In June, Brussels proposed the law that would do it. By September, defence officials were pushing back through the Financial Times, warning that strict sovereignty rules could break NATO-interoperable systems and cut them off from AI capability no European provider currently matches.
Nineteen European countries run their defence systems on Microsoft's cloud, according to reporting by Euronews. Microsoft is the largest cloud supplier to European defence.
The law is the Cloud and AI Development Act, the centrepiece of the Commission's Tech Sovereignty Package published on 3 June 2026. Strip away the Brussels-speak and it does one thing. Every public body, defence ministries included, must grade every cloud contract on a four-level sovereignty scale before signing.
The Commission's own estimates put about 70% of public contracts at Level 1 and 20% at Level 2. Less than 10% at Level 3. Roughly 1% at Level 4.
Level 4 is where the fight lives. It demands no third-country ownership, no third-country control, no residual exposure to a foreign law such as the US CLOUD Act. That standard does not bend for a data centre on German soil when the parent company is incorporated in Washington state. Industry lawyers read it as a de facto ban on the American hyperscalers for that narrow slice of work. The Commission insists it is no such thing.
One of them is telling the truth. An oath already gave the answer.
In June 2025, Anton Carniaux of Microsoft France told a French Senate commission of inquiry, under oath, that he could not guarantee French citizens' data would never be transmitted to US authorities, wherever the servers sit. The Commission's own impact assessment reaches the same conclusion in colder language: a binding third-country request may still compel access, a risk that "exists independently of the technical robustness of the service."
That is the whole argument in one sentence. Sovereignty-branded products put data inside EU borders and add local oversight. The parent company remains American, and the CLOUD Act does not care where the servers sit.
The machinery has already turned, and not in a hypothetical. In February 2025 the United States sanctioned Karim Khan, the International Criminal Court's chief prosecutor, by executive order. Within months his Microsoft account was disconnected, as the Associated Press first reported. Microsoft disputes the framing, insisting it never suspended services; its lawyers' position is that it merely provides the platform and customers control the access. The practical difference is thin: the prosecutor moved to Proton, and the court confirmed in late October 2025 that it is replacing Microsoft 365 with OpenDesk, the open-source suite from ZenDiS, Germany's centre for digital sovereignty, across roughly 1,800 workstations. The ICC sits in The Hague under an international treaty. Its prosecutor's inbox sat under Washington's jurisdiction. The institution built to prosecute the world's worst crimes is moving its email off American infrastructure because American law reached it.
If that machinery reaches a chief prosecutor in The Hague, a European defence ministry is not a stretch. It is a smaller target.
So why are the defence ministries objecting? Three reasons recur in the reporting. NATO interoperability: the alliance's January 2026 digital strategy commits it to a federated cloud model for its operational networks, and those networks run partly on American infrastructure. Capability: by the Commission's own figures, the three American hyperscalers hold around 70% of Europe's cloud market, while European providers' combined share fell from 29% in 2017 to 15% in 2022 and has gone nowhere since. Speed: restructuring ownership and control takes years, and procurement deadlines move faster.
You do not get to call yourself sovereign while your most sensitive defence data sits under a foreign statute. The ministers are right that Europe cannot replace American cloud this year. They are wrong if they read that as a reason to wait. Dependency is a fact to be engineered out on a schedule, not a condition to be managed forever.
There is an honest counterweight. A procurement law does not pour concrete. Europe cannot certify its way to scale; the binding constraints are capital, energy, grid connections and chips, none of which CADA touches. The Act creates a market incentive. Building the capacity is still a decade of unglamorous work.
The draft even contains an escape valve. Where no adequate alternative exists, a contracting authority may buy a service that does not meet the required level. Expect it to be used often in defence. Every use will be a quiet public admission that Europe cannot yet supply its own militaries.
Now the speculation, labelled as such. Everything above is documented. The three scenarios below are not.
Scenario one: the sealed order
A European defence ministry's personnel files or logistics data gets caught in a US investigation or a sanctions action. The provider is served with a CLOUD Act order carrying a gag. The ministry is not told, and may never be. Under GDPR Article 48 the disclosure may itself be unlawful in the EU, but the provider's obligation under US law stands regardless. The ministry discovers nothing. It signs next year's renewal.
Scenario two: the lever
A European government defies Washington on sanctions, base rights, or export controls. Nobody threatens anything. A mid-level official reminds a journalist, on background, that the government's cloud contracts answer to American jurisdiction. The reminder is not a threat and does not need to be. The ICC precedent shows the trigger is a political choice, not a technical failure.
Scenario three: the paperwork exit
CADA passes at Level 4. A ministry three years deep in Azure cannot comply by the deadline. The escape valve lets a contracting authority buy a non-compliant service where no adequate alternative exists, so the ministry files the derogation, rebrands the contract, and carries on. Europe gets a sovereignty law and keeps the same American cloud. The dependency survives, now with forms attached.
Of the three, the lever is the most dangerous and the paperwork exit the most likely. None of these scenarios requires a villain. They only require the machinery to keep existing and someone, eventually, to reach for it.
The negotiation runs into 2027. The ministries will argue for softer tiers. The hyperscalers will restructure just enough to claim they qualify. Both may succeed. Meanwhile the dependency compounds. Every year on American cloud adds data gravity, trained staff and integrated AI tooling that makes the exit more expensive than it was the year before.
When the law finally bites, your country's most sensitive defence data will sit under one statute or another. There is no third location.
Which one would you rather it answered to?