The Kyndril-Solvinity Case: A Barometer for Investment Security Reviews?
Photo: da-kuk/Getty Images
Investment screening, once a backstop against discrete security threats, has become a primary instrument in the geopolitics of technology. The United States and the United Kingdom were early movers, adopting inbound investment security regimes in 1975. In 2018, the U.S. Committee on Foreign Investment in the United States (CFIUS) was significantly strengthened. Then, in 2023, the United States stood up one of the only outbound investment screening regimes, further codified through the 2025 COINS Act. China has also pursued a more assertive investment screening regime, launching a comprehensive outbound screening regime in June 2026. This instrument equips the Chinese government with new retaliatory authority that could curtail commercial activities in foreign jurisdictions—for example, chip fabrication in Europe. Countries across Europe, meanwhile, are tightening their own frameworks, and the European Commission is poised to make significant changes to its investment security regime later this calendar year.
While investment security as an instrument is not new, the velocity and scope of changes are beginning to alter countries’ management of sensitive technologies, from artificial intelligence (AI) to quantum technologies with military end-use capabilities. This growing global appetite for closer investment scrutiny will create a new bundle of regulatory hurdles at the nexus of technology, data sovereignty, and the physical inputs that feed advanced technology systems. A recent case in the Netherlands highlights an emerging trend that companies across supply chains will need to follow closely, from rare earth element suppliers to cloud service providers.
Kyndryl-Solvinity Case Details
In November 2025, IBM spinoff Kyndryl announced it had reached an agreement to buy Solvinity, a Dutch cloud service provider, in a deal valued at roughly €100 million. Kyndryl is the world’s largest digital infrastructure provider, servicing most Fortune 500 companies. Solvinity, on the other hand, hosts DigiD, the Dutch digital identity system used by Dutch citizens to access tax, pension, healthcare, and government services. Solvinity also operates the infrastructure behind MijnOverheid, the government’s citizen communications portal, and Digipoort, the service for business-to-government digital services. Together, these platforms form the backbone of Dutch public digital infrastructure and are run from a secure government data center.
Dutch regulators reviewed and cleared the deal in February 2026, despite growing political opposition to a foreign takeover of critical domestic technological services. Journalist Eric Smit and Privacy First, an independent civil society foundation focused on privacy protection, initiated legal action seeking judicial intervention in the process, arguing that the acquisition could expose sensitive data to foreign jurisdiction. The Dutch parliament then recommended that DigiD, the government’s national authentication system, be removed from Solvinity ahead of the takeover due to national security concerns. The court permitted an extension of the Dutch Cabinet’s contract with Solvinity, rejecting calls to block the renewal over concerns about deepening extraterritorial access to sensitive personal data.
However, in May 2026, the deal was ultimately blocked. Willemijn Aerdts, state secretary for the digital economy and sovereignty within the Dutch Ministry of Economic Affairs, acted on advice from the Investment Screening Bureau (BTI), the Dutch equivalent of CFIUS. It is the first BTI transactional denial involving an attempted U.S. acquisition. Commenting on the decision, Aerdts cited the “great value to the presence of foreign, especially U.S.-based tech companies, and their added value to the Dutch economy and digital infrastructure.” Yet, as a national security imperative, mounting sovereignty can supersede associated commercial value.
Data Sovereignty and Processing Concerns
A central concern on the Dutch side revolved around the U.S. CLOUD Act. The 2018 law provides U.S. law enforcement and intelligence agencies the authority to compel U.S.-headquartered companies to hand over data stored on their servers anywhere in the world, regardless of the host country’s data protection laws. Kyndryl’s ownership of Solvinity could thus subject sensitive Dutch digital identity data to significant foreign exposure.
The importance of this decision is unfolding in an increasingly tense environment in which countries worldwide—including the United States—are applying greater skepticism to the harvesting, processing, and end-uses of citizens’ data. While European civil society has been very active in designing and maintaining digital privacy protections, what began a digital generation ago as a civil liberties movement has shifted considerably toward a national security conversation.
This new era interweaves digital privacy considerations with protections against advanced AI systems and the perceived hoovering of civilian data for unstated future uses. These concerns have manifested in pullbacks in other jurisdictions of contracts with U.S. firms. In June 2026, a bipartisan group of parliamentarians in the United Kingdom voted to terminate a Palantir contract before the initial contractual deadline, citing fears about data security. In France, the intelligence agency, DGSI, severed a decade-long contract with Palantir, following a similar decision in Germany in favor of European providers like ChapsVision to provide critical government services. The uncertain future of AI systems and data privacy has already refocused international attention on emerging geopolitical fault lines, with major consequences for using trade and investment instruments to govern intangible products like AI and the knowledge that feeds AI systems. Strength and influence were once measured in relationships based on hard power, but dominance over advanced technologies has led some foreign policy experts to predict a return to “spheres of influence” that would mean a further splintering of the internet and international means of governing digital goods and services.
The European Union has spent the last generation of technology caught between two technological superpowers. Chinese vendors Huawei and ZTE have become deeply embedded in European 5G networks, while U.S. cloud services dominate the European market. Early attempts to de-risk from Chinese telecoms had mixed success. The European Union’s 5G toolbox was voluntary, designed to provide a coordinated guidance and risk mitigation framework for member states that chose to opt in. In reality, adoption and implementation was rather uneven across the bloc, since member states largely ignored it. In January 2026, however, EU Executive Vice-President for Tech Sovereignty Henna Virkkunen presented a cybersecurity package designed to convert that voluntary instrument into a stronger one, requiring the removal of high-risk vendor components from key network infrastructure within 36 months. These efforts also represent a more assertive and geopolitical commission that has begun to bolster European independence from foreign reliance. This bid to advance technological sovereignty has thus far culminated in the Tech Sovereignty Package, unveiled on June 3, 2026. The package includes the Chips Act 2.0, the Cloud and AI Development Act, The EU Open Source Strategy, and the Strategic Roadmap for Digitalisation and AI in Energy. The Cloud and AI Development Act introduces an EU-wide framework of sovereignty tiers for cloud computing, reflecting a novel response to growing European concerns about sovereign control and proactively seeking to avoid worst-case kill-switch scenarios.
Fears about data and advanced AI systems also continue to manifest on the U.S. side. During the Biden administration, the White House introduced an executive order to stem the flow of sensitive data to countries and entities of concern, built largely on the discovery that entities affiliated with China’s People’s Liberation Army were able to purchase—for pennies on the dollar—data about U.S. active military personnel. More recently, the June 2026 U.S. directive to suspend all access to Anthropic’s Fable 5 and Mythos 5 by any foreign national has sent shockwaves through foreign communities about the reliability of U.S. technology and the now very concrete reality that service disruptions can happen abruptly and without robust interagency coordination.
U.S. Context
The Kyndryl-Solvinity transaction denial has invited considerable concern about potential U.S. retaliation. These fears are not unfounded in an environment in which the U.S. Department of State has sanctioned and applied a visa ban to former EU Commissioner Thierry Breton. In the announcement, State Secretary Aerdts emphasized the “country-neutral, risk-based, and proportionate” nature of the decision, highlighting objectivity and risk mitigation on behalf of public interest. She overtly praised foreign technology companies, “especially American ones,” and their weight in the Dutch economy. Dutch State Secretary Eric van der Burg indicated that the United States would understand the national security critical considerations at play.
Looking forward, the Kyndryl-Solvinity case is unlikely to stand alone. Companies and governments that treat these developments as routine regulatory noise risk misreading a fundamental reorientation in how countries worldwide intend to govern their own digital future. Max Schrems, famous for launching the political fight that resulted in greater enforcement of the General Data Protection Regulation (GDPR), is allegedly considering a “Schrems III” case to enforce European data privacy standards.
A foreign attempt to acquire or even access large swaths of U.S. citizens’ data would indeed face significant pushback. In fact, the United States does not currently maintain a single large database for coalescing citizens’ data. The U.S. Privacy Act of 1974 establishes protocols for how federal agencies can use citizens’ data, institutionalizing data silos that serve as guardrails against building social scoring systems. In the United States, threats to the Privacy Act, coupled with ongoing concerns about CLOUD Act exposure, could further imperil U.S. reputational integrity. Under enough sustained pressure, U.S. lawmakers may even be forced to make significant revisions to the CLOUD Act.
Relatedly, the U.S. Supreme Court ruling in Trump v. Slaughter, which addressed the U.S. president’s authority to remove Federal Trade Commission commissioners, creates new challenges for the EU-U.S. Digital Privacy Framework. Key questions about the independence of the Federal Trade Commission have raised concerns about the reach of U.S. executive power in a transatlantic context, including whether the agency responsible for enforcement of the framework remains independent enough to comply with EU law. As concerns about U.S. tech have begun to grow across Europe, additional concerns surrounding this ruling shed light on the deeply embedded nature of the transatlantic tech governance system.
The Kyndryl-Solvinity case is less an isolated transaction denial than an early data point in a structural shift, signaling a new chapter in Europe’s approach to investment security reviews. The European Union has unveiled €381 billion in defense spending, with potential major spillovers into the tech sector. U.S. companies are keen to play deeper roles across the continent, recognizing that Europe’s population and market are significantly larger and also under the philosophical inclination to support NATO supply chains from within the European Union.
Companies seeking to get in on this new chapter of EU defense and technology spending could encounter considerable investment security review processes. As investment screening frameworks mature on both sides of the Atlantic, the companies and governments best positioned will be those that recognize this not as a regulatory inconvenience, but as a new operating environment—one in which the architecture of data, not just the flow of capital, is itself a matter of national security.
Emily Benson is a senior associate (non-resident) with the Europe, Russia, and Eurasia Program and the Center for Strategic and International Studies (CSIS) in Washington, D.C. Lexi Linafelter is a program coordinator and research assistant with the CSIS Europe, Russia, and Eurasia Program.