
Beyond Sovereignty: France Reframes Digital Dependencies as an Economic Security Issue
July 21, 2026
On 15 July, the French National Assembly the conclusions of its inquiry committee on digital dependencies and systemic vulnerabilities in the digital sector. The diagnosis is now difficult to ignore: France remains heavily dependent on non-European providers for a significant share of its digital infrastructure, software, cloud services and artificial intelligence (AI) capabilities. However, its central message is not that France can or should eliminate all non-European technologies from its digital stack. It is that this unmanaged dependency has become a strategic vulnerability for the state, the economy and critical services.
This is not an entirely new concern. This diagnosis echoes the Senate’s 2025 on public procurement. The Senate inquiry approached the issue through the lens of public spending and purchasing practices, highlighting the gap between the French administration’s stated sovereignty objectives and the reality of procurement decisions.
The Assembly’s report goes beyond. It shifts the debate from compliance and procurement discipline toward resilience and strategic autonomy. Its recommendations combine governance measures, procurement requirements and more interventionist industrial-policy tools, from support for open source to stronger safeguards around strategic assets.
Taken together, the two reports suggest that France’s digital sovereignty debate is entering a more pragmatic phase. Less about drawing a binary line between whether a solution is simply “sovereign” or “non-sovereign.” It is which dependencies are acceptable, which must be reduced and where credible European alternatives are needed.
For many companies operating in France, this matters. This matters because the political question is no longer whether they can claim to be sovereign in abstract terms. It is whether they can demonstrate that their technology choices are open, competitive, able to avoid vendor lock-in and capable of creating value within the local ecosystem.
From Data Access to Service Continuity
The more consequential shift sits in what kind of risk the Assembly’s report is willing to name. Since the Snowden disclosures, much of the French sovereignty debate has run on one question: ”Who can read our data?” SecNumCloud, General Data Protection Regulation enforcement, and the clauses in both reports all answer that question. Another question is on the table: ”Can a foreign government simply switch a service off?”
The Assembly’s report puts that second question on the table for the first time in a French parliamentary text. First, it cites Microsoft’s own disclosure of 5,587 U.S. data-access requests in the second half of 2025. It also highlights two important cases that have nothing to do with data access but are equally demonstrating:
Neither case involves a data request. Both involve a foreign government stopping access to a service outright.
That distinction did not appear in the Senate’s report, and it could not have, since both episodes postdate it by close to a year. The Assembly is describing a different kind of risk, based on evidence the Senate simply did not have.
The world is rarely the same as it was a year before and the Assembly’s analysis is describing a different kind of risk, in which access to critical digital services can no longer be treated as politically neutral.
A company can hold full SecNumCloud certification and still have no complete answer to the continuity question. Certification can address data protection, operational security and exposure to extraterritorial law, but it does not, on its own, guarantee that a critical service will keep running if access is disrupted by a foreign government decision.
Where the Report Stops Short
The Assembly frames digital dependency primarily as a strategic vulnerability rather than as a purely technological or commercial issue. In that respect, the report moves beyond a simple sovereign-versus-foreign divide. At the same time, some of its flagship recommendations, including a “Zero Microsoft” policy in schools, a target of 100% open-source software procurement in the public sector by 2030 and state golden shares in strategic technology companies, reflect a more interventionist vision of digital sovereignty. The report therefore sits at the intersection of two approaches: one focused on identifying and reducing critical dependencies, the other on reshaping market incentives in favour of European alternatives.
This logic can be taken further by assessing dependencies segment by segment across the digital value chain. In some areas, credible European alternatives already exist and the challenge is one of adoption, procurement and scale. In others, particularly in active network equipment, critical software layers, advanced semiconductors or certain cloud capabilities, the priority may be less to substitute immediately than to reduce exposure, diversify suppliers and preserve room for manoeuvre.
The Assembly report does not yet reach that level of granularity. It tends to treat cloud and AI dependency as a single policy question, drawing heavily on Union des Groupements d’Achats Publics (UGAP)—France’s national public procurement agency—data. This is a useful indicator of national public procurement patterns, but it remains only one part of France’s broader digital dependency landscape. Other layers of the value chain, from network infrastructure and hardware to satellite connectivity, receive far less attention, even though they are central to any operational assessment of strategic autonomy.
For companies in France, this scope gap should not be dismissed. A report based on a partial view of the market can still shape the next phase of policy debate, especially if its findings are translated into future budget measures, procurement rules or cybersecurity and resilience legislation.
The immediate question is therefore not whether each of the Assembly’s recommendations will become law. Many may not, at least not before 2027. What matters is that the report is likely to shape the language of future budget, procurement, cybersecurity and resilience debates. For digital providers, this means the sovereignty conversation will increasingly move beyond legal compliance and data localisation. As France approaches the 2027 presidential election, digital sovereignty is emerging as a cross-cutting economic security issue, likely to influence debates on public spending, competitiveness, taxation, industrial strategy and geopolitical resilience. The significance of the report lies less in any individual recommendation than in what it reveals about the direction of travel: digital dependencies are no longer being treated as a technology policy issue alone, but as a factor shaping France’s economic resilience, strategic autonomy and long-term growth model.