“European Cloud Sovereignty Is Not What Most Organizations Think It Is”
- Erik Kling

- May 13
- 6 min read

The Next Industrial Revolution Is Already Being Built
The next industrial revolution is no longer theoretical.
It is already being built through cloud infrastructure, AI systems, energy corridors, semiconductor supply chains, digital identity layers, compute architecture, and global orchestration platforms.
This infrastructure will determine: who retains sovereignty,who retains optionality,who retains leverage,and who becomes structurally dependent.
That makes this moment historically important.
Because digital dependency compounds faster than industrial dependency.
Once governments, enterprises, healthcare systems, financial systems, AI ecosystems, and public infrastructure become deeply integrated into external architecture layers, reversibility becomes increasingly difficult.
Not politically.
Structurally.
The strategic question is no longer:“Which platform is cheapest?”or“Which provider is most scalable?”
The real question is:
Which architecture preserves long-term optionality, sovereignty, and strategic freedom?
Because the next global power centers will not be determined by geography alone.
They will be determined by infrastructure architecture.
Architecture determines optionality.
Optionality determines leverage.
Leverage determines control.
Europe’s Sovereign Cloud Architecture Push Is Accelerating
Europe is accelerating sovereign cloud initiatives rapidly.
National cloud programs are expanding.European operational entities are being created. Local data centers are increasing.Sovereign AI initiatives are emerging.
Regulatory frameworks are tightening.Governments are prioritizing digital resilience.
On the surface, this appears to represent a major shift toward European digital independence.
But one strategic question remains largely unanswered:
Who ultimately controls the architecture?
Because sovereignty is not determined by geography alone.
It is determined by dependency.
And dependency exists in layers.
Most organizations still confuse:
operational localization,
compliance visibility,
and data residency,
with actual sovereignty.
They are not the same thing.
A European legal wrapper on top of foreign-controlled infrastructure is not necessarily sovereignty.
A local data center is not necessarily sovereignty.
A European operating entity is not necessarily sovereignty.
The dependency architecture can still remain external underneath.
That distinction changes everything.
Operational Sovereignty vs Architectural Sovereignty
Most organizations evaluate sovereignty at the operational layer.
They look at:
data residency,
local staffing,
regional operations,
compliance certifications,
local contracts,
European legal entities,
localized infrastructure.
These are operational characteristics.
They improve governance visibility.
They improve regulatory alignment.
They improve localized operational control.
But they do not necessarily change strategic control.
That exists at a deeper layer.
Real sovereignty is architectural.
Architectural sovereignty asks different questions:
Who controls orchestration?
Who controls the cloud operating model?
Who controls platform evolution?
Who controls APIs?
Who controls identity systems?
Who controls AI frameworks?
Who controls firmware and semiconductor dependencies?
Who controls roadmap direction?
Who controls security patch authority?
Who can technically compel access?
Who can legally compel access?
Who controls reversibility?
This is where sovereignty is actually determined.
Not at the branding layer.
At the architecture layer.
A System Is Not Sovereign Because Servers Sit Inside Europe
A system is not sovereign because servers are physically located inside Europe.
A system becomes sovereign when strategic control remains reversible.
That distinction is fundamental.
Most sovereign cloud models still rely on external control layers:
foreign orchestration systems,
foreign AI ecosystems,
foreign compute architecture,
foreign semiconductor dependency,
foreign APIs,
foreign cloud operating models,
foreign roadmap control,
foreign jurisdictional exposure.
The operational layer appears European. The architecture layer often does not.
And that creates a dangerous illusion of control.
Because compliance does not eliminate dependency. It formalizes it.
The European Commission Tender Reveals The Structural Reality
In April 2026, the European Commission awarded a €180 million sovereign cloud framework to multiple European provider groups including:
STACKIT,
Scaleway,
OVHcloud/CleverCloud/Post Luxembourg,
and Proximus together with S3NS, Clarence, and Mistral AI.
At first glance, this appears to signal a major European sovereignty shift.
But one detail matters enormously.
S3NS is a joint venture between Thales and Google Cloud.
That example perfectly illustrates the modern sovereignty tension.
The operational structure can become European while critical architecture layers still originate externally.
This does not automatically invalidate the model. But it changes the sovereignty discussion completely.
Because the real question is no longer:“Is the operator European?”
The real question becomes:
Which layers of dependency remain structurally external and potentially irreversible?
That is the strategic layer most organizations still avoid discussing.
France’s Health Data Hub Exposed The Jurisdiction Problem
France made one of the clearest sovereignty decisions Europe has seen so far.
The French government decided to move the national Health Data Hub away from Microsoft Azure toward Scaleway.
Why?
Because the issue was no longer simply data residency.
The issue became jurisdiction.
France recognized something strategically important:
A European workload running on foreign-controlled architecture can still remain exposed to foreign legal reach.
This is where sovereignty discussions become far more serious.
Because the question is no longer:“Where is the data physically stored?”
The question becomes:
Which legal systems can ultimately compel access?
This is exactly why France’s SecNumCloud framework became important.
The framework attempts to reduce exposure to non-European extraterritorial jurisdiction and legal compelability.
That is not merely a compliance discussion.
It is a sovereignty discussion.
And it raises a critical strategic question for Europe:
Why did jurisdiction become decisive for French healthcare infrastructure while many other European organizations still treat localization as sufficient?
Because if jurisdiction matters for healthcare infrastructure,why would it not matter for:
AI systems,
industrial systems,
government platforms,
defense systems,
digital identity,
telecommunications,
financial infrastructure,
or strategic national infrastructure?
That question becomes increasingly difficult to ignore.
AWS and Microsoft Sovereign Cloud Models Reveal The Core Structural Tension
AWS and Microsoft are both investing heavily into sovereign cloud offerings for Europe.
These initiatives include:
regional operational segregation,
European staffing controls,
localized infrastructure,
dedicated sovereign cloud structures,
compliance frameworks,
and stronger governance boundaries.
These are significant operational developments.
But the architecture question remains.
AWS European Sovereign Cloud still operates within AWS architecture.
Microsoft Sovereign Cloud still operates within Azure architecture.
That matters.
Because:
AWS still controls service evolution,
AWS still controls orchestration logic,
AWS still controls API structures,
AWS still controls roadmap direction,
AWS still controls core platform architecture.
The same logic applies to Microsoft.
This is not criticism. It is structural reality.
The operational layer becomes localized. The architecture layer often remains external.
And that distinction determines long-term optionality.
The Hidden Layers Of Dependency
Most sovereignty discussions remain too shallow because they only analyze the visible operational layer.
Real dependency exists deeper in the stack.
Layer 1 — Physical Infrastructure
land,
energy,
cooling,
fiber,
subsea cables,
data centers.
Layer 2 — Compute Infrastructure
CPUs,
GPUs,
accelerators,
semiconductor supply chains,
firmware.
Layer 3 — Cloud Operating Architecture
virtualization,
orchestration,
networking stack,
storage systems,
hypervisors.
Layer 4 — Control Layers
identity systems,
IAM,
telemetry,
monitoring,
administrative authority,
update authority.
Layer 5 — AI Infrastructure
models,
training ecosystems,
inference systems,
AI frameworks,
AI APIs.
Layer 6 — Jurisdictional Exposure
CLOUD Act,
sanctions exposure,
export controls,
legal compelability.
Layer 7 — Strategic Roadmap Dependency
pricing control,
platform deprecation,
ecosystem lock-in,
externally controlled innovation direction.
This is where long-term dependency actually accumulates.
Not at the visible branding layer.
At the invisible architecture layer.
Europe Does Not Need Zero Dependency
This discussion is often misunderstood.
The goal is not isolation.
The goal is not fragmentation.
The goal is not anti-American positioning.
Complete independence is unrealistic in a globally interconnected infrastructure system. But unmanaged irreversibility creates structural fragility.
That is the real risk.
Europe does not need zero dependency.
Europe needs dependency architectures that remain strategically reversible.
That means:
interoperability,
migration capability,
multi-vendor flexibility,
sovereign orchestration capability,
independent AI pathways,
semiconductor strategy,
energy resilience,
controllable jurisdictional exposure,
and long-term optionality preservation.
Because once optionality disappears,sovereignty becomes performative rather than real.
This is where the discussion moves beyond cloud.
The future of sovereignty will increasingly be determined by:
energy,
compute,
AI infrastructure,
semiconductor access,
cable systems,
orchestration platforms,
identity architecture,
and infrastructure corridors.
The next industrial power centers are being built now.
And they are being built through architecture.
Not slogans.
Not branding.
Not regulatory language alone.
Architecture.
This is why RHODES matters.
Because RHODES is fundamentally about civilization-scale optionality.
Who controls:
compute corridors,
energy corridors,
AI infrastructure,
semiconductor access,
and digital orchestration layers,
will increasingly shape the next global power structure.
The future of sovereign cloud architecture is becoming fundamental.
The Real Strategic Questions Europe Must Now Answer
Europe now faces a series of difficult but unavoidable questions:
Which architecture layers must Europe directly control?
Which dependencies are acceptable?
Which dependencies become strategically irreversible?
Should sovereign European cloud require majority European governance control?
Should sovereign cloud architectures require operational reversibility?
Should orchestration layers remain externally controlled?
Should Europe develop independent AI infrastructure layers?
Should cloud interoperability become mandatory?
Should sovereign identity systems remain dependent on external architecture?
Should semiconductor strategy become part of sovereignty policy?
What does an independent European AI infrastructure corridor actually require?
What architecture preserves long-term optionality for Europe?
Because the real strategic question is no longer:
“Is this cloud European?”
The real question is:
Which dependencies remain structurally irreversible?
Because long-term sovereignty is determined before the contract is signed.
It is determined at the architecture layer.
Architecture determines optionality.
Optionality determines leverage.
Leverage determines control.
Erik Kling



Comments