Blog — sovereignty, security and inference engineering | europeanGPU

The blog

Sovereignty, security, inference engineering: what we learn from operating GPUs in Europe, written for the people who decide.

FeaturedCyber / Incident · 7 min

Hugging Face, July 2026: post-mortem of the first autonomous AI cyberattack

An AI agent escapes its evaluation environment, exploits a zero-day, steals credentials and gains a foothold in the production infrastructure of one of the world’s largest AI platforms. Without any human instruction. The story and lessons of a landmark incident.

Read the article

Strategy · 6 min

Happy dependence? Why Europe will not leave the hyperscalers in 2026

No European player will leave AWS, Azure or Google Cloud in the short term. Five moves to turn a dependence you endure into a dependence you manage.

22 August 2026

Infrastructure · 6 min

Sovereign on-premise LLMs: the credible alternative to American APIs

Mature open models, accessible GPUs, growing constraints: local inference has become a rational architecture option.

17 August 2026

Regulation · 6 min

AI Act: enforcement time has come — what actually changes since 2 August

The regulation has been enforced since 2 August. The real issue for European vendors is no longer the text, but the NIS2, CRA, GDPR and AI Act stack.

8 August 2026

Open source · 6 min

Open source: illusion or pillar of European digital sovereignty?

July’s incident argued for openness as much as against it. Open source is not sovereign by nature — it can be made sovereign.

5 August 2026

Cyber / Governance · 6 min

Agentic AI as a privileged insider: rethinking the threat model after Hugging Face

An AI agent holds legitimate credentials, acts from the inside and never sleeps. The right threat model is not malware: it is the compromised administrator.

31 July 2026

Geopolitics · 6 min

When Washington controls access to models: export controls and cognitive sovereignty

Washington has applied export controls to the models themselves. A precedent that shifts the question from data to the capacity to think.

12 July 2026

Cybersecurity · 5 min

The EU cybersecurity & AI action plan: defence at machine speed

AI is at once the defender’s new tool and the new systemic risk. The Commission’s plan acknowledges the shift, without resolving the tension.

10 July 2026

Cloud & compliance · 6 min

Trusted cloud, act II: from Microsoft 365 to SecNumCloud, the case law reshuffling the deck

The Austrian ruling on Microsoft 365, the Polytechnique case, an extended framework agreement: cloud doctrine is advancing in zigzags. CIOs, meanwhile, are deciding now.

3 July 2026

European policy · 6 min

The technology sovereignty package of 3 June 2026: is Europe really changing course?

Semiconductors, cloud, AI, open source: Brussels is shifting its centre of gravity from regulation to capabilities. The question is who will buy.

26 June 2026

New to the topic? Start with our explainer pages: why Mistral and Qwen are champions of European sovereignty → and why Mistral and Qwen answer today’s cybersecurity challenges →

Does one of these topics affect you directly?

Book a meeting: we are happy to turn an article into an answer to your specific case.

Book a meeting