Europe is committing billions of dollars to sovereign cloud infrastructure, but that spending leaves an enterprise with a harder question: what exactly must it control? Data location, provider ownership, operational authority and legal jurisdiction can point in different directions. For CIOs and infrastructure leaders, sovereignty has to be established workload by workload, with evidence showing who can access and operate each environment, which laws apply and where its data can move.

Europe is spending heavily on sovereignty, but spending and sovereignty are different outcomes

The pressure behind that question is substantial because the European Commission estimates that the EU depends on countries outside the bloc for “over 80% of key digital products, services, infrastructure, and intellectual property.” Reducing the risks created by this dependence has become part of Europe’s economic strategy. Enterprises making cloud and AI decisions consequently face sovereignty as a current procurement, architecture and compliance issue while European policy continues to develop.

That policy has already moved from broad ambition to concrete measures. In June 2026, the Commission put forward the European Technological Sovereignty Package, covering semiconductors, AI, cloud and open source. Two months earlier, it had awarded a sovereign-cloud contract worth up to €180 million over six years to four European providers. That procurement was the first time EU institutions had applied explicit, measured sovereignty criteria when buying cloud services.

Cloud spending is moving faster still. Gartner, a commercial technology research and advisory firm that sells research about markets including cloud infrastructure, put European sovereign-cloud infrastructure-as-a-service spending at $6.9 billion in 2025. It forecasts spending of $12.6 billion in 2026 and $23.1 billion in 2027.

Year European sovereign-cloud IaaS spending
2025 $6.9 billion
2026 $12.6 billion
2027 $23.1 billion

The European increase is part of a wider regional shift in Gartner’s forecasts, driven mainly by governments and regulated industries. Its 2026 growth forecasts show similar acceleration across three regions.

Region Gartner forecast growth in 2026
Europe Roughly 83%
Middle East and Africa 89%
Mature Asia/Pacific 87%

By 2027, Gartner projects that Europe will overtake North America in sovereign-cloud IaaS expenditure for the first time. Those figures show growing demand for services sold around sovereignty, but demand and control are separate questions. Purchasing a sovereign offering still leaves the buyer to establish how much authority it has over workloads, data and access.

That distinction matters because Gartner has questioned the degree of genuine sovereignty afforded by some provider-operated sovereign offerings, including services from U.S. hyperscalers. As a commercial research company, Gartner has an interest in organizations buying analysis of cloud-market choices, so its judgment should remain clearly attributable to it. Its concern also gives buyers a concrete test: spending on sovereign infrastructure does not establish the legal and operational authority a particular architecture provides.

The ownership test breaks down when jurisdiction and control diverge

The gap between spending and control became concrete in June 2025, when testimony to the French Senate established that a major U.S. cloud provider could not guarantee that data stored in its French data-center regions would never be disclosed to U.S. authorities in certain legal circumstances. The relevant issue includes exposure under the U.S. CLOUD Act. Physical storage inside France can therefore satisfy a location requirement while leaving a separate route for foreign legal authority.

That legal route makes data residency and legal sovereignty separate tests. Residency tells an enterprise where data is stored or processed under the relevant architecture, but residency alone cannot establish whether a foreign authority has a legal route to compel the organization operating the service to provide access. For regulated businesses, the distinction affects the assurances they can credibly give regulators, customers and their own boards.

Once residency is separated from jurisdiction, provider headquarters becomes one input among several. In a neutral colocation arrangement, for example, the customer can retain possession, custody and control of its infrastructure and data while the infrastructure provider neither operates its workloads nor controls its data layer. A provider’s nationality remains relevant to legal analysis, but a risk team also needs to know which organization has operational access to the specific customer environment.

The European Commission’s Cloud Sovereignty Framework makes that broader legal test explicit. Its assessment considers legal, contractual and technical routes through which authorities outside the EU could compel access, including direct consideration of the U.S. CLOUD Act. Examining those routes separately makes an EU data-center address one part of the evidence needed to establish control.

Provider-operated sovereign clouds require the same scrutiny because their operating structure determines which entities retain authority. Gartner’s concern about sovereign services operated by U.S. hyperscalers does not establish that every such service fails a sovereignty requirement. Buyers still need to determine which entity can operate the environment, what contractual protections govern it, what technical barriers constrain access and which legal obligations can reach the entities involved.

Those questions also explain what changes when the customer operates the environment. Customer operation can materially alter custody and operational access, although foreign law may remain relevant depending on the companies, infrastructure and services involved. Ownership and nationality are useful inputs to a sovereignty review, while the full legal, contractual, technical and operational arrangement determines what control can be demonstrated for each workload.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

A better sovereignty test asks what the enterprise can actually control

Once ownership, operation, location and jurisdiction are separated, the enterprise decision becomes more precise: how much of the technology stack needs to be owned, and how much needs to be under demonstrable control? Demonstrable control means the organization can establish who governs its data, infrastructure, access permissions, operational authority and data flows. Legal and contractual exposure belongs in the same test because technical authority cannot cancel an external legal obligation.

That test becomes concrete for a technology-intensive European financial institution serving customers inside the EU and around the world. Its services depend on data moving across systems, while regulators and customers want specific answers about who controls its data and infrastructure, how that authority is exercised and which laws apply. Replacing every external technology provider would answer some of those questions through ownership, but workloads with different sensitivity and regulatory requirements do not require identical safeguards.

Those differences make the workload the useful unit of analysis. The institution can start with each system’s sensitivity and regulatory requirements, then determine which data must remain within a jurisdiction, who may administer the infrastructure, which parties can reach the data layer, how access is governed and where information may travel. Contracts and applicable laws must then be checked against that operating model so the technical design and legal position support the required level of control.

The Commission framework supports this workload-level approach because it examines multiple channels through which control or compelled access can arise. Infrastructure design reaches the same point from the operational side, since custody, access rights and responsibility for running an environment depend on how that environment is structured. For policymakers and enterprise governance teams, these two views provide a basis for calibrating safeguards to the sensitivity of each workload.

Workload separation and controlled connectivity put the test into practice

That calibration becomes practical when sensitive workloads are separated from external capabilities they need to reach. A European bank, for example, can keep regulated workloads and market data in-region while connecting privately to cloud-based AI and analytics services. The regulated environment can retain its required location and controls, while selected connections provide access to services outside the same operating boundary.

Those connections make data movement part of sovereignty design. Network architecture and routing policies can follow jurisdictional requirements so traffic uses permitted paths during ordinary operations. The same policies need to hold during resilience events because failover to alternative infrastructure can change traffic routes. A compliant primary path provides incomplete protection if backup arrangements send data through a path with different jurisdictional consequences.

Because connectivity is governed at the boundary, the infrastructure operator’s role can also be narrower. Under the neutral colocation model described earlier, the enterprise retains possession, custody and control of its data and infrastructure environment, while the colocation provider does not operate the workload or control its data layer. The enterprise consequently retains operational authority even though another organization supplies the physical infrastructure service.

That operational authority can also affect how lawful requests are handled. Where customers retain operation of their environments, they may retain primary responsibility for responding to lawful requests concerning their data. The arrangement can make the answer to “who controls this environment?” more concrete and verifiable, although the full legal and infrastructure configuration still determines whether foreign authority can reach an entity involved.

Keeping that authority with the customer can preserve access to multiple external providers as well. Customer-operated infrastructure can connect to global clouds and networks as well as certified sovereign providers while the enterprise retains ownership and operation of its own environment. For a business using multiple cloud, network, AI and analytics services, this structure can reduce infrastructure lock-in while allowing each connection to be governed according to the workload and data involved.

Those governed connections extend beyond stored data because data in motion can cross jurisdictions as services interact. Resilience arrangements can redirect the same data when components fail, making the earlier failover requirement part of ongoing sovereignty governance. An organization can specify permitted traffic paths for standard operation and account explicitly for jurisdictional requirements when alternate systems take over.

This combination of domestic control and external connectivity supports a broader policy model of managed interdependency. Oxford Economics uses the term for an approach that combines domestic oversight with continuing access to global AI infrastructure. In Europe, such an arrangement can let member states establish domestic terms while regulated industries retain sensitive workloads within the required jurisdiction and connect to global AI capabilities where their safeguards allow it.

For the financial institution, managed interdependency turns an estate-wide sovereignty decision into governed workload boundaries. Market data and regulated processing can remain under in-region safeguards; approved connections can supply cloud AI or analytics; and routing controls can govern how data moves between them. Regulators and the board can then examine where systems run, who operates them, who can access their data and how traffic is governed.

Those operational controls strengthen evidence of control, but architecture cannot make jurisdiction disappear. Controlled interconnection, customer operation, workload separation and carefully designed failover can all affect which entities can reach a workload, while a legal authority may still be able to compel an entity involved in a particular configuration. Each architecture therefore needs its legal, contractual and technical pathways assessed together.

Over-restriction has costs, so controls should follow workload sensitivity

That need for workload-specific safeguards also has an economic dimension because tighter restrictions change more than the infrastructure bill. Oxford Economics modeled this issue in May 2026 in work commissioned by the AI Adoption Initiative, tying the analysis to an initiative with an interest in AI adoption. It divided sovereign-AI policies into five levels of restrictiveness, ranging from approaches that preserve access to global providers while applying residency requirements selectively to sensitive workloads, through to mandates for a fully domestically owned technology stack.

As policies move toward the restrictive end, they can require additional data centers, processors and skilled people. That duplication raises the ongoing cost of running technology, while delayed access to newer capabilities can reduce productivity and slow innovation. In Europe, those effects can become harder to manage when an enterprise already operates across fragmented national jurisdictions.

The modeled adoption effect is substantial, but its geographic scope matters. Oxford Economics estimates that highly restrictive policies could delay enterprise AI adoption by approximately three to five years. The modeling covers Asia-Pacific, so the figure is an estimate for that analysis rather than a forecast for European companies. Its relevance to European decision-makers lies in the mechanism Oxford Economics identifies: duplicated capacity and constrained access to technology can create costs through adoption delays as well as additional infrastructure and talent.

That mechanism changes how sovereignty investments can be judged as Europe directs substantial resources toward sovereign-cloud infrastructure and enterprises seek access to leading AI, cloud, network and analytics capabilities. A control that materially reduces a sensitive workload’s legal or operational exposure may justify its cost. A workload with lower exposure may support broader provider choice under appropriate governance, avoiding additional run-rate and adoption costs that do not correspond to its risk.

Policy design consequently affects technology adoption as well as compliance. Matching safeguards to workload sensitivity gives highly regulated systems stronger constraints while allowing other systems to use a wider range of providers under appropriate governance. The practical requirement is to make each restriction correspond to the risk being controlled, especially when stronger restrictions can require duplicated infrastructure, scarce talent and delayed access to useful technology.

Main highlights

  • Define sovereignty before spending: European sovereign-cloud investment is rising rapidly, but procurement alone does not establish control. CIOs and infrastructure leaders need evidence of who operates workloads, who can access data, which laws apply and where data can move.
  • Assess jurisdiction and operational authority: Data stored in Europe may remain exposed to foreign legal authority depending on the entities involved. Risk and procurement teams need to assess legal, contractual, technical and operational access for each architecture.
  • Set controls by workload: Workload sensitivity and regulatory requirements provide a practical basis for deciding the level of sovereignty required. Governance teams can map residency, administration, access rights, data flows and applicable laws for each system.
  • Govern connectivity and failover: Enterprises can keep sensitive workloads in-region while connecting them privately to global cloud, AI and analytics services. Architecture teams need routing and resilience policies that preserve jurisdictional requirements during normal operations and failover.
  • Match restrictions to risk: Highly restrictive sovereignty policies can require duplicated infrastructure and scarce skills while delaying access to new technology. Decision-makers can reserve stronger controls for higher-risk workloads and preserve broader provider choice where safeguards permit.

Alexander Procter

October 9, 2026

11 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.