EU cloud sovereignty rules face defence pushback over US providers
European defence officials are pushing back against parts of the EU’s proposed Cloud and AI Development Act that would introduce stricter sovereignty requirements for cloud services used by military and other sensitive public-sector systems, according to the Financial Times.
The report said officials from several EU countries, including eastern and Nordic member states, are concerned that the provisions could restrict the use of US cloud providers for some high-security workloads.
The European Commission proposed the Cloud and AI Development Act, or CADA, in June. The proposal covers data-centre capacity, public-sector cloud procurement, and dependencies on non-European cloud and AI providers.
CADA introduces a four-level framework for assessing the sovereignty of cloud services used by EU institutions and public-sector organisations. The criteria cover infrastructure location, operational control, ownership, software supply chains, and exposure to third-country jurisdictions, with requirements becoming stricter at higher assurance levels.
Under Article 29, member states and EU entities would carry out risk assessments to identify public-sector activities that use cloud services and contribute to preserving public order. Activities identified through those assessments in areas including national security, defence, internal security, border management, justice, and law enforcement would have to use cloud services recognised at assurance Levels 2, 3, or 4 under Article 30.
The proposal does not impose a blanket ban on US cloud providers. It allows exceptions where compliant services are unavailable, procurement processes fail to produce suitable offers, or other conditions set out in the regulation apply.
Defence cloud requirements
NATO’s January 2026 Alliance Digital Strategy calls for a federated, multi-classification, scalable, and hybrid cloud model integrated with tactical edge computing. The strategy says its interoperability framework becomes mandatory for countries joining federated networks used for NATO-led operations, while NATO’s infrastructure objectives call for international standards and NATO-agreed reference architectures.
NATO says the underlying networks must provide resilient, high-bandwidth, and low-latency connectivity for mission-critical operations, including in degraded, contested, and denied environments. It also calls for federated platforms that allow participating organisations to share data, digital services, and computing resources.
The Financial Times reported that some defence officials are concerned that stricter sovereignty requirements could limit access to cloud and AI capabilities supplied by Amazon, Microsoft, and Google. The officials also raised concerns about interoperability with NATO systems, according to the report.
The European Defence Fund’s 2026 programme provides additional detail on the technical requirements for military cloud infrastructure. It allocated an indicative €40 million to military multi-domain operations cloud services covering land, air, maritime, cyber, and space operations.
The programme requires military cloud infrastructure and associated networks to self-form, self-heal, degrade gracefully, and maintain redundancy. It also requires recovery mechanisms to maintain data consistency after a failure, alongside failover capabilities for operations affected by communication disruptions.
Interoperability is also included in the EDF requirements. The programme calls for consideration of NATO-agreed interfaces and processes, including NATO Architecture Framework requirements, Standardization Agreements, or STANAGs, and Federated Mission Networking specifications.
The same programme sets objectives for European military and technological sovereignty while supporting EU contributions to NATO initiatives focused on technical and procedural interoperability.
NATO is also deploying cloud-enabled infrastructure for classified operations. In July, the NATO Communications and Information Agency awarded Accenture a contract valued at approximately €200 million for its Protected Business Network programme.
NCIA said the programme will establish a common cloud operating model for classified digital operations across NATO. Accenture is scheduled to design, implement, and operate the core platform across an NCIA-provided multi-cloud environment supporting about 29,000 users between 2026 and 2033.
NATO’s Digital Transformation Implementation Strategy describes its wider Digital Backbone as a federation of networks and systems providing cloud and edge services across organisational, national, operational, and security boundaries.
Europe’s cloud dependence
The Commission’s CADA impact assessment estimates that AWS, Microsoft, and Google account for around 70% of Europe’s cloud infrastructure services market. European providers’ combined share fell from 29% in 2017 to 15% in 2022 and has remained around that level, according to the assessment.
The figures cover the broader European cloud market rather than military workloads. The Commission lists dependence on non-European providers, exposure to third-country laws, and possible service disruption among the issues CADA is intended to address.
US hyperscalers have also introduced European cloud offerings intended to address some sovereignty requirements.
AWS made its European Sovereign Cloud generally available in January 2026, with its first region in Brandenburg, Germany. AWS said the environment is physically and logically separate from its existing regions, with infrastructure located inside the EU and systems designed to continue operating if connectivity with infrastructure outside the bloc is interrupted.
Microsoft provides European sovereignty controls through its Sovereign Public Cloud, including Data Guardian oversight for remote administrative access. Google Cloud offers sovereign configurations with European partners including S3NS in France and T-Systems in Germany.
The Commission’s CADA impact assessment says sovereign-branded offerings from non-European providers do not necessarily remove exposure to third-country laws affecting data access or policies affecting service continuity.
The Commission has also started applying sovereignty criteria to cloud procurement outside CADA. In April, it awarded framework contracts allowing EU institutions and agencies to procure up to €180 million in sovereign cloud services over six years.
Contracts went to Post Telecom with CleverCloud and OVHcloud, STACKIT, Scaleway, and Proximus with partners including S3NS, Clarence, and Mistral.
The providers were assessed under the Commission’s Cloud Sovereignty Framework, covering strategic, legal, operational, supply-chain, technological, security, environmental, and EU-law requirements. S3NS, one of the partners in the Proximus consortium, is a joint venture between Thales and Google Cloud.
CADA remains a legislative proposal and has not entered into force. The proposal is still moving through the EU legislative process as member states and EU institutions consider its sovereignty requirements.
(Photo by ALEXANDRE LALLEMAND)
See also: AWS and Microsoft launch multicloud link between AWS and Azure
Want to learn more about Cloud Computing from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events, click here for more information.
Cloud Computing News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Post Comment