← all musings

Europe Built a Sovereign ID on American Rails

You cannot build digital sovereignty on top of a stack you don't control — and the EU just built its national ID system on Google and Apple's trust layer.

The European Union spent years designing a digital identity wallet to escape American tech dependence — and then handed the keys to Google and Apple.

That’s the story buried in the Waag Institute’s analysis of eIDAS 2.0, the EU regulation meant to give every European citizen a sovereign digital ID. The wallets are real. The ambition is real. But the “safety attestation” layer — the cryptographic root of trust that confirms your phone hasn’t been compromised — runs through Google’s Play Integrity API and Apple’s DeviceCheck. Two American companies. Two American legal jurisdictions. Two sets of terms of service that can change without a vote in the European Parliament.

This is the infrastructure layer problem that nobody in Brussels wants to say out loud: you cannot build digital sovereignty on top of a stack you don’t control.

Everyone says the EU is the world’s most effective tech regulator. The opposite is closer to true — the EU is the world’s most effective tech rule-writer, which is a completely different thing. GDPR is a rule. The DMA is a rule. eIDAS 2.0 is a rule. Rules without substrate are just strongly-worded letters. When the regulation’s own technical implementation requires Apple and Google to vouch for device integrity, the regulation has already conceded the foundational question: who controls the trust layer? Answer: not Brussels.

The steelman for this design is real and worth respecting. Google and Apple have invested billions into Trusted Execution Environments, secure enclaves, and device attestation infrastructure. Building a parallel European stack from scratch would take a decade and produce something worse. Speed and interoperability matter. Better to use the best available trust layer and regulate access to it aggressively. That’s a coherent position.

Here’s why it still fails. Regulatory access is not the same as infrastructural control. When the US government serves Google with a lawful order under CLOUD Act or signals Apple under national security letters, European digital ID data doesn’t get a veto. When Apple changes its DeviceCheck API terms — as it can and does unilaterally — the entire European attestation architecture shifts on a corporate decision made in Cupertino. The EU can fine Apple €20 billion after the fact. It cannot un-expose the identity records of 450 million people. Enforcement is retrospective. Vulnerability is permanent.

This is exactly how dependency compounds quietly. The hardware layer (TSMC, mostly). The cloud layer (AWS, Azure, GCP). The AI layer (OpenAI, Anthropic, Google DeepMind). And now the identity attestation layer. Each individual dependency has a coherent justification. Together they describe a continent that has written the world’s most ambitious digital sovereignty regulations while systematically outsourcing every piece of infrastructure those regulations run on.

The Antares nuclear criticality milestone from this same news cycle is instructive by contrast. A private American company just achieved first criticality on a novel reactor design — a significant early milestone on one of the hardest engineering problems in energy. Europe has no equivalent in digital infrastructure. The EU has launched programs like the European Chips Act, committing tens of billions to semiconductor manufacturing — but those efforts are focused on production scale, not on the secure enclave and attestation stack that digital sovereignty actually requires. The EU regulates the outputs without shaping the inputs that matter most.

The stakes are not abstract. Digital ID is not a convenience feature — it’s the authentication layer for healthcare records, tax systems, voting eligibility verification, and cross-border legal identity. When that layer has a foreign dependency at its root of trust, you have built a critical national security infrastructure with a structural single point of geopolitical failure. Russia’s invasion of Ukraine showed how fast infrastructure assumptions collapse under adversarial pressure. Imagine the EU discovering mid-crisis that its identity attestation layer is subject to US executive order.

The fix exists in theory: open, auditable attestation standards that don’t require routing trust through proprietary American APIs; investment in European HSM and secure enclave manufacturers; a long transition period with real deadlines. RISC-V exists. Open security standards exist. The engineering problem is solvable. The political economy problem — convincing member states to fund boring infrastructure instead of visible programs — is the actual blocker.

Sovereignty isn’t declared. It’s compiled.