The stack behind the invoice: ranking Europe's digital build list¶
A plain-language companion to the draft working paper "An Open Internet Stack: What to Build, in What Order, and Why" (v0.6, July 2026). The paper carries the crosswalk, the frozen classification rule, the sourced market table, the perturbation suites, and the caveats; this text carries the ideas.
Read the full draft working paper (PDF)
The short version. Europe has several careful lists of what a sovereign digital stack requires. Lists name what the stack needs; they cannot rank it, because a list scores blocks one by one while dependence accrues along whole supply chains. The paper converts one such list, the fifteen Technological Building Blocks of a European Open Internet Stack, into a ranking by composing two measurements: the dependency structure of a 52-category graph, and sourced market economics behind each block. The composition discriminates. Six blocks classify captured and seven thin, and the split lines up with the markets: the captured blocks are where non-EU providers hold the market nearly outright, the thin blocks are where Europe's largest measured positions sit. The graph then explains why the exposure is easy to miss: European demand lands on cloud, communication, and applications, while the blocks the exposure arrives through never appear on an invoice.
Lists name; they do not rank¶
A budget forces questions no list answers: which block first, with which instrument, and why this one before that one. The paper answers them with a rule fixed in writing before any number was computed: each block is crosswalked onto the measured dependency graph, scored for independent realizations, jurisdictional reach, forkability, and exit friction, and classified into four classes (adequate, thin, captured, absent). New at this version, every block also carries its market economics, each figure fetched from a public source with URL, access date, and a confidence flag, and commissioned or interested-party sources flagged as such. Of the fifteen blocks, the twelve substantive ones are scored (one split into its silicon and cloud halves; the three cross-cutting concerns are lenses, out of the rule's scope).
Captured where the market is gone, thin where Europe still plays¶
Six blocks classify captured: digital identity, cybersecurity supply, operations tooling, development tooling, market platforms, and end-user computing and edge. Captured is a measurement class (foreign legal reach covering every category in the block, or worst-level codings throughout); it describes measured exposure and alleges no deliberate act of control. Where a share is published for a captured block, the market says the same thing as the graph: non-European players hold 60 to 70 percent of EU cybersecurity, international schemes carry about 61 percent of euro-area card payments with 13 countries fully reliant on them, and the operating-system and app-store layer is effectively entirely non-European, a 99.97 percent mobile duopoly.
The seven thin blocks hold Europe's largest measured market positions: telecom services at EUR 407bn (2024), cloud at EUR 61bn (2024) with a 15 percent EU-provider share against 70 percent for the three US hyperscalers, and chip demand of USD 54.1bn (2025) against roughly 10 percent EU production share. Thin means one unreached category short of captured: real European assets exist, and the unreached categories name what procurement could compound. Two of the six captured verdicts (operations and development tooling) rest entirely on US jurisdictional reach into open-source commons that is already forkable: stewardship problems (where the forges and registries are hosted, who sits in governance, whether fork capability is maintained), misread as build problems until forkability is priced, and the cheapest gap class on public cost records.
The cone: what you buy is where you are not exposed¶
Contracting the 52-category graph onto the blocks (new at this version, cross-checked edge by edge against the category graph) shows where dependencies concentrate. Seven blocks are net suppliers, and four carry most of the inbound weight: the silicon chain, the development toolchain, operations tooling, and market platforms; three of those four classify captured and the fourth is the semiconductor floor. Cloud is the hinge, supplying the application layer while consuming every foundation block, which is why a 70 percent big-three share at the hinge taxes everything above it. The application and AI blocks are pure consumers: nothing in the stack depends on them, so the blocks that earn the revenue are the blocks with no structural leverage, and the leverage blocks earn theirs as inputs or tolls (the platform block's supplier position is distribution, the priced door between applications and users).
The demand layer makes the finding concrete. The six measured European demand categories place their dependency edges on cloud, communication and collaboration, applications, end-user computing, and the network; they place zero direct edges on data and AI foundations, operations tooling, or development toolchains, and exactly one on identity. What procurement never sees directly, it consumes by composition, so a per-block checklist would fund the visible layer while the visible layer's exposure is set upstream, in blocks the demand side never sees on an invoice. The downstream stake is sourced in the paper with its weights stated: commissioned estimates put 80 percent of European business cloud and software spending with US vendors (EUR 265bn per year) and the drain from price rises on the locked base at a further EUR 93bn per year.
The floor, in one sentence, and the money map¶
Traced far enough upstream, every realization of every block crosses the semiconductor floor, where each of five actors (the United States, China, Japan, Korea, Taiwan) alone could cut it, so compute-floor policy and block-level instruments are complements and neither substitutes for the other. The instrument map then matches families to measured gaps: substrate stewardship, the cheapest family on public records (hundreds of thousands to millions of euros per component engagement), addresses the two commons-captured blocks; build-or-buy, at billions, is reserved for the captured blocks with no forkable substrate, of which identity compounds worst (the highest measured exit friction, mean 0.77); demand aggregation, at tens to hundreds of millions, fits the thin blocks; capacity investment, at tens of billions, addresses the floor. The ranking holds at family level only, and no instrument on the list is claimed to deliver sovereignty: the matrix states which measured gap each instrument class addresses, and whether a gap actually moves is a separate, unmeasured event.
The small print¶
This is a draft working paper, and its verdicts inherit the resolution and codings of the instruments it computes on. All classifications survive a 500-draw perturbation of every ordinal judgment the rule reads, and a separate perturbation of the jurisdictional reach edges shows where the weight sits: identity and market platforms stay captured on every draw, anchored by worst-level concentration codings, while the captured verdicts of cybersecurity supply, the two tooling blocks, and end-user computing rest on one or two single-coder reach edges each, and a single miscoded edge would move any of them to thin. No independent coder has re-coded those edges yet; the paper names that re-code as its outstanding item. The market table is honest about its own limits: scopes differ row by row and are never harmonized, usage shares stand in for revenue shares only where no revenue split exists, and eight of the thirteen scored blocks carry a published market size, with the gaps concentrated exactly where the substrate is unpriced. The matrix diagnoses and does not deliver: nothing in it measures an intervention actually closing a gap.