In June 2025, a Microsoft executive sat in front of the French Senate and gave a straight answer to a direct question. Could the company guarantee that data belonging to French public-sector customers, stored in Microsoft's French data centres, would never be handed to the American authorities without France's consent? No, was the answer. It could not guarantee that.
The Law, Not a Scandal
Nothing improper was being confessed. The executive was simply describing the law. The US CLOUD Act, passed in 2018, allows American authorities to compel US-headquartered companies to produce data they hold, wherever in the world that data physically sits. A French data centre run by an American company is, in the way that matters, an American data centre in France.
That one straight answer did more for European digital sovereignty than a decade of white papers, because it collapsed a comfortable assumption held by public bodies and businesses across the continent, and across Britain too: that if your data resides in Europe, it is governed by Europe. It is not.
Residency is geography. Sovereignty is jurisdiction. Where the server sits matters far less than who the operator answers to.
Brussels Responds
A year on, almost to the day, Brussels responded in force. On 3 June the European Commission published its Technological Sovereignty Package, the most ambitious attempt yet to reduce Europe's dependence on non-European technology, spanning chips, cloud, AI and open source. Its centrepiece, the Cloud and AI Development Act, proposes a four-level sovereignty framework for cloud services sold to the public sector. The lowest level is a baseline of good security practice. The highest demands full EU ownership and control, security-cleared EU personnel, no transfer of AI inference data outside the Union, and independent audit.
The Commission's own estimate is that only around one contract in a hundred, mostly in defence, would need that top tier. But for the sensitive middle tiers, covering workloads in banking, energy and healthcare, the American giants would struggle to qualify, not because of anything they have done, but because of the law their home country passed.
The symbols arrived within days. The European Parliament switched its default search engine from Google to the French engine Qwant. The Netherlands had already blocked an American acquisition of Solvinity, the company that operates the Dutch digital identity system. And in April, the Commission ran the first procurement in its history to apply explicit sovereignty criteria, awarding a €180 million sovereign cloud contract to four European provider groups. These are small moves against the scale of the dependency, US providers hold roughly three quarters of the European cloud market, and the European share has been falling, not rising, for years. But direction of travel is set by exactly such moves.
Three Ways This Could Go Wrong
I find the direction right, and I have argued for it in these pages before. Which is precisely why the three ways this could go wrong deserve setting out plainly.
The first is arithmetic. Regulation creates demand for sovereign services; it does not create supply. European providers are growing fast from a small base, and the hyperscalers are investing more in a single year than Europe's alternatives have raised in their lifetimes. A framework that requires public bodies to buy what the market cannot yet sell does not produce sovereignty. It produces waivers, delays and quiet non-compliance. The buy side of the market will only ever be as sovereign as the sell side allows, and the unglamorous work of building supply, capital, talent, energy, data centre capacity, matters more than any assurance level.
The second is definition. Everything turns on what counts as foreign control. Draw the line crudely, foreign investors, foreign customers, foreign listings, foreign staff, and the framework strangles the very European companies it exists to grow, because every European technology firm with global ambitions has all four. One analysis put the failure mode memorably: a bad definition protects European mediocrity while penalising European ambition. The people drafting the detail hold the whole project in their hands.
The third is precedent. Europe has been here before. An earlier attempt to write sovereignty criteria into cloud certification spent years in dispute between member states and was never adopted. The politics of sovereignty are easy to declare and brutally hard to codify, and a proposal that cannot be agreed is worse than no proposal, because it freezes the market while it dies.
The Harder Half Is Industrial
So where does that leave us? Europe has correctly named the problem, built a serious framework to address it, and now faces the harder half of the work, which is industrial rather than legal. Sovereignty, as one European cloud veteran puts it, does not mean doing everything yourself. It means having strategic options for the things that are critical. That is the standard against which the package should be judged in five years: not whether the hyperscalers were inconvenienced, but whether a European public body choosing where to place its most sensitive workloads has real choices it did not have before.
Britain, Watching From Outside the Room
The jurisdictional arithmetic does not change at Dover. A UK organisation running sensitive workloads on a US-headquartered cloud has exactly the exposure the French Senate heard described, and the UK public sector is at least as concentrated on the American providers as Europe's. We are not writing a CADA, and I am not arguing we should. But the discipline underneath it travels, and any British organisation that handles data worth worrying about can apply it now, without waiting for policy.
It looks like this. Classify your workloads by what would actually hurt: most data genuinely does not matter, and pretending it all does is how sovereignty becomes theatre. For the workloads that do matter, know the jurisdiction of the operator, not just the location of the server, because the second is marketing and the first is law. Price your exit before you need it: portability, exportable data, tested migration paths, contractual switching rights. And treat concentration itself as a risk, the way we already do for suppliers of anything else critical. None of this requires abandoning the hyperscalers, whose engineering remains genuinely excellent. It requires knowing, precisely and in advance, which of your eggs are in whose basket, and what it would take to move them.
The Jurisdictional Layer
I have written before about the physical layer of this question, the cables, the energy, the compute that sovereignty ultimately stands on, and about the governance layer, who watches the rules when the rules are code. This is the jurisdictional layer, and it is the one most organisations have never mapped. The comfortable assumption died in a French Senate hearing room. What replaces it is a question every board should be able to answer: for the data that matters most to us, who, finally, can compel its handover, and did we choose that answer or inherit it?