Decoding the world of cybersecurity

EU defence officials resist cloud sovereignty rules

European defence officials are pushing back against parts of the EU’s proposed cloud sovereignty regime, warning that strict restrictions on non-European providers could undermine military capability and interoperability.

EU defence officials resist cloud sovereignty rules
Summary
  • Defence officials are resisting the strictest sovereignty requirements proposed under the Cloud and AI Development Act.
  • The Commission's framework contains four assurance levels, with stronger control and supply chain requirements at the upper tiers.
  • The dispute exposes tension between reducing strategic dependency and retaining access to established US cloud and AI capability.

European defence officials are pushing back against proposed restrictions on foreign cloud providers under the European Commission‘s Cloud and AI Development Act, exposing a fault line between digital sovereignty policy and military operational requirements.

The proposed regulation, known as CADA, would establish a common EU framework for assessing the sovereignty of cloud and artificial-intelligence services used by public authorities. It forms part of a broader effort to reduce strategic dependency on non-European digital infrastructure while increasing the bloc’s data-centre and computing capacity.

The Commission’s framework contains four assurance levels. The first requires data processing and storage in EU infrastructure, while higher levels add requirements around independence from third countries, software supply chain transparency, EU ownership and control, and protection against third-country interference.

Defence officials are now resisting the strictest application of that model to sensitive military and public-sector systems, according to Financial Times reporting. Their concern is that excluding established US suppliers too quickly could leave European defence organisations with weaker capabilities and create interoperability problems with NATO allies.

The development follows political pressure from France and the Netherlands for a stronger approach to cloud sovereignty, covered by Cyber Insider on 4 September.

The objections expose the practical difficulty at the centre of the policy. Europe’s reliance on large US cloud providers is increasingly treated as a strategic dependency, particularly for sensitive government functions and critical infrastructure. Removing that dependency, however, can introduce another form of risk if organisations are required to abandon mature platforms before technically and operationally equivalent alternatives exist.

Defence systems make the trade-off unusually stark. Cloud procurement can be connected not only to data location or provider ownership, but also to intelligence sharing, analytics, communications, software ecosystems, AI capability, and interoperability with allies. NATO operations create dependencies that do not fit neatly within an EU-only infrastructure model.

The Commission has attempted to contain that tension by creating several sovereignty levels rather than imposing one standard across the public sector. Public bodies would select a level through risk assessment, while the Commission says the vast majority of the cloud and AI market would remain open to international partners.

Even a relatively narrow highest tier can nevertheless have large procurement consequences because the workloads likely to attract the strictest controls are also those governments regard as strategically important. If European providers are expected to take more of that market, procurement rules will become one of the mechanisms used to create domestic scale.

That turns cloud sovereignty into an industrial-policy question as well as a security one. Restricting foreign providers can increase demand for European services, but customers can bear transition and capability risk if policy moves faster than the domestic market. Leaving current arrangements largely unchanged, meanwhile, preserves dependencies Brussels increasingly regards as strategically uncomfortable.

The defence pushback also shows that sovereignty and resilience are not automatically the same objective. A system can have strong local legal and ownership guarantees while being operationally weaker than an alternative, just as a technically capable foreign platform can create concerns about jurisdiction, strategic leverage, or external dependency.

The dispute is likely to shape negotiations over the final CADA framework and the way member states classify their most sensitive workloads. The legislation would affect more than military systems: its public-sector procurement model could influence how other regulated and strategically important industries evaluate cloud dependency.

Europe’s cloud debate has therefore moved beyond a binary choice between domestic and foreign technology. The harder questions concern which dependencies governments are prepared to accept, where European control must be demonstrable, and how much operational disruption they will tolerate while trying to reduce reliance on non-European infrastructure.

×