What is a sovereign cloud?
A sovereign cloud is a cloud computing service designed to keep its data, operations and technology under the legal and practical control of one jurisdiction. The European Commission measures cloud sovereignty in graded assurance levels.
Also known as: sovereign cloud services, cloud sovereignty
Researched and fact-checked by AI, with no human review. 8 sources listed below. How we verify
Last updated
How it works
Cloud computing, in the NIST definition, is a model in which users reach a shared pool of computing resources over a network on demand. NIST's examples include servers, storage and applications. A sovereign cloud adds assurances about who controls those resources and which laws reach them. In January 2026 the European Parliament called for a definition of sovereign cloud.
One published yardstick is the European Commission's Cloud Sovereignty Framework, dated October 2025 and written for a cloud tender. It assesses a service against eight objectives: strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability. Factors it weighs include:
- whether non-EU authorities could compel access to data
- whether only the customer controls the encryption keys
- whether EU operators can run the service without a non-EU vendor
Each objective gets a Sovereignty Effectiveness Assurance Level (SEAL). SEAL-0 means exclusive control by non-EU parties. SEAL-4 means complete EU control with no critical non-EU dependencies.
Why it matters
Amazon, Microsoft and Google together hold more than 60% of the global cloud market, Reuters reported in June 2026. Reuters attributed the EU's push for sovereignty requirements to concern about that dominance and about laws such as the US CLOUD Act. That law can require US-based providers to give authorities data stored abroad.
US providers have launched their own offerings. Amazon Web Services says its European Sovereign Cloud, generally available since January 15, 2026, is physically and logically separate from its other regions and operated only by EU residents.
Where things stand in 2026
In April 2026 the Commission awarded a sovereign cloud tender worth up to €180 million over six years to four providers or partnerships led by European companies. Bidders had to reach SEAL-2. Three reached SEAL-3. A Proximus-led partnership that draws on Google Cloud technology operated by EU companies reached SEAL-2. The Commission said an updated framework would follow.
On June 3, 2026, the Commission published its proposal for a Cloud and AI Development Act, according to Parliament's legislative tracker. The Commission's summary says the act would set four sovereignty assurance levels for use by public sector bodies. Level 1 covers services whose data is processed and stored on infrastructure in the EU. As of September 20, 2026, the tracker listed the proposal as awaiting a decision by Parliament's committees, so it was not yet law.
Sources
- SP 800-145, The NIST Definition of Cloud Computing, NIST Computer Security Resource Center
- Cloud Sovereignty Framework, Version 1.2.1 (October 2025), European Commission, Directorate-General for Digital Services
- Sovereign Cloud Framework explained, European Commission, Directorate-General for Digital Services
- Commission advances cloud sovereignty through strategic procurement, European Commission, Directorate-General for Digital Services
- Cloud and AI Development Act, European Commission
- Cloud and AI development act (Legislative Train Schedule), European Parliament
- EXCLUSIVE: EU cloud rules to curb Big Tech's access to strategic tenders, draft document shows, Reuters
- AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe, Amazon