Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
Europe runs its economy on cloud infrastructure owned by three American companies, and has spent a decade trying to change that. Federated data initiatives, sovereign cloud regions operated under European control, and procurement rules favouring local providers have all been attempted. The technical problem is solvable and expensive; the commercial problem, that European customers keep choosing the cheaper and better American option, is harder.

Digital sovereignty is the only European industrial policy debate where the customers voting against the policy are European companies themselves. Understanding why requires separating the legitimate legal concern from the technical and commercial reality. This case study closes the software pillar of the Germany Company Stories hub.

Key Takeaways

What is the actual concern?
Extraterritorial legal access to data held by companies subject to foreign jurisdiction, plus dependency risk if access were restricted for political reasons.

What has been tried?
Federated data space initiatives, sovereign cloud regions operated by European entities under licence, and public procurement preferences.

Why is it difficult?
Hyperscale infrastructure has enormous scale economies, and European alternatives are more expensive with narrower service catalogues.

What is the legal issue underneath the debate?

Extraterritorial reach. Legislation in some jurisdictions can compel a company subject to that jurisdiction to produce data it controls, regardless of where the data is physically stored, which means physical location in Europe does not by itself resolve the question.

That creates a genuine tension with European data protection law, which restricts transfers to jurisdictions without adequate protection and has invalidated successive transatlantic transfer frameworks through litigation.

The practical consequence for a European company is legal uncertainty rather than prohibition. Using a hyperscale provider is lawful under current arrangements, and those arrangements have been overturned before and may be again, which is an unquantifiable compliance risk on a multi-year infrastructure commitment.

That uncertainty, more than any concrete incident, is what drives the sovereignty programmes. Organisations handling health records, defence data, judicial information or critical infrastructure control cannot accept an unresolvable legal question.

Where sovereignty concerns are strongestGovernment and defence dataLegal and security requirements are absoluteHealth and judicial recordsRegulated data with strict transfer constraintsCritical infrastructure controlContinuity of access is a national security matterGeneral enterprise workloadsCommercial considerations dominate in practice
The concern is concentrated in a minority of workloads, which is why blanket policies fail.

What did the federated data initiatives try to do?

Establish standards rather than build infrastructure. The approach was to define common rules for data exchange, identity, portability and transparency so that European providers could interoperate and customers could move between them.

The reasoning was sound: the binding problem is not that Europe lacks data centres but that it lacks the integrated service catalogue and interoperability that makes a hyperscale platform convenient.

The execution difficulty was governance. A consortium with hundreds of members, including the very hyperscale providers whose dominance motivated the initiative, produces standards through consensus at the pace of the slowest participant, while the commercial market moves annually.

The outcome has been useful specification work with limited market impact. Standards do not create adoption unless customers face a real cost for non-compliance, which is why procurement rules matter more than technical frameworks.

💡 Pro Tip: If sovereignty matters to your organisation, classify workloads rather than choosing a provider. Most enterprises find that a small minority of data genuinely requires sovereign hosting, and separating that minority is far cheaper than migrating everything to a more expensive platform.

Do sovereign cloud regions actually solve the problem?

Partially, and the details determine how much. The model involves a hyperscale provider licensing its technology to a European entity that operates the infrastructure, controls access and employs the personnel, so that no foreign-controlled entity can access customer data.

When the operating entity is genuinely independent, has European ownership and controls the encryption keys and administrative access, the legal argument is reasonably strong. When the arrangement is a subsidiary of the original provider with contractual assurances, it is considerably weaker.

The practical trade-offs are service breadth and timing. Sovereign regions typically offer a subset of the full service catalogue and receive new capabilities later, which matters increasingly as artificial intelligence services become central to platform selection.

Cost is the third factor. Sovereign operation carries a premium, and for most commercial workloads that premium exceeds the value customers place on resolving a legal risk they consider theoretical.

⚠ Risk: Sovereignty claims should be assessed on key control and administrative access, not on data centre location. If the provider or any entity subject to foreign jurisdiction can technically access the data or the keys, physical location in Europe changes little legally.

Why has no European hyperscaler emerged?

Capital intensity and time. Building a competitive platform requires sustained investment measured in tens of billions across data centres, chips, networking and, critically, a service catalogue of hundreds of managed products built over fifteen years.

The capital is theoretically available in Europe; the willingness to deploy it into a decade of losses against entrenched competitors is not, which is the same growth capital constraint described in the startup ecosystem pillar.

There is also a demand problem. A new platform needs anchor customers willing to accept a narrower catalogue and higher risk, and European enterprises have not volunteered in sufficient numbers, while public procurement has been fragmented across member states rather than aggregated.

The realistic European positions are therefore higher in the stack: enterprise software, industrial applications and specialised infrastructure, where the SAP case shows that European companies can compete globally.

The layers where sovereignty is achievablePhysical infrastructureCapital-intensive;hyperscalersentrenchedPlatform servicesBroad cataloguesbuilt over fifteenyearsApplicationsEuropean strength inenterprise andindustrial softwareData governanceStandards andcontractual controlare achievable now
Sovereignty is more attainable at the application and governance layers than at the infrastructure layer.

What is changing with artificial intelligence?

The stakes and the dependency both rise. Model training requires compute at a scale that concentrates capability further, and enterprises embedding agents into core processes create a dependency deeper than storage or hosting.

That has produced a second wave of sovereignty initiatives focused on compute capacity, model availability and the ability to run capable models on European infrastructure, including open weight models that can be deployed independently of any provider.

Open weight models are the most practically significant development for sovereignty, because a model that can be downloaded and run in a controlled environment removes the legal question entirely for the inference workload, even if training occurred elsewhere.

For enterprises the emerging pattern is hybrid: sensitive inference on controlled infrastructure using open models, general workloads on hyperscale platforms, and a data governance layer that determines which is which. That is a pragmatic answer and it requires real architectural work rather than a procurement decision.

What should a European CFO or CIO actually do?

Quantify the exposure before responding to it. The useful analysis identifies which data would create a legal or operational problem if accessed or if access were withdrawn, and how quickly the organisation could migrate if it had to.

The migration question is the practical one. Dependency risk is proportional to switching time, so an architecture using portable formats, containerised workloads and avoiding provider-specific managed services can use a hyperscale platform while retaining the ability to leave.

That portability costs efficiency, because provider-specific services are usually cheaper and better than portable equivalents. The decision is therefore an explicit insurance premium, and it should be sized against the assessed probability of needing it.

The third element is contractual: data export rights in usable formats, defined notice periods, access transparency reporting and clarity on where keys are held. These provisions are negotiable at contract signature and unavailable afterwards.

What does public procurement actually do here?

It is the strongest available lever and it has been used weakly. Governments are large technology customers, and procurement rules that require sovereign hosting, data portability and exit provisions would create guaranteed demand for European providers.

The obstacle is fragmentation. Procurement is conducted by member states, regions and individual agencies, so demand that would be significant in aggregate arrives as hundreds of small tenders with different requirements, none large enough to underwrite an infrastructure investment.

Aggregating public demand across member states would change the economics materially, and it runs into the same fiscal and competence questions as every other European industrial policy proposal.

A more achievable intermediate step is common technical requirements: identical standards for portability, exit and transparency applied across public procurement, which lowers the cost of serving the public sector for any provider meeting them.

How should a company structure a cloud exit plan?

By testing it rather than documenting it. Exit plans that exist only on paper consistently underestimate migration effort by a wide margin, because the dependencies discovered during an actual migration are not visible in an architecture diagram.

The practical approach is to maintain at least one meaningful workload on an alternative platform and to move a workload between platforms periodically. That surfaces the provider-specific dependencies while the stakes are low.

Data export is the component most often assumed and least often verified. Confirm that data can be exported in a documented, usable format at production volume within an acceptable window, and test it, because export interfaces designed for compliance are frequently impractical at scale.

Is sovereignty a competitiveness cost or an advantage?

Both, depending on the customer. For companies serving European regulated sectors, demonstrable sovereignty is increasingly a sales requirement rather than a cost, and providers who can offer it credibly win business they would otherwise lose.

For companies competing globally on cost, sovereignty requirements raise infrastructure spending against competitors who face none, which is a genuine disadvantage that policy discussion tends to understate.

The resolution is proportionality: applying sovereignty requirements where the risk is real and refraining where it is theoretical. Blanket requirements impose the cost everywhere and capture the benefit only in the minority of cases where it matters.

What role do open weight models play?

They convert a sovereignty problem into an infrastructure problem, which is far easier to solve. A model whose weights can be downloaded and run on controlled hardware means the inference workload never leaves the organisation, regardless of where the model was trained.

That matters most for the workloads where sovereignty concerns are genuine: health records, judicial data, defence and critical infrastructure. For those, a capable open model running on European infrastructure resolves the legal question outright.

The trade is capability. Frontier proprietary models generally outperform open alternatives at any given moment, so the sovereign option carries a performance cost that narrows over time but does not disappear.

What should a mid-sized company actually spend on this?

Very little, if the exposure assessment is honest. A manufacturer with no regulated personal data, no defence contracts and no critical infrastructure role faces a theoretical legal risk and a real operational dependency, and the dependency is the one worth spending on.

The cost-effective measures are architectural and contractual rather than infrastructural: portable data formats, documented exit procedures, negotiated export rights and avoidance of deep dependence on provider-specific managed services for core processes.

Those measures cost engineering discipline rather than capital, and they preserve optionality without paying a sovereignty premium on workloads that do not require it.

Frequently Asked Questions

What is digital sovereignty?

The ability to control where data is held, who can access it and under whose law, so that critical systems are not subject to foreign jurisdiction or unilateral access.

Does hosting data in Europe solve the problem?

Not by itself. Extraterritorial legislation can reach data controlled by companies subject to that jurisdiction regardless of storage location, so key control and operating entity structure matter more.

What is a sovereign cloud region?

Infrastructure using a hyperscale provider’s technology but operated by a European entity that controls access and keys, offering a narrower service catalogue at a premium price.

Why has Europe not built its own hyperscaler?

The capital requirement runs to tens of billions over a decade against entrenched competitors, and neither private growth capital nor aggregated public procurement has been available at that scale.

Last Updated: August 2026 · Reviewed by the Kurums Startup editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading