Germany's Nuclear Approval Puts EU Energy Sovereignty Under Scrutiny
Germany has approved a nuclear facility with ties to the Kremlin, triggering alarm across Brussels and reigniting a debate that energy professionals, policymakers, and digital sovereignty advocates know all too well: how far will European governments go to maintain strategic independence from Russian state infrastructure? The decision, first reported by Euractiv, places the European Commission in an uncomfortable position — one that echoes similar dilemmas seen in debates over Chinese-linked telecoms infrastructure and Russian cloud services.
The approval has drawn sharp criticism from European Commission officials and MEPs who argue that allowing Kremlin-backed entities to operate within the EU's critical energy infrastructure fundamentally contradicts the bloc's stated goals around strategic autonomy. For those tracking digital sovereignty and data infrastructure policy closely, the parallels are striking: this is not merely an energy story. It is a story about who controls the essential systems that European citizens and institutions depend upon.

Russia's state nuclear corporation Rosatom has long maintained a footprint across Eastern and Central Europe, operating reactor contracts and supply chains in countries including Hungary, Finland, and the Czech Republic. Germany's decision to approve a facility linked to the Kremlin — even as the EU maintains sanctions against Russia following its invasion of Ukraine — has exposed a persistent fault line between national energy policy decisions and the European Commission's broader geopolitical stance.
What Rosatom's European Presence Really Means for Critical Infrastructure
Rosatom is not a private corporation. It is a state-owned enterprise operating directly under the authority of the Russian government — and by extension, the Kremlin. For IT decision-makers and policy professionals accustomed to GDPR compliance and data sovereignty debates, the risk model is immediately recognizable: when a foreign state-controlled entity operates infrastructure that a nation depends upon, that dependency becomes a lever of geopolitical influence.
According to reporting by Reuters, Rosatom has actively sought to expand its European nuclear contracts even amid the broader geopolitical deterioration following Russia's invasion of Ukraine. Critics argue that unlike oil or gas — which Europe has made measurable progress in decoupling from Russian supply — nuclear fuel supply chains and reactor maintenance agreements are far more technically complex to exit quickly. A country that installs a Russian-built reactor may find itself dependent on Rosatom for fuel, spare parts, and operational expertise for decades.
The problem is structural. The Nuclear Energy Agency and the International Atomic Energy Agency have both noted in published assessments that transitioning a nuclear reactor from Russian-supplied fuel to Western alternatives requires significant technical adaptation, time, and cost. This is not a supply chain that can be switched off like a software subscription. For EU policymakers, this makes the German approval all the more troubling — it potentially locks in a form of critical infrastructure dependency that could persist well beyond any political resolution to the current conflict.
"Allowing Kremlin-linked entities to build or operate facilities inside the EU's energy system is not just an energy policy question — it is a security architecture question that deserves the same scrutiny we apply to foreign telecoms equipment vendors."
— Senior EU energy policy analystHow Brussels Is Responding — and Why Its Toolkit Has Limits
The European Commission has been vocal about reducing dependency on Russian energy since the invasion of Ukraine, publishing its REPowerEU plan as the primary framework for accelerating that transition. But nuclear energy has always occupied an awkward legal space within EU architecture. Under the Euratom Treaty — the legal framework governing nuclear energy in Europe, which predates the EU itself — member states retain significant sovereign authority over their nuclear programs. This means Brussels has limited direct jurisdiction over Germany's approval decision.
This is where the situation becomes politically and legally complex. The Commission can pressure, advise, and create incentive structures, but it cannot simply veto a member state's nuclear licensing decision the way it can intervene in, say, a state aid case or a merger review. According to analysis published by the European Council on Foreign Relations, this governance gap has been exploited repeatedly, with individual member states pursuing bilateral energy arrangements that undermine collective EU energy independence goals.

For developers and IT architects working within EU compliance frameworks, this dynamic will feel familiar. The EU's approach to digital sovereignty — from GDPR to the European Data Act to proposed cloud switching regulations — similarly faces the challenge of harmonizing national-level decisions with bloc-wide ambitions. The recurring pattern is one where strategic intent exists at the European level, but execution authority remains fragmented across 27 member states.
The Digital Sovereignty Parallel: From Cloud Infrastructure to Nuclear Reactors
For the audience tracking European technology and digital sovereignty policy, the nuclear infrastructure debate carries direct analogues to ongoing conversations about cloud dependency, foreign-controlled AI infrastructure, and data localization. The core question in both domains is identical: when a European institution, company, or government depends on infrastructure controlled by a foreign state actor, what are the security, policy, and operational implications?
The EU's push for digital sovereignty through frameworks like GAIA-X, the European Cloud Federation initiative, and the Cybersecurity Act all rest on a foundational premise — that critical infrastructure should not be subject to foreign government override or surveillance. The same logic applies to a Kremlin-backed nuclear facility operating on European soil. If a software dependency on a non-EU cloud provider is considered a sovereignty risk worth regulating, the physical dependency on a Russian state nuclear operator sits in an entirely different — and arguably more serious — risk category.
| Domain | Risk Type | EU Policy Response | Enforcement Strength |
|---|---|---|---|
| Cloud/Data Infrastructure | Data access by foreign states | GDPR, Data Act, GAIA-X | Moderate |
| Telecoms (e.g., Huawei) | Network backdoors, espionage | 5G Toolbox, NIS2 | Strong |
| Nuclear Energy (Rosatom) | Geopolitical leverage, supply control | REPowerEU (soft guidance) | Weak |
| AI Systems | Model dependency, data exfiltration | EU AI Act | Emerging |
The contrast is worth noting: when it comes to telecoms equipment from Huawei, the EU and its member states moved with relative speed to coordinate exclusion policies under the 5G Toolbox framework. No equivalent hard-law mechanism exists for nuclear infrastructure dependencies. This asymmetry in regulatory muscle is something both energy policy professionals and tech sovereignty advocates are increasingly pointing to as a systemic gap.
Why Member States Keep Making Deals That Contradict EU Policy
Germany's decision does not exist in a vacuum. Hungary has been one of the most conspicuous examples, having signed a multi-billion-euro agreement with Rosatom to expand the Paks nuclear plant despite EU-level pressure. Finland had a Rosatom-contracted Hanhikivi project — though that contract was eventually terminated following the invasion of Ukraine. The Czech Republic, Bulgaria, and Slovakia all have Soviet-era VVER reactors that maintain some level of Russian supply chain dependency.
The recurring political reality is that energy costs, grid stability, and national industrial interests often outweigh bloc-level geopolitical strategy when domestic decision-makers are under pressure. For small business owners and entrepreneurs operating in EU markets, this kind of structural incoherence in infrastructure policy creates real business uncertainty — particularly for organizations that have made compliance and supply chain decisions based on the assumption that the EU is moving consistently toward greater strategic autonomy.