Sovereign Cloud3 min read

Reflections on Europe’s Cloud Ecosystem: Learnings from Customers and Partners

Photo for Ilias ChantzosIlias Chantzos
Row of European Union flags flying in front of the Berlaymont building in Brussels, EU headquarters

In recent weeks, I have had the pleasure of speaking to Cloud Services Provider (CSPs) partners and customers on the evolution of Europe’s cloud landscape. Mounting regulatory and geopolitical pressures formed the undercurrent of multiple conversations - emerging as key factors driving the shift to private or sovereign cloud. This is particularly true for highly regulated industries - it is no longer a matter of preference, but a move to ensure business continuity.

Sovereignty's Centre of Gravity is Now Control and Access

For years, sovereignty was primarily viewed on the basis of where data physically sits. The conversation has since traced a shift from solely focusing on data location to overarching control.

There is a continued return to practical considerations: who can access a customer's data; under which legal jurisdiction; and whether European providers can run their own infrastructure without a foreign authority able to compel access to it.

For customers, these considerations are now central to infrastructure decisions. They need to know that their data not only stays within their borders, but under their control and the proliferation of AI has sparked a definite increase in urgency.

Sovereignty in terms of control of the technological stack is a consideration but not a priority in an environment where supply chains are integrated and technological performance drives competitive advantages. The technology needs to work, it needs to be safe, reliable and scalable, operated, supported and governed by a local industrial base.

AI as a Driver for Sovereignty Demand

Restricted access to US AI models has further fueled the debate, pushing the need to manage operational risks and dependencies even further up the agenda for European organisations.

The picture that emerged from my conversations was strikingly consistent with the insights coming out of Forum Europe’s EU Sovereign Cloud Day (EUSCD). Participants and attendees alike made it clear that sovereign AI is firmly front of mind - from CSPs, EU and national policymakers to standards bodies and academics.

The European Sovereign Cloud Day panel discussion in Brussels.

In a live poll carried out during the event’s opening session, around three-quarters said that AI makes cloud sovereignty significantly more important to their organisation. This demand was characterised by four key concerns: the confidentiality, privacy and security of company data, and the availability of the models themselves. Another compounding element worth noting is cost. As AI usage scales, so does token consumption on hyperscaler infrastructure and, with it, the risk of losing control over spend.

While AI is a prominent point of discussion across the board, it’s far from the only factor driving the sovereignty debate.

Scale is the Barrier to a Stronger Sovereign Cloud Market

A clearer definition of sovereignty remains the single most important topic requiring greater clarification. To prevent sovereignty-washing, the desire for a common, verifiable bar remains a priority.  This is precisely the gap the DG DIGIT Cloud Sovereignty Framework (CSF) was designed to close, and which the Cloud and AI Development Act (CADA) now carries into legislative text. Legal requirements will help drive discipline, but striking the right balance between compliance and over-regulation is key, and this is where CADA’s co-legislators have the potential to tip the scales.

However, when asked what the biggest barrier to a stronger European sovereign cloud market is, over half of the EUSCD attendees pointed to one thing: limited European-scale infrastructure and capacity. Larik-Jan Verschuren-Parchomov, CTO of Fundaments, made a related point during the event, arguing that consolidation among providers may be a precondition for reaching that scale, rather than a threat to it.

This doesn't mean definitions and certifications matter less. What it points to is a second constraint that holds equal weight: ensuring European players can sufficiently serve customers; deliver sovereign services credibly; and develop the financial muscle to build more capacity to meet demand, especially in rapidly expanding areas like AI. The European industrial base does not lack skills or innovation capacity but needs to have the scale to invest and further grow these capabilities to capture market share. A unified definition of sovereignty means little if the market lacks the capabilities to deliver against it at scale.

The Path Ahead

The general consensus is that jurisdictional sovereignty, operational control and the strength of the local industrial base matter substantially more than technological control or the software licensing model.

Although building Europe’s digital infrastructure in isolation still features in the debate, Henric Skalberg, Head of Cybersecurity and Compliance at Advania, cautioned at the event that being fully sovereign does not equal being secure: it simply exchanges one set of risks for another. This signals the need for a market judging sovereignty not on complete ownership, but on factors such as whether customers can keep operating, or exit cleanly, if a supplier relationship breaks down.

For the European cloud ecosystem, the path ahead lies in partnerships. Those that: actively invest in CSPs to strengthen their capabilities; enable them to retain control where it matters most while remaining competitive and technologically relevant; assure sovereignty throughout the supply chain; and ensure the economic value stays within the region.