
Sweden Wants Off US Tech. Sweden Also Just Signed With Washington.
Eighty-five percent. That's how many Nordic users and organizations told Proton this year they want EU alternatives to American tech. Not "would consider." Want. That number should be on every board slide in Stockholm right now. Instead, the same week that survey lands, Sweden signs a new Technology Cooperation Agreement with the United States on the defense side, and Trump's lawyers are back in court trying to gut the €1.7 trillion EU-US data transfer deal that half of Swedish SaaS runs on. Nobody in Rosenbad seems to notice these three things happened in the same news cycle. I noticed. You should too.
The Contradiction Is the Strategy, Not a Mistake
Here's what I think is actually going on, and it's less stupid than it looks from the outside. Sweden is doing two things at once because it has to. On defense and hard security, we need the Americans. Nobody in Jönköping or Stockholm thinks Sweden alone, or even Sweden plus the Nordics, can build an air defense umbrella without US hardware and US intelligence sharing. That's the Technology Cooperation Agreement. It's real, it's necessary, and it has nothing to do with whether Microsoft should be running your payroll system.
But on civilian infrastructure, on the SaaS stack every Swedish company from Ikea to a five-person startup in Huskvarna runs on, the market has already voted. 85% want out. That's not policy, that's demand. People who write the checks for cloud contracts, procurement officers, CTOs doing vendor risk assessments after NIS2 came into force, they've made the call already. The politicians just haven't caught up to their own market.
The problem is these two tracks are not actually separate. They just pretend to be. And when Trump's legal team goes after the data transfer framework, as Politico reported this week, the defense cooperation doesn't save you. Every company running Microsoft 365, AWS, or Salesforce on the assumption that EU-US data flows are legally stable just got a reminder that the ground under that assumption is a court ruling away from disappearing. Again. This is the third time in a decade we've been here, after Schrems I and Schrems II. Nobody learns.
Sweden's Selective Speed Problem
Here's the part that actually annoys me. Reuters reports Sweden may block Tesla's supervised self-driving feature over speeding concerns. Fine, maybe that's the right call on road safety. But look at the speed. Swedish regulators saw a consumer safety story, a car going too fast, something a journalist can put in a headline, and they moved in weeks. Now compare that to AI Act enforcement. Compare that to how long it's taken Swedish authorities to actually operationalize NIS2 compliance requirements for mid-size companies, or to give clear guidance on what "high-risk AI system" actually means for a Swedish manufacturer bolting a computer vision model onto a production line. Glacial. Vague. Committees. Working groups. Meanwhile the actual existential stuff, who owns the data, who can subpoena it, what happens when a US court order says a US company must hand over EU citizen data regardless of GDPR, that gets negotiated in a defense agreement nobody outside Rosenbad reads closely. We move fast when the story is simple and the political cost is low. We move slow when the stakes are structural and the political cost of confronting Washington is high. That's not a regulatory strategy. That's cowardice with better PR.
Where the EU Broadly Stands
This isn't just a Swedish problem, to be fair. The whole EU sovereignty conversation has the same split personality. Germany talks "digital sovereignty" while its federal agencies run on Microsoft. France has OVHcloud and Scaleway and actually uses them for sensitive workloads, which puts Paris ahead of most of the Nordics on this specific point. The EU Cloud Sovereignty framework exists on paper. In procurement reality, American hyperscalers still win almost every serious enterprise contract because the alternatives, however good, don't have the same scale, the same tooling maturity, or the same "nobody gets fired for buying it" safety.
Sweden vs the World: Who's Actually Doing Something
Let's be honest about where Sweden sits globally on this, because I don't think it's flattering.
The US doesn't have this problem because it's the one exporting the infrastructure. Its only tension is internal, states vs federal AI policy, and Trump's administration actively fighting to keep US companies unbound by foreign privacy law. They're playing offense.
China solved sovereignty by fiat a decade ago. No debate, no market signal needed, the state simply mandated domestic infrastructure. Not a model I want, but it's decisive, and it means Chinese companies aren't waking up in 2026 discovering their entire SaaS stack has a legal cliff edge.
Sweden and the Nordics have the market appetite (85%!) and the technical talent to build real alternatives. What we don't have is political will translated into procurement policy. Public sector contracts, the biggest lever a government has, still overwhelmingly go to American vendors. If Rosenbad wanted to signal seriousness, the fastest move isn't another cooperation agreement, it's requiring EU-sovereign infrastructure for a defined set of government and critical infrastructure workloads. That's a real policy lever. A joint statement with Washington is not.
Compare this to what I see building here in Jönköping and across Sweden's second-tier tech cities, not Stockholm's startup scene chasing the next SaaS unicorn pitch, but manufacturing-adjacent companies quietly building compliance and infrastructure tooling because they got burned by a vendor risk assessment or a customer audit. That's where the real sovereignty movement is happening. Not in press releases. In procurement departments saying no.
Where This Actually Goes: 2026 to 2030
Here's my honest read on the trajectory, and I'll say the uncomfortable part first: full EU tech sovereignty inside five years is not happening. Not for compute, not for foundation models, not for cloud at scale. The capital and infrastructure gap versus the US and China is too large to close that fast. Anyone selling you "Europe will be independent by 2030" is selling a narrative, not an engineering plan.
What's realistic, and what I think actually matters more, is sovereignty at the data layer and the compliance layer, not the compute layer. You don't need to own the GPU cluster if you can guarantee, provably, that your data never leaves jurisdiction, that access is auditable, and that no foreign legal order can silently compel disclosure. That's a solvable problem right now, with open source tooling, without waiting for Brussels to finish another framework.
As AI agents move deeper into actual business operations over the next few years, this gets more urgent, not less. An AI agent making autonomous decisions on procurement, on customer data, on financial transactions, that's a much bigger sovereignty exposure than a static SaaS contract. When the underlying model, the orchestration layer, and the data pipeline are all sitting on infrastructure that a foreign court can reach into, you've built a governance problem into your architecture from day one. The companies that will handle this well over the next three to five years are the ones building auditability and jurisdiction control into their AI agent stacks now, not bolting it on after a regulator asks.
This is exactly the kind of problem we build for at HEIMLANDR. When we architect AI agents for clients, data residency and audit trail aren't an afterthought, they're a design constraint from the first sprint. Same with AI solutions more broadly. If you can't tell a customer exactly where their data lives and who can legally compel access to it, you haven't finished the job.
The AGI Question Nobody in Rosenbad Is Asking
Zoom out further. If frontier labs get anywhere close to AGI-level systems in the next few years, and I think the honest probability on a five-year horizon is meaningfully above zero, the sovereignty question stops being about SaaS contracts and starts being about who controls the most powerful economic and military tool in human history. Right now that's three or four American labs and whatever China is doing behind its own wall. Europe, including Sweden, is not in that race in any serious way. We are a customer, not a builder, of frontier AI.
That should worry Swedish policymakers more than a Tesla driving too fast. It doesn't, because AGI risk doesn't fit in a news cycle, and speeding cars do.
What to Actually Look At
Enough diagnosis. If you're a CTO or founder reading this in Sweden or anywhere in the Nordics, here's where I'd point you this week, tools that give you real sovereignty gains without waiting for policy to catch up:
- immudb — tamperproof, cryptographically verifiable data storage. If your argument to a regulator or a customer is "we can prove nobody altered this record," this gets you there without a vendor lock-in story attached.
- Prowler — open source cloud security and compliance scanning across any provider. Run this before your next NIS2 or DORA audit, not after.
- CISO Assistant — genuinely useful GRC platform covering GDPR, ISO 27001, NIS2, DORA mapping out of the box. Most Swedish mid-size companies are still doing this in spreadsheets. Stop.
- Probo — open source SOC2, GDPR, ISO27001 tooling if you're a smaller shop that needs compliance credibility without paying for an enterprise GRC platform you'll never fully use.
None of these solve the geopolitics. All of them buy you real, provable, auditable control over your own data posture while the politicians figure out theirs. If you're building this into a product from scratch, whether it's SaaS development or a fast MVP, bake it in now. Retrofitting sovereignty into an architecture after a customer audit fails is three times the cost and half as convincing.
What You Should Actually Do This Week
If you're running a Swedish company and you've read this far, here's the practical list. One, audit your actual data flows, not your contracts, your flows, and know exactly which of your vendors are exposed if the EU-US data transfer framework gets struck down again. It's happened twice before. Plan like it happens a third time, because the legal fight is active right now. Two, stop waiting for Rosenbad or Brussels to hand you clarity on AI Act enforcement. They won't, not fast enough. Build your own compliance posture using open tools and get ahead of it. Three, if you're evaluating an AI development company in Europe for your next build, ask them directly where the data lives and what happens legally if a foreign court comes asking. If they don't have a fast, specific answer, that's your answer.
Swedish tech has always punched above its weight because we build practical things without waiting for permission. Spotify didn't wait for a Swedish streaming policy framework. Klarna didn't wait for an EU fintech consensus. The 85% who want off American infrastructure aren't going to get there through another government cooperation agreement. They'll get there because enough builders in Jönköping, Gothenburg, and Stockholm decided sovereignty is an engineering problem you solve this quarter, not a political outcome you wait for in five years.
Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.
CEO & Writer
CEO of HEIMLANDR.IO. Punk rock tech from Jönköping, Sweden. Building AI systems, blockchain infrastructure, and writing about where this industry is actually heading — no echo chamber, no hype.