
Here is the case that tells you what the queue looks like when it moves: Stargate Norway, announced July 2025. From announcement to a 100,000-GPU target inside eighteen months, 230 MW growing toward 520 MW on Norwegian hydropower. The metal appears at record speed on European soil, when the mind-owner leads and NVIDIA's best customer is the buyer. Europe's own neoclouds, Nscale and Nebius, build and host at scale, for Microsoft, Google and OpenAI. None of them trains a frontier model.
At least one delivery does arrive on schedule in December: Track B's racks, into the Vienna colocation hall, weeks from purchase order to first power-on. The consortium signs Mistral's commercial licence the same month, the weights land in an owned registry alongside mirrors of every open release the program depends on, and the first evaluation suite runs on held weights before Christmas. The hedge works - a Christmas present.
Month 5
Done: the investment decision is signed, transformers ordered the same week, and Track B is live in Vienna before Christmas.
Open: transformers arrive 2029. GPU allocation is multi-quarter, behind contracts signed in 2024.
Who can move it: NVIDIA, the memory and packaging suppliers.
January 2027. The weights.
The next line item is a model to start from and the market for that item does not exist. The top tier is not offered as downloadable weights on published commercial terms. What exists is API access, managed sovereign-cloud arrangements, and prerelease access for "trusted partners" under American export discretion, the mechanism the Mythos letters demonstrated. There is no possibility that a European customer can buy those weights, which means, hold the thought until 2030.
One tier down, the picture looks better. Near-frontier weights are open, about four months behind the frontier on Epoch's index. Mistral is the frontier-adjacent European lab you can verify offering Large weights for deployment inside your own environment under commercial terms. It is not alone: Canada's Cohere offers private and on-premises deployment, and released Command A+ with downloadable weights under Apache 2.0. The European fact is important: the continent has a supplier from which durable custody rights can at least be negotiated.
The cost of downloading is zero, which is both the appeal and the trap: zero time needed, no guaranteed next version. The contract with Mistral you signed in December for Track B does more work than the word licence usually implies. For each delivered version it grants perpetual offline use, modification and audit rights, and operation without a vendor key server. The registry, release mirrors and the tooling to fork them if upstream stops are the cheapest insurance the program you will ever buy. Physical possession of a file is not custody if the contract can switch it off.
At the January board meeting a shareholder asks the obvious question: if the baseline is licensed and downloaded weights, why has nobody simply forked Qwen, put a European label on it, and handed it to every EU company at no charge? The question goes to Counsel and comes back the way counsel's work always does: two hundred pages of defined terms behind a two-sentence cover note. The cover note contains the answer; the defined terms explain the invoice.
The answer comes in three parts. First, under the Commission's non-binding guidelines, a modification using more than roughly one-third of the base model's training compute is an indicative threshold for you becoming the modified model's provider - that means liability.
Second, holding weights gives you continuity and allows far deeper inspection than an API. It does not prove provenance. The 2025 wave of DeepSeek bans, Commerce, the Pentagon, Italy's Garante, all targeted the hosted app, not self-hosted weights, so no law forbids forking. But frontier-lab research found that 250 poisoned documents could backdoor models from 600M to 13B parameters in a narrow denial-of-service experiment. The authors explicitly leave frontier scale and more harmful behaviours open. That is evidence of a supply-chain risk.
Third, the treadmill. The open frontier moves quarterly, so a fork is not a product but a verdict to do permanent rebasing. Nobody has funded your standing lab that such a way of working requires. There is simply no sovereign fork of a Chinese model anywhere, and the serious European open-model efforts, Poro, Viking, Teuken, Apertus, all chose to train from scratch instead. Cheap to start is not the same as cheap to stand behind.
Month 6
Done: near-frontier weights licensed, with perpetual offline use, modification and audit on every version delivered.
Open: the next version. Nobody owes you one.
Who can move it: Beijing, the foreign lab boardrooms, Washington.
February 2027. The printing press.
NVIDIA's answer to the allocation request arrives in February, and it is polite: your GPUs land in "quarters," plural. In allocation language, the plural is the schedule.
The board asks for the detailed version at the February meeting, so you give it to them, starting with what Europe actually holds. ASML is the only company on Earth that builds extreme-ultraviolet lithography machines, the tools every leading-edge AI chip requires; its market value crossed roughly $700 billion in June 2026, around three and a half SAPs, making it Europe's most valuable technology company by a multiple. The optics come from Zeiss in Oberkochen, the drive lasers from Trumpf near Stuttgart.
Its history is less European than its address. The machine descends from an American research program: EUV LLC, the consortium Intel organized in 1997 with Motorola and AMD around three US national laboratories, which built the first working EUV system and generated the foundational patents. ASML entered in 1999 as a licensee, on admission terms that required 55 percent American content and a US factory, conditions that were never enforced and quietly forgotten. The light source, the plasma heart of every EUV machine, is built by Cymer in San Diego, a company ASML bought in 2013. When Washington wanted a $150 million machine kept out of China in 2019, it needed no statute; a diplomatic campaign sufficed, and the Dutch export licence never came. In June 2026 the sequence repeated in miniature: the US Commerce Secretary personally questioned ASML's CEO about a rumored EUV machine in China, and Fouquet answered that no such machine exists there and never has.
Then the part the board actually asked for: between an ASML scanner and a rack of accelerators stand four industries, and Europe lacks a frontier-scale answer in each of those. Leading-edge fabrication: the TSMC-led fab in Dresden makes 12-to-28-nanometer automotive chips, generations from the edge, and Intel cancelled its Magdeburg fab outright in July 2025, releasing €9.9 billion in pledged German aid back into the void. High-bandwidth memory: made by SK Hynix, Samsung and Micron, none of it in Europe. Advanced packaging exists in Europe, but not the frontier-scale HBM-integrating CoWoS-class capacity the build needs; the industry's tightest bottleneck remains in Taiwan. Chip-design software: two American firms and a Siemens unit built on an American acquisition, all inside US export jurisdiction. Beneath all four sits the software wall: CUDA, twenty years old and, by NVIDIA's own count, some six million developers deep, a stack AMD has spent years failing to match with far more money than Europe has ever directed at the problem; alternatives exist, but no European project operates at comparable maturity. NVIDIA's research budget for its last fiscal year alone, $18.5 billion, runs roughly 250 times the European Processor Initiative's entire current phase.
The European counterexamples fit on one slide, one sentence each, which is itself the finding. SiPearl's Rhea1, the sovereign processor Europe has funded since 2018, taped out in July 2025, at TSMC. In JUPITER, Europe's flagship exascale machine, its 324 chips were still listed by the operating lab as not yet installed while the American CPUs in the same module were already going in, and the 23,536 GPUs doing JUPITER's actual AI work are NVIDIA's. Graphcore, once Europe's GPU hope, belongs to SoftBank and is building its next campus in Bengaluru. Axelera's EuroHPC-funded chiplet is for inference, in 2028. No European-designed accelerator is known to power a frontier-scale pretraining run.
The board takes it the way boards take weather reports. The advisor takes it as an opportunity.
He is not exaggerating. ASML put an official 851-piece LEGO model of its High-NA machine on public sale on 1 December 2024 at $227.95; within roughly three weeks demand had overwhelmed the store, ASML cancelled all non-employee orders, and the product page has been gone since. A fan has since reverse-engineered the machine from photographs and published free building instructions. The genuine article was real, world-leading and unavailable; what consumers could hold was a faithful reconstruction, built at home from a licence-free design. A Reddit thread titled the set "The pride of Europe". Nobody knew whether that was a joke.
Month 7
Done: nothing. The board now knows about Europe's relevance in the semiconductor supply chain.
Open: leading-edge fabrication, high-bandwidth memory, advanced packaging, design software and CUDA.
Who can move it: NVIDIA and BIS directly; TSMC, the HBM makers and Taiwanese packaging.
Spring 2027. The people who have done it before.
Your recruiter's report lands in March. It reframes the problem. The scarce resource is not machine-learning PhDs; Europe produces those at world class. It is scar tissue: the people who have shipped a frontier run end to end, the pretraining, the reinforcement learning, the evaluations, the interpretability work, and that population numbers in the hundreds worldwide. Of the field's top researchers, 59% work in US institutions, and the flow is one-way. Nobody has publicly counted how many of them sit in Europe. The continent's most strategic resource for this build is a population it has never measured.
The wall has one demonstrated lever: capital is upstream of talent. When Yann LeCun founded AMI Labs in Paris with a $1.03bn seed round in March 2026, reported as Europe's biggest-ever seed, a frontier research team assembled around it within months. Mistral had already proven the pattern: founders out of DeepMind and Meta's FAIR lab, moving frontier knowledge into a Paris company.
Your hiring plan has three layers.
- The school: hundreds of graduates a year from ETH, EPFL, Oxford, Cambridge, TUM, LMU, Tübingen, INRIA, Amsterdam, Warsaw; the ELLIS network alone put over 200 papers into NeurIPS 2023.
- The team: twenty to fifty shipped practitioners, poachable over two to four years from DeepMind London, FAIR Paris, and the Mistral and AMI talent networks, who train the graduates the way Black Forest Labs grew out of LMU Munich's computer-vision group.
- The backbone: the two to five marquee scientists who make the whole organisation worth joining. AMI happened because LeCun; Mistral because Mensch, Lample and Lacroix. A consortium that fails to land its anchors does not hire slowly. It fails.
You spend the spring doing the things a plan can actually do. You put the research office in Paris, walking distance from the talent pool. You set compensation off the AMI market, not off a Brussels salary band. And you place two calls to two marquee names, offering the one thing the incumbent labs cannot: a mandate with a balance sheet behind it and no workshare committee above it. On this story's charitable clock, one of them says yes in the autumn. And meanwhile good fortune: twenty hires, evaluation, assurance, security engineering, come out of the ordinary European market inside the year.
Month 9
Done: the research office is in Paris, pay is set off the AMI market, twenty hires have landed.
Open: Nothing at the moment.
Who can move it: a few hundred people, choosing where to work.
Summer 2027. The second memo.
The first counsel memo answered why nobody forks Qwen. The second, commissioned after a board retreat, answers the broader question: what does the law you are building under actually demand. The findings sort into three groups: a narrow comfort, a trap and a myth.
The comfort sits in Article 2(3) of the AI Act. The Act does not apply to AI systems insofar as they are placed on the market, put into service or used exclusively for military, defence or national-security purposes, regardless of the type of entity. That comfort only covers those deployments; it does not convert critical infrastructure or foundational science into defence. Your Counsel treats these obligations on the underlying general-purpose model as a separate question. Recital 24 is use-specific: military-built software used for a civilian purpose falls inside that use, while civilian software later used for defence remains outside for the defence use. So you are out and back in.
The trap concerns everything the consortium does that is not exclusively defence, and the underlying model itself. The Commission's FAQ says an own general-purpose model used for purely internal processes can avoid being treated as placed on the market only if those processes are not essential to a product or service for third parties, no natural person's rights are affected, and the model is not one with systemic risk. Your frontier run is planned orders of magnitude past the 10²⁵-operation presumption. Your Counsel treats the internal-use route as closed unless the consortium successfully denies that systemic-risk classification. The model is too large to be nobody's business, even with no customer and no public API. The Counsel adds supplying the model to a member that is a separate legal person is at least presumptively "making available".
The myth is escape. The naive version says a serious lab would simply train in Switzerland or London and spare itself the chapter. Counsel's annex on this is one page: the Act attaches at the EU market, not at the training site, and a foreign provider needs an authorised representative in the Union like any other manufacturer. Apertus, trained entirely on Swiss soil with no EU obligation whatsoever, states in its own release that it was built with due consideration to the Act's transparency duties, machine-readable opt-outs respected in the pipeline.
The memo's last page holds the year's quiet irony. The Digital Omnibus, the simplification package Brussels celebrated in the summer of 2026, deferred the high-risk rules to late 2027 and 2028 and granted watermarking a grace period; the general-purpose-model regime it left exactly where it was: enforcement and fines live from 2 August 2026. The relief went to someone else, but you. For a frontier builder, the calendar did not change. Behavior around the voluntary Code of Practice tells you who has priced this in: twenty-three signatories including Mistral, Aleph Alpha and Black Forest Labs, both of Europe's frontier seats among them; xAI signed the safety chapter alone, electing to prove transparency and copyright compliance by other means; Meta's name is simply absent from the list.
The memo concludes on a distinction the board debate missed. The AI Act is not a licence you apply for; it is a set of records you either kept from the first training run or did not. Training-data provenance, evaluation logs and copyright documentation cost little when they are generated as you go, and are close to unrecoverable four checkpoints later. That is why the compliance line in your budget sits under engineering rather than legal, and why it does not move when Brussels adjusts a deadline.
Month 12
Done: the records are kept from the first run.
Open: enforcement, live since August 2026, and a systemic-risk classification you cannot argue your way out of.
Who can move it: the EU AI Office, and the courts.
2028. The corpus, against your own law.
The data team's year is spent on a wall a European builder faces in a very distinctive form: assembling a frontier-scale corpus that is legally usable in Europe. American labs generally train while asserting fair use, an argument still being tested in court; China's copyright law has no express AI-training exception and its treatment remains unsettled. Europe gives you an explicit text-and-data-mining framework, but the DSM directive's machine-readable opt-out is one publishers can exercise, alongside GDPR and the AI Act's training-data transparency duties. This is the input where EU's own regime is the binding constraint. Operationally it becomes a licensing and provenance program: negotiate, document, filter, prove. Every document meets the Counsel before it meets the tokenizer.
What "legally usable" means is itself in motion. Two German decisions illuminated different layers five weeks apart. Munich's regional court found against OpenAI in November 2025, holding that a model's memorization of nine song lyrics is a form of reproduction the text-and-data-mining exception does not cover. Hamburg's higher regional court sided with LAION in December 2025: creating a dataset for possible training can fall within the exception when opt-outs are machine-readable, with the burden of proof on the rightsholder. The federal court's hearing in the LAION case is scheduled for 3 September 2026. They are not opposite answers to one clean question; together they show why ingestion, memorization and output need separate controls. Your data team reads the Munich ruling twice. Deduplication and anti-memorization stop being engineering hygiene and become legal controls.
Copyright clearance still does not make personal data lawful. The European Data Protection Board's Opinion 28/2024 makes anonymity, legitimate interest and the consequences of unlawfully processed training data case-specific. Your team therefore needs lineage down to source classes, a defensible lawful basis, deletion and objection handling, and an early relationship with its lead data-protection authority. The copyright lawyer tells you whether you may copy the document. The privacy lawyer asks whether the person allowed it.
It can be done, at least at the scale where it has been tried. Apertus, trained by ETH Zürich, EPFL and the Swiss national supercomputing centre on public infrastructure, shipped in September 2025: 8B and 70B models, Apache 2.0, roughly 15 trillion tokens across more than 1,000 languages, with the data pipeline documented end to end and framed explicitly around European compliance. Note: the cleanest proof that a compliant sovereign model is buildable came from Switzerland, outside the Union. And note the scale: proven at 70B. Nobody has proven it at frontier scale. You budget three years and start signing licences.
Your hedging track outgrows its colocation cage the same year, but only after the workload exercise begun in December: which systems must survive, their peak tokens per second, latency, redundancy, classification and recovery targets. The first expansion stays in contracted colocation and brownfield capacity on Upper Austrian hydro; a new grid connection can queue at this scale too. Google is building a 185-acre AI campus at Kronstorf, and APG is spending €3.5bn on the grid, which proves the corridor can host density, not that spare capacity waits for you.
Year 2
Done: the licensing and provenance program is running. Deduplication and anti-memorisation are legal controls now.
Open: a lawful frontier-scale corpus.
Who can move it: rights holders, the lead data-protection authority, and the courts.
2029. The drill.
The mandate comes from the board. The July 2026 mandate specified sovereignty is specified like an uptime guarantee against a threat model. At the spring meeting the defence-ministry shareholders ask the question every uptime guarantee eventually faces: prove it. There is no decision, just execution on Track B - the post-trained model.
Your Legal Counsel supplies the standard from the only European rulebook that has one. DORA, the banking regulation in force since January 2025, does not accept an exit strategy that has never been tested, and in November 2025 the supervisors designated nineteen critical IT providers, AWS, Google Cloud, Microsoft, Oracle and SAP among them, that banks must demonstrably be able to leave. The board votes the same discipline: So for one week in 2029, a red team plays Washington and Beijing at once: a letter gates the top American tier, and the Chinese releases stop appearing upstream of the registry mirrors. Seventy-two hours, production systems, no advance warning to the teams.
Two elements of that rulebook complicate the exercise: Not one of the nineteen designations concerns AI-model supply, and the term "foundation model" appears nowhere in the regime. Google and Microsoft are designated as clouds, not as enterprise backbone; Europe's dependency law was written for infrastructure and ignores model sitting on top of it. The ECB's 2024 stress test made 109 banks practice a database breach, and the Bank of England practices settlement failure; No public exercise in any sector that simulates withdrawal of a model provider. So, you are not copying a best practice. You are inventing one, with the enthusiasm of someone who would have preferred to copy.
Under the exercise assumptions, the rented tier degrades first and then completely: every workflow routed through the gated American APIs to Anthropic or OpenAI is unreachable by the afternoon of day one, and the drill grants notice periods that the real letters of June 2026 gave nobody.
Track B holds. What breaks is everything the consortium never controlled, and the report says so in procurement language: single-source dependency, no tested exit, and, in its sharpest line, no denominator. Nobody publishes what share of European AI actually runs on the American tier; the statistic everyone quotes is a survey of US enterprises. Europe has not measured the dependency it debates.
Italy supplied the drill's substance from real life. When the Garante blocked DeepSeek's data processing in January 2025, the company, with no European establishment, simply stayed reachable, and the regulator ended up writing to Italian internet providers for help, a step Italian privacy lawyers called unprecedented. Withdrawal is orderly when the vendor cooperates and improvised when it does not. Your exercise assumes the second kind.
Year 3
Done: the drill. Seventy-two hours, no warning. Held weights carried the workloads pre-qualified for them.
Open: provenance.
Who can move it: the consortium.
2030. The datacenter is powered up. Now, can you trust it?
The transformers you ordered at inception are on installed at last. Racks are landing, and burn-in will take six to nine months, because you are not NVIDIA's priority customer; Colossus's nineteen days from first rack to training remains the exception that proves what priority looks like. While the machines warm up, the charter's first clause comes due: defence, intelligence and critical infrastructure, running on AI no foreign decision can abruptly withdraw.
Those workloads need what the safety field calls a control stack. Google DeepMind's roadmap gives the design assumption: treat advanced agents as untrusted insiders, then layer sandboxing, permissions, monitoring, response and shutdown around them. Anthropic's interpretability work published this July shows the experimental deep end: an imperfect lens into a model's internals that surfaced evaluation-awareness and deceptive intent in selected tests. It needed white-box access.
That is what an API cannot give you. A tenant can sandbox tools, restrict permissions, log actions, run black-box evaluations and shut down its own integration. What it cannot do is inspect activations, validate the delivered artefact or reproduce the runtime.
Track B has spent three years building the wrapper controls and the deeper tests together. You can apply the same to track A. But, that still does not certify every strategic workload: the highest-provenance tier needs training disclosure, audit rights and eventually the European-from-scratch fallback.
Year 4
Done: the wrapper controls and the deeper tests, built together over three years.
Open: assurance never closes, and the highest tier needs training disclosure and audit rights.
Who can move it: you, for everything you can inspect.
March 2031. First training token.
On the most charitable reading of every queue, this is the quarter your first frontier-scale pretraining run starts on your own GPUs. You remember what went right: RTE has delivered megawatts at the site; the transformers have arrived at the three-year end of a three-to-five-year quote; the allocation from NVIDIA has come through; the leading scientists have said yes. Each was plausible. The calibration is that 2031 is the best possible scenario. You know that a more realistic path starts in 2033 to 2036.
You try to be precise about what waited and what did not. Model development, the recipe, the team, the post-training craft, started in 2026 on rented compute; what waited for the metal was frontier-scale pretraining.
The run you start, 10²⁶ to 10²⁷ operations, is roughly the frontier scale of 2027: four years behind at startup. Epoch's central 2030 projection puts the live target near 2×10²⁹ operations and six gigawatts, on a cluster costing more than $100bn. If scaling flattens or efficiency compounds faster than cluster size, you may arrive somewhere relevant. If it does not, you have built sovereign renewal capability without catching the live frontier.
Year 5
Done: the run starts. Power, transformers, allocation, team and corpus have all landed.
Open: the training run itself.
Who can move it: the machine.
2032. Qualified deployment.
A first training token is not a model. The run has to finish without a restart, the model has to survive post-training, capability and safety evaluation, red-teaming, accreditation and production-inference burn-in. Realistically you budget another year. The earliest qualified deployment is therefore 2032. The first run is a project. European sovereign capability is the cadence that can fund and execute the second one.
Some might say what was achieved is only custody, operational continuity and model-training capability, not full-stack sovereignty: every hardware refresh still depends on NVIDIA and BIS, TSMC, HBM, packaging and a software stack Europe does not control.
Two footnotes: The one delivered European compute win of these years, JUPITER, the exascale machine ranked #5 on the TOP500 list in June 2026, came from EuroHPC, a vehicle two decades in the making; every new sovereignty-branded instrument, the gigafactories, the Act, the Competitiveness Fund, was still pre-tender or pre-enactment in August 2026. And the AI Act, whose evaluation and red-teaming duties are the right duties, presumes systemic risk at 10²⁵ operations, one order of magnitude below the 10²⁶ line in Washington's short-lived 2025 export framework. The Act also demands information an API tenant cannot independently verify, which after six years you can appreciate as its own small tragedy.
Track B barely disturbed the story because its problems were smaller, not nonexistent. Its weights and durable rights were secured before the program's first Christmas; its twenty hires landed inside the first year; its capacity grew from measured workload demand; and its continuity-qualified workloads sailed through the modeled drill.
Four build gates decided whether the run could start: an institution that could decide and fund repeated runs; a site that could take power and hardware; a team that could train on a lawful corpus; and an armada of licenses for training data. Qualified deployment then added evaluation, red-teaming, accreditation and production burn-in: Renewal makes the funding and foreign-hardware gates permanent. Track B's ledger fits in one line: held weights under audit before the first Christmas, then continuous proof that the workloads assigned to them still fit.
The End.
Year 6
Done: a qualified sovereign frontier-scale deployment — 2032.
Open: 2034 to 2037 on the default path, into a frontier that may already be 10²⁹ operations, multi-gigawatt and $100bn-plus.
Who can move it: every hardware refresh still runs through NVIDIA and BIS, TSMC, HBM and packaging.
What the EU can realistically achieve
The constructive answer comes in three parts. The first part answers "what keeps selected strategic workloads running if access stops." The second part answers "where the EU can still lead." The final part answers "how can we ensure continuity"
What keeps EU AI workloads running?
You have read how the baseline get built. It is two commitments.
First, post-trained weights with durable offline rights and capacity sized for workloads that cannot tolerate a cut-off: near-frontier models we can license or hold, mirrored and forkable.
Second, a maintained, independently auditable Europe-trained model with corpus and process attestations, because a foreign base can provide continuity without proving how it was trained.
July's Soofi audit showed the missing pieve: the finding was an afternoon's work for one outsider with a coding agent, and no European institution had done it first. Apertus shows that a compliant, documented model on public infrastructure is buildable. Mistral shows that a frontier-adjacent European lab can license weights into sovereign environments.
Track B's Austrian geography was no accident; it is where I live. A country with no nuclear plant. Zwentendorf built and never switched on. Hydro power plus existing colocation, is enough to start. What is missing is mandate and maintenance money: the EU's much-cited "€2bn for open source" is an indicative budget across all open-source activities, of which the maintenance instrument is roughly €350M. None of it is enacted; the academic EuroLLM line, at up to 22B parameters, is respectable but far from a strategic.
Dear EU, budget the baseline like the insurance it is. It costs a rounding error of one gigafactory and can be running this year.
Where the EU can still lead?
The frontier seats are exactly two.
- Image: Black Forest Labs in Freiburg, grown directly out of LMU Munich's CompVis group, raised $300M at a $3.25bn valuation in December 2025, with FLUX.2 ranked second on the image leaderboard at launch; checking the same leaderboard the week I write this, newer American releases have pushed it out of the top five. Eight months from second place to outside the top five is the moving-goalposts lesson in miniature, and an argument for backing the seat, not resting on it.
- World models: Paris hosts two funded bets, AMI Labs' $1.03bn seed and Kyutai, launched with nearly €300M, which released the MIRA world model this month. The grade: a real seat at a frontier that has not hit its compute wall yet, a timing advantage, not an exemption.
How we can ensure continuity?
If the EU wants frontier, the governance answer was the first scene: one company, one balance sheet, the Airbus shape and not the FCAS shape. The price should be stated without anaesthetic: guaranteed compute and offtake, compensation set off the market, a workable data regime, recurring hardware refresh and training budgets, and a ten-year horizon that survives the first failed run. Financing the first token finances a demonstration; the program lives or dies on the second machine and the second generation of the model. Underneath it all sits the only rational strategic bet available: that scaling flattens enough for the program to arrive somewhere relevant, which is precisely the bet Airbus made on a stabilizing jet market.
Dear EU, make that commitment to one accountable entity, Mistral-shaped or BFL-shaped, or stop announcing gigafactories. Both are defensible positions. The current middle, tenders that slip while commitments multiply, is not.
The build chain, answered
The walkthrough exists to be entertaining. The topics it adresses are the ones I actually get asked and which are frequently discussed in the media.
| Layer | The question everyone asks | The short answer | Scene |
|---|---|---|---|
| Governance | Why not make it another consortium? | Because workshare and national vetoes turn the build into FCAS. The viable shape is one company, one balance sheet, an independent board and ten-year offtake commitments that survive elections | Jul 2026 |
| Energy | Europe has electricity, why not just plug in? | Grid queues run 7–13 years in the legacy hubs; the Netherlands restricts hyperscale projects to two zones and Frankfurt is effectively closed until 2030. Firm nuclear and hydro narrow the search, but Gravelines only works if RTE grants the connection | Nov 2026 |
| Buildings | Isn't the data centre the hard part? | No. Proven European contractors deliver a 150–300 MW shell in 18–24 months; of a six-to-ten-year default path, only about three years is construction. It is the easy 20% | Dec 2026 |
| Public compute | Why not train on JUPITER or Leonardo? | They are shared science instruments: Leonardo runs two-generation-old A100s, and access comes as allocations that top out at a few million GPU-hours a year. A frontier pretrain wants ~200 million, exclusively; the record public grant, Apertus, got ten million | Sep 2026 |
| Buying chips | Why not just buy the GPUs? | At 100,000 GPUs you do not buy, you negotiate allocation with NVIDIA, behind long-term agreements signed before; AI-class memory was sold out for 2026 and nearline drives allocated into 2028 | Dec 2026 |
| Making chips | We own ASML, why not print our own? | A scanner is not a fab. Europe has no leading-edge fab (Dresden is 12–28 nm, Magdeburg was cancelled), no HBM, no frontier-scale HBM-integrating packaging capacity, US-controlled design software and no accelerator stack at CUDA's maturity; no European-designed accelerator publicly powers a frontier-scale pretrain | Feb 2027 |
| Weights | Why not buy the model, or fork Qwen? | Top-tier weights are not publicly offered; near-frontier weights are. The Commission's one-third-compute threshold for a modified model is indicative and creates liability. The harder problems are durable custody rights, provenance and funding the permanent rebase treadmill | Jan 2027 |
| People | Doesn't Europe have brilliant AI researchers? | Graduates, at world class. The population that has shipped a frontier run numbers a few hundred worldwide, 59% of top talent works in US institutions, and nobody has counted Europe's share | Spring 2027 |
| Data | Can you even train legally in Europe? | Apertus proves a documented 70B model and 15-trillion-token pipeline, from Switzerland. Frontier scale remains unproven; copyright, memorisation and GDPR create distinct controls and legal gates | 2028 |
| Law | Doesn't the AI Act kill it anyway? | No. Exclusive military and national-security system use sits outside; civilian use and the underlying general-purpose model still need analysis. Above 10²⁵ FLOPs, the internal-use route presumptively closes unless the systemic-risk classification is rebutted | Summer 2027 |
| Capital | Who pays? | Pension funds put 0.02% of their €2.7tn into such asset classes; insurers face separate Solvency II rules; foreign LPs need to pour cash into European vehicles. The real package also needs decade-long public offtake, state-aid and foreign-subsidy clearance, FDI screening and ring-fenced non-EU capital | Dec 2026 |
| Assurance | If the API works, why does holding weights matter? | API tenants can sandbox, monitor and test externally. If you hold the weights you add the ability to artefact validation, reproducible runtimes and experimental internal inspection; training provenance still requires disclosure and audit rights | 2030 |
| Continuity | What actually breaks if access stops? | In the modelled drill, API-only workflows fail by lunch; pre-qualified EU-held-weight workloads continue. | 2029 |
| The clock | So when does Europe deploy its own model? | Training starts in 2031; qualified deployment follows in 2032, or 2034–37 on the default path. It is frontier-scale capability, not necessarily the live frontier | 2031–32 |
| Sustainment | Isn't one successful run enough? | No. A sovereign model is a project; sovereign capability is a cadence of hardware refresh, repeat training, failed-run capacity, evaluation and accreditation. Every refresh remains exposed to foreign chips and software | After 2032 |
Most people reading this run companies, not the EU. So these are my recommendations:
- Treat frontier-model supply as concentrated external dependency, and classify workloads by what breaks if access is throttled by a foreign state actor.
- Move the critical workloads onto models held under perpetual offline-use, modification and audit rights.
- Write a model-exit plan the way DORA already makes regulated firms write cloud-exit plans, and test it. Put weight portability and weight escrow on the procurement questionnaire.
- Build the evaluation capability this quarter, before a forced migration happens.
The consortium is invented, but every constraint is real. What remains is the difference between the EU announcing intent and funding it continuously. Armin's four words were the right instruction. Europe, please wake up. You can't rent a frontier.
I write about the intersection of technology, sales and management in Europe, and this piece continues an argument from my post on the Cloud and AI Development Act. If you're wrestling with model-supply risk in your own architecture, or you read the ledger differently, I'd genuinely like to hear it: find me on LinkedIn or write to kontakt@richard-stahl.at.
Occasional notes on technology, Europe, and whatever else has my attention. No spam — unsubscribe anytime.
Member discussion