One small detail in Belgium caught my attention this spring. Defence personnel and intelligence officials began moving their work conversations onto an app called Beam. Soon, other public servants followed. Belgium expects the system eventually to serve roughly 750,000 civil servants and military personnel.
At first glance, this looks like another cybersecurity story. Governments have sensitive conversations, so they need secure software. Fair enough.
But Beam belongs to something larger. Across Europe, governments are trying to pull official communications away from the consumer internet and place them inside systems they can govern themselves. France has Tchap. Poland has developed mSzyfr. NATO is experimenting with NI2CE for unclassified communications. Germany already uses sovereign messaging systems in parts of government and defence.
I think the distinction matters more than the apps themselves.
Europe is gradually creating two communications environments. Citizens continue to live largely inside WhatsApp, Signal and other commercial or independent platforms. Governments increasingly want a separate layer in which they control the infrastructure, membership rules and jurisdiction.
That is not quite a surveillance state.
It is something more institutional, and perhaps more consequential.
Europe Is Taking Official Communication Back
Belgium’s Beam shows how the model works.
The service runs on the open Matrix protocol. Access is designed for government organisations, while the infrastructure remains under Belgian government control. Beam also uses end-to-end encryption, which means the Belgian state does not simply receive a readable copy of every conversation. According to Beam itself, only the participants can read the messages.
France has taken a similar approach with Tchap, its messaging platform for public-sector employees. Tchap is hosted in France on state infrastructure. It also uses end-to-end encryption, and the French government’s documentation explicitly says technical administrators cannot read the contents of conversations.
That distinction changes the argument.
European governments are not necessarily building messaging systems so that officials can be watched more easily. They are building systems in which the institution, rather than a foreign technology company, defines the operating environment.
Who receives an account? The institution decides.
Where does the system run? The institution can decide that too. Rules on authentication, connected devices and organisational access no longer depend entirely on the policies of an external platform.
Poland makes the sovereignty argument even more openly. Its government completed work on mSzyfr this year and says the country retains control over the data, server infrastructure and software lifecycle. In May, Polish cybersecurity authorities recommended that public bodies use mSzyfr for official communications after identifying advanced phishing campaigns targeting Signal accounts belonging to politicians and government personnel.
The issue, then, is not simply encryption.
It is control over the communications environment.
Signalgate Changed the Political Mood
The urgency became easier to understand after Signalgate.
In March 2025, senior officials in the Trump administration discussed planned US strikes against the Houthis in Yemen through Signal. A journalist from The Atlantic had accidentally been added to the group. The controversy later produced a court order requiring the administration to preserve relevant Signal messages amid concerns about federal record-keeping requirements.
Signal’s encryption was not the problem.
Human behaviour was.
That distinction is important because governments sometimes speak about consumer messaging applications as though encryption itself creates the danger. It does not. A highly secure application can still sit outside an institution’s identity system, records policy and administrative controls. Officials can use disappearing messages. Someone can add the wrong participant. A departing employee may retain access longer than an organisation wants.
A sovereign platform cannot abolish stupidity or carelessness. Nothing can.
It can make certain mistakes harder.
NATO’s NI2CE project illustrates the logic. NATO describes it as an experiment for everyday unclassified communication based on Matrix. Its architecture allows organisations to operate their own deployments while linking them through federation. Enterprise functions can include authentication and access management, along with administrative oversight.
This is less dramatic than claiming that governments want to read every message.
It is also more convincing.
Pfizergate Exposed a Different Weakness
Security is only half the problem. Records matter too.
The dispute over messages exchanged between European Commission President Ursula von der Leyen and Pfizer chief executive Albert Bourla exposed the strange position governments enter when major public business moves through informal communications.
Journalists sought access to text messages exchanged between the two during the Covid vaccine procurement period. The Commission said it did not possess the requested messages. On 14 May 2025, the EU’s General Court found that the Commission had failed to give plausible explanations for why the messages did not exist or were no longer in its possession.
The lesson is not that a sovereign messenger would automatically have preserved every Von der Leyen message forever.
Retention does not work that way. Governments still need records policies, preservation rules and appropriate technical configuration.
But institutionally controlled communications make those rules easier to enforce.
That matters. Government communication is not merely private conversation conducted by people who happen to hold public office. Some messages become administrative records. Others may later become evidence of how decisions were made.
A consumer application places much of that process outside the institution’s architecture.
Sovereign messaging brings part of it back.
The Bigger Story Is European Digital Dependence
Messaging apps are one visible part of a much wider argument.
Europe depends heavily on technology developed elsewhere, particularly in the United States. An analysis published by the Atlantic Council cites a European Parliament estimate that the EU relies on non-EU countries for more than 80 per cent of its digital products, services, infrastructure and intellectual property.
That dependency once looked mostly commercial.
It now looks strategic.
Cloud computing stores public-sector data. Communications platforms carry discussions between senior officials. Artificial intelligence systems increasingly sit inside administrative workflows. A change in foreign law or corporate policy can therefore become a European governance problem.
The US CLOUD Act reinforces those anxieties because American providers can, subject to US legal process, be required to produce data within their possession or control even when that information is stored overseas. This is one reason a server physically located in Europe does not automatically satisfy European ideas of digital sovereignty.
Brussels has started turning the concept into procurement policy.
In April 2026, the European Commission awarded contracts worth up to €180 million for sovereign cloud services available to EU institutions and agencies. The Commission explicitly described the procurement as part of an effort to strengthen the Union’s digital sovereignty.
Messaging apps therefore should not be viewed in isolation.
They are an early layer of a larger institutional migration.
Chat Control Reveals the Difficult Part
Then Europe runs into encryption.
The debate usually called “Chat Control” has become confusing because two different legal projects are often treated as though they were one.
The temporary system, sometimes called Chat Control 1.0, allows communications providers voluntarily to detect and report child sexual abuse material under a derogation from normal electronic-privacy rules.
The European Parliament rejected an extension on 26 March 2026 by 311 votes to 228. The previous regime consequently expired on 3 April.
But that was not the end of it.
After further negotiations, the EU reinstated a narrower temporary regime in July. Regulation 2026/1881 now permits voluntary detection again and remains applicable until 3 April 2028. The compromise excludes number-independent interpersonal communications where end-to-end encryption applies.
The permanent legislation, commonly called Chat Control 2.0, remains unresolved.
Negotiations continue over detection obligations and their relationship with encrypted communications. Five negotiating rounds had failed to settle the central disagreement by early September. According to Council minutes tracked by the independent Chat Control Tracker, another political trilogue is planned for 29 September 2026.
Here the two-tier architecture becomes more interesting.
European governments want communications systems for officials in which infrastructure and organisational governance remain under European control. Yet those same governments still disagree over how far the state should reach into encrypted communications used by everyone else.
That is not a simple contradiction.
It is a struggle over two different kinds of sovereignty.
One concerns the state’s ability to control its own infrastructure. The other concerns how much authority that same state should exercise over private communications it does not own.
Europe has made more progress on the first question than the second.
The Security Pressure Is Not Going Away
Recent events will push governments further in this direction.
On 24 March 2026, attackers compromised cloud infrastructure supporting parts of the European Commission’s Europa.eu web platform. The Commission said data appeared to have been taken, although its internal systems were not affected.
Then came a more direct warning.
In August, European cybersecurity officials acknowledged that state-backed actors had attempted to compromise Signal and WhatsApp accounts belonging to senior EU officials. The attacks relied on spearphishing and social engineering rather than defeating the underlying encryption. More than 190 threat actors had reportedly targeted the EU institutional ecosystem during the preceding twelve months.
Again, encryption was not necessarily the weak point.
The user was.
That makes sovereign platforms attractive because governments can combine encrypted messaging with controlled identity systems and institutional security policies. They can remove accounts when employees leave. They can restrict who enters the network. They can decide where the infrastructure sits.
None of this makes a government network invulnerable.
It makes it governable.
Europe Is Separating the State From the Consumer Internet
I find the direction more important than any individual application.
Europe spent much of the internet era allowing government officials to communicate through systems originally designed for consumers. Convenience won. Institutional control came later.
That order is now reversing.
Beam, Tchap and mSzyfr represent an attempt to create an official communications layer that sits closer to the state. NATO’s NI2CE experiment points in the same direction without yet representing a wholesale NATO migration. The European Commission’s sovereign-cloud procurement suggests that the logic will not stop at messaging.
Microsoft Teams could eventually face the same sovereignty questions. So could cloud storage and other administrative infrastructure.
Europe is therefore not simply “ditching American apps.”
Something more precise is happening.
Governments are trying to separate official digital space from the wider consumer internet.
For officials, sovereignty increasingly means infrastructure under domestic or European jurisdiction and membership controlled by the institution. It can also mean rules that governments themselves can enforce. For ordinary users, the communications environment remains much more fragmented, while Brussels continues arguing about what privacy should mean when strong encryption collides with law-enforcement demands.
That is the emerging two-tier system.
Not one tier where governments can read everything and another where citizens disappear behind perfect encryption. Reality is messier than that.
The real division concerns who controls the architecture.
European states increasingly want that control for themselves when their own officials communicate. They have not yet decided how much control they should have when everyone else does.
For the moment, Europe is answering the easier question first.
This article was researched and written with AI assistance, combined with the author’s own expertise and editorial judgment.

