# EU Cloud Sovereignty Push Sparks Tension Among Member States as Defence Sector Weighs In
European governments are expressing significant reservations about proposed legislation that would impose tighter cloud sovereignty rules on public-sector and defence organisations across the EU. The tensions highlight a growing struggle between the bloc’s ambitions for technological self-sufficiency and the practical realities of relying on established international cloud infrastructure for critical operations.
## What Is the Proposed Regulation?
The European Commission introduced a legislative proposal earlier this year that sets out a comprehensive framework for how cloud services should be evaluated and governed when used by EU institutions and public-sector bodies. At its core, the regulation aims to address growing concerns about Europe’s reliance on cloud platforms operated by non-European technology companies.
The framework introduces a tiered rating system with four distinct assurance levels. Each level places increasing demands on where data centres are physically located, who holds operational control over infrastructure, the ownership structure of the cloud provider, the integrity of software supply chains, and how exposed a service might be to the laws and regulations of countries outside the EU. The higher the assurance level required for a particular workload, the more stringent these conditions become.
Public-sector organisations and member state governments would be expected to conduct thorough risk assessments to determine which activities depend on cloud services and contribute to maintaining public order. Any work falling within areas such as national security, defence operations, internal security, border management, judicial processes, and law enforcement would then need to rely on cloud platforms rated at one of the upper tiers within this framework.
Critically, the legislation does not call for a complete prohibition on any specific provider. Instead, it includes provisions that allow for exceptions in situations where compliant services simply cannot be found, where competitive procurement processes fail to deliver suitable alternatives, or where other qualifying circumstances outlined in the regulation apply.
## Defence Officials Raise Alarms Over Interoperability
The defence community within Europe has been among the most vocal groups raising concerns about the proposed rules. Officials from several member states, particularly those in eastern and Nordic regions, are worried that the tightening sovereignty requirements could significantly limit the ability of military organisations to access cloud and artificial intelligence capabilities from major US technology companies such as Amazon, Microsoft, and Google.
These concerns are not happening in a vacuum. They come at a time when the transatlantic defence alliance has been actively modernising its own digital infrastructure. NATO’s strategic digital plan, released earlier this year, lays out a vision for a federated cloud environment that spans multiple classification levels, integrates with tactical edge computing, and is designed to scale across diverse operational scenarios. The alliance’s interoperability framework is set to become mandatory for any country wishing to participate in federated networks used for collective operations.
The backbone of this vision relies on networks capable of delivering high bandwidth and low latency, even in environments where communications are degraded, contested, or deliberately denied by adversaries. NATO also envisions federated platforms that enable different participating organisations to share data, digital services, and computing resources in a seamless way.
European defence funding mechanisms are already translating these strategic goals into concrete technical requirements. A major funding programme for 2026 includes an allocation of approximately €40 million for military cloud services spanning land, air, maritime, cyber, and space domains. The technical specifications demand that military cloud infrastructure be capable of self-forming, self-healing, and graceful degradation, with built-in redundancy and failover mechanisms that preserve data consistency even after failures or communication disruptions.
Interoperability remains a central pillar of these requirements. The programme specifically calls for alignment with NATO-agreed interfaces, standardisation agreements known as STANAGs, and specifications from federated mission networking initiatives. At the same time, the programme seeks to balance the pursuit of European military and technological sovereignty with meaningful contributions to NATO-led efforts around technical and procedural integration.
Meanwhile, NATO itself has begun putting classified cloud infrastructure into practice. A major contract awarded recently to a leading technology consulting firm for a protected communications programme valued at roughly €200 million aims to establish a unified cloud operating model for classified digital operations across the alliance. The programme involves designing, building, and running a core platform across a multi-cloud environment for approximately 29,000 users over a multi-year period stretching into the early 2030s.
## How Dependent Is Europe on Non-European Cloud Providers?
The question of Europe’s cloud dependence has become a central focus of policy discussions. Assessments conducted by the European Commission indicate that three major US-based cloud platforms collectively account for roughly 70% of Europe’s cloud infrastructure services market. The share held by European providers has contracted significantly over the past decade, dropping from close to 30% in 2017 to approximately 15% by 2022, and has remained broadly stable at that level since.
These figures encompass the broader commercial cloud market and are not limited to military or classified workloads. The Commission has identified several specific risks associated with this level of dependence, including exposure to laws enacted by non-European governments, the potential for sudden service disruptions, and the broader strategic vulnerability that comes from relying on external entities for foundational digital infrastructure.
In response, the major US cloud providers have launched specialised European offerings designed to address some of these sovereignty concerns. One provider made a European-specific cloud environment available across the bloc in early 2026, with its initial region situated in Germany. The provider has described this environment as both physically and logically separate from its existing global regions, with infrastructure housed entirely within EU borders and systems engineered to continue functioning even if connections to infrastructure outside the bloc are severed.
Other major providers have also introduced sovereignty-focused products and partnerships with European firms. One offers oversight mechanisms for remote administrative access, while another has partnered with local European organisations to deliver sovereign configurations on the continent.
However, the Commission’s own assessment cautions that simply rebranding services as “sovereign” does not automatically eliminate the exposure to third-country laws that could affect data access or the risk of service continuity disruptions. The distinction between marketing claims and genuine regulatory independence remains a point of close scrutiny.
## Sovereign Cloud Procurement Efforts Underway
Even before the proposed regulation enters into force, the Commission has begun implementing sovereignty criteria in its procurement practices. In a recent development, framework contracts were awarded to allow EU institutions and agencies to acquire up to €180 million worth of sovereign cloud services over a six-year period.
The contracts were granted to a group of European and European-partnered providers following evaluation under a dedicated cloud sovereignty framework. This evaluation process covered a wide range of criteria including strategic alignment, legal compliance, operational capabilities, supply chain integrity, technological maturity, security posture, environmental sustainability, and adherence to EU law. Notably, one of the partners involved in a winning consortium is itself a joint venture between a major European defence company and one of the largest global cloud providers, highlighting the complexity and sometimes contradictory nature of these relationships.
The proposed regulation is still working its way through the EU legislative process and has not yet entered into force. Member states and EU institutions continue to debate the specifics of the sovereignty requirements, with the defence community’s reservations adding an important dimension to the ongoing negotiations.
—
## Frequently Asked Questions
**What is the Cloud and AI Development Act (CADA)?**
CADA is a legislative proposal from the European Commission designed to establish rules around how cloud services and AI capabilities are procured, evaluated, and used by EU institutions and public-sector organisations. It focuses heavily on sovereignty — the degree to which these services are controlled, hosted, and governed within Europe — rather than imposing outright bans on any particular provider.
**Does the regulation ban US cloud providers?**
No. The proposal does not impose a blanket ban on services from US or other non-European providers. Instead, it introduces a risk-based framework where higher-assurance workloads — particularly those related to national security and defence — must use cloud services that meet stricter sovereignty criteria. Exceptions are permitted where compliant options are unavailable or procurement processes do not yield suitable alternatives.
**Why are defence officials concerned about the proposed rules?**
Defence officials worry that stricter sovereignty requirements could restrict access to cloud and AI capabilities provided by major global technology companies, many of which are US-based. They also raise concerns about potential interoperability challenges with existing NATO systems and infrastructure, which are designed to operate across multiple nations and classification levels.
**How does NATO plan to use cloud technology?**
NATO’s strategy calls for a federated, multi-classification cloud model that integrates with edge computing and can operate across land, air, maritime, cyber, and space domains. The alliance envisions networks that are resilient, low-latency, and capable of functioning in degraded or contested environments, with federated platforms enabling different nations and organisations to share data and computing resources.
**How dependent is Europe on non-European cloud providers?**
According to Commission assessments, three major non-European providers account for approximately 70% of Europe’s cloud infrastructure services market. European providers collectively hold around 15% of the market, down from nearly 30% a decade ago.
**What are US providers doing to address European sovereignty concerns?**
Major US cloud companies have launched European-specific offerings with infrastructure located inside the EU, designed to be physically and logically separate from other global regions. These include guarantees around continued operation even if external connectivity is lost, as well as oversight mechanisms for remote administrative access.
**Are sovereign-branded cloud services truly free from third-country legal exposure?**
The European Commission’s assessment suggests otherwise. It notes that simply rebranding a service as sovereign does not automatically remove exposure to third-country laws governing data access or policies that could affect service continuity. The distinction between branding and genuine regulatory independence is being closely examined.
**What happens next for the proposed regulation?**
CADA remains a legislative proposal and has not yet entered into force. It continues to move through the EU legislative process, with member states and EU institutions debating the specifics of its sovereignty requirements, including the concerns raised by the defence community.
—
## Conclusion
The debate surrounding cloud sovereignty in Europe reflects a broader reckoning with digital dependency on non-European infrastructure. As military operations, public-sector services, and critical national functions increasingly move to the cloud, the tension between leveraging the best available technology and maintaining strategic autonomy grows more acute. The proposed regulation represents a significant attempt to recalibrate that balance, but its success will depend on whether European policymakers can craft rules that genuinely enhance sovereignty without undermining the interoperability and capability that comes from engaging with the global cloud ecosystem. The concerns raised by defence officials serve as an important reminder that any framework must account for the practical demands of alliance operations and the fast-evolving nature of digital warfare. The coming months of legislative negotiation will be pivotal in determining whether Europe can chart a path that satisfies both its strategic ambitions and its operational realities.
Thank you for reading



