Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.
When a major U.S. cloud provider admitted before the French Senate in June 2025 that it could not guarantee data held in its French data centres would never be disclosed to U.S. authorities, the admission landed with unusual force. The legal exposure under the U.S. CLOUD Act was not new information. What changed was the public, on-record acknowledgement that geography alone does not equal sovereignty. For European enterprises, that moment crystallised a question that boards and regulators had been circling for years: who is actually in control?
The answer is now driving one of the fastest-growing segments in enterprise technology spending. Gartner estimates that European sovereign cloud infrastructure-as-a-service spending will rise approximately 83% in 2026, climbing from $6.9 billion in 2025 to a forecasted $12.6 billion. By 2027, that figure is projected to reach $23.1 billion, at which point Europe would surpass North America in sovereign cloud IaaS spending for the first time. The numbers reflect a structural shift in how regulated industries and governments are procuring technology, and the implications extend well beyond Europe.
Policy Is Moving Fast, and the Market Is Moving With It
The European Commission has been explicit about the scale of the problem it is trying to solve. Its own estimates put EU dependence on non-EU countries at over 80% of key digital products, services, infrastructure, and intellectual property. That figure has become a reference point for a wave of policy action.
In June 2026, the Commission introduced the European Technological Sovereignty Package, covering semiconductors, artificial intelligence, cloud, and open source software. Two months earlier, in April 2026, EU institutions awarded a sovereign cloud contract worth up to €180 million over six years to four European providers, the first time cloud procurement was subjected to explicit, measurable sovereignty criteria. The direction is deliberate and consistent.
Gartner attributes the spending surge primarily to governments and regulated industries, and notes that the pattern is not uniquely European. The Middle East and Africa are forecast to see an 89% increase in sovereign cloud IaaS spending in 2026, while Gartner’s Mature Asia/Pacific region is projected to rise 87%. The common driver across all three regions is the same: institutions that cannot afford regulatory or geopolitical exposure are moving to structures where they can demonstrate, not merely assert, that they control their own data environments.
The Binary Framing Is the Wrong Frame
The instinct in policy debates is to treat sovereignty as a binary: either you use domestic infrastructure owned by domestic companies, or you do not. That framing is increasingly being challenged, including by European policymakers who are worried about what excessive restriction actually costs.
Oxford Economics modelling from May 2026, commissioned by the AI Adoption Initiative, categorises sovereign AI policies across five levels of restrictiveness. At one end sit control-and-choice approaches that retain global providers while applying residency rules only to sensitive workloads. At the other end sit ownership-centric mandates requiring a fully domestically owned technology stack. Most enterprises, the analysis suggests, will not sit comfortably at either extreme.
The economic case against over-restriction is concrete. The Oxford Economics analysis estimates that highly restrictive approaches could delay enterprise AI adoption by approximately three to five years. While the modelling focuses on the Asia-Pacific region, the underlying logic applies wherever infrastructure duplication and delayed access impose costs. In Europe, those costs compound the fragmentation that already exists across national jurisdictions, translating into slower innovation and higher operational run-rates. That is the trade-off Europe is weighing as it directs billions toward sovereign cloud: the cost of genuine control versus the cost of restrictions that go further than control requires.
Control Is a Governance Question, Not an Ownership Question
The more useful frame, and the one gaining traction in European policy discussions, is to ask not who owns the infrastructure but who governs it. The Commission’s Cloud Sovereignty Framework reflects this directly, assessing the legal, contractual, and technical channels through which non-EU authorities could compel access to data, with explicit reference to the U.S. CLOUD Act.
In a neutral colocation model, the customer retains possession, custody, and operational control of its own environment. The provider does not operate the customer workload or control the customer data layer. Crucially, the location of a provider’s headquarters does not automatically determine who can access customer data. What matters is how control, custody, operational responsibilities, and legal obligations are structured and enforced in the contract and in practice.
Where customers retain operational control of their environments, they may also retain primary responsibility for responding to lawful requests relating to their data. That structure gives an enterprise a defensible, verifiable answer to the question regulators and boards are now asking. It also creates a meaningful distinction between provider-operated sovereign cloud offerings, where questions about the depth of genuine sovereignty remain, and customer-operated environments built on neutral interconnected infrastructure.
A European bank, for example, could keep regulated workloads and market data within the EU while still reaching cloud-based AI and analytics tools through private, controlled interconnection. Network architectures and routing controls can be designed to support jurisdictional requirements for data in motion, including during resilience and failover scenarios, without requiring the bank to replicate the entire global technology stack domestically.
Why This Matters Beyond Europe
The European sovereignty debate is often framed as a regional concern, but its resolution will set precedents that matter globally. The frameworks being developed in Brussels for assessing demonstrable customer control, for calibrating safeguards to workload sensitivity rather than applying uniform rules, and for distinguishing genuine sovereignty from sovereignty-branded products are frameworks that regulators in other jurisdictions will study and adapt.
For businesses and investors in Malaysia and Singapore, the trajectory is directly relevant. Both countries operate in a region where sovereign cloud spending is accelerating sharply, and where regulators at bodies such as the Monetary Authority of Singapore are already engaged with questions about data residency, operational control, and third-country legal exposure. The European experience is providing a live test of which governance models hold up under regulatory scrutiny and which do not.
The core lesson emerging from Europe is that sovereignty, understood as the agency to govern rather than the obligation to own everything, is achievable without isolation. Enterprises that grasp this distinction early will be better positioned to satisfy regulators, retain global reach, and avoid the productivity penalty that comes with over-restriction. Those that conflate ownership with control risk building expensive, fragmented architectures that satisfy neither goal. That is a lesson with no geographic expiry date.
Read More: Airbus Flies 24 Hours Nonstop to Prove the World’s Longest Commercial Route Is Real