Executive Summary
Cloud sovereignty has rapidly evolved from a compliance consideration into a resilience requirement for European organizations, driven by geopolitical exposure and jurisdictional reach beyond the EU. This blog maps key European initiatives, specifically the EU Cloud Sovereignty Framework (EU CSF) and the most recent Cloud and AI Development Act (CADA). CADA proposes four cloud sovereignty assurance levels that standardize sovereignty and make it appraisable. Under the current proposal, the EU doesn’t push global hyperscalers out of the market. The European Commission expects roughly 70% of public contracts to sit at Level 1 and 20% at Level 2 which are both reachable by global hyperscalers with the right controls. Less than 10% are estimated to exclude global hyperscalers. We also examine the EU provider landscape and what the CADA proposal means for their long-term competitiveness with only the highest level of security-sensitive workloads reserved. We conclude with the future outlook and practical migration considerations for organizations within the current European regulatory framework.
What is cloud sovereignty?
Before getting into the regulatory detail, it's worth being precise about what “sovereignty” actually means, because residency and sovereignty are not the same thing.
Residency is primarily about where data is stored and processed. Many hyperscalers advertise their “sovereign” offering using geographic constraints (for example “EU-only”) through mechanisms such as region selection, contractual commitments, and technical controls like geo-fencing. Residency is often necessary for regulated workloads because it supports auditability and reduces exposure to cross-border transfer rules, but it does not, by itself, determine who can legally compel access or who can operate the service.
Sovereignty is the broader concept and adds who ultimately controls the service and under which legal and operational conditions. In practice, that means jurisdictional exposure (which courts and laws can compel the provider), operational control (who can administer systems and respond to incidents), technology independence (portability and lock-in risk), and supply chain dependencies.
Hyperscaler offerings have been criticised to be “sovereign washing” as they advertise cloud sovereignty without all the verifiable controls or legal guarantees to back it up.
Why cloud sovereignty matters now
Europe wants to reduce its dependence on cloud infrastructure from providers it doesn't fully control. As European Commission President Ursula von der Leyen put in a press statement, “We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure.”
The main driver is geopolitical risk. If diplomatic or trade tensions escalate, organizations face two consequences. The first is extraterritorial access risk: the US CLOUD Act, passed in 2018, lets US law enforcement compel US-based providers like Microsoft, Google, and Amazon to produce data in their “possession, custody, or control,” even when it's stored abroad. This doesn't mean such access happens routinely, but it's why residency alone is treated as insufficient for cloud sovereignty in the stricter sense. The second is service discontinuity risk, the so-called “kill switch”: the possibility that sanctions, export controls, or policy shifts constrain a foreign provider's ability to deliver services, support, or updates.
A second driver is adoption and trust. Concerns about trust, security, and national dependency are among the biggest barriers to AI adoption in the EU. By focusing on sovereign cloud capabilities these barriers can be significantly reduced. A third driver is vendor lock-in and switching friction. Cloud sovereignty discussions often converge with commercial and technical concerns about portability and interoperability. European legal frameworks are increasingly targeting dependency and aim to make switching between data processing services easier.
The current EU regulatory landscape
In 2024, Mario Draghi, the former European Central Bank President and Italian Prime Minister was commissioned by the European Commission to assess Europe's competitiveness in technology and industrial policy. The report emphasized the need to reduce dependencies on non-EU cloud service providers, culminating in the EU Cloud Sovereignty Framework (EU CSF) and the more recent Cloud and AI Development Act (CADA).
The EU CSF is a European Commission policy that makes the broader notion of cloud sovereignty explicit. The SEAL Level (Sovereignty Effectiveness Assurance Level) sets a minimum assurance level for projects that providers have to meet to qualify. The sovereignty score is a global weighted percentage calculated using eight objectives (SOV-1 to SOV-8) , to sort and rank the providers. Providers that do not meet the minimum SEAL levels of assurance consistently across all objectives are rejected.
In April 2026, four sovereign cloud consortia were awarded a €180 million tender based on their EU CSF alignment, closing a procurement process launched in October 2025.
- Post Telecom (with CleverCloud and OVHcloud)
- STACKIT
- Scaleway
- Proximus (with S3NS - joint venture between Thales and Google Cloud, Clarence, and Mistral)
The selection of the Proximus consortium with Google Cloud is the most significant addition. The commission directly addressed this by stating that “non-European technologies, when operated within a strict and appropriate framework, can meet the minimum level of sovereignty required”. This tender has been positioned as a benchmark for what “sovereign cloud” means in practice.
CADA is the centerpiece of the Commission's Tech Sovereignty package published on 3 June 2026. It is still a legislative proposal, with final adoption targeted for Q4 2027. However, given the strong political support, organizations should start preparing now rather than waiting for formal adoption. CADA establishes an EU-wide framework comprising four assurance levels; providers must pass an audit at the relevant level to serve EU organizations. These requirements currently target the public sector, but public procurement typically signals where private-sector standards head next. Private companies in NIS2-regulated critical sectors (energy, transport, health, public administration, banking, financial market infrastructure, digital infrastructure) can already use CADA voluntarily. Under Article 31, the Commission can also make this mandatory for those sectors under specific circumstances. CADA also introduces “data centre acceleration zones” for EU member states to accelerate approvals, signalling their intention to invest in growing cloud infrastructure capacity.
Here's how the four levels compare at a glance:
LEVEL |
REQUIREMENTS |
|
Level 1 Baseline |
• Provider must be established in the EU; all infrastructure, assets, and customer data must remain in the EU. • Outsourced technical support is permitted with full traceability and security. • Non-EU-controlled providers must not be subject to foreign vulnerability-disclosure laws. • Self-assessed, no external audit required. • Hyperscaler eligibility: ✓ Current sovereign offerings would already qualify. |
|
Level 2 Data sovereignty |
• Providers and all subcontractors must be established in the EU, with all infrastructure, assets, and personnel EU-located. • Personnel must be screened; EU citizenship required where necessary. • Data generated cannot be used to train or fine-tune AI systems operated by a third country, and cannot leave the EU. • Non-EU providers must prove via independent audit that no foreign country can access customer data, disrupt service, or force sanctions compliance. • Technical support must be performed exclusively within the EU. • EU cybersecurity certificate at ‘substantial’ assurance required. • Hyperscaler eligibility: ✓ Achievable with the right governance and audit (e.g. the Proximus model). |
|
Level 3 Digital resilience |
• Customer data must remain exclusively within the EU. • All personnel must be EU citizens, with national security clearances where necessary. • Providers must be owned and controlled from the EU; the Commission can recognise third-country providers as exceptions. • Neither the provider nor any subcontractor may be controlled by a non-EU country or entity (unless Commission-designated). • Data generated cannot be used to train or fine-tune AI systems operated by a third country, and cannot leave the EU. • EU cybersecurity certificate at ‘substantial’ assurance required. • Technical support must be performed in the EU by EU-citizen personnel. • Hyperscaler eligibility: ✗ Generally excluded, except by exceptional Commission designation. |
|
Level 4 Full sovereignty |
• Data must remain within the EU at all times, no exceptions. • All personnel must be EU citizens with the necessary security clearances. • Provider and all subcontractors must have total independence from non-EU countries, no exceptions. • Providers must demonstrate effective control over every software component and product; no non-EU country influence permitted. • EU cybersecurity certificate at ‘high’ assurance required. • Hyperscaler eligibility: ✗ Excluded entirely, not currently met by any provider. |
What this means for cloud providers and users in the EU
Hyperscalers
Amazon, Microsoft, and Google dominate the European cloud market, with a combined market share of 70% according to Synergy Research Group. All three have responded with “sovereign cloud” offerings. AWS positions its European Sovereign Cloud as a separate EU-staffed entity incorporated under German law. Microsoft offers a “Sovereign Public Cloud” within the EU Data Boundary and an air-gapped “Sovereign Private Cloud”. Google markets air-gapped sovereign solutions of its own. Both Microsoft (Bleu, Delos Cloud) and Google (Thales, T-Systems) have also partnered with EU players who act as the legal and operational firewalls to offer sovereign solutions.
These tailored offerings allow the hyperscalers to satisfy CADA Levels 1 and 2. By decoupling the operations from the US parent companies they neutralise the jurisdictional reach of the US CLOUD ACT which can otherwise compel access to data stored abroad. While CADA Level 1 allows for self-assessment, achieving Level 2 or higher requires non-EU providers to formally prove compliance through an independent audit. The success of the Proximus tender proved this model works in practice: Google's services ran inside a localized, EU partner-operated environment to reach SEAL-2, broadly equivalent to CADA Level 2. Level 3 generally excludes US hyperscalers except under exceptional designation while Level 4 excludes them entirely, since it requires full EU control of the entire stack which is a bar no provider, European or otherwise, currently meets.
It's tempting to assume CADA pushes US hyperscalers out of the EU market entirely. However the European Commission itself estimates roughly 70% of public contracts will sit at Level 1 and 20% at Level 2, both reachable with the right controls. Less than 10% require Level 3, and roughly 1% require Level 4. CADA also leaves room for exceptions where “no adequate or reasonable alternative or comparable cloud computing service exists.” By these estimates, the global hyperscalers, provided that they can implement certain controls, will still be able to service the vast majority of projects.
EU cloud providers
Meanwhile, European-headquartered providers are growing but remain fragmented. Synergy Research puts their collective EU market share at around 15%, with SAP and Deutsche Telekom each at just 2%. Whilst it is encouraging to see this growth in the number of EU based providers, their infrastructure scale and breadth of service offerings does not yet match that of the hyperscalers. As a result, a direct swap in vendor is likely not yet realistic for most and becomes a workload-by-workload decision based on the specific requirements at play.
SAP positions SAP Sovereign Cloud (including an on-premise variant) as a way to meet country-specific standards, while still using hyperscaler technology for other solutions. Deutsche Telekom runs its own physical datacenters and maps natively to the upper CADA levels; in April 2026 the two launched a Munich AI factory built on nearly 10,000 NVIDIA Blackwell GPUs, with Deutsche Telekom providing infrastructure and SAP the software platform.
OVHcloud, Europe's largest pure cloud provider, reached SEAL-3 in the April 2026 tender, roughly equivalent to CADA Level 3, alongside fellow winning providers STACKIT and Scaleway. STACKIT (Schwarz Group) runs its own datacenters on an open-source stack, Scaleway (Iliad Group) is the primary training cloud behind Mistral and Hugging Face.
Scaling remains the open question for all of them. The hyperscalers have built global infrastructure and offer an extensive range of services that these smaller regional players cannot compete with. Due to the brutal economics of the cloud market, unless these sovereign EU providers can reach a competitive scale, they might not have a long-term future. France’s OVHcloud CEO Octave Kalba has estimated it needs 15% of EU public-sector procurement walled off from foreign competition to reach competitive scale. However, the Commission's own estimates suggest less than 10% of contracts fall outside Level 1 and 2, where hyperscalers could compete if they meet requirements. Political momentum may bring more investment to European providers, but the economics could still leave them competing with each other for a narrow slice of the market. Therefore making it difficult for any single EU provider to achieve the scale needed for long-term competitiveness.
What does this mean going forward?
We expect cloud sovereignty pressure to keep building, but not toward excluding hyperscalers entirely. The more likely outcome is stringent requirements at the top, with the bulk of cloud projects still favouring hyperscalers' mature portfolios and economies of scale. European providers will likely concentrate in regulated or security-critical sectors where cloud sovereignty outweighs commercial considerations. Another emerging outcome is the partnership model, European operators combine hyperscaler technology with EU-controlled governance, legal accountability, and operational control. The Proximus arrangement with Google is the clearest example of this: Google's infrastructure and capabilities are retained, but all encryption, operations, and legal responsibility sit with a European entity, placing the data structurally beyond the reach of the CLOUD Act. This allows organizations to benefit from hyperscaler scale and service breadth without sacrificing sovereignty compliance, and may prove to be the most pragmatic path for projects in the Level 2 to Level 3 range.
The risk worth flagging here is that prioritising policy objectives over market efficiency could slow Europe's AI ecosystem. Supporting domestic cloud providers that are not yet economically competitive could eventually trickle down increased costs and/or operational complexity for European organisations reliant on them.
Another note to make is that many of these regulations are initially targeted at the public sector. However, the private sector is likely to follow similar procurement and compliance standards, meaning the broader impact of CADA will extend well beyond government institutions.
If the designation of projects change and require more sovereign cloud solutions then a migration away from a current hyperscaler solution may be necessary. Migration may also get easier as Amazon and Microsoft were preliminarily designated Digital Markets Act (DMA) gatekeepers for their cloud businesses on 25 June 2026. If confirmed this would bring stricter EU mandates on vendor lock-in. (Google is already a DMA gatekeeper, but its cloud business isn't included.) Switching fees will also be banned from 12 January 2027 under Article 25 of the EU Data Act, making it easier to change cloud and data processing providers.
If your cloud sovereignty requirements change, here's what each migration path actually involves. A hyperscaler-to-hyperscaler move is usually least disruptive, since managed-service categories are comparable. The identity, networking, and governance models differ, and re-implementing the surrounding platform layer (logging, monitoring, backups, policy enforcement) often dominates the timeline more than the compute move itself. A hyperscaler-to-European-cloud move tends to expose a managed-service gap: European cloud service providers are particularly strong in Infrastructure as a Service (IaaS) and selected areas of Platform as a Service (PaaS), so you'll likely either de-platform onto portable, open-source tooling or accept more operational responsibility. This should be treated as a platform redesign, not a lift-and-shift. A hyperscaler-to-self-hosting move carries the highest complexity, gated by GPU procurement, power, cooling, and networking lead times rather than the software stack.
Conclusion
Cloud sovereignty is best treated as a multidimensional requirement, not a binary label. Hyperscaler sovereign cloud offerings can meaningfully improve data residency and operational control, but they generally can't eliminate jurisdictional risk while the provider remains subject to non-EU legal demands. However, under the current CADA proposal this doesn't disqualify hyperscalers from Level 1 projects. At Level 2, hyperscalers can still qualify through specific partnership and operating structures. European providers offer the stronger legal and strategic alignment for Levels 3 and 4 but typically lag on service breadth, operational maturity, and scale. Organizations will have to weigh the cloud sovereignty requirements of projects against the compute and scale they need for each part of their digital infrastructure. Your next step should be to map your EU workloads against the four assurance levels before choosing which providers to work with.
How ML6 can help?
At ML6, we engineer AI solutions for both public and private sectors. We are one of Europe’s fastest growing AI-firms, with 13 years and 400+ projects behind us. We guide organizations through the legal, ethical, and security dimensions of AI, helping you align with current regulations as well as prepare for the future. We pride ourselves in developing battle-tested architectures for protecting critical infrastructure and sensitive data with a privacy-first design.
We help on both fronts, with our AI advisory and AI engineering teams. Our advisory team works through the sovereignty, compliance, and architecture decisions with you. Helping with platform design assessments, target architecture design, resilience/disruption readiness planning, and phased roadmapping. Our engineering teams help build and ship the infrastructure once you've decided. Unfortunately, many of our projects are subject to an NDA; for a look at what we can share, explore our publicly available client cases & testimonials.
We are official partners with leading providers across the full AI ecosystem. Our partners include: cloud providers (AWS, Google Cloud, Microsoft), model labs (Anthropic, OpenAI, ElevenLabs), and infrastructure vendors (NVIDIA, Cisco). You decide where and how AI runs, choose the setup that fits your security, compliance, and performance needs. As a vendor-neutral sovereignty advisory with deep AI platform engineering capabilities, we make sure the AI adapts to your infrastructure, not the other way around. Scale quickly and cost-effectively on cloud, without compromising on cloud sovereignty.
If you're ready to prepare for EU cloud sovereignty, talk to our team.




