Table of contents of the article:
Dear Europe, let's be clear. At some point, even patience runs out. Because protecting citizens is good, data protection is good, cybersecurity is good, protecting consumers is good, leading vulnerable users by the hand through the digital Wild West is good. But here we've gone too far. Here we've entered the terminal phase of moral bureaucracy: where every technological problem is solved with a new regulation, a new policy, a new register, a new penalty, a new box to tick, and possibly a consultant to pay.
Over the past ten years, the European Union has transformed the Internet into a condominium managed by a depressed surveyor: constant meetings, endless minutes, thousandths to calculate, responsibilities to pass on, and no one to actually fix the elevator. The result? A slower, more expensive, more fearful and less competitive European digital ecosystemWhile platforms, cloud providers, artificial intelligence models, global infrastructures, and scalable supply chains are emerging in the United States, we produce PDFs, guidelines, committees, regulatory authorities, and public consultations.
The European specialty now is this: arrive late in production, but arrive first in regulationWe haven't mastered the cloud, but we've regulated the cloud. We haven't mastered social media, but we've regulated social media. We haven't mastered artificial intelligence, but we wrote the AI Act. We don't have hyperscalers comparable to the American giants, but we have so many obligations, disclosures, procedures, and penalties that the civil code looks like a post-it note.
And this is where the real problem arises. Because an industrial civilization doesn't thrive on considerations alone. Technological power isn't built with paragraphs. Digital sovereignty isn't achieved with institutional webinars. And above all, progress isn't created simply by deciding what others can and can't do.
The absolute masterpiece: cookie banners
Let's start with the wonder of wonders: cookie banners. That visual, cognitive, and technical plague that has made European web browsing an obstacle course of "Accept all," "Reject," "Customize," "Save preferences," "Partner 738," "Legitimate purposes," "Legitimate interest," "Improved experience," and other formulas concocted by someone who clearly hates both users and web designers.
The point isn't to deny the right to privacy. The point is that the solution was ridiculous. Was it really necessary to force every single website to build its own consent interface? Couldn't preferences really be managed natively by browser, operating system, or user profile? Was Europe's great digital breakthrough really supposed to force millions of people to compulsively click buttons they don't read, don't understand, and don't want to see?
The practical result was a disaster waiting to happen: worse user experience, weaker tracking, less accurate advertising attribution, less efficient campaigns, higher acquisition costsAnd when the cost per lead increases, guess who pays? The company? Yes, initially. But then that cost ends up in prices, margins, reduced budgets, postponed hiring, and less competitive services. Congratulations: to protect the user, we made him navigate worse and pay more.
And the most grotesque thing is that today Europe itself is talking about simplifying cookie banners and reducing "cookie fatigue." But thank you. After years of pop-ups, CMPs, audits, configurations, multilingual banners, consent logs, and legal advice, we realized that perhaps turning every visit to a site into a referendum on advertising profiling wasn't exactly a stroke of genius.
GDPR: A beautiful principle, a terrible liturgy.
The GDPR stems from a noble principle: personal data isn't confetti to be thrown at the advertising carnival. That's fine. The problem is that, in its actual implementation, it has often become a documentary liturgy. Processing records, privacy notices, appointments, DPAs, DPIAs, technical and organizational measures, internal policies, rights management, retention periods, transfers outside the EU, SCCs, assessments, reports, audits. All things that make sense in theory. All things that, in the daily practice of thousands of SMEs, translate into a huge question: "How much does it cost me to formally comply?"
And this is where Europe shows its best talent: transform a real need into an administrative labyrinthBecause protecting data is essential. But if a small business, an e-commerce site, a software house, or a provider has to spend more time demonstrating privacy considerations than actually improving system security, something is broken. And no, it's not the server. It's the minds of those who think that compliance automatically equates to protection.
We've confused form with substance. The banner with consent. The information with awareness. The documentation with responsibility.And so we've created a parallel market of fear: consultants, templates, automatic generators, audits, checklists, webinars, courses, stamps, and manuals. All around the most European promise there is: "I can't guarantee you'll be safer, but at least you can prove you tried."
NIS2: Cybersecurity explained with the stamp
Then comes NIS2. Here too: a sacrosanct objective. Cybersecurity is necessary, attacks are increasing, supply chains are interconnected, critical infrastructures must be protected. No serious person can argue otherwise. But the enormous risk is that NIS2 becomes yet another standard where companies rush to produce procedures, roles, documents, classifications, and notifications, while the real problem remains: Outdated systems, bad passwords, untested backups, lack of segmentation, insufficient logging, untrained staff.
In Italy, we've already seen this film with the old Security Policy Document: a monument to paper-based compliance, often more useful for filling folders than stopping an attack. NIS2 risks being its European cousin in a new guise: more modern, more ambitious, more comprehensive, but with the same underlying danger: believing that cybersecurity stems from a document and not from investment, expertise, proper architecture, continuous monitoring, and real technical responsibility.
Security isn't achieved through emotional self-certification. It's achieved through patch management, hardening, verified backups, MFA, vulnerability assessment, incident response, centralized logging, Web Application Firewall, access control, and capable people. Everything else is paper. Very elegant paper, of course. European paper. European paper that sucks.
The question is simple: will NIS2 really drive companies to invest in better infrastructure, or will it lead to yet another race for the formally correct document? Because if the result is more policies but the same exposed servers, more organizational charts but the same backups never restored, more notifications but the same legacy systems, then we won't have achieved cybersecurity. We'll have created bureaucracy with antivirus.
DSA, DMA and the passion to regulate giants by tripping up everyone else
The Digital Services Act and the Digital Markets Act have been presented as Europe's grand response to the excessive power of Big Tech. And on paper, the target is understandable: massive platforms, gatekeepers, global marketplaces, search engines, social networks, and opaque advertising systems. The problem is that every time Europe attempts to attack the giants, it ends up creating a regulatory climate that weighs on even those who aren't giants.
Large platforms have armies of lawyers, compliance officers, public policy managers, and dedicated budgets. European SMEs don't. European startups don't. Independent providers don't. E-commerce sites with four employees don't. So the paradox is always the same: The rule was created to limit the giants, but the giants are the ones best equipped to survive the rule.The others struggle, procrastinate, pay for consultancy, reduce risk, avoid functionality, and don't experiment.
In practice, Europe continues to say it wants to create digital champions, but it is creating an environment in which, to launch a product, you must first ask yourself whether you are violating three regulations, two directives, a guideline, a recital, and the mood of the national data protection authority on Thursday afternoon.
Omnibus: When You Need to Simplify the Mess You've Created
The word "Omnibus" is wonderful. It sounds like a regulatory bus full of tired people, suitcases, packages, amendments, and good intentions. We had the Omnibus Consumer Directive, with new rules on discounts, marketplaces, reviews, transparency of rankings, and commercial practices. Here too: understandable objectives. No one wants fake discounts, purchased reviews, or opaque marketplaces. But once again, the European solution is the same: add layers.
Every promotion becomes a matter of interpretation. Every review requires verification procedures. Every ranking must be explained. Every marketplace must declare roles, responsibilities, and parameters. All correct, in theory. All expensive, in practice. Especially for those who sell, develop, integrate, maintain, update, and must also compete with non-EU operators who often enter the market with a recklessness unheard of by the average European company.
The funny part is that then comes the Digital Omnibus, that is, Europe saying: "Maybe we've gone too far, let's simplify." Wonderful. It's like setting fire to the kitchen and then showing up with a glass of water and saying: "We've implemented a fire prevention strategy."
Data Act, Data Governance Act, AI Act: the "don't innovate without moral authorization" trifecta.
Meanwhile, on the data and artificial intelligence front, Europe has decided to leave nothing to chance. Data Governance Act, Data Act, AI Act. Data access, sharing, intermediaries, obligations, risk, transparency, documentation, governance, accountability. It all seems reasonable, until you're the one who actually has to build a product.
The problem is not having rules. The problem is having rules layered before even having a fully mature industryThe United States has built hyperscalers, AI ecosystem chips, cloud platforms, AI models, software marketplaces, developer tools, and global infrastructure. Then, with all their flaws, they debate how to regulate them. Europe often does the opposite: first they build the fence, then realize there's no horse inside.
The AI Act is the perfect example of our cultural posture: being the first in the world to regulate artificial intelligence. Great, applause, standing ovations, a medal for regulatory prowess. But in the meantime, who's leading the market? OpenAI, Google, Anthropic, Meta, xAI, American companies, and, increasingly, Chinese players. Europe? Europe holds conferences on digital sovereignty and funds plans to become an "AI continent." One day, perhaps. Meanwhile, the world uses American APIs.
Cyber Resilience Act, DORA, accessibility: each sector has its own brick.
That wasn't enough. We also have the Cyber Resilience Act for products with digital elements, DORA for the digital operational resilience of the financial sector, the Product Liability Act updated to include software and AI, and the European Accessibility Act to make digital products and services, including e-commerce, accessible. Here too: often shared objectives: security, responsibility, accessibility. Who could be against it?
But the point is the cumulative burden. Each regulation, taken individually, seems defensible. Disaster arises from the sum. It's like carrying a backpack: one book doesn't weigh much, two don't, three are manageable, ten start to hurt, thirty break your back. The European digital enterprise today is carrying that backpack: privacy, cookies, security, accessibility, consumers, platforms, data, AI, contracts, liability, notifications, audits, suppliers, subcontractors, transfers, logs, and disclosures.
And then we wonder why many companies don't scale. Perhaps because before scaling, they have to fill out forms.
RAMageddon: When you discover that digital requires real factories
And here we come to the point that should make us blush more than any infringement procedure: production. Because beyond all the laws, regulations, directives, strategic plans, solemn declarations, and conferences on "digital sovereignty," comes the material reality. And the material reality is called RAM. It's called DRAM. It's called HBM. It's called NAND. It's called storage. It's called silicon, wafer, fab, supply chain, energy, ultrapure water, lithography machines, advanced packaging, production yield, industrial capacity.
Digital, surprise of surprises, doesn't exist in the hyperuranion of policies. It lives in data centers. And data centers need servers. Servers need CPUs, GPUs, RAM, SSDs, controllers, cards, power, cooling, and networking. Artificial intelligence—the real kind, the kind everyone calls for in press releases—is hungry for memory. Brutal. RAM isn't a detail. It's the oxygen of modern computing. Without memory, you can't train models, you can't run large-scale inferences, you can't serve complex applications, you can't build a competitive cloud, you can't handle enterprise workloads, you can't run HPC—you can't do anything.
And what do we discover with the crisis dubbed "RAMageddon"? That when global demand for memory explodes, especially for AI and data centers, European consumers, European companies, European providers, and European systems engineers find themselves exposed like tourists in flip-flops during a hailstorm. Prices rise, availability shrinks, lead times lengthen, quotes change, hardware refreshes slip, margins evaporate. And what about us? We can always pass a directive on the user's right to receive a comprehensible explanation for the price increase. Beautiful. It doesn't lower the price of a DIMM, but what about regulatory compliance?
The problem is simple and gigantic: Europe is not independent in the production of fundamental memories for modern digital technologyWe have extraordinary excellence in the semiconductor supply chain, starting with ASML in lithography, and we have major players in industrial, automotive, and power electronics chips. But when it comes to DRAM, HBM, and NAND on a global scale, the center of gravity is elsewhere: South Korea, the United States, Japan, Taiwan, and China. The memory world is dominated by a few giants, with immense production capabilities, billions in investments, and control of strategic segments of the supply chain.
And then the question is brutal: What digital sovereignty do you want if you don't produce the memory that runs digital technology? What strategic autonomy do you want to assert if every European server depends on components produced, allocated, priced, and prioritized outside Europe? What kind of European AI do you want to build if you buy memory late, after the American hyperscalers arrive with huge contracts and outsized spending power?
RAM is not printed with a public consultation
Here the irony becomes almost overwhelming, because the situation is tragically real. While we debate governance, major Asian and American manufacturers are investing in new plants, increasing capacity, shifting lines to HBM, advanced NAND, and high-margin memory. AI has changed global demand: we don't just need more computing power, we need more memory, more bandwidth, more storage, more capacity to power models and applications. Memory has become a strategic resource, not an IT supermarket accessory.
For years, many have treated RAM like a commodity: an interchangeable component, to be bought when needed at the best price. Then comes the shortage, and suddenly you discover that the commodity wasn't so trivial. You discover that behind those modules are extremely expensive factories, highly advanced manufacturing processes, fragile supply chains, multi-year investment cycles, industrial and geopolitical concentration. You discover that if you don't have production, you don't have leverage. And if you don't have leverage, you suffer.
You suffer from prices. You suffer from manufacturers' priorities. You suffer from tensions between states. You suffer from AI build-outs from others. You suffer from hyperscalers' memory hunger. You suffer from component allocation. You suffer from storage, too, because the problem isn't just about volatile RAM. It also affects NAND flash, enterprise SSDs, high-capacity storage, data center infrastructure, hot and cold storage, distributed systems, backup, disaster recovery, object storage, appliances, and virtualization servers.
Every time the cost of memory or storage increases, the cost of infrastructure increases. And when the cost of infrastructure increases, the cost of cloud computing, hosting, managed services, backups, cybersecurity, AI, e-commerce, and digital productivity increases. Ultimately, the bill always ends up in the same place: businesses and citizens.
Digital sovereignty without industry is theater
The phrase "digital sovereignty" has become the catch-all phrase in institutional discourse. You find it everywhere. Digital sovereignty here, strategic autonomy there, European resilience above, competitive ecosystem below. But without production, this sovereignty is theater. A well-lit stage set with a void behind it.
To be sovereign, it is not enough to write rules about how others should behave. You have to know how to produceWe need to know how to manufacture chips, servers, storage, networking equipment, operating systems, cloud platforms, AI models, core software, databases, hypervisors, orchestrators, and critical components. We need affordable energy, capital, skills, supply chains, universities, venture capital, smart procurement, and a real industrial policy. Not an industrial policy for conferences, but an industrial policy for warehouses, plants, hiring, wafers, machines, shifts, maintenance, and production capacity.
Progress doesn't come from law alone. Law can create conditions, correct abuses, and protect rights. But progress comes from productionIt is born from those who design, build, make mistakes, invest, risk, hire, patent, scale, and export. A company that thinks it can govern technology without producing it becomes a notary public: it certifies the world created by others.
And that's precisely the European risk. Becoming the moral notary of global technology. The one who doesn't own the platforms, doesn't produce enough strategic hardware, doesn't dominate the cloud, doesn't drive AI, doesn't control memory, but tells everyone how they should behave. An almost touching figure: red pen in hand while others build factories.
Chips Act: good, but after the party, who actually builds?
The European Chips Act stems precisely from the recognition of a real vulnerability: dependence on fragile and concentrated global supply chains. Good. Finally, someone has understood that semiconductors aren't a technical detail for nerds, but an infrastructure of power. Too bad that understanding this in 2023, after pandemic crises, shortages, geopolitical tensions, and years of industrial delay, feels like calling the fire department when all that's left is the chimney.
Europe wants to increase its share of global semiconductor production, reduce dependencies, and strengthen the ecosystem. Excellent. But the key is scale. Because while we plan, others are investing enormous sums. While we negotiate authorizations, others are building factories. While we discuss governance, others are signing multi-year contracts for strategic supplies. While we imagine a more autonomous future, we are buying the present from outside.
The problem isn't that the Chips Act is useless. The problem is that it arrives in a continent that for years has treated industry as something dirty, slow, and inelegant, while celebrating services, finance, regulation, and the advanced tertiary sector. Then, when the world brutally returns to being material, we discover that production matters. That factories matter. That supply chains matter. That mines, materials, energy, and plants matter. That it's not enough to be good at writing regulations if you can't then produce what those regulations are supposed to govern.
The real damage: a culture of zero risk
The most serious damage isn't even the direct cost of compliance. The real damage is cultural. Europe is educating digital companies to think first about legal risk and then about the product. First about sanctions and then about the market. First about policy and then about the user. First about the consultant's opinion and then about the roadmap.
This mindset silently kills innovation. Not with an explicit ban, but with a toxic question that enters every meeting: "Can we do this?" Not "Does it work?", not "Does it help users?", not "Does it make us competitive?", not "Is it technically sound?" No: "Can we do it without getting into regulatory trouble?"
In digital, speed is a competitive factor. Iterate, test, measure, fail, correct. But if every test becomes a potential compliance dossier, the experiment dies before it's born. And when Europe slows down its operators, it doesn't slow down the world. It only slows itself down.
This also applies to industry. Building plants, producing semiconductors, developing storage, designing hardware, and competing in AI requires risk. It requires patient capital, costly mistakes, rapid authorizations, stable energy, and a domestic market capable of buying European not out of folklore but out of strategy. If, however, every initiative is swamped by permits, checks, uncertainties, opposition, procedures, and endless delays, then we shouldn't be surprised if investments go where construction is actually taking place.
Europe preaches, others build
And here we come to the bitter end. Europe talks about digital sovereignty, strategic autonomy, citizen protection, the data economy, the European cloud, trustworthy AI, critical infrastructure, and sustainable innovation. Beautiful words. It's a shame that while we talk, others are building.
The United States has hyperscalers, platforms, AI models, venture capital, developer ecosystems, product culture, and the ability to scale. South Korea dominates key memory components. Japan remains strategic in NAND storage and materials. Taiwan is central to advanced manufacturing. China is advancing with a completely different model, debatable as it may be, but industrially aggressive. Europe, on the other hand, excels in an Olympic discipline all its own: arrive late, regulate early and be surprised that you are not a leader.
And the final provocation is inevitable: dear Europe, after years spent explaining to the world how to do "right" digital, where is your great global AI model? Where is your true infrastructure champion? Where is the European platform the world cannot ignore? Where is the European memory supply chain? Where is our dominance in storage? Where is the production capacity that makes us independent when the global market decides that RAM costs double, triple, or simply isn't available?
There are some worthy examples, of course, and they shouldn't be underestimated. There's expertise, research, major companies, and industrial excellence. But the center of innovation remains elsewhere. And this should make us less likely to hold conferences and more likely to be ashamed.
Because protecting citizens is our duty. Securing digital is essential. Defending consumers is the right thing to do. But if, to do so, you build a continent where innovation costs more bureaucracy than development, and at the same time you don't produce enough to support that innovation, then you're not protecting the future: you're managing it to death.
There can be no progress without production. There may be regulation, there may be control, there may be compliance, there may be a wonderful European portal with institutional graphics and a downloadable PDF document. But true progress comes where construction takes place. Where manufacturing takes place. Where investment takes place. Where risks take place. Where the memory that powers the servers is produced, the storage that stores the data, the chips that perform the calculations, the infrastructure that makes everything else possible.
Dear Europe, you're broken. Not because you want rules. But because you've forgotten that rules are supposed to make things work better, not replace things you didn't have the courage to build.