Austria - Digital Sovereignty Measures (2025)
Digital Austria Act 2.0
Austria
RAI-AT-NA-DA2DAXX-2025The Digital Austria Act 2.0 establishes a strategic national framework to strengthen digital sovereignty, interoperability and resilience across Austrian public administration, emphasising open standards, sovereign cloud infrastructure, trusted AI and procurement criteria that favour European or open-source solutions. It sets governance mechanisms, a "Sovereignty Compass" for risk assessment, and a timetable for connecting registers and shared services.
Summary
Read full text ↗Plain English
Overview
The Digital Austria Act 2.0 is a national strategic framework adopted by the Austrian government in late 2025 that sets out measures to strengthen Austria's digital sovereignty and resilience in public administration. It was introduced as a Ministerratsvortrag on 12 November 2025 and publicly described on the Digital Austria portal. The Act centres on a "Sovereignty Compass" for mapping dependencies, a move to open standards and open-source alternatives, and the establishment of a sovereign cloud and shared PaaS services inside the public sector (implemented in partnership with the Bundesrechenzentrum (BRZ)). It also sets procurement and funding incentives to prioritise European or open solutions and tasks AI governance bodies with ensuring trustworthy AI in administration. Primary documents and the ministerial paper are published by the Federal Chancellery; see the Ministerratsvortrag for the set of 12 concrete measures and timeline.
Definitions
Key terms used in the Act include "digital sovereignty" (capacity of institutions to act independently in the digital domain while respecting interoperability and openness), "Sovereignty Compass" (an instrument for mapping and assessing digital dependencies), "souveräne Cloud" (cloud infrastructure under European jurisdiction and standards), "trusted/vertrauenswürdige AI" (AI that meets legal, ethical and technical safeguards), and "souveränitätsbonus" (procurement/funding preference for European or open-source solutions). These definitions prioritise capability and control rather than isolation from global markets.
Governance and Institutional Framework
Implementation is coordinated through cross‑departmental bodies: the CDO‑Taskforce, the Generalsekretärs‑ and Präsidialkonferenz, and a planned GovTech‑Austria structure. The Federal Chancellery (Digitalisation portfolio) leads strategic oversight and receives semi‑annual implementation reports; the Digital Austria platform functions as the public hub for strategies and monitoring. The BRZ is designated as an operational competence centre for the sovereign PaaS and shared AI services. Ministries remain responsible for operational delivery within their sectors, while the Federal Procurement authorities and the Förder‑Taskforce integrate sovereign criteria into procurement and funding instruments. The governance model includes stakeholder engagement with industry, research and civil society and aligns national oversight roles with the European AI supervisory architecture.
Key Focus Areas
The Act identifies twelve primary measures and focus areas: (1) stronger use of open-source alternatives and migration planning for office and administrative software; (2) promotion of open standards and interoperability (aligned with EU interop rules); (3) digital competence building and awareness in public bodies; (4) trusted AI adoption via AI:AT and national AI oversight alignment; (5) establishment of a sovereign PaaS and cloud standards inside BRZ; (6) creation of a shared LLM service for administration; (7) consolidation of IT procurement across federal, state and municipal levels for economies of scale; (8) a national cloud framework agreement prioritising European control for sensitive data; (9) a "souveränitätsbonus" in grant and procurement decisions to favour domestic/European solutions; (10) secure cross‑authority communication solutions; (11) targeted funding instruments and a sovereign focus within Förder‑Taskforce activities; (12) reporting, monitoring and periodic review with half‑yearly reporting to the Staatssekretär and the Nationalrat. These priorities balance technical, organisational and procurement levers to reduce dependency, enhance security and foster local innovation.
Implementation Framework
Operationalisation relies on ministerial action plans, a rolling implementation schedule and resource alignment with existing budgets (BFG/BFRG references are cited in the ministerial paper). A Digi‑Ready check and interoperability assessments are required for new legal and IT initiatives. The BRZ will deliver a sovereign PaaS and host services such as a shared LLM offering; registries are to be connected to the Austrian Micro Data Center (AMDC) by 1 July 2026. Procurement rules are to be adjusted through the BVergG revision to include "digital sovereignty" as an evaluative criterion under §20 (subject to international agreements). The governance structure mandates semi‑annual implementation reports, stakeholder consultations, and an emphasis on public procurement and grant guidance.
Monitoring and Evaluation
Monitoring is twofold: internal administrative monitoring (CDO Taskforce, GovTech‑Austria, ministry-level KPI reporting) and parliamentary oversight through semi‑annual reports to the Staatssekretär and the Nationalrat. Digital Austria and the Federal Chancellery will publish progress updates, including indicators on register connectivity, adoption of PaaS standards, procurement outcomes and measures to reduce vendor concentration. Independent evaluation is foreseen via existing audit and oversight bodies, and impact assessments (including Digi‑Ready checks) will be used to validate interoperability and legal fit. Progress milestones and timelines are set out in the ministerial paper.
Penalties, Liability, and Appeals
The Act itself is a policy framework rather than a penal statute; enforcement leverages procurement law, contractual remedies and administrative accountability. Where procurement or grant rules are violated, standard procurement sanctions, contract termination rights and clawback of funds apply. Administrative non‑performance is addressed through reporting obligations, executive oversight and, where relevant, disciplinary or managerial measures under public‑service rules. Liability for data breaches or rights infringements continues to be governed by existing legislation including data protection law; appeals against procurement decisions remain in the competent procurement review institutions and courts. The Act instructs ministries to embed compliance checks into project lifecycle governance.
Relationship to Other Instruments
The Digital Austria Act 2.0 is designed to operate alongside and influence existing legal instruments: it proposes to embed digital sovereignty into the Bundesvergabegesetz (BVergG), aligns with the European AI regulatory framework and interoperability rules, and complements Austria’s Digital Decade commitments. The ministerial text explicitly references coordination with EU instruments and notes constraints imposed by international agreements. It does not repeal prior statutes but seeks amendments and administrative practices to promote sovereign outcomes.
International Alignment
The Act explicitly aligns with a pan‑European "Declaration on Digital Sovereignty" initiated by Austria and Europe‑wide coordination on cloud standards, interoperability and AI governance. It seeks to strengthen European supply chains, participate in EU cloud and data infrastructure initiatives, and implement measures in a way that is compatible with EU law and international procurement obligations. The policy emphasises cooperation rather than autarky and aims to make Austria an active participant in European standard setting.
Implementation Timeline
| Milestone | Target Date |
|---|---|
| Ministerratsvortrag (adopted) | 2025-11-12 |
| Committee endorsement (Digitalisation Committee) | 2025-11-26 |
| Nationalrat resolution / parliamentary reporting requirement | 2025-12-12 |
| Declaration on European Digital Sovereignty (EU) | 2025-11-18 |
| Connect register data to AMDC (target) | 2026-07-01 |
| Start of semi‑annual reporting to Staatssekretär & Nationalrat | First report due within 6 months of adoption (2026-06) |
Compliance Checklist
| Requirement | Evidence / Action |
|---|---|
| Sovereignty Compass assessment | Documented dependency mapping and risk register |
| Procurement criteria updated | BVergG amendments or internal procurement directives |
| AMDC registry connection | Technical onboarding certificates and test logs |
| BRZ PaaS adoption | Service agreements / migration plans |
| Trustworthy AI labelling | AI register entries, impact assessments and transparency notices |
Sources and References
| Source | Type |
|---|---|
| Ministerratsvortrag: Maßnahmen zur Stärkung der digitalen Souveränität ... (Digital Austria Act 2.0) | Primary Source |
| Digital Austria portal: Digital Austria Act 2.0 | Primary Source |
The Digital Austria Act 2.0 is a strategic policy framework for Austrian public administration, aiming to strengthen its digital independence and resilience. This initiative applies broadly to all levels of Austrian public administration – federal, state, and municipal – and indirectly impacts technology providers and companies seeking public contracts or grants.
Under this framework, public bodies must increasingly favour open standards, open-source software, and European-controlled solutions in their IT systems and procurement. This includes a "sovereignty bonus" that gives preference to domestic or European solutions in tenders and funding decisions. Administration is also required to use shared, secure "sovereign cloud" infrastructure and services, such as a common platform-as-a-service (PaaS) and a shared large language model (LLM) service, primarily provided by the Bundesrechenzentrum (BRZ). A "Sovereignty Compass" tool will be used to map and assess digital dependencies, guiding decisions to reduce reliance on non-European or proprietary solutions. The Act also mandates the adoption of "trustworthy AI" within administration, aligning with European ethical and technical safeguards.
While the framework was adopted in late 2025, key operational milestones are set for 2026. For instance, all public register data is targeted to be connected to the Austrian Micro Data Center (AMDC) by July 1, 2026, and semi-annual progress reports to parliament begin in mid-2026.
This isn't a law with new direct penalties. Instead, its "teeth" come from existing legal frameworks. Non-compliance with procurement rules, for example, could lead to standard sanctions like contract termination or clawback of funds. Administrative non-performance is managed through reporting, oversight, and public service rules. A key practical consideration for businesses is that the "sovereignty bonus" – the preference for European or open-source solutions in procurement and grants – is explicitly subject to existing international agreements. This means the preference isn't absolute and might have limitations, so companies shouldn't assume a blanket ban on non-European solutions.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Austria - Digital Sovereignty Measures (2025). Not legal advice — verify against the official text before relying on it.
- #1CriticalImplementation Framework
Applies to: Federal Procurement authorities and Förder-Taskforce
“Procurement rules are to be adjusted through the BVergG revision to include 'digital sovereignty' as an evaluative criterion under §20.”
- #2ImportantImplementation Framework⏰ Jul 1, 2026
Applies to: Ministries responsible for public registers
“registries are to be connected to the Austrian Micro Data Center (AMDC) by 1 July 2026.”
- #3ImportantGovernance and Institutional Framework⏰ 2026-06
Applies to: Ministries and relevant public bodies
“The Federal Chancellery ... receives semi‑annual implementation reports; ... half‑yearly reporting to the Staatssekretär and the Nationalrat.”
- #4ImportantImplementation Framework⏰ Before new legal and IT initiatives
Applies to: Public bodies initiating new legal or IT projects
“A Digi‑Ready check and interoperability assessments are required for new legal and IT initiatives.”
- #5ImportantOverview
Applies to: Public administration bodies
“The Act centres on a 'Sovereignty Compass' for mapping dependencies”
- #6ImportantOverview
Applies to: AI governance bodies and public administration using AI
“tasks AI governance bodies with ensuring trustworthy AI in administration.”
- #7ImportantOverview
Applies to: Federal Procurement authorities and Förder-Taskforce
“It also sets procurement and funding incentives to prioritise European or open solutions”
- #8ImportantPenalties, Liability, and Appeals
Applies to: Ministries and public bodies managing projects
“The Act instructs ministries to embed compliance checks into project lifecycle governance.”
- #9ImportantKey Focus Areas
Applies to: Public administration bodies
“promotion of open standards and interoperability (aligned with EU interop rules)”
- #10RecommendedKey Focus Areas
Applies to: Public bodies and their employees
“digital competence building and awareness in public bodies”
- #11RecommendedGovernance and Institutional Framework
Applies to: Cross-departmental bodies coordinating implementation
“The governance model includes stakeholder engagement with industry, research and civil society”
- #12RecommendedKey Focus Areas
Applies to: Federal Procurement authorities and public bodies
“consolidation of IT procurement across federal, state and municipal levels for economies of scale”
Related Regulations
Digital Austria Act (Digital Austria Act / Digitales Arbeitsprogramm der Bundesregierung)
Austria94% similar
Strategy of the Federal Government for Artificial Intelligence – Implementation Plan 2024 (KI-Umsetzungsplan 2024)
Austria91% similar
Nationaler strategischer Fahrplan für die Digitale Dekade Österreich (National strategic roadmap for the Digital Decade)
Austria91% similar
Datenstrategie für Österreich (Data Strategy for Austria)
Austria90% similar
Artificial Intelligence Mission Austria 2030 (AIM AT 2030)
Austria90% similar
© Regulations.AI — created on 13-Jun-2026