European AI sovereignty was the conversation nobody at TechBBQ in Copenhagen could stay away from this week, on stage, at the rooftop bars, in the hallway between panels. Emad Mostaque, who co-founded Stability AI and now runs something called Intelligent Internet, told a room there that sovereignty is “the ability to resist power being exerted over you,” and that inevitably “every country will be run by AI” because “the person that controls the AI controls the country.” That’s a heavy claim for a Nordic startup conference wedged between a panel on women’s health and a rooftop barbecue sponsored by Nvidia and OpenAI, and TechCrunch’s write-up of the event makes clear Mostaque wasn’t an outlier. Every conversation there, according to the reporter who sat through most of them, kept circling back to the same question: who actually controls the AI Europe is building its economy on.

The reason this felt urgent in Copenhagen and not, say, a year ago, is Anthropic. Two of its models, Mythos and Fable, went dark for everyone outside Europe earlier this year over a citizenship-verification dispute, switched off inside a single day by a company most of those users had never seen make a decision about them personally. One startup executive at TechBBQ told the TechCrunch reporter the incident wrecked his software team’s week. Another shrugged, because for now everything’s still mostly fine. Both are reactions to the same event, and the gap between them is the whole European AI sovereignty debate in miniature: everyone agrees the risk is real; nobody agrees it’s urgent enough to change what they’re building on.

Here’s what bothers me about a room full of smart, well-connected people treating this as a conversation still worth having in the present tense. The infrastructure decisions that would actually answer Mostaque’s question were already made this year, mostly in the other direction. Mistral, the company Paris and Brussels spent three years holding up as proof Europe didn’t need to rent its intelligence from anyone, started hosting Z.ai’s GLM-5.2 unmodified on its own platform this month, a Chinese model running with zero European contribution beyond the GPUs underneath it, because its own CTO said there was “no good reason for us not to do it.” AXA spent two years building SecureGPT, an actual sovereign gateway with prompt anonymization and full audit logging, then rolled out Microsoft 365 Copilot on top of it anyway, routing special-category insurance data through an ambient semantic index sitting on US-controlled infrastructure the CLOUD Act can reach. Denmark’s own sovereignty project, built on the Gefion supercomputer, turns out to be a drop-in OpenAI-compatible router rather than anything that touches the model or the compute underneath it.

None of that is a scandal exactly. Every one of those companies made a rational, defensible commercial call given what their own customers will actually click on. But it means the sovereignty Mostaque described from a stage, the kind where Europe resists power being exerted over it, keeps losing to the sovereignty that actually gets funded, which mostly amounts to a jurisdiction stamp on a building that still runs someone else’s weights through someone else’s cloud. The clearest number I have for that gap is almost comically direct: Alibaba raised $10.2 billion in a single afternoon this month, more than the entire public funding envelope for all seven of the EU’s AI gigafactories combined, and that was one Chinese company topping up a quarter of compute, not a sovereignty initiative of any kind.

I don’t think the TechBBQ conversation was wasted air, for what it’s worth. Meredith Whittaker’s panel on privacy, running alongside Mostaque’s, made a point worth pulling apart on its own: she’s arguing about a “data collection apparatus” AI labs are building regardless of whose flag sits on the server rack, which is a genuinely different problem from the geopolitical one and deserves its own answer instead of getting folded into the same word. Sovereignty is doing a lot of different jobs right now: jurisdiction, privacy, model control, compute ownership, and even the week the EU AI Act’s own transparency rules went live, Brussels only really answered one of them. Copenhagen mostly used all four interchangeably. That’s worth naming, even without a clean fix.

What I keep coming back to is that “the person who controls the AI controls the country” is a genuinely sharp line, and it gets a lot less comfortable once you ask who currently controls the AI running inside Europe’s own champion companies. Ask me again once GLM-5.2 and Copilot are both quietly running on European soil under someone else’s terms, and see if the panel still gets billed as a conversation about the future.

Sources