{"id":1001036,"date":"2026-06-02T18:53:27","date_gmt":"2026-06-02T18:53:27","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/1001036\/"},"modified":"2026-06-02T18:53:27","modified_gmt":"2026-06-02T18:53:27","slug":"eu-restricts-us-cloud-services-plan-key-rules-and-questions","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/1001036\/","title":{"rendered":"EU restricts US cloud services plan: key rules and questions"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" width=\"900\" height=\"600\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/06\/Abstract-Data-Display-1-900x600.png\" alt=\"Abstract Data Display\" class=\"wp-image-247846\"  \/><\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-31\">The European Commission is moving forward with rules that could restrict US cloud services from handling sensitive government data, targeting financial records, health data, and judicial information held by public-sector bodies across all 27 member states. This is not a broad ban; private-sector cloud use remains untouched. But for AWS, Microsoft Azure, and Google Cloud, which together command roughly 70% of cloud infrastructure revenues in Europe, even a targeted public-sector restriction represents a significant shift in how the EU does business with American tech.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-32\">The proposals are the centrepiece of the long-awaited Tech Sovereignty Package, built around the Cloud and AI Development Act (CADA). Led by Executive Vice-President Henna Virkkunen, the package has faced repeated delays due to intense institutional debate. Following a brief slip past its late-May target, the finalised strategy is set for imminent official presentation. Once unveiled, the package will still require unanimous approval from all 27 member states before taking effect.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-33\">What makes this moment fundamentally different from past EU sovereignty rhetoric is that the Commission has already built, tested, and deployed a <a href=\"https:\/\/commission.europa.eu\/news-and-media\/news\/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en\" target=\"_blank\" rel=\"nofollow noopener\">concrete scoring system for cloud sovereignty<\/a>. The upcoming legislation will determine exactly how high that statutory bar gets set.<\/p>\n<p>Why US cloud law makes the EU nervous<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-34\">Under the 2018 US CLOUD Act, American companies can be compelled by domestic law enforcement to hand over user data regardless of where that data is physically stored. A server in Frankfurt provides no legal insulation if the company operating it is headquartered in Seattle. For government-held financial, judicial, and health data, this extraterritorial exposure is the core of the Commission\u2019s concern. Where data lives matters less than who can be legally ordered to produce it.<\/p>\n<p><a href=\"https:\/\/www.internetforum.eu\/events\/events\/2163-building-a-sovereign-eu-cloud-ecosystem.html\" target=\"_blank\" rel=\"nofollow noopener\">Thibaut Kleiner<\/a>, Director for Future Networks at DG CONNECT, previously framed the strategic stakes plainly:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cUnless we get our acts together, we are going to be in the mode of becoming a technological colony of some kind, where we are not able to develop our own products.\u201d<\/p>\n<\/blockquote>\n<p>He also acknowledged that the initiative has run into sustained lobbying built around the argument that moving away from US tech is too difficult and too expensive. These tensions sit at the heart of why digital governance is a European imperative, as the continent attempts to assert regulatory control over architectural ecosystems it did not build.<\/p>\n<p>Moving sovereignty from principle to metric<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-35\">Before the Commission developed its <a href=\"https:\/\/commission.europa.eu\/document\/download\/2ad80a48-166f-4c77-a513-80c53ca2a128_en?filename=Cloud%20Sovereignty%20Framework%20-%20Implementation%20guidance.pdf\" target=\"_blank\" rel=\"nofollow noopener\">Cloud Sovereignty Framework<\/a>, there was no standardised way to translate \u201csovereignty\u201d into procurement criteria. The new framework changed that by measuring providers across eight dimensions\u2014including legal jurisdiction, operational resilience, supply chain transparency, open architecture, and EU law compliance.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-36\">These metrics score providers on a five-tier scale called the Sovereignty Effectiveness Assurance Level (SEAL):<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>SEAL-0:<\/strong> No digital sovereignty demonstrated.<\/li>\n<li><strong>SEAL-2 (Data Sovereignty):<\/strong> Achieves baseline compliance with EU laws without requiring additional customer-side technical protections, though material non-EU dependencies may remain.<\/li>\n<li><strong>SEAL-3 (Technological Autonomy):<\/strong> Demands an open architecture and structural immunity from non-EU supply chain or third-party disruptions.<\/li>\n<li><strong>SEAL-4 (Full Sovereignty):<\/strong> Requires a completely localised EU supply chain, from physical silicon chips to the software stack.<\/li>\n<\/ul>\n<p>What the commission\u2019s own tender revealed<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-41\">The Commission did not wait for formal legislation to put these criteria to work. It utilised the framework to award a massive six-year, <a href=\"https:\/\/digital-strategy.ec.europa.eu\/cs\/news\/commission-awards-eu180-million-tender-sovereign-cloud-four-european-providers\" target=\"_blank\" rel=\"nofollow noopener\">\u20ac180 million cloud procurement contract<\/a> to four European provider groups.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-46\">The tender was explicitly designed to encourage the market to develop sovereign digital solutions. However, it also exposed a deep pragmatic compromise. Purely European tech stacks \u2014 such as Scaleway, STACKIT, and the Post Telecom\/OVHcloud alliance \u2014successfully achieved SEAL-3 status. Meanwhile, the Proximus consortium qualified at SEAL-2 because its framework relies on S3NS \u2014 a joint venture utilising US-origin Google Cloud technology under European operational management.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-47\">By anchoring the tender\u2019s minimum eligibility baseline at SEAL-2, the Commission proved its own stated position: that non-European tech, when wrapped in strict local operational controls, can meet baseline requirements. It allowed the EU to maintain a diversified, multi-vendor ecosystem and avoid vendor lock-in, but it drew sharp criticism from European cloud CEOs who wanted a total exclusion of foreign-exposed stacks.<\/p>\n<p>What changes for big tech \u2014 and what remains open<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-48\">The upcoming CADA rules will not lock US hyperscalers out of Europe entirely. Instead of a binary system of exclusion, the draft strategy leans toward a risk-based, tiered access model. Member states will be required to conduct formal \u201csovereignty risk assessments,\u201d defining specific public-sector workloads that must be hosted on verified sovereign capacity.<\/p>\n<p>The unresolved legislative battle comes down to where the law will mandate those thresholds:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>If the final law mandates SEAL-2:<\/strong> The \u201cwrapper\u201d approach survives. European entities can continue using highly automated US tech stacks managed by local partners (like the Proximus-S3NS model).<\/li>\n<li><strong>If the final law mandates SEAL-3 or higher:<\/strong> Wrapped US infrastructure will fail the test. Highly sensitive public-sector workloads will be legally forced onto fully native European architectures.<\/li>\n<\/ul>\n<p>The debate highlights how deeply European regulators are scrutinizing the gap between where data is processed and who owns the underlying code. Similar boundary-testing has increasingly surfaced across consumer platforms \u2014 such as the ongoing regulatory scrutiny over whether certain cross-border data tracking features violate the GDPR \u2014 proving that data residency is no longer a sufficient defense.<\/p>\n<p>Market realities and the blueprint ahead<\/p>\n<p>The scale of the industrial challenge is massive. European cloud providers collectively hold only about 15% of regional cloud infrastructure revenues, compared to the 70% dominated by the US hyperscalers. Yet, momentum is shifting; high-profile migrations, such as France\u2019s Health Data Hub moving workloads to Scaleway, point in the exact direction the Commission wants to go.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-49\">The Commission is <a href=\"https:\/\/www.digitalsme.eu\/who-owns-europes-digital-future\/#:~:text=Europe%20must%20actively%20stimulate%20demand,they%20can%20deliver%20at%20scale.\" target=\"_blank\" rel=\"nofollow noopener\">actively using its purchasing power<\/a> to shape the market, creating guaranteed demand conditions that European providers can scale into. The \u20ac180 million tender is signed, the SEAL framework is active, and the Commission is preparing to push national governments to align their domestic public procurement with this exact methodology.<\/p>\n<p>The final piece of the puzzle is the statutory threshold written into the Cloud and AI Development Act. The SEAL metric remains the critical number to watch: if member states mandate a strict SEAL-3 baseline for sensitive government records, the Commission\u2019s own compromise procurement model will no longer pass its own test.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/06\/Abstract-Data-Display-1-900x600.png\" alt=\"Abstract Data Display\" class=\"wp-image-247846\"\/><\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-31\">The European Commission is moving forward with rules that could restrict US cloud services from handling sensitive government data, targeting financial records, health data, and judicial information held by public-sector bodies across all 27 member states. This is not a broad ban; private-sector cloud use remains untouched. But for AWS, Microsoft Azure, and Google Cloud, which together command roughly 70% of cloud infrastructure revenues in Europe, even a targeted public-sector restriction represents a significant shift in how the EU does business with American tech.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-32\">The proposals are the centrepiece of the long-awaited Tech Sovereignty Package, built around the Cloud and AI Development Act (CADA). Led by Executive Vice-President Henna Virkkunen, the package has faced repeated delays due to intense institutional debate. Following a brief slip past its late-May target, the finalised strategy is set for imminent official presentation. Once unveiled, the package will still require unanimous approval from all 27 member states before taking effect.<\/p>\n<p id=\"p-rc_a10ce1d4b17d0d46-33\">What makes this moment fundamentally different from past EU sovereignty rhetoric is that the Commission has already built, tested, and deployed a <a href=\"https:\/\/commission.europa.eu\/news-and-media\/news\/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en\" rel=\"nofollow noopener\" target=\"_blank\">concrete scoring system for cloud sovereignty<\/a>. The upcoming legislation will determine exactly how high that statutory bar gets set.<\/p>\n","protected":false},"excerpt":{"rendered":"The European Commission is moving forward with rules that could restrict US cloud services from handling sensitive government&hellip;\n","protected":false},"author":2,"featured_media":1001037,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[5174],"tags":[91307,14270,2000,299,5187,53],"class_list":["post-1001036","post","type-post","status-publish","format-standard","has-post-thumbnail","category-eu","tag-c-suite","tag-cloud-computing","tag-eu","tag-europe","tag-european","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/116682032417995934","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1001036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=1001036"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1001036\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/1001037"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=1001036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=1001036"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=1001036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}