The European Union is once again legislating sovereignty with its proposed Cloud and AI Development Act, or CADA. The legislation would establish a four-level sovereignty framework for cloud services used by EU institutions and public-sector organizations, with the most sensitive workloads (defense, national security, justice, and law enforcement) required to run on services at the higher assurance levels. The thinking is straightforward: With AWS, Microsoft, and Google controlling roughly 70% of Europe’s cloud infrastructure market, the continent’s public sector is exposed to overseas laws, mostly American ones, in ways that make Brussels uncomfortable.
Not everyone in Europe is on board, and that’s where the story gets interesting. According to Financial Times, defense officials from several member states, particularly the eastern and Nordic countries closest to a contested border, are pushing back. Their argument is practical, not ideological. Stricter sovereignty rules could restrict access to the cloud and to AI capabilities supplied by the major US hyperscalers and could complicate interoperability with NATO systems.
This matters because NATO’s own digital strategy mandates federated, multi-classification hybrid clouds with binding interoperability standards for nations participating in NATO-led operations. In other words, one arm of Europe’s security apparatus is telling the other that its well-intentioned sovereignty rules could make joint military operations harder to execute. CADA isn’t a blanket ban; it carves out exceptions where compliant services don’t exist, but the pressure it applies to procurement decisions is real, and it’s arriving at precisely the moment European militaries need to move faster, not slower.
I’ve watched this debate play out in various forms for more than two decades, and I keep seeing the same fundamental misunderstanding. So let’s talk about what’s actually being traded away here.
The biggest misconception in the cloud sovereignty debate is that organizations use AWS, Microsoft, and Google to save money. They don’t. Public cloud is more expensive than almost any alternative you can name. That’s the dirty secret nobody puts in the marketing materials. The reason enterprises and governments flock to the hyperscalers is that they’re not buying infrastructure; they’re renting a sophisticated, mature ecosystem as a service. AI systems, business analytics, accounting systems, databases, integration platforms, security tools, development pipelines, and thousands of other services can be provisioned at a moment’s notice and interoperate with each other because they were designed to.
All three of the big providers offer this breadth. That’s the value proposition. You’re buying 20 years of accumulated innovation, operational maturity, and service depth, available on demand with a credit card and a login.
Sovereign clouds, by contrast, are simply not as populated with services. The European providers are legitimate businesses doing credible work. OVHcloud, STACKIT, Scaleway, and their peers offer the basics: compute, storage, even GPU access for AI workloads. But when you need thousands of specialized tools, prebuilt AI services, mature managed offerings, and the operational tools that surround them, they can’t compete with the hyperscalers. Nobody should pretend otherwise, and frankly, the European providers themselves don’t.
So when a government or a business mandates sovereign cloud for a workload, it’s frequently agreeing to replicate functionality that already exists elsewhere. They must either build it, integrate, or do without. That costs additional money, additional time, and additional risk. And in many cases, the replication effort fails to reach the quality of what it replaced.
None of this means sovereignty is a bad idea. For certain data sets and workloads, sovereign attributes just make sense, and security or legal requirements may leave no room for negotiation. Classified military systems, core justice data, and border management platforms all should live under European control, and CADA’s exceptions framework at least acknowledges that reality.
But the endgame here is a functional trade-off, and the EU needs to be honest about it. Some workloads and data sets can’t realistically exist in sovereign clouds, not because of stubbornness or vendor lock-in conspiracy theories, but because the capabilities simply don’t exist there yet. Those workloads need to remain on the popular hyperscalers, despite the fact that many governments consider that to be a bad thing. Forcing usage of sovereign platforms means accepting degraded capability, inflated costs, and slower delivery in exchange for jurisdictional comfort.
Businesses caught in the middle of this need to do the math, workload by workload. For each system, ask: What specifically am I gaining by going sovereign? What am I giving up in service depth and operational capability? What will it cost to close that gap? In many instances, you’re giving up too much to make the sovereign move happen, and the security benefit is more theoretical than real. A hyperscaler operating in EU-hosted regions with European governance controls may well satisfy the actual threat model without sacrificing the ecosystem.
Governments, unfortunately, can’t have both. You can demand data independence and you can demand cutting-edge AI capability and NATO interoperability, but insisting on both simultaneously, at scale, on a timeline, is a fantasy. The realistic path is a tiered, pragmatic approach: sovereign where it’s genuinely required, hyperscaler where the capability gap demands it, and a regulatory framework that distinguishes between the two instead of punishing both.
The defense officials pushing back on CADA understand this. Brussels should listen to them.