Europe should build AI leverage, not an AI wall The European Union's proposed Cloud and AI Development Act (CADA) would steer sensitive public-sector work away from non-EU providers, including the United States, potentially cutting Europe off from state-of-the-art American AI in cybersecurity, intelligence, and defense, according to a senior news editor. The policy risks leaving Europe with second-best systems just as Chinese models like Zhipu AI's GLM-5.2 narrow the gap with the American frontier, with independent testing by Semgrep finding it outscoring Claude Code on a vulnerability-detection benchmark. Europe has taken one step towards a Western technology alliance and another towards technological self-denial. At a signing ceremony at the US State Department on June 23, the European Union formally joined “Pax Silica”, the US-led effort to secure artificial-intelligence AI supply chains and reduce Western dependence on China. That was the right move. But it sits uneasily beside Brussels’ proposed Cloud and AI Development Act CADA , the centrepiece of the European Technological Sovereignty Package presented by the European Commission on June 3. CADA would steer sensitive EU public-sector cloud and AI work away from providers tied to non-EU countries, including the United States. In the name of sovereignty, it could cut Europe off from state-of-the-art American AI in precisely the domains where the best technology matters most: Cybersecurity, intelligence, defence and other national-security functions. That should concern Europeans. Europe needs greater technological capacity and less strategic dependence. But it also needs access to the strongest tools available, especially as Chinese models narrow the gap with the American frontier. Sovereignty should not mean regulating Europe into second-best systems. CADA is being presented as Brussels’ answer to the kind of cutoff that hit Anthropic’s Mythos and Fable AI models on June 12, when a US Department of Commerce export-control directive barred access by any foreign national, whether inside or outside the United States, leading the company to disable both models for every customer. That episode made Europe’s dependence on American frontier AI painfully clear. But CADA draws the wrong lesson. Washington lifted the controls at the end of June and Fable 5 returned to users worldwide on July 1, though Mythos 5 has been restored only to approved US organisations. Mythos matters because its cybersecurity capabilities appear to be significant. Systems in that class could help defenders find and fix vulnerabilities before attackers exploit them. Partners in Anthropic’s Project Glasswing , the defensive-security initiative launched in April 2026, had used Mythos Preview to find more than 10,000 high- or critical-severity flaws in widely used software, according to the company. The key question is not whether Europe should reduce dependence where it can. It should. The question is what happens when adversaries gain comparable capabilities. That moment may arrive soon. The Chinese model GLM-5.2 has prompted serious concern. Released as an open-weight system by the Beijing-based laboratory Zhipu AI on June 13, it can be downloaded and run by anyone. Analysts once discounted claims that Chinese systems were only months behind the American frontier, partly because many models performed well on synthetic benchmarks without matching that performance on real tasks. GLM-5.2 appears harder to dismiss. Independent testing by the security firm Semgrep found it outscoring Claude Code on one vulnerability-detection benchmark. The emerging view is that, in some capabilities, it may be several months, and perhaps less than a year, behind the strongest publicly released models. In cybersecurity, months matter. Defenders must secure vast digital terrain. Attackers need only find one exploitable weakness. AI can help patch systems, but it can also help attackers discover vulnerabilities at unprecedented speed. If a Mythos-class model can find weaknesses today, trailing models may find them soon enough for hostile states and criminal groups to act. That is why Europe cannot afford to lose access to frontier American AI. In adversarial domains such as cybersecurity, military operations, intelligence and financial markets, a brief lead can create an enormous advantage. CADA does start from a sensible premise. It sorts public-sector cloud and AI services into four “assurance levels”, meaning tiers of security and sovereignty requirements. The obligations are meant to scale with risk, and they formally apply only to the public sector. The European Commission estimates that the top two tiers would cover about 10 per cent of public-sector use cases. The problem starts at the top tiers. CADA tries to protect European buyers from foreign-government interference by excluding providers subject to non-EU control. That means an American-owned provider may fail even if it can meet rigorous technical-security standards. CADA includes a possible exception for countries recognised as “associated third countries”, but the conditions look difficult for the United States to satisfy. They are cumulative, and no such exception exists at the highest tier. One would disqualify countries with measures that “impede the provision of state-of-the-art technologies”. Read literally, that penalises export controls. Yet export controls are central to the Western technology alliance Europe just joined through Pax Silica. This is CADA’s central contradiction. Brussels wants American chips, American AI models and American-led supply-chain security, while writing rules that could exclude American providers from the most sensitive work. Europe’s answer should be leverage, not autarky. It should use “good enough” non-frontier models for routine tasks where appropriate. It should build far more data-centre capacity on European soil. And it should make dependence mutual by hosting US firms’ workloads in Europe, so that any future cutoff would harm American customers and companies, not merely reduce foreign revenue for US labs. European Commission President Ursula von der Leyen put the matter well at the G7 summit in Évian, France, on June 16: “We want our own AI future, not in isolation, that is very important, but together with our trusted partners.” That principle is right. CADA’s top tiers do not yet reflect it. A stronger European technology base would serve Europe’s interests. More European compute capacity, better cyber defences and more resilient Western supply chains would reduce vulnerability without cutting Europe off from the frontier. But technological sovereignty should not become technological self-denial. Europe should build compute, harden systems and align with the democratic technology bloc. It should not wall itself off from the best AI in the world just as China is trying to catch up.