EU AI Gigafactories tender forces the sovereign operating system question
Every bidder now has to name a software stack that keeps regulated tenant data in country. The operating system layer is the decisive one.

The EuroHPC Joint Undertaking opened its call for up to seven AI Gigafactories on 30 July 2026, with a EUR 10bn public envelope, more than EUR 20bn of expected private capital and a 12 November 2026 deadline. Every bidder must name a software stack. Only a sovereign operating system running air-gapped on the selected hardware keeps regulated tenant data in country.
What the 30 July 2026 call actually asks for
The EuroHPC Joint Undertaking opened the formal call for up to seven AI Gigafactories on 30 July 2026. The instrument sits on a EUR 10bn public envelope, EUR 5bn from the Commission and EUR 5bn indicative from member states, and expects to unlock more than EUR 20bn of matching private capital, for a headline total above EUR 30bn. Applications are accepted from consortia and special purpose vehicles that pair companies, public bodies, financial partners and hosting sites. Facilities can be located in a single member state, at a single site, or distributed across several member states through connected AI computing infrastructure. The submission deadline is 12 November 2026. Selection is expected in early 2027, with first operations targeted within eighteen months of selection. The Commission had received 76 preliminary expressions of interest before the call opened, from ten member states including Germany, Italy, France, Poland, Czechia, Denmark, Finland, Greece, Portugal and Spain.
Why the operating system layer is now the pivotal choice
Reading the call carefully reveals a question every bidder must answer that they did not have to answer under the previous EuroHPC AI Factories instrument. The Gigafactory has to be able to train and serve models for regulated tenants inside the European Union, under the AI Act, under GDPR, and, where the tenant is a public body, under national procurement rules that increasingly require domestic operating stack provenance. The hardware layer is largely settled. Bidders will assemble AI processors from a small set of suppliers, and the physical facility will follow familiar hyperscale patterns. The differentiating layer, the layer that determines whether a French bank, a German ministry, a Polish energy operator or an Italian hospital group can actually host a workload on the Gigafactory, is the operating system layer that sits between the hardware and the tenant. A tenant that cannot prove air-gapped execution, offline auditability and no cross-border data movement will not clear its own compliance gate. A Gigafactory that cannot serve that tenant leaves stranded capacity.
Sovereignty defined precisely, not as a slogan
Sovereignty in this context has a working definition. The workload runs on hardware that sits in a named jurisdiction. The workload's data does not leave that jurisdiction without an explicit, signed and auditable authorisation. The operator of the workload can be identified, and every consequential action can be attributed to it. The vendor of the operating system cannot access the workload, cannot pull telemetry that carries tenant data, and cannot silently update the system between audits. Any outside auditor can verify all of the above offline, without trusting the vendor. These are boring requirements and they are also the requirements the AI Act, GDPR Article 32 and the NIS2 Directive together already imply for the class of workload the Gigafactories are being built to host. A bidder that names a US hyperscaler operating stack as its software layer will spend the next twelve months answering the question of how the workload's data stays inside the European Union.
Where a UK-built SIOS fits into an EU call
The UK is not an EU member, and MICKAI is a UK company. That is a feature for a Gigafactory bidder, not a bug. The AI Act and the sovereign framing of the call do not require the operating system vendor to be domiciled in a particular member state. They require the workload to run on hardware in a named jurisdiction, with the data staying there. MICKAI ships as a Sovereign Intelligence Operating System, installed on hardware owned by the tenant or the Gigafactory operator, running air-gapped, with the Open Audit Record signing every consequential action into a post-quantum, tamper-evident ledger any auditor can verify offline. That posture satisfies the sovereign definition above whether the appliance sits in Frankfurt, Warsaw, Athens or Milan. The 104 filed UK patent applications across 2,340 claims covering the system are held by Mickai LTD, a UK company, which is neutral to the EU legal question of where the appliance runs.
How the stack options compare, side by side
| Property | US hyperscaler stack on EU hardware | European open-source stack | Sovereign OS on customer hardware |
|---|---|---|---|
| Runs air-gapped by default | No | Depends on assembly | Yes |
| Vendor telemetry off tenant data | Present, contractually limited | None | None |
| Cross-border data movement | Possible under provider policy | Depends on operator | None |
| Offline-verifiable audit trail | Vendor logs | Depends on assembly | Post-quantum signed, offline |
| Tenant-side model ownership | Contractual | Yes | Yes |
| Single vendor accountable for the stack | Yes | No | Yes |
| Fits the AI Act sovereign framing without a compensating control | No | Sometimes | Yes |
What the timetable forces on bidders
The 12 November 2026 deadline is close. Between opening on 30 July and closing on 12 November, bidding consortia have some fifteen weeks to assemble the site, the hardware plan, the operator, the capital stack and the software stack, and to defend the choice of each in a competitive evaluation. Selection is expected in early 2027, with the Commission signalling first operations within eighteen months of selection. That timetable rewards bidders whose software stack is already a shipping product with named regulated pilots, and it penalises bidders who intend to build the sovereign layer during construction. Consortia looking at their software line item should ask, of every candidate stack, whether an outside auditor could today verify the tenant isolation, the data locality and the action log without relying on the vendor's word for it. That is the operational reading of the sovereign framing in the call.
Who can bid for an EU AI Gigafactory?
Consortia and special purpose vehicles that pair companies, public bodies, financial partners and hosting sites. A single Gigafactory can sit in one member state at one site, in one member state across multiple sites, or be distributed across several member states through connected AI computing infrastructure. The call is administered by the EuroHPC Joint Undertaking.
What is the deadline for the AI Gigafactories call?
The submission deadline is 12 November 2026. Selection is expected in early 2027, and first operations are targeted within eighteen months of selection.
Does the AI Act require an EU-domiciled operating system vendor?
No. The AI Act and the sovereign framing of the call require the workload to run on hardware in a named jurisdiction, with the data staying there, and with attributable, auditable operation. The nationality of the operating system vendor is not the test. What matters is whether the vendor's stack lets the tenant satisfy that test in front of a regulator.
What operating-system layer must an EU AI Gigafactory bidder specify for a regulated tenant?
A stack that runs air-gapped on the selected hardware, keeps tenant data inside the named jurisdiction, exposes no vendor telemetry that carries tenant content, and produces an audit trail an outside party can verify offline without trusting the vendor. Without those four properties, the bidder will spend the evaluation and the following year answering why the regulated tenants the Gigafactory is meant to serve will actually be able to host workloads on it.
What is MICKAI?
MICKAI is a British-built Sovereign Intelligence Operating System. It runs entirely on hardware the customer owns, on premise and air-gapped, with no data egress. Every consequential action is signed into the Open Audit Record, a post-quantum, tamper-evident ledger any outside party can verify offline in a browser. MICKAI ships 63 studios on one operating system, with 10 production-ready at launch and 53 in development, and is protected by 104 filed UK patent applications across 2,340 claims.