EU region is not EU sovereignty

16 July 2026

📎 drag this file into Substack here → campaign/banners/cover_sovereignty.png — use as the post COVER image (top)

Do you ever worry you are not using AI the most secure way, even inside your own company? Are you always comfortable handing company files to it? We feel the same.

That half-second pause before you paste a contract, a customer list, or a board deck into a chat box is not paranoia. It is a reasonable response to a real gap between what “EU region” appears to promise and what it actually delivers. This piece is about that gap, and about the difference between where your AI runs and who is legally allowed to read what you feed it.

Where your AI runs decides who can read it

When you send a prompt with a company file attached, that file lands on compute somewhere. The provider’s page tells you the region: Frankfurt, Dublin, Paris. What it usually does not tell you is the jurisdiction: which government’s courts can compel the company that operates that compute to produce the file, regardless of the region it sits in.

Those are two different questions. Region is a map pin. Jurisdiction is a question about who controls the legal entity behind the compute, and what a court in that entity’s home country can order it to do. The argument of this essay is simple: the second question is the one that matters, and a European region in front of US-controlled compute answers only the first.

The CLOUD Act, and why geography is not the point

The clearest statement of the problem comes from the party that wrote the law. In its own white paper on the CLOUD Act, the U.S. Department of Justice explains that a US-based provider can be compelled to disclose data in its “possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.” The statutory text quoted by the IAPP says the same thing in plainer words: a service provider must comply “regardless of whether such communication, record, or information is located within or outside of the United States.” The location of the server is not the operative fact. Control of the provider is.

Europe’s own regulators reached the matching conclusion from the other side. The EDPB-EDPS joint response to the LIBE Committee found that the CLOUD Act has “an extraterritorial reach” and that providers subject to the GDPR “will be susceptible to facing a conflict of laws between US law and the GDPR.” Their assessment is that, absent an international agreement such as an MLAT, “service providers subject to EU law cannot legally base the disclosure and transfer of personal data to the US on such requests.” So the EU-region datacentre puts a provider in an impossible position: obey a US order and breach the GDPR, or obey the GDPR and breach a US order.

Standing up an EU subsidiary does not solve this. The law firm CMS puts the point bluntly in its white paper on the CLOUD Act: “if the provider has a US parent company the local entity will still be subject to the US CLOUD Act.” And this is not a purely American quirk. Orrick documents a case where an Ontario court ordered the French provider OVHcloud to disclose EU-stored data to Canadian police, “illustrating that location is not an absolute shield.” Even AWS, on its own CLOUD Act page, acknowledges that data “produced can include data stored in the U.S. or outside the U.S.” The reassurance layered on top is that it has never actually happened. Note what that is: a promise about behaviour, not a limit on power.

The deeper legal backdrop is Schrems II, in which the Court of Justice struck down the EU-US Privacy Shield because US surveillance law does “not meet the minimum safeguards resulting, under EU law, from the principle of proportionality,” and, combined with the lack of redress for EU individuals, does not ensure protection “essentially equivalent” to the EU Charter. That is a ruling about personal data transfers. Applying its logic to where you run compute is a downstream reading, not a line in the judgment, but the direction is consistent: US legal reach is the concern, and an EU postcode does not remove it.

📎 drag this file into Substack here → campaign/banners/banner_trap.png — inline near the CLOUD Act / trap point

The market has already priced it in

If this were a fringe worry, budgets would not move. They are moving. Gartner figures reported by The Register put European sovereign cloud spending at 6.9 billion dollars in 2025, forecast to more than triple from 2025 to 2027, with worldwide sovereign cloud spend reaching 80 billion dollars in 2026. CIO Dive reports the same 35.6% global rise to 80 billion dollars, with organisations expected to shift 20% of existing workloads from global public clouds to local providers. As Gartner’s Rene Buest puts it, “large cloud providers must seriously acknowledge the sovereignty concerns and requirements per country, and act accordingly.”

The demand comes from the people who sign the contracts. A Gartner survey of 214 Western European CIOs, reported by Computerworld, found that 61% intend to shift more workloads to local or regional providers, 53% plan to restrict use of global hyperscalers, and 44% have already started. “The political environment is changing very fast,” the piece notes. This sits inside a large market: IDC figures via HostingJournalist put European public cloud spending at 221 billion dollars in 2025, rising to 373 billion by 2028. That growth is driven by platform services, not sovereignty specifically, so treat it as backdrop, not proof. The sovereign-cloud numbers above are the ones carrying the argument.

Governments have moved from surveys to procurement. The European Commission launched a 180 million euro sovereign cloud tender that “establishes a benchmark for how sovereignty is applied in practice,” then awarded four contracts to “ensure diversification and resilience, avoiding potential lock-in by a single provider,” scored against a formal sovereignty framework. That framework, explained by nLighten, grades providers on SEAL levels, and its level one, “Jurisdictional Sovereignty,” is defined as the state where “EU law formally applies, but enforceability is limited and control remains with non-EU parties.” That is the thesis of this essay written into an official rubric. Meanwhile Schleswig-Holstein has migrated tens of thousands of accounts off Microsoft as a “milestone for digital sovereignty,” the Dutch parliament has urged a move away from US cloud services as a “threat to the autonomy and cybersecurity,” and Denmark’s digital ministry is moving employees to open-source software.

“I cannot guarantee it”

The moment that made this concrete was a hearing room. On 10 June 2025, the French Senate’s public-procurement inquiry heard Microsoft France. Its director of public and legal affairs, Anton Carniaux, was asked under oath whether he could guarantee that French citizens’ data would never be handed to the US government. The Senate report records the answer: “Non, je ne peux pas le garantir.” The Register reported it in full: “No, I cannot guarantee that, but, again, it has never happened before.” Forbes carried the same admission, as did SDxCentral and, in French, IT Social.

The revealing part is the pairing. In the same hearing, technical director Pierre Lagarde described the EU-region protection, reported by PPC Land: “Since January 2025, under contractual guarantee, the data of our European clients does not leave the EU.” Two officials, one hearing, one company. The data stays in the EU. The guarantee against US access does not exist. That is region and jurisdiction, side by side. Germany’s heise online sharpened it: Microsoft “can only refuse requests for information from the USA if they are formally unfounded.” A well-founded order cannot be declined.

What practitioners are actually saying

This is not only a lawyers’ argument. The unease is everywhere developers gather. On a Hacker News thread about AWS’s European Sovereign Cloud, a commenter wrote that a US-owned cloud “claims their cloud is ‘sovereign’ and ‘independent’ while remaining owned by a US corp subject to US law (including the CLOUD Act). That’s not how sovereignty works.” It is one voice, but it lands the point cleanly.

The fear is older and broader than the sovereignty debate. In r/ChatGPT, a user asked plainly whether people processing “sensitive data of your company” are “afraid of any consequences or are you trusting the data protection guidelines.” In r/cybersecurity, a thread titled “Employees Are Feeding Sensitive Business Data to ChatGPT” drew hundreds of votes from security professionals. And the instinct to keep the data close shows up as behaviour, not just worry: a practitioner on an offensive security team at a large financial institution reported that “it’s taken as a matter of course that if we want to process anything during an exercise it has to be done on local infrastructure and even that needed accepting from a committee.” Another user, before trusting a local model, asked for reassurance that they “can trust putting personal/work information, project ideas, etc in the chats.”

Named voices say it too. Vitalik Buterin warns that “we are on the verge of taking ten steps backward by normalizing feeding your entire life to cloud-based AI.” Ethan Mollick makes the harder point that sovereignty has limits from the model side: “There is no sovereign model. You will be dependent on the production of Chinese (or US or French) open models as a base.” And the raw telemetry underneath the anxiety is real. Cyberhaven measured that a meaningful share of what workers paste into ChatGPT is confidential, and warned that such content can be absorbed as training data. The pause you feel is the correct reading of the situation.

📎 drag this file into Substack here → campaign/banners/banner_own.png — inline near the close

What actually fixes it

None of this means AI is off the table. It means the guarantee has to attach to jurisdiction, not to a region label. In practice that is three things pinned down and recorded: the region, the legal entity that operates the compute, and the subprocessors behind it, with a signed record on every run. Not a marketing claim. A record you can produce.

Regulation is moving the same way. DORA already requires it for financial entities: Article 30 says ICT contracts must specify “the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location,” plus advance notice before those locations change. The EU AI Act reinforces the jurisdiction-follows-use logic: Article 2 binds providers and deployers “located in a third country, where the output produced by the AI system is used in the Union.” And the EDPB’s Article 48 guidelines restate the core rule: “a request from a foreign authority does not in itself constitute a legal basis for the processing or a ground for the transfer.”

The off-switch test

Here is the one question to ask your provider. If a government your provider answers to ordered your access cut, or your data produced, could the provider refuse? Under the CLOUD Act, per heise, a well-founded order cannot be declined. And access can be pulled: The Register reported that a sanctioned ICC official was “disconnected from Microsoft services,” though Microsoft said institutional service continued and asked Parliament to correct the record. Read it narrowly and the point still stands: the switch exists, and someone else’s law can reach it.

Be honest about the limits. Sovereignty is a direction of travel, not a solved problem. The SEAL levels exist precisely because there are gradations, and Mollick is right that the base models themselves carry dependence. The goal is not a perfect guarantee. It is knowing exactly whose jurisdiction your data sits under, and being able to prove it, run by run.

If you have ever hesitated before pasting a company file into an AI tool, that instinct was right. The fix is not to feel braver. It is to make where your AI runs a fact you can sign for. That is what we build at Socaity.

Sources

### News and official

### Community

Enjoyed this? Follow us for the next one.

New posts on sovereign AI infrastructure, model portability and building without lock-in, free to read on Substack.