Sovereign Cloud in Europe: Where Is the New Legal Framework Heading and What Does It Mean for Your Business?

Sovereign Cloud in Europe: Where Is the New Legal Framework Heading and What Does It Mean for Your Business?

Digital transformation and the rise of artificial intelligence have skyrocketed the technological dependence of governments, businesses, and citizens. At the center of this revolution is the cloud, the infrastructure that supports everything. But this dependence, concentrated in providers outside the European Union, has raised alarms in a context of geopolitical tensions. The buzzword is 'digital sovereignty,' and it is now materializing in concrete regulations, such as the recent EU proposal: the Cloud and AI Development Act (CADA). Its goal: to move towards a sovereign European cloud and reduce dependence on US hyperscalers. But how did we get here, and what does it really mean for organizations?

EU cloud legal framework

Regulatory evolution: from free market to technological sovereignty

The regulatory framework for the cloud in the EU has not been static. As Roger Segarra, partner in the Information Technology and Intellectual Property department at Osborne Clarke, explains, "the evolution has been progressive, from positions aimed at fostering the market towards increasingly specific regulation aimed at guaranteeing technological sovereignty."

One of the first milestones was Regulation (EU) 2018/1807, which facilitated the free flow of non-personal data in the Union, recognizing cross-border processing in cloud environments. However, the most significant qualitative leap came with the NIS2 Directive, which classified cloud computing service providers as high-criticality sectors, imposing new security and notification obligations. Added to this was the Data Act, which seeks to regulate access to and use of data generated in the EU.

This transformation responds to an unavoidable reality: the growing concentration of the market in non-European hyperscalers. Segarra points out that "Europe has limited and geographically concentrated computing capacity, which significantly increases the risks associated with dependence on cloud services provided by non-European providers."

Diego Ríos, Managing Director for Southern EMEA at SUSE, provides compelling data: a report puts the spending on European cloud services and software going to US providers at €265 billion, that is, 80% of the total. Another analysis estimates that the market share of European providers has fallen from 29% in 2017 to 15% in 2022. These figures highlight the urgency to act.

Digital sovereignty Europe

CADA: the shift towards open source and strategic resilience

The proposal for the Cloud and AI Development Act (CADA) marks a turning point. Beyond data protection and cybersecurity, there is now talk of digital sovereignty and Europe's ability to control its critical digital infrastructures. Ríos highlights that, for the first time, the 'Open source first' principle goes from being a recommendation to becoming an operational requirement. "This reflects an important mindset shift: the cloud is no longer seen solely as a technological issue, but also as a key element for economic competitiveness, innovation, and strategic resilience."

This approach is no coincidence. The EU has seen how dependence on external technologies can become a vulnerability, especially in times of instability. Fernando Suárez, president of the General Council of Computer Engineering, agrees that this concern is legitimate and recalls that in other areas, such as AI regulation, a similar path is being followed. "It is feasible to legislate without that being a handicap," he says, but adds: "we cannot simply prohibit." It is about limiting obstacles to the development of a sovereign ecosystem while maintaining the capacity to innovate.

CADA also has direct implications for major cloud players. Amazon Web Services (AWS) and Microsoft Azure, the main hyperscalers, are under scrutiny. The European Commission has proposed classifying them as 'gatekeepers' under the Digital Markets Act, which would require them to comply with stricter requirements on interoperability, data portability, and control over monopolistic practices. These giants are already reacting: AWS has launched its European Sovereign Cloud, and Microsoft has proposed its Microsoft Sovereign Cloud, adapted to the European market and regulation.

However, Segarra clarifies that the package of measures does not seek to prohibit these companies from contracting with European governments, but rather to limit their ability to process certain public sector data on their platforms, given the special sensitivity of such data. It is a fine line between openness and protection.

Impact on businesses sovereign cloud

Opportunities for European providers and for businesses

For European providers, this new framework represents a significant opportunity. Ríos insists that "it is not about excluding international providers or closing the market. Europe remains an open economy. What the new framework seeks is to ensure that organizations have a real choice and avoid situations of excessive dependence on a single provider or technological ecosystem."

This change also has positive effects for European businesses. Ríos envisions greater freedom of choice, a reduction in risks associated with technological dependence, and greater ease in adopting more customized infrastructures. Furthermore, the operational continuity of critical systems will be reinforced in the face of regulatory, commercial, or geopolitical changes. Segarra adds that these measures will act as a "lever for the growth of investments in data centers" in Spain and the rest of the EU.

But it is not all smooth sailing. Suárez warns that total independence from foreign providers is complex, but "we do need to have our own European developments and for Europe to be competitive at a technological level as well." And he goes further: "Really, what we are talking about is power structures and the independence of countries, and therefore we need to be able to guarantee that Europe, at a time of high uncertainty and political instability, can also make decisions and not depend on others."

Suárez also warns about other dependencies, such as chip manufacturing, which perhaps were not foreseen in advance. "Europe needs to have the option of relying simply on its own infrastructure," he summarizes. And he stresses that regulation must be accompanied by investments, capabilities, future commitment, and talent. "Regulating alone is not enough. If we only set limits, if we don't generate industries here, in the end dependence keeps growing."

Practical implications for businesses

For companies operating in Europe, this new regulatory landscape has clear practical implications. First, they will need to assess the sovereignty of their cloud providers and consider European alternatives or open-source solutions. Interoperability and data portability will become increasingly important, as we have already seen in other areas such as artificial intelligence and synthetic data.

Additionally, cybersecurity will remain a fundamental pillar. The NIS2 Directive already imposes strict obligations on digital service providers, and companies must ensure compliance. In this sense, having practices such as ethical hacking and penetration testing can be a key differentiator.

On the other hand, the commitment to open source opens new opportunities. Solutions such as Linux and server hardening will gain prominence, as will automation platforms like Home Assistant for smart office environments. Even productivity tools like Microsoft 365 will need to adapt to the new sovereignty requirements.

Conclusion: a necessary balance

The EU faces a delicate balance between protecting its digital sovereignty and not stifling innovation. The legal framework is evolving rapidly, and businesses must be prepared to adapt. The key will be combining regulation with investments in infrastructure, talent, and proprietary technology. Only then can Europe maintain its independence in an increasingly digitalized world.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: