Five Watchdogs, One Warning
On July 10, 2026, five of the Netherlands' most powerful regulators — the Authority for Consumers and Markets (ACM), the Authority for the Financial Markets (AFM), the Data Protection Authority (AP), De Nederlandsche Bank (DNB), and the Authority for Digital Infrastructure (RDI) — jointly published De route naar digitale autonomie ("The Route to Digital Autonomy"), presented to State Secretary for Digital Economy and Sovereignty Willemijn Aerdts. Their message: the Netherlands' near-total reliance on a handful of mostly American cloud and IT providers is a structural risk, not just a market preference, and both government and business need to actively engineer their way out of it.
The regulators aren't wrong about the dependency itself. Roughly 80% of European organizations' professional cloud and software spending — an estimated €265 billion a year — flows to US providers, concentrated in AWS, Microsoft Azure, and Google Cloud, according to an April 2025 study commissioned by the French digital-industry groups Cigref and Numeum. Gartner separately forecasts European spending on sovereign cloud infrastructure-as-a-service to jump from $6.9 billion in 2025 to $12.6 billion in 2026 — an 83% increase — and to nearly double again in 2027, reflecting genuine buyer anxiety about geopolitical exposure, not just regulator alarmism.
The Case the Regulators Are Making
Steelmanning their position first: concentration risk is real and it isn't hypothetical. When a Dutch hospital, pension fund, or ministry runs core infrastructure on a single foreign hyperscaler, an outage, a US sanctions decision, or a unilateral pricing or terms-of-service change becomes a domestic continuity problem the Netherlands cannot unilaterally fix. DORA and NIS2, both binding on Dutch financial institutions and critical infrastructure operators from mid-2026, already require exactly this kind of resilience planning. The five authorities argue that if the state wants operators to plan for vendor concentration risk, government itself should stop being the biggest offender — hence recommending the state act as a "launch customer" (eerste afnemer) for European cloud and software alternatives, and that public and private procurement build in open standards, interoperability, and switching rights as baseline requirements rather than afterthoughts. That is a coherent, narrowly-tailored ask: it targets procurement rules, not market structure, and it explicitly notes that "competition rules provide ample scope" for smaller providers to collaborate — an implicit acknowledgment that antitrust shouldn't be stretched to force this outcome.
Where the Proportionality Breaks Down
But the report's own framing exposes the tension: it treats "digital autonomy" and consumer/business welfare as automatically aligned, when procurement mandates that prioritize origin over capability routinely aren't. A hospital or municipality forced to weight bids toward EU-headquartered vendors for compliance or security services that are objectively less mature — Europe's sovereign cloud and AI stack remains years behind on scale, tooling, and talent depth — pays for autonomy with degraded service, higher cost, or slower digitization, and taxpayers and citizens bear that cost, not the regulators writing the recommendation.
There's also a credibility problem one level up. Just a day before the Dutch report, on July 9, 2026, the European Commission opted not to mandate the kind of platform-to-platform interoperability that groups like the Electronic Frontier Foundation say would meaningfully reduce lock-in for EU users on dominant social platforms — choosing instead to leave switching costs largely where they are. If Brussels won't use its strongest interoperability lever against Big Tech platforms even when explicitly asked, five national regulators recommending that government "bundle demand" for unproven European alternatives looks less like a coordinated EU strategy and more like the Netherlands hedging alone, with procurement rules as its only tool. Genuine digital autonomy — reducing single-vendor concentration risk without sacrificing service quality — is better served by interoperability and open-standards requirements imposed evenhandedly on all providers, foreign and domestic, than by procurement preferences that pick winners by nationality before they've proven themselves technically competitive.
What Comes Next
The report carries no legal force on its own — it is a joint position paper, not a binding rule — but ACM in particular has independent enforcement powers under the EU's Digital Markets Act and Dutch competition law that could translate its recommendations into actual procurement conditions or guidance for regulated sectors. Financial institutions already under DORA's third-party risk rules, and critical-infrastructure operators under NIS2, are the most likely first movers, since they must document concentration risk regardless of what procurement policy eventually says. The open question is whether "digital autonomy" stays a resilience requirement — diversify, document dependencies, ensure exit rights — or hardens into a nationality-based preference scheme that raises costs without meaningfully reducing risk. The former is proportionate regulation responding to a documented vulnerability. The latter is industrial policy wearing a competition-law costume.