
Key takeaways |
|---|
|
Choosing a cloud computing provider was once a question of performance, cost and convenience. For Europe, it’s now a question of control.
European cloud providers held less than 15% of the European market in 2025. Now governments and businesses are asking whether sensitive data and critical infrastructure can really be under European control if the underlying cloud infrastructure is operated by companies subject to foreign jurisdictions.
This is where sovereign cloud comes in.
What Is Sovereign Cloud, Exactly?
A sovereign cloud is a cloud environment designed to give an organization greater control over its data, infrastructure and operations within a particular legal or geographic jurisdiction.
But there is an important distinction between data residency and genuine data sovereignty.
- Data residency concerns where information is physically stored.
- Data sovereignty concerns which country's laws govern that data.
That distinction matters because putting servers in Europe does not automatically make a cloud European. True cloud sovereignty goes considerably further, explained Solange Viegas Dos Reis, chief legal officer at OVHcloud, at VivaTech 2026:
Digital sovereignty aims to provide freedom of choice based on three pillars: data sovereignty—who can access and control your data; operational sovereignty—who can operate your infrastructure; and technological sovereignty—who controls all the technical stack you have.
As AI makes cloud infrastructure more strategically important, conversations about cloud sovereignty have moved from the IT department into the boardroom—and increasingly into government policy.
From Data Residency to Full Operational Control
A sovereign cloud approach can involve several layers of control.
At the most basic level, an organization may need its data to stay inside a particular country or region. But depending on factors such as the sensitivity of the data or the regulatory environment, more demanding approaches could be required. Restrictions may be put on who is allowed to access that data, where support staff can be located, which subcontractors can be involved and whether foreign authorities could legally compel the provider to disclose information.
The European Commission has proposed the Cloud and AI Development Act to address these layers of control. The framework introduces four EU sovereignty assurance levels, with increasingly stringent requirements around infrastructure, personnel, data location, ownership, software control and exposure to third-country laws.
How Sovereign Cloud Differs From a Standard Public Cloud
A conventional public cloud can provide excellent security and allow data to be stored in a particular European region. But cloud sovereignty introduces additional questions, such as:
- Who owns the provider?
- Where are its executives and operational teams located?
- Who controls the software stack?
- Can a foreign government require the company to provide information?
- Can workloads be moved to another provider if geopolitical circumstances change?
True digital sovereignty encompasses data, operational, technological and AI sovereignty. It’s an important distinction as cloud infrastructure increasingly hosts AI models, corporate intellectual property and critical public services.
Why Has Sovereign Cloud Become Europe's Top Tech Priority?
Europe's concern is partly about privacy and regulation—but it’s also about strategic dependency.
“Those who control the tools have the power,” said Sebastiano Toffaletti, secretary general of the European DIGITAL SME Alliance, on the VivaTech stage.
Much of Europe's cloud infrastructure is supplied by U.S. hyperscalers and that dependence is increasingly uncomfortable for European policymakers.
The U.S. CLOUD Act and Europe's Dependency Problem
One reason European policymakers are uneasy with the continent's cloud dependency is the U.S. CLOUD Act. This 2018 federal law allows American law enforcement to compel U.S.-based tech companies to turn over requested data via warrant or subpoena, even if the servers and data are stored on foreign soil.
This caused European governments to reassess their reliance on U.S. technology providers because of the potential legal and geopolitical implications.
We have the collective realization that technology is not a commodity,” said Toffaletti. “We have been living for the last maybe two decades in this fictional reality where we were told, you just use it, take whatever is cheaper, take whatever is available, or whatever is at scale. Now this has become a societal talk and politicians started understanding what we are talking about.
GDPR, Regulation and the Push for Control
Europe's regulatory environment adds another layer.
The EU’s General Data Protection Regulation (GDPR) already outlines strict requirements on the handling and transfer of personal data. Other legislation, including DORA and NIS2, has increased the emphasis on operational resilience and technology risk in critical sectors.
But Europe is moving beyond regulation toward infrastructure policy.
In June 2026, the European Commission announced a technological sovereignty package covering semiconductors, AI, cloud and open source. Its proposed Cloud and AI Development Act would create an EU-wide framework for assessing cloud and AI sovereignty while supporting European cloud and computing capacity.
“The objective is not to ban non-European technologies from Europe,” says Dos Reis Viegas. “The objective is to have freedom of choice again.”
Europe's Sovereign Cloud Market Is Accelerating Fast
Europe is moving from policy ambition toward practical implementation of cloud and AI sovereignty.
From GAIA-X to the EU's New Sovereign Cloud Framework
Europe's push is not entirely new. Initiatives such as GAIA-X, launched in 2019, have spent years trying to create a more interoperable and trusted European data infrastructure.
But the current push is broader: it’s increasingly about strategic autonomy, not just data sharing.
In April 2026, the European Commission awarded four European cloud providers a €180 million contract for sovereign cloud services for EU institutions, bodies, offices and agencies. The procurement used a Cloud Sovereignty Framework designed to assess providers according to sovereignty and resilience criteria.
The framework is significant because it turns sovereignty from an abstract political principle into something that can actually be measured. It assesses providers across 48 criteria covering areas including strategic, legal and jurisdictional issues, data and AI, operations, supply chains, technology, security, compliance and environmental sustainability.
How AWS, Microsoft and European Providers Are Responding
Some European providers can offer infrastructure that is locally owned and operated. Global hyperscalers can also work with European partners to create environments with additional legal, operational and technical controls.
AWS and Microsoft have developed sovereign cloud offerings for Europe designed to help their customers meet stringent digital sovereignty requirements.
There are also a growing number of European native sovereign cloud providers such as OVHcloud and Scaleway that are focused on European digital independence.
Sovereignty and Ethics: The Debate Behind the Infrastructure
There is also the deeper question of what technological sovereignty really means for Europe.
Can a Cloud Ever Be Fully Sovereign?
Absolute sovereignty is difficult. That’s because modern cloud infrastructure depends on complex global supply chains. Servers contain components manufactured across multiple countries. Software often incorporates open-source projects maintained internationally. Hardware, chips, networking equipment and specialized technologies may originate outside Europe.
Even a European-owned cloud can still have international dependencies.
Balancing Security, Rights and Democratic Values
Sovereignty is ultimately about deciding whose rules govern technology.
For Europe, that means trying to preserve principles around privacy, accountability and democratic oversight while maintaining access to the world's most advanced technology.
That creates a tension. A highly restrictive sovereign environment could provide greater control but may sacrifice some of the scale, performance and innovation offered by global platforms. A completely open approach could maximize technological choice while leaving Europe exposed to external political or legal decisions.
“If sovereignty means more expensive, less performance, because there are not enough volumes, not enough power to make it efficient, we will have a big issue,” says Olivier Biton, director of technological transformation at the French bank Crédit Agricole.
In response, Europe is moving toward a model in which organizations choose the level of sovereignty appropriate to the sensitivity of their data and operations.
What Sovereign Cloud Means for Businesses and Policymakers
For businesses, sovereign cloud is becoming less about making a political statement and more about managing risk.
Economic dependency, this is something that is coming quite new in the game with this sovereignty reflection,” Benoit Parizet, deputy managing director at Docaposte, told the VivaTech 2026 crowd. “It's not only a question of the operational and legal risk. It's also becoming a question of economic dependency.
Greater sovereignty can mean higher costs, additional infrastructure requirements or reduced flexibility. At the same time, investing in sovereignty can reduce regulatory exposure, improve resilience and protect strategically important data.
Weighing Compliance Against Cost and Performance
Sovereign cloud is not an all-or-nothing decision. The right approach depends on what a business needs to protect and the level of risk it faces.
A defense organization handling sensitive information will have very different requirements from an e-commerce company. For less sensitive workloads, a standard public cloud may provide the scalability, performance and innovation a business needs without requiring full sovereignty.
This makes hybrid cloud a practical option. Businesses can combine public, private, sovereign and on-premises environments, applying stronger controls where they are genuinely needed while retaining access to innovation and managing costs.
Christian Vrancic, head of strategy for SAP Sovereign Cloud, says a hybrid cloud is what most people want: “This is what we see with 99% of our customers: the end solution that we design with them, with our partners and the ecosystem, ends up in a hybrid solution. There's hardly any customer that fully goes with our fully sovereign solution.”
Building a Sovereignty Strategy That Holds Up
A sovereignty strategy should start by mapping assets, data and risks. Organizations should identify their most sensitive “crown jewels,” understand which risks could affect them, and then decide what level of sovereignty is appropriate.
Invest into this topic as a company,” recommends Vrancic. “Don't take it as a side topic. Bring the right people into the room in your companies. Bring your information security officers together with the people within your organization owning the processes and make them work together.
Businesses should also consider the risks of becoming dependent on a single provider, including price increases, technical lock-in and the possibility of losing access to critical services.
So, Is Europe Actually Taking Back Control of Its Cloud?
Europe won’t replace the global cloud overnight, and it doesn’t necessarily need to. What’s changing is the definition of what Europe considers acceptable dependency.
The European Commission's new framework explicitly treats cloud sovereignty as a matter of strategic, legal, operational and technological control—not just cybersecurity.
Dos Reis Viegas’s advice for business leaders on the continent: “Be curious and courageous. Stop thinking that we do not have the strengths and the technology in Europe. It's not true. You can go through VivaTech and discover European technology, strong players, smaller ones. So try to get to know them, and try to give yourself a chance to rely on them.” Dos Reis Viegas’s advice for business leaders on the continent: “Be curious and courageous. Stop thinking that we do not have the strengths and the technology in Europe. It's not true. You can go through VivaTech and discover European technology, strong players, smaller ones. So try to get to know them, and try to give yourself a chance to rely on them.”
The real European ambition is not to build a cloud completely isolated from the rest of the world. It’s to make sure that when sovereignty matters, Europe has the ability to choose.
Want to learn more about how digital sovereignty is shaping business? Check out this article: Digital Sovereignty: What It Means and Why It Matters
FAQ
What is sovereign cloud?
A sovereign cloud is a cloud environment designed to give an organization greater control over its data, infrastructure and operations within a particular legal or geographic jurisdiction.
Why does Europe care so much about sovereign cloud?
Europe's concern is partly about privacy and regulation—but it’s also about strategic dependency.
Much of Europe's cloud infrastructure is supplied by U.S. hyperscalers and that dependence is increasingly uncomfortable for European policymakers.
How is sovereign cloud different from a public cloud?
A conventional public cloud can provide excellent security and allow data to be stored in a particular European region. But cloud sovereignty introduces additional questions, such as:
- Who owns the provider?
- Where are its executives and operational teams located?
- Who controls the software stack?
- Can a foreign government require the company to provide information?
- Can workloads be moved to another provider if geopolitical circumstances change?
Is true cloud sovereignty achievable in Europe?
Absolute sovereignty is difficult. That’s because modern cloud infrastructure depends on complex global supply chains. Servers contain components manufactured across multiple countries. Software often incorporates open-source projects maintained internationally. Hardware, chips, networking equipment and specialized technologies may originate outside Europe. Even a European-owned cloud can still have international dependencies.


