← Thought Leadership

Sovereignty

Europe's missing compliance layer

Europe is building sovereign payments and sovereign AI. The system that reads its own regulation still runs on foreign software.

Martin Foerster
Co-founder
· Updated on · 3 min read
The European Parliament building flanked by EU member-state flags

Photo: paws and prints / Unsplash

New to the topic? Start with What sovereign compliance actually means.

SWIFT is a messaging network. It carries the instructions that move money between banks, and nearly every cross-border payment in Europe runs across it. In November 2018 the US Treasury reached into that network and told SWIFT, a Belgian company operating on European soil, to disconnect Iran's banks. Europe objected, updated its blocking statute, and stood up a dedicated payments vehicle, INSTEX, to keep trading in defiance of Washington, and none of it held. SWIFT complied with the United States, European trade with Iran collapsed anyway, and a continent with the law, the institutions, and the political will on its side found that its position didn't prevail where the system actually ran. That episode is where European payment sovereignty stopped being a talking point and became a programme.

Two layers are already under construction

Eight years on, the programme is visible in the parts that cost the most to build. Wero, the wallet from the European Payments Initiative, has passed 43 million users. On 3 June 2026 the Commission wrote sovereignty into industrial policy with its Technology Sovereignty Package, citing a dependence on non-EU providers for more than 80% of the continent's key digital technology. European model builders such as Mistral and Aleph Alpha are contesting the AI layer. Payments and intelligence are the two most capital-intensive layers of the stack, and both are being built in earnest.

The third layer, and who governs it

Sitting on top of both is a third layer that draws almost none of the same attention. A compliance system reads a regulation, works out what it requires of a given institution, and produces the evidence that the institution obeys it. Follow that chain for a typical European bank and it runs on American software, hosted on US infrastructure, with the models that do the interpreting under US jurisdiction.

Definition
The interpretation layer
Compliance software handles storage and workflow. Its core act is interpretation: reading a legal provision and deciding what it requires of a specific institution. When a foreign-controlled system performs that act, the institution has handed over both its data and its reading of its own law.

The consequence arrives without anyone choosing it. When the software that reads European law is built and governed in the United States, the reading of European law becomes a foreign dependency, assembled one procurement decision at a time. It is the same failure as SWIFT, moved to a place no one is watching.

Building the missing layer

Rejecting foreign technology outright would be impossible and self-defeating. The code and the cloud are wired too deep into the stack to pull out. The workable answer is to build the compliance layer to the standard Europe now demands of payments and AI: developed, hosted, and governed under European control. That is the layer we build at Harpocrates, and it is the one the sovereignty debate has yet to name.

Europe would not accept its payment rails or its foundational models being switched off from abroad. It should be no more relaxed about the systems that tell it what its own laws require.

Sources