Is Europe's AI Sovereignty Debate Missing a Layer?
— by Isabelle Ulfsdotter
Tags: AI, Sovereignty, Trust
AI agents will need identity, authority and payment infrastructure. Europe risks creating a new dependency between AI and finance.
Since the pandemic, Europe has gone from one humiliating reminder of its dependencies to another.
First, COVID exposed how much we relied on other countries for medicines, protective equipment, computer chips and all sorts of things we suddenly could not get. Then Russia invaded Ukraine, and our dependence on Russian gas became an immediate security problem. Now the Trump administration is telling Europe, in rather blunt terms, that we cannot continue relying on the United States for our defense. We can now add to that list of sovereignty discussion points payment sovereignty, technological sovereignty and, increasingly, AI sovereignty.
In AI, the gap is particularly notable of course. Europe is not spending anything close to what America and China are spending across the AI stack, from chips and data centers to frontier models. So what is Europe to do? One response is: do not try to match them. Economists Luis Garicano and Jesús Saa-Requejo call this the "smart second mover" strategy: benefit from the investment others have already made and concentrate European resources on the application layer, where they expect more of the value to be captured. That does not mean having no European capability, but having enough infrastructure and alternatives to avoid being trapped, without trying to win the frontier race.
The other side worries that this would deepen a familiar European dependency: the applications may be European, but the models, cloud infrastructure and much of the software beneath them would not be. EuroStack, for example, argues that Europe needs credible alternatives across more of the digital stack. Between the two are proposals to keep working with American companies while building enough capacity in Europe to retain some leverage.
While digging into agent reputations, I stumbled across another potential dependency. Specialists may already be discussing it, but I have seen very little about it in the broader public debate over AI sovereignty.
When AI starts acting on our behalf
AI currently mostly answers questions and builds things. The alleged next big unlock is when it starts acting.
Imagine asking an AI agent to organize a trip or order your groceries. It might compare hotels, book a flight and pay. A company's agent might order replacement parts or buy advertising without asking a human to approve every step.
Before anyone accepts those orders, they will want to know:
- Whose agent is this?
- Is it really allowed to spend this money?
- How much may it spend?
- Has it behaved suspiciously before?
- Who is responsible if something goes wrong?
Those questions need answers. We might call the infrastructure that provides them the agent trust layer.
So who is building this trust layer now?
From what I can tell, it is again mostly American companies that have a head start. Visa and Mastercard are developing ways for agents to make authorized payments. Experian is working on identity and fraud signals for agents, in collaboration with Visa, Cloudflare and Skyfire. And Stripe has agreed to acquire OpenRouter, a marketplace and gateway that connects users and agents to hundreds of different AI models.
To be clear, there is obviously nothing nefarious about American companies addressing an emerging market need (that is what they should be doing!). The concern is the network advantage they bring with them. Visa and Mastercard already connect consumers, banks and merchants around the world. These are formidable incumbents, not companies trying to build a network from scratch.
Like payment networks and much of the infrastructure behind our other sovereignty vulnerabilities, trust networks reward size. Agent principals (the people or entities the agents represent) will want credentials accepted by the most merchants. Merchants will prefer the system used by the most agents. The largest system will see the most activity, which will likely make its fraud judgments better and attract still more users.
The equivalent for agents could be a company (or a small group of companies) that effectively decides which agents are trustworthy enough to participate in the economy.
What is Europe up to?
Europe is not starting from zero. Its digital-identity framework could help people and companies prove who they are. The proposed European Business Wallet could allow a company to delegate an agent to act legally on its behalf in certain circumstances (likely more benign ones like inventory management and advertising, at least to start). Europe also has its own bank-payment infrastructure, instant payments, Wero and the proposed digital euro in the works.
There is some private-sector activity too. Fime has launched what it calls a trust layer for agentic commerce, while Ireland's Trustap is building trusted transaction infrastructure for AI agents.
But for the time being these are separate and relatively early efforts. As one panelist at Cristina Caffarra's recent conference on European sovereignty pointed out, Europe often has the component parts but American companies tend to be much better at building the plumbing that connects them. The concern is not that Europe will have nothing. It is whether these efforts can connect and scale before the incumbent networks become the default.
Why this matters
Farrell and Newman make a similar point in Underground Empire. SWIFT and much of the internet were built for convenience. Over time, the United States gained remarkable visibility and leverage over both, even though SWIFT is based in Belgium.
This can all sound rather abstract. But in 2025, US sanctions against Kimberly Prost, a Canadian judge at the International Criminal Court, left her unable to use credit cards issued outside the United States and sometimes blocked her bank transfers. Prost has described what this did to her daily life. If existing payment infrastructure can be used that way, it seems worth asking who will control the systems that decide whether an AI agent can transact.
That is the layer I think Europe's AI sovereignty debate may be missing.
Europe may not need to build the world's most powerful AI model. But it should probably care who builds and controls this layer before it becomes another dependency that is difficult to undo.
Selected sources
- Luis Garicano and Jesús Saa-Requejo, "The smart second mover"
- EuroStack, overview of its European digital-sovereignty proposal
- International Monetary Fund, How Agentic AI Will Reshape Payments
- European Commission, European Digital Identity and European Business Wallets
- Company announcements from Visa, Mastercard, Experian and Stripe
- European initiatives from Fime and Trustap
- Cristina Caffarra, Rebuilding Europe's Sovereignty conference
- Henry Farrell and Abraham Newman, Underground Empire and "Weaponized Interdependence"
- Associated Press, report on the effects of US sanctions on ICC personnel, and an interview with Judge Kimberly Prost