Are we worried about the wrong technology risks?
Everyone is asking the same questions about artificial intelligence at the moment: what will it do to our jobs, our decision-making, the way we work. Let’s face it, pretty much everything about AI is uncharted waters, but I do think there are other concerns, just as material, off on the sidelines that we should be talking about more.
I worry about access and dependency. What happens if the digital tools that we take for granted simply stop being available, but not (as you might assume) because the technology fails. It’s more about data concentration, territorial reliance and uncertainty. I wonder which jurisdiction might be giving everyone pause in this scenario?
Europe Is Thinking Ahead
Across Europe, governments and institutions are actively reducing their dependence on US technology providers, and the scale of change is by no means small.
Austria's military has already completed its move, migrating all 16,000 workstations from Microsoft Office to LibreOffice, with officials framing the change explicitly around resilience, the need to keep functioning even if foreign-controlled software became unavailable.
Denmark's Ministry of Digital Affairs is partway through the same shift for its own staff, with its Digital Minister explaining the logic bluntly: "We must never make ourselves so dependent on so few that we can no longer act freely."
France has gone further in ambition than either. In February 2026 it mandated that Visio, an open-source video conferencing tool, replace Zoom, Teams, Webex, and GoTo Meeting entirely by 2027. In April 2026, it ordered every government ministry to draw up a plan for eliminating dependence on Microsoft entirely, across 2.5 million desktops, the largest such undertaking any European government has attempted. A full migration is expected to take years, but the direction has been set at the highest level of government, and the language used to justify it, regaining "control of our digital destiny", is telling.
In January 2026, the European Parliament voted 471 to 68 in favour of a resolution on European technological sovereignty.
Much of this is being driven by the US CLOUD Act, a law that allows American authorities to compel US companies to hand over data they hold, regardless of where in the world that data physically sits. But the Act itself isn't new, it's been on the statute books since 2018. What's changed is Europe's confidence that it would stay unused. There’s new willingness to take the threat exposure seriously. Watching it, and powers like it, get exercised has persuaded Europe that “it hasn't happened yet” is not a prudent basis for the status quo.
Shifting Expectations
The assumption that the status quo is, well, stable and that US regulatory bodies sit meaningfully outside political reach has, in several places, turned out to be flawed. The recent confirmation by the Supreme Court that the commissioner terminations at the FTC stand (raising questions over the Data Privacy Framework's legal footing) and the sudden use of export control powers over Anthropic’s Fable 5 and Mythos 5 are cases in point. Powers and authorities previously used sparingly as a matter of convention are being flexed.
A Case in Point
On 12 June 2026, the US government issued an export control directive suspending access to Anthropic’s Fable 5 and Mythos 5, for any foreign national, wherever in the world they were based. The stated justification was a disputed cybersecurity concern, a jailbreak risk Anthropic publicly pushed back on as overstated.
What this example shows is unsettling: the power to (in this case) suspend access to a specific AI model, for reasons a foreign business has no visibility into and no say over, exists and has now been used. It’s a relatively constrained example in terms of consequences; Fable had only been rolled out to the public three days prior to the suspension and access was restored three weeks later. But what the example highlights is the potential for real harm when a single sovereign power can trigger catastrophic, wide-reaching consequences beyond its own borders, for any country that has built critical reliance without any corresponding control.
What if next time it was all AI models, or just most AI models, or only the model you'd installed to monitor your nuclear plant's safety systems?
Why AI Is a Different Kind of Dependency
The migration away from Microsoft has a relatively comfortable ending in sight, the alternatives might be a patchwork solution, but they work, and public bodies across Europe are able to roll them out at scale. If Microsoft became unavailable to a European government tomorrow, there is a credible, tested alternative sitting ready.
AI doesn't have that yet. Europe isn't without its own efforts, France's Mistral AI and Germany's Aleph Alpha are companies building genuine frontier-adjacent models. But neither currently operates at the same capability tier as the leading US labs, and Europe and the UK simply don’t have the current data centre capacity to compete at that level. If a European business or public body has built something important on a frontier US model, there usually isn't a European equivalent sitting in reserve, ready to take over.
Office software is a mature, commoditised category with workable substitutes on the shelf and it runs on nothing more than commodity hardware, no data centre required. Frontier AI capability is concentrated, in a small number of labs, nearly all of them American, and that concentration is exactly what makes the potential for future export-control type episodes alarming.
What’s the take-away for business?
This is not a boycott manifesto or a scare piece.
For most businesses, walking away from the most capable tools available isn't a serious strategy. Most of the SMEs I work with are only just getting to grips with how to wrangle AI, let alone deciding whether it is a good fit for their business.
It’s a manifesto for keeping a wider risk awareness than the narrow field of reporting in the news. Yes, the advent of AI may well completely change the fundamental architecture of the working environments that have been in place for decades. But that shouldn’t be the only concern you grapple with.
It is a case for knowing exactly what you're dependent on, understanding what is in your control and what the potential exposure might be should the worst happen. Treat it the way you'd treat any other single-supplier dependency in a critical part of your operations: understand where the exposure sits, have some sense of what you'd do if access disappeared without warning, and revisit that plan periodically rather than assuming today's arrangement is permanent.

