If you had said, a few years ago, that European governments would start ripping American software out of their offices on principle, you would have sounded paranoid. In 2026 it is just the news. This shift did not appear from nowhere, and it is worth understanding the arc, because it explains a lot about why so many European companies now draw a line around their most sensitive data.

It started in a courtroom

The turning point most people can name is Schrems II, the 2020 ruling from the EU's top court that struck down the main legal bridge for sending personal data to the United States. The court's problem was structural, not petty: US surveillance law let American agencies reach data held by American providers, and a European whose data got caught up had no real way to object. That mismatch has never been fully resolved. Each replacement arrangement has been challenged, and the current one sits on the same fault line as the two that fell before it.

Then people read the fine print

Underneath the court case was a quieter realisation about the US CLOUD Act. In plain terms, it can compel American providers to hand over data they hold, even when that data is stored on servers physically located in Europe. Read that twice. Your data can sit in a data centre in Frankfurt or Stockholm and still be reachable under a foreign law, because the company holding it answers to a foreign government. For a hospital, a ministry or a bank, that is not a comfortable footnote. It is the whole problem.

2026 is when talk turned into moving vans

For years this was a debate. Recently it became action. In June 2025 Denmark's digitalisation ministry announced it was moving off Microsoft software toward open-source alternatives, citing sovereignty and cost, as reported at the time. The German state of Schleswig-Holstein set out to shift tens of thousands of machines to Linux and open tools, as the trade press covered. And in May 2026 the Swedish government adopted its first national cloud policy, stating outright that the country is too dependent on suppliers outside the EU. The European Commission followed with a proposed Cloud and AI Development Act built around the same worry.

None of this is anti-American, whatever the headlines suggest. It is about control. A country or a company that cannot function without a supplier it does not govern has handed away something important, and after five years of unease, a lot of Europe decided to take some of it back.

Where AI walked straight into it

Here is the irony. Just as Europe grew wary of sending sensitive data to foreign clouds, along came a technology that wants to send it all: prompts, documents, context, the lot, straight to a provider's model. Adopting cloud AI carelessly undoes years of careful work on data transfers in a single procurement.

Which is why running AI locally is not really a fringe stance any more. It is the same instinct that is moving government offices to open source, expressed at the level of a single tool. Keep the capability, keep the data at home. We happen to be a Swedish company that built AI this way from the start, so we are not surprised the continent is arriving here. We just got here early.