Skip to content
Tillbaka till bloggen
We Signed a Tech Deal With the US While Fighting Cookie Banners
Svensk Teknik

We Signed a Tech Deal With the US While Fighting Cookie Banners

F
Fredrik BrunnbergVD & Skribent
3 september 20267 min läsning

Sweden signed a Technology Cooperation Agreement with the United States this week. Defense sector, Nordic framing, the kind of announcement that gets a polite press release and a photo of two officials shaking hands. Same week, closing arguments wrapped in US v. Google, a case that will decide how much control one American company has over the infrastructure every Swedish founder builds on. Nobody in Stockholm is talking about the second thing. Everyone should be.

Here is the pattern I keep seeing from my desk in Jönköping. Europe writes the rules. America and China build the thing the rules are about. We are exceptional at governance. We are not shipping frontier models, we do not have a credible AGI strategy, and our biggest antitrust case against big tech is happening in a Washington DC courtroom, not a Brussels one. We are spectators with a very detailed rulebook.

The Deal Nobody Is Reading Closely

A defense-sector tech cooperation agreement with the US sounds good on paper. Access, interoperability, alignment with a superpower whose companies build the models, chips, and cloud infrastructure the entire Nordic economy already runs on. Fine. Pragmatic even. But look at the timing. We are signing bilateral tech deals with Washington in the same week a US federal court is deciding whether Google's search and ad dominance constitutes an illegal monopoly, a case with direct consequences for every ad-dependent Swedish media company and every startup that has ever had to negotiate distribution through a gatekeeper it did not choose. We have no leverage in that courtroom. We have no equivalent case. We have no European Google, no European OpenAI, no European Nvidia. We have GDPR enforcement actions and cookie consent lawsuits. That is not a strategy, that is a coping mechanism.

The EU Is World Class at One Thing

DGAP recently published a piece on Germany's role in Europe's digital regulatory power, and it is worth reading precisely because it is honest about what "regulatory power" actually means when you have no industrial base to back it up. The EU AI Act is genuinely the most detailed AI regulation on earth. Risk tiers, conformity assessments, obligations cascading down the supply chain. It is a serious piece of legal engineering. It is also the regulatory equivalent of writing an exhaustive rulebook for a sport you are not fielding a team in. China, meanwhile, is running what Geopolitical Monitor calls a coordinated strategic response to US tech dominance, building domestic compute, domestic models, domestic chip supply chains, state-subsidized and state-directed. Different failure mode than Brussels, but at least it is a strategy pointed at building capability, not just constraining it. Turkey-Iran arms pipelines get real-time sanctions enforcement and intelligence coordination. AGI preparedness gets a working group and a green paper due sometime next year. That tells you everything about where the actual sense of urgency sits inside European institutions right now.

Sweden vs the World, From Jönköping

From where I sit, running an AI development company in Europe out of a mid-sized Swedish city, not Stockholm, not Berlin, the contrast is stark. Sweden has excellent engineers, a strong startup culture, world-class universities, and founders who genuinely want to build. What we don't have is capital depth or political urgency matched to the moment. Breakit has covered this repeatedly, Swedish AI startups raising rounds that would be considered a rounding error in a Bay Area seed deal. DI has run the numbers on how far behind Nordic venture capital is on AI infrastructure investment compared to the US. The US signs tech deals from a position of overwhelming capability. Their leverage is the model, the chip, the cloud region. Our leverage, if we have any, is trust, rule of law, engineering talent, and energy infrastructure that is genuinely better than most of the world's. That is not nothing. But trust does not build a frontier model. Engineering talent without capital and compute access does not either. Compare this to how South Korea and Japan are positioning, quietly building sovereign compute and chip capacity while also signing cooperation deals with the US. They are hedging. Doing both. Sweden and the EU broadly are doing one thing, regulation, and calling it a strategy.

Where This Actually Goes

Play this forward two to five years. If the current trajectory holds, the EU ends up as the world's most sophisticated AI compliance layer sitting on top of American and Chinese infrastructure. Every company doing AI solutions work in Europe will spend more engineering hours on AI Act conformity documentation than on the actual differentiated capability of their product. That is already starting. I see it in client conversations. The compliance tax on AI deployment in Sweden is real and it is growing, and it is landing on companies that had nothing to do with training frontier models in the first place. Meanwhile the actual AGI conversation, model capability progressing toward general reasoning and autonomous agents that can plan, code, and execute multi-step business processes without a human in the loop, is happening entirely outside European jurisdiction. OpenAI, Anthropic, Google DeepMind, and now a serious cluster of Chinese labs are the ones setting the pace. Europe's AI Act was drafted largely assuming a world of narrow, deployed AI systems. It was not built for a world where an agent can autonomously run a customer support function, write and ship code, or negotiate a contract. The regulatory architecture is already behind the capability curve, and the gap is widening every model release cycle, not narrowing. Here is the uncomfortable part. If AGI-adjacent capability keeps compounding the way frontier labs project, the country and company that controls the infrastructure controls the leverage in every negotiation downstream, trade, defense, cyber, everything. Sweden signing a tech cooperation deal with the US is a tacit admission that we know this. We are choosing to align with the infrastructure owner rather than build our own. That might be the correct pragmatic choice for a country of 10 million people. But we should say that out loud instead of pretending our AI Act makes us a peer in this negotiation. It does not. It makes us a well-regulated customer.

What Builders Should Actually Do About It

I am not writing this to depress founders. I am writing it because the gap between European rule-writing and American and Chinese rule-breaking is exactly where opportunity lives if you move correctly. First, stop waiting for European infrastructure that is not coming in a useful timeframe. Build on what exists, US clouds, US and Chinese open models, and put your engineering effort into the layer above it: workflow, agents, vertical specialization, trust and compliance tooling that turns the regulatory burden into your product. If the EU is going to force every company to document AI risk exhaustively, be the company that makes that easy instead of the company drowning in it. Second, if you are building anything that touches personal data, financial data, or regulated industries in Sweden or the EU, get your compliance tooling in order before a regulator makes you. Open source tools like CISO Assistant and Probo map straight onto GDPR, NIS2, and DORA requirements and will save you a very expensive consultant bill. Pair that with something like Prowler for continuous cloud security and compliance automation, and immudb if you need tamper-proof audit trails, which you increasingly will under AI Act transparency obligations. This is not glamorous work but it is the work that lets you actually ship instead of getting stuck in review. Third, if you are a founder in the Nordics reading this and thinking "we need to build faster," that is the right instinct and it is exactly why we exist. We help teams go from idea to shipped product without drowning in either bureaucracy or bad architecture decisions, whether that is a Rapid MVP to prove the model works, AI agents to automate the operational grind, or full SaaS development built to scale past your first hundred customers. If you're trying to hire an AI developer in Sweden who understands both the technical build and the regulatory reality you're operating in, that combination is rarer than it should be. It should not be.

What To Look At This Week

  • CISO Assistant, open source GRC covering NIS2, DORA, GDPR mapping if you're a Swedish company trying to get ahead of compliance instead of scrambling after an audit notice.
  • Prowler, cloud security and compliance automation, genuinely useful if you're multi-cloud and tired of manual audits.
  • GoAccess, real-time log analysis, boring but essential if you actually want to know what is happening on your infrastructure instead of guessing.
  • Read the closing arguments coverage on US v. Google directly, not the summary. The ruling will shape distribution economics for every European company depending on search and ad infrastructure for the next decade.

The Honest Take

I like that Sweden is pragmatic enough to sign a tech deal with the US instead of pretending European strategic autonomy in AI is around the corner. It is not. What I do not like is doing that quietly while the political conversation at home stays fixated on cookie banners and consent frameworks as if that is the frontier of the fight. It is not the frontier. It is the parking lot. If you are building a tech company in Jönköping or anywhere in the Nordics right now, understand the actual terrain. Europe will keep regulating in exquisite detail. The US and China will keep building the thing being regulated. Your job is to build something valuable enough, and compliant enough, that it survives contact with both realities. That is a harder job than either pure hype or pure fear suggests. It is also the only job worth having right now.

Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.

#EU AI policy#Sweden tech#AGI strategy#US-EU tech relations#Nordic startups#AI regulation#tech sovereignty
F
Fredrik Brunnberg

VD & Skribent

VD för HEIMLANDR.IO. Punk rock-teknik från Jönköping, Sverige. Bygger AI-system, blockchain-infrastruktur och skriver om vart branschen faktiskt är på väg — inget ekokammare, ingen hype.