Austria - Digital Sovereignty Measures (2025)

Digital Austria Act 2.0

Austria

RAI-AT-NA-DA2DAXX-2025
Adopted(Adopted)
PolicyGovernance and OversightRisk Management
Export PDF

The Digital Austria Act 2.0 establishes a strategic national framework to strengthen digital sovereignty, interoperability and resilience across Austrian public administration, emphasising open standards, sovereign cloud infrastructure, trusted AI and procurement criteria that favour European or open-source solutions. It sets governance mechanisms, a "Sovereignty Compass" for risk assessment, and a timetable for connecting registers and shared services.

Overview

The Digital Austria Act 2.0 is a national strategic framework adopted by the Austrian government in late 2025 that sets out measures to strengthen Austria's digital sovereignty and resilience in public administration. It was introduced as a Ministerratsvortrag on 12 November 2025 and publicly described on the Digital Austria portal. The Act centres on a "Sovereignty Compass" for mapping dependencies, a move to open standards and open-source alternatives, and the establishment of a sovereign cloud and shared PaaS services inside the public sector (implemented in partnership with the Bundesrechenzentrum (BRZ)). It also sets procurement and funding incentives to prioritise European or open solutions and tasks AI governance bodies with ensuring trustworthy AI in administration. Primary documents and the ministerial paper are published by the Federal Chancellery; see the Ministerratsvortrag for the set of 12 concrete measures and timeline.

Definitions

Key terms used in the Act include "digital sovereignty" (capacity of institutions to act independently in the digital domain while respecting interoperability and openness), "Sovereignty Compass" (an instrument for mapping and assessing digital dependencies), "souveräne Cloud" (cloud infrastructure under European jurisdiction and standards), "trusted/vertrauenswürdige AI" (AI that meets legal, ethical and technical safeguards), and "souveränitätsbonus" (procurement/funding preference for European or open-source solutions). These definitions prioritise capability and control rather than isolation from global markets.

Governance and Institutional Framework

Implementation is coordinated through cross‑departmental bodies: the CDO‑Taskforce, the Generalsekretärs‑ and Präsidialkonferenz, and a planned GovTech‑Austria structure. The Federal Chancellery (Digitalisation portfolio) leads strategic oversight and receives semi‑annual implementation reports; the Digital Austria platform functions as the public hub for strategies and monitoring. The BRZ is designated as an operational competence centre for the sovereign PaaS and shared AI services. Ministries remain responsible for operational delivery within their sectors, while the Federal Procurement authorities and the Förder‑Taskforce integrate sovereign criteria into procurement and funding instruments. The governance model includes stakeholder engagement with industry, research and civil society and aligns national oversight roles with the European AI supervisory architecture.

Key Focus Areas

The Act identifies twelve primary measures and focus areas: (1) stronger use of open-source alternatives and migration planning for office and administrative software; (2) promotion of open standards and interoperability (aligned with EU interop rules); (3) digital competence building and awareness in public bodies; (4) trusted AI adoption via AI:AT and national AI oversight alignment; (5) establishment of a sovereign PaaS and cloud standards inside BRZ; (6) creation of a shared LLM service for administration; (7) consolidation of IT procurement across federal, state and municipal levels for economies of scale; (8) a national cloud framework agreement prioritising European control for sensitive data; (9) a "souveränitätsbonus" in grant and procurement decisions to favour domestic/European solutions; (10) secure cross‑authority communication solutions; (11) targeted funding instruments and a sovereign focus within Förder‑Taskforce activities; (12) reporting, monitoring and periodic review with half‑yearly reporting to the Staatssekretär and the Nationalrat. These priorities balance technical, organisational and procurement levers to reduce dependency, enhance security and foster local innovation.

Implementation Framework

Operationalisation relies on ministerial action plans, a rolling implementation schedule and resource alignment with existing budgets (BFG/BFRG references are cited in the ministerial paper). A Digi‑Ready check and interoperability assessments are required for new legal and IT initiatives. The BRZ will deliver a sovereign PaaS and host services such as a shared LLM offering; registries are to be connected to the Austrian Micro Data Center (AMDC) by 1 July 2026. Procurement rules are to be adjusted through the BVergG revision to include "digital sovereignty" as an evaluative criterion under §20 (subject to international agreements). The governance structure mandates semi‑annual implementation reports, stakeholder consultations, and an emphasis on public procurement and grant guidance.

Monitoring and Evaluation

Monitoring is twofold: internal administrative monitoring (CDO Taskforce, GovTech‑Austria, ministry-level KPI reporting) and parliamentary oversight through semi‑annual reports to the Staatssekretär and the Nationalrat. Digital Austria and the Federal Chancellery will publish progress updates, including indicators on register connectivity, adoption of PaaS standards, procurement outcomes and measures to reduce vendor concentration. Independent evaluation is foreseen via existing audit and oversight bodies, and impact assessments (including Digi‑Ready checks) will be used to validate interoperability and legal fit. Progress milestones and timelines are set out in the ministerial paper.

Penalties, Liability, and Appeals

The Act itself is a policy framework rather than a penal statute; enforcement leverages procurement law, contractual remedies and administrative accountability. Where procurement or grant rules are violated, standard procurement sanctions, contract termination rights and clawback of funds apply. Administrative non‑performance is addressed through reporting obligations, executive oversight and, where relevant, disciplinary or managerial measures under public‑service rules. Liability for data breaches or rights infringements continues to be governed by existing legislation including data protection law; appeals against procurement decisions remain in the competent procurement review institutions and courts. The Act instructs ministries to embed compliance checks into project lifecycle governance.

Relationship to Other Instruments

The Digital Austria Act 2.0 is designed to operate alongside and influence existing legal instruments: it proposes to embed digital sovereignty into the Bundesvergabegesetz (BVergG), aligns with the European AI regulatory framework and interoperability rules, and complements Austria’s Digital Decade commitments. The ministerial text explicitly references coordination with EU instruments and notes constraints imposed by international agreements. It does not repeal prior statutes but seeks amendments and administrative practices to promote sovereign outcomes.

International Alignment

The Act explicitly aligns with a pan‑European "Declaration on Digital Sovereignty" initiated by Austria and Europe‑wide coordination on cloud standards, interoperability and AI governance. It seeks to strengthen European supply chains, participate in EU cloud and data infrastructure initiatives, and implement measures in a way that is compatible with EU law and international procurement obligations. The policy emphasises cooperation rather than autarky and aims to make Austria an active participant in European standard setting.

Implementation Timeline

MilestoneTarget Date
Ministerratsvortrag (adopted)2025-11-12
Committee endorsement (Digitalisation Committee)2025-11-26
Nationalrat resolution / parliamentary reporting requirement2025-12-12
Declaration on European Digital Sovereignty (EU)2025-11-18
Connect register data to AMDC (target)2026-07-01
Start of semi‑annual reporting to Staatssekretär & NationalratFirst report due within 6 months of adoption (2026-06)

Compliance Checklist

RequirementEvidence / Action
Sovereignty Compass assessmentDocumented dependency mapping and risk register
Procurement criteria updatedBVergG amendments or internal procurement directives
AMDC registry connectionTechnical onboarding certificates and test logs
BRZ PaaS adoptionService agreements / migration plans
Trustworthy AI labellingAI register entries, impact assessments and transparency notices

Sources and References

SourceType
Ministerratsvortrag: Maßnahmen zur Stärkung der digitalen Souveränität ... (Digital Austria Act 2.0)Primary Source
Digital Austria portal: Digital Austria Act 2.0Primary Source
Plain English

The Digital Austria Act 2.0 is a strategic policy framework for Austrian public administration, aiming to strengthen its digital independence and resilience. This initiative applies broadly to all levels of Austrian public administration – federal, state, and municipal – and indirectly impacts technology providers and companies seeking public contracts or grants.

Under this framework, public bodies must increasingly favour open standards, open-source software, and European-controlled solutions in their IT systems and procurement. This includes a "sovereignty bonus" that gives preference to domestic or European solutions in tenders and funding decisions. Administration is also required to use shared, secure "sovereign cloud" infrastructure and services, such as a common platform-as-a-service (PaaS) and a shared large language model (LLM) service, primarily provided by the Bundesrechenzentrum (BRZ). A "Sovereignty Compass" tool will be used to map and assess digital dependencies, guiding decisions to reduce reliance on non-European or proprietary solutions. The Act also mandates the adoption of "trustworthy AI" within administration, aligning with European ethical and technical safeguards.

While the framework was adopted in late 2025, key operational milestones are set for 2026. For instance, all public register data is targeted to be connected to the Austrian Micro Data Center (AMDC) by July 1, 2026, and semi-annual progress reports to parliament begin in mid-2026.

This isn't a law with new direct penalties. Instead, its "teeth" come from existing legal frameworks. Non-compliance with procurement rules, for example, could lead to standard sanctions like contract termination or clawback of funds. Administrative non-performance is managed through reporting, oversight, and public service rules. A key practical consideration for businesses is that the "sovereignty bonus" – the preference for European or open-source solutions in procurement and grants – is explicitly subject to existing international agreements. This means the preference isn't absolute and might have limitations, so companies shouldn't assume a blanket ban on non-European solutions.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Austria - Digital Sovereignty Measures (2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalImplementation Framework

    Applies to: Federal Procurement authorities and Förder-Taskforce

    Procurement rules are to be adjusted through the BVergG revision to include 'digital sovereignty' as an evaluative criterion under §20.
  2. #2ImportantImplementation FrameworkJul 1, 2026

    Applies to: Ministries responsible for public registers

    registries are to be connected to the Austrian Micro Data Center (AMDC) by 1 July 2026.
  3. #3ImportantGovernance and Institutional Framework2026-06

    Applies to: Ministries and relevant public bodies

    The Federal Chancellery ... receives semi‑annual implementation reports; ... half‑yearly reporting to the Staatssekretär and the Nationalrat.
  4. #4ImportantImplementation FrameworkBefore new legal and IT initiatives

    Applies to: Public bodies initiating new legal or IT projects

    A Digi‑Ready check and interoperability assessments are required for new legal and IT initiatives.
  5. #5ImportantOverview

    Applies to: Public administration bodies

    The Act centres on a 'Sovereignty Compass' for mapping dependencies
  6. #6ImportantOverview

    Applies to: AI governance bodies and public administration using AI

    tasks AI governance bodies with ensuring trustworthy AI in administration.
  7. #7ImportantOverview

    Applies to: Federal Procurement authorities and Förder-Taskforce

    It also sets procurement and funding incentives to prioritise European or open solutions
  8. #8ImportantPenalties, Liability, and Appeals

    Applies to: Ministries and public bodies managing projects

    The Act instructs ministries to embed compliance checks into project lifecycle governance.
  9. #9ImportantKey Focus Areas

    Applies to: Public administration bodies

    promotion of open standards and interoperability (aligned with EU interop rules)
  10. #10RecommendedKey Focus Areas

    Applies to: Public bodies and their employees

    digital competence building and awareness in public bodies
  11. #11RecommendedGovernance and Institutional Framework

    Applies to: Cross-departmental bodies coordinating implementation

    The governance model includes stakeholder engagement with industry, research and civil society
  12. #12RecommendedKey Focus Areas

    Applies to: Federal Procurement authorities and public bodies

    consolidation of IT procurement across federal, state and municipal levels for economies of scale

© Regulations.AI — created on 13-Jun-2026