Public vs Sovereign Cloud

Blog

The Shift from Public Clouds to Sovereign Clouds: Why Businesses Are Moving Away from Hyperscalers

Sovereign cloud moved from European policy debate to shipped product in January 2026, when AWS opened its European Sovereign Cloud in Brandenburg under a separate EU-controlled parent company. Microsoft extended its EU Data Boundary to cover AI workloads the same year. Options now exist at several price and control points, which makes the procurement question sharper: which layer of sovereignty does this workload actually require, and what does each option cost in service depth and exit risk.

This article sets out what sovereign cloud means in practice, what the hyperscaler offerings solve, what the EU Data Act obliges every provider to do by January 2027, and how to compare a sovereign platform against a public cloud region.

What Is a Sovereign Cloud?

A sovereign cloud is infrastructure whose data, operations and governing law sit inside one jurisdiction. The word gets applied to four different things, and a contract that delivers one layer rarely delivers the rest.

  • Data sovereignty: where data is stored and processed. Easiest to satisfy, and where most marketing claims stop. An EU region address on its own is residency rather than sovereignty.
  • Operational sovereignty: who can technically reach the platform. Support staff location, break-glass procedures, administrative authority.
  • Technology sovereignty: what the stack depends on. Hypervisor, licensing, APIs and update channels controlled from outside the jurisdiction create denial-of-access exposure no matter where the disks sit. This is the layer nobody asks about in the RFP and everybody discovers during a licence renegotiation.
  • Jurisdictional sovereignty: which legal system can compel disclosure. A US-parented provider stays in scope of the CLOUD Act wherever its hardware is.

Most procurement failures we see come from buying the first layer while the actual requirement was the fourth.

What Changed in 2026: The Hyperscalers Built Their Own

AWS opened the AWS European Sovereign Cloud on 15 January 2026, with its first region in Brandenburg and more than 7.8 billion euros committed in Germany. The corporate structure is the notable part: a separate parent company with German subsidiaries, led exclusively by EU citizens, an advisory board carrying two independent European members, and operations run by EU residents with no critical dependency on non-EU infrastructure. More than 90 services were available at launch, with expansion announced for Belgium, the Netherlands and Portugal.

Microsoft took a different route. Its 2026 sovereignty stack extends the EU Data Boundary to AI workloads and Microsoft 365 Copilot, adds Azure Local for disconnected and air-gapped deployments, and relies on partner-operated clouds such as Bleu in France and Delos in Germany.

Both narrow the gap. Neither closes it. KuppingerCole’s assessment of the Microsoft stack is worth reading before a procurement decision: storage and processing are localised, but Microsoft remains US-headquartered and in scope of extraterritorial frameworks such as the CLOUD Act. Regional administration improves without decoupling ultimate administrative authority from the parent. Technology sovereignty is largely unchanged, since customers still depend on Microsoft-controlled licensing, APIs and update mechanisms. The analyst conclusion is that the offering converts sovereignty into a set of risks the customer chooses to accept.

The AWS EU-controlled parent structure addresses jurisdictional exposure more directly than a data boundary does. Whether it holds against a contested CLOUD Act request has not been tested in court.

The Regulatory Floor: EU Data Act and EUCS

The EU Data Act became applicable on 12 September 2025 and changed cloud contracts more than any sovereignty datasheet did.

  • Contracts must let a customer switch provider or repatriate data to on-premises IT within a maximum 30-day transition, following a notice period capped at two months.
  • Until 12 January 2027, switching charges cannot exceed the costs the provider directly incurs for the switch. From that date, switching charges are generally prohibited.
  • Providers must remove commercial, technical, contractual and organisational obstacles to switching, and give reasonable assistance during exit.

Egress pricing as a lock-in mechanism now has an expiry date in the EU. Any business case that assumed exit was prohibitively expensive should be rebuilt before January 2027, while the renewal conversation still carries leverage.

The certification piece has not landed. The EU Cybersecurity Certification Scheme for Cloud Services stays blocked at an impasse over whether sovereignty requirements, including immunity from foreign law, belong in a cybersecurity certification at all. One line of argument holds that the question exceeds the scope of an implementing regulation and belongs to EU lawmakers. Until it resolves, no single EU label certifies a cloud as sovereign, and the assessment sits with the buyer. In practice that means reading the operator’s incorporation, ownership and support model, and treating ISO 27001, ISO 27017 and SOC 2 Type II as evidence of control maturity rather than proof of jurisdiction.

Sovereign Cloud vs Public Cloud: How They Compare

Jurisdiction and legal exposure

A public cloud region in Frankfurt is subject to the law that governs its operator’s parent company. A platform operated by a company incorporated and controlled in the target jurisdiction answers to that jurisdiction alone. For supervised data such as health records, defence material, banking supervision files and criminal justice records, this difference is the entire procurement case. For a marketing website, it is irrelevant. The mistake is applying one answer across a whole estate.

Cost structure and exit

The objection we hear most often is that sovereign hosting has to cost more than the public cloud bill it replaces. It depends entirely on the shape of the workload.

Hyperscaler pricing rewards elastic consumption and penalises steady-state workloads that run continuously at predictable capacity. Sovereign providers price on committed capacity, which looks expensive per unit while utilisation is low and cheaper once it settles. One comparison we ran recently makes the gap concrete. A client spending around 90,000 euros a month on Azure reaches 3.24 million euros over three years. The sovereign equivalent, 350,000 euros of infrastructure plus a managed service at 20,000 euros a month, comes to 1.07 million over the same period. The difference is 2.17 million euros, roughly 67%.

Read that figure with the caveat that matters. It covers infrastructure and operations. It does not cover application remediation and testing, and across our migrations that is the line which overruns the client’s own estimate almost every time. Teams budget carefully for moving bytes, then underbudget the weeks spent fixing what breaks when the platform underneath changes. Data transfer usually lands close to plan. Scope the remediation work before you commit to a number, because it decides whether a three-year case like the one above survives contact with the project plan.

From January 2027 the Data Act takes switching charges out of the EU comparison, so exit cost stops being a variable. What is left is a run-rate calculation against your real utilisation curve over twelve months, with egress, cross-zone traffic, snapshot storage and support tier counted in both columns.

Operational control and support

Escalation on a hyperscaler platform runs through a support tier and a shared runbook. On a sovereign platform operated by a managed services provider, it reaches named engineers who already hold the design context for your environment. The trade is reach. A hyperscaler answers at any hour in any region, while a regional operator has to demonstrate its round-the-clock coverage contractually rather than by sheer scale.

Get the on-call model in writing, including who holds the pager at three in the morning and what sits above them on the escalation ladder. Get the SLA credit mechanism and the evidence standard that triggers it. And ask for the list of roles that can reach the hypervisor, with the legal authority each one answers to. That last question separates operators who have thought about sovereignty from operators who have written about it.

Service depth and portability

Public clouds win this one by a wide margin. Managed database engines, serverless runtimes, mature ML platforms and a decade of ecosystem tooling have no equivalent on a regional IaaS platform. AWS launched its sovereign region with just over 90 services against a global catalogue several times that size, and that gap applies to every sovereign offering on the market.

Portability decides how much the gap costs you. Workloads built on open technology, meaning virtual machines, Kubernetes, PostgreSQL and S3-compatible object storage, move between platforms at low cost. An application wired into a proprietary managed service pays for sovereignty in a rewrite. Audit that dependency before pricing the migration, because it usually dominates the business case.

Energy reporting and CSRD

AI training and inference pushed power consumption into the procurement conversation. Both categories of provider now publish carbon figures, so the useful differentiator is granularity. A datacenter-level PUE number tells a sustainability team almost nothing. Per-tenant consumption attributable to your own workloads is what goes into a CSRD disclosure without an estimate footnote.

Ask for the reporting format and frequency before signing, and check whether the figures are attested by a third party or self-declared.

Where AI Workloads Change the Calculation

Gartner predicted in February 2024 that by 2027, 70% of enterprises adopting generative AI would cite sustainability and digital sovereignty as the top criteria for choosing between public cloud GenAI services. Two years on the prediction has aged well: Microsoft extended its EU Data Boundary specifically to cover AI workloads and Copilot telemetry, and AWS shipped AI services in its sovereign region on day one.

AI raises the stakes on three sovereignty layers at once, and it does so in ways that classification exercises usually miss.

  • Training and fine-tuning data concentrates the organisation’s most sensitive material in a single location with a single access path.
  • Prompts and inference logs routinely contain regulated data that nobody classified as such, because users paste it in.
  • Fine-tuned model weights derived from proprietary data are an asset in their own right, and jurisdiction applies to them.
  • Retrieval pipelines inherit the sovereignty requirements of every document the index can reach, not the requirements of the average document.

The practical control is placement rather than policy. Keep the retrieval layer, the vector store and the logs inside the sovereign boundary, and treat any model API call that leaves it as a data export subject to the same review as any other transfer. That pattern lets a team use a frontier model for general reasoning while keeping regulated context on infrastructure they control.

When Sovereign Hosting Is the Right Call

The case holds when at least one of these applies:

  • A regulator or a customer contract names the jurisdiction. Banking supervisors, health authorities and defence procurement increasingly specify where data sits and who may access it. Where the requirement is written down, the decision is already made and the work is evidencing it.
  • The workload is steady-state. Predictable capacity running continuously rarely earns back the premium attached to elastic pricing.
  • The stack is portable. Virtual machines, Kubernetes and open database engines move at low cost. Deep dependency on proprietary managed services changes the arithmetic.
  • Contractual access control matters. When you need to name who can touch the platform and under which law, an operator incorporated in the target jurisdiction gives a shorter answer than a data boundary does.
  • Latency to a specific market. Serving Lebanon or the Gulf from a European region adds round-trip time that some applications cannot absorb.

We turned a prospect away last year on exactly these criteria. They ran small cloud-native workloads leaning heavily on managed services, their public cloud bill was modest, and no regulator required a move. Transformation cost, running cost and the agility they would have given up all exceeded the savings available. We told them to stay where they were and put the effort into governance and security instead. When the arithmetic does not work, sovereignty is an expensive way to buy a principle.

For most estates the answer is a split rather than a wholesale move: regulated data and its retrieval layer on sovereign infrastructure, everything else where the tooling is deepest.

The Bottom Line

Sovereignty is a spectrum now, with real options at several points along it. Hyperscaler sovereign regions close the data and operational gaps, and in the AWS case they restructure the corporate control question, while the technology dependency stays exactly where it was. Regional providers settle jurisdiction by construction and hand you a smaller service catalogue in exchange.

What makes the decision defensible is unglamorous. Classify each workload by the sovereignty layer it genuinely needs rather than applying one answer across the estate. Verify that layer in contract language, since a datasheet commits nobody. Then reopen your exit terms against the January 2027 Data Act deadline, while renewal still gives you leverage.

EXEO operates sovereign infrastructure from Uptime Institute Tier 3 certified datacenters in Paris and Beirut and a Tier 4 certified facility in Kesrouan, built on European-origin technology with no dependency on US-controlled hypervisor platforms. Our practice is certified ISO 27001, ISO 27017, ISO 27701 and SOC 2 Type II. We compare total cost across three years with migration and operations included, and we say so when the numbers point to staying put. See our sovereign cloud hosting services or get in touch.

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent