Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

European cloud operators are urging the EU to define cloud sovereignty by who controls the technology, data and operations—and which laws can reach them—not by data-center location alone. In a letter dated March 17, 2026, 25 signatories asked the European Commission to build those tests into the proposed Cloud and AI Development Act (CAIDA). Their recommendations are an industry position, not enacted EU rules.

What the cloud operators mean by ‘sovereignty-washing’

The signatories warn against treating a European data-center address or a cybersecurity label as proof that a cloud service is sovereign. A provider’s location does not, by itself, establish who owns or controls its technology, who can direct its operations, or whether a foreign jurisdiction can compel access to data. As Clever Cloud public-affairs head Axel Laniez put it to Network World, the proposal concerns non-technical factors too, “like territorial laws.”

The letter says sovereignty criteria should cover “effective control, ownership of technology, and protection from extraterritorial jurisdiction,” citing principles applied in European Defence Fund and EDIRPA regulations. Its signatories argue that cybersecurity certification alone does not resolve exposure to foreign laws, including the U.S. Cloud Act. That is their policy argument; the letter does not establish that any particular provider or certification fails a legal test.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Five principles in the March 17 letter

The letter to European Commission Executive Vice-President Henna Virkkunen sets out a connected policy agenda. These are recommendations from its signatories, not confirmed CAIDA provisions.

1. Assess control, ownership and legal exposure

They want sovereignty assessments to examine who effectively controls a service, who owns its underlying technology and whether extraterritorial jurisdiction could apply. This goes beyond the physical location of stored data.

2. Preserve operational autonomy during interference

Where sovereign services are unavailable, the signatories want customers to retain effective control of and access to data, infrastructure and workloads if a foreign government or another third party interferes. The emphasis is on whether operations can continue and customers can reach what they depend on—not merely where systems are hosted.

3. Tie public procurement to resilience

For sensitive data and workloads, the letter proposes reserving a share of public procurement for European cloud providers. Its fallback formulation is “Buy European – or Ensure Resilience – or Explain”: if a buyer does not choose a European provider, the signatories say it should ensure resilience or explain the decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Support competition and interoperability

The signatories call for competition, interoperability and federated European cloud initiatives. They also urge policymakers to avoid anti-competitive bundling of AI and cloud services and to recognize open-source software.

5. Invest in European capacity sustainably

They want public investment to prioritize Europe’s ecosystem and help develop local alternatives for components such as memory and chips. They pair that industrial-policy goal with strict environmental sustainability requirements.

Why resilience is part of the sovereignty debate

Sovereignty and resilience overlap, but they are not identical. A service might meet a location or certification requirement while leaving a customer dependent on systems, technology or operational decisions it cannot control. The letter’s focus on continued access to data, infrastructure and workloads during interference makes continuity a practical test: can a public body keep operating and retain access if a provider is pressured or a service is disrupted?

The procurement proposal reflects that concern. It would make resilience a stated part of the choice, rather than assuming a European supplier is automatically the right fit or that a non-European supplier is automatically unsuitable. The letter does not specify a procurement quota, define a resilience test or set out how an explanation would be assessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this means for cloud buyers

Organizations evaluating sensitive workloads can use the letter’s criteria as questions for procurement, without treating them as an adopted EU standard. Ask providers to document:

  • Who has effective operational control over the service and its infrastructure?
  • Who owns the technology, and what parts depend on third parties?
  • Which jurisdictions may apply to the provider or its operations, including potential extraterritorial demands?
  • How customers would retain access to data, infrastructure and workloads if a government or third party interfered?
  • What interoperability, portability and open-source options are available?
  • How the service addresses environmental requirements relevant to the procurement?

The letter names providers including UpCloud, Aruba, Leaseweb, Infomaniak, Opiquad, Anexia, Deda Tech, Reevo, Clever Cloud, Ikoula Cloud, Seeweb and Nextcloud. Their signatures show participation in the advocacy effort; they do not establish that these companies have equivalent capabilities or that any one is suitable for a particular workload. Buyers still need provider-specific evidence against their own technical, legal and continuity requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains uncertain about CAIDA

On March 19, 2026, Network World reported that the proposed Act’s text had not been finalized and that its eventual form remained under debate. The reporting also described a concern that stringent sovereignty requirements could make it harder for European businesses to replace existing suppliers. Safetica CTO Zbyněk Sopuch predicted that incentives, procurement preferences and sovereignty requirements were more likely than an explicit ban on U.S. companies; that was his forecast, not a confirmed legislative outcome.

Sopuch also estimated that U.S. hyperscalers account for roughly two-thirds of the EU cloud market, as quoted by Network World. The report did not provide the estimate’s underlying methodology, so it should be read as an attributed figure rather than a verified measurement from the letter. The letter itself lists 25 signatories; Network World describes the group as the CISPE chair and 24 cloud-company CEOs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.