Sovereignty

The Patch as Hostage: Why Sovereignty and Hyperscale Are Incompatible

JP Ahonen · · 14 min read

Imagine a critical zero-day vulnerability discovered tonight in infrastructure software running across a hyperscaler's European sovereign region — the kind of flaw that, unpatched, exposes hospital records, bank ledgers, and defence procurement systems simultaneously. Imagine, in the same week, a US executive order classifies the patch — or the threat intelligence describing the vulnerability — as a controlled technology subject to export licensing, citing national security. Not an outright ban. Just a review period. A pause, while lawyers determine whether releasing the fix to a foreign-incorporated subsidiary satisfies the license requirements.

European sovereign cloud customers sit exposed for the duration of that review. Courts may eventually strike the order down. That takes months. The vulnerability does not wait for the judiciary.

This scenario has not happened. It is not the most probable form this risk will take — the more likely manifestation is quieter: a deprioritised patch, a delayed advisory, a support ticket that moves slower than it should for a region under diplomatic strain. But the clean version is useful precisely because it is clean. It isolates a single mechanism — jurisdiction reaching into the operational security pipeline, not merely the data at rest — and makes it visible in a way the mundane version obscures. Risk analysis works this way: model the severe case to understand the shape of the exposure, then map the realistic probability around it. Both versions rest on the same underlying fact, and that fact is the one hyperscalers' own marketing has been quietly confirming for two years.


What the Hyperscalers Actually Claim

The claims are worth reading in their own words, because the language is more careful than it first appears — and the gaps in that language are where this essay lives.

AWS's European Sovereign Cloud materials promise a "dedicated Security Operations Center under European management that monitors the entire cloud infrastructure around the clock, detects security-relevant events in real time, and coordinates measures to avert threats." The January 2026 governance announcement adds that "only EU-resident AWS employees located in the EU have control over the operations and support of the environment," under a new German parent company with "separate governance and operational autonomy from existing global AWS operations."

Microsoft's language is structurally similar but more candid about the limit. Its own 2026 sovereignty documentation states plainly that "some processing deemed necessary for global security operations or threat response may still involve transfers outside the EU with safeguards" — an admission, in Microsoft's own words, that the security function is not actually bounded by the sovereignty boundary everything else is supposed to respect. At Microsoft's own 2026 Digital Sovereignty Summit, the company's leadership went further, arguing directly against operational segregation: "disconnecting systems or building digital walls can create blind spots by limiting access to shared threat intelligence, coordinated response capabilities, and real-time threat detection." Microsoft's Security Program elsewhere boasts that its platform "analyzes over 84 trillion threat signals daily" — a figure that is only possible, by definition, as a single global aggregate. There is no version of 84 trillion daily signals that is simultaneously a global capability and a nationally segregated one.

Read those two statements together and the essay's argument is not an outside accusation. It is Microsoft's own position, stated at its own summit: sovereignty and security are in tension, and when forced to choose, the global pool wins, because the global pool is what makes the detection work at all.

The most direct admission, however, came not from a keynote but from a support interaction. A Microsoft France executive, asked directly by a French Senate committee whether the company could guarantee French data would never be accessed by US authorities under compulsion, answered: "No, I cannot guarantee French data won't be seized by US authorities." That is not a hypothetical from a critic. That is the vendor, under oath, declining to make the claim its own marketing implies.


The Legal Skeleton Underneath the Marketing

French MP Philippe Latombe has spent two years turning this gap into a formal legal challenge. His position, stated repeatedly: AWS cloud cannot be sovereign because it remains subject to US FISA and the CLOUD Act — laws that compel American companies to produce data and cooperate with security agencies regardless of where the processing occurs or which subsidiary formally operates it. The EU General Court dismissed his initial challenge to the EU-US Data Privacy Framework in September 2025, confirming the framework's adequacy on the facts as they stood at the time of its 2023 adoption. Latombe appealed to the CJEU on 31 October 2025; the case, C-703/25 P, remains pending.

What has changed since is not the appeal. It is the ground underneath it. On 29 June 2026, the US Supreme Court ruled in Trump v. Slaughter that the President may remove Federal Trade Commission commissioners at will, eliminating ninety years of for-cause removal protection and overturning the precedent — Humphrey's Executor — that had insulated independent regulators from direct presidential control. This is not adjacent to the sovereignty question. It is the sovereignty question's legal foundation, because the European Commission's 2023 adequacy decision cites FTC independence as a safeguard 259 times. The Privacy and Civil Liberties Oversight Board, another pillar the adequacy decision leans on, had already lost its quorum when Trump removed its Democratic members in January 2025. The Data Protection Review Court, the body specifically created to give EU citizens redress, is — despite the name — an executive body inside the Department of Justice, established by an executive order the president can amend or revoke at will. All three legs the framework stands on are now either structurally compromised or one signature away from it. Max Schrems's noyb wrote to the European Commission on 30 June demanding an orderly withdrawal of the adequacy decision, and is preparing what practitioners are already calling Schrems III. The adequacy decision remains formally in force — the Commission has strong political and economic incentive not to move first, and past precedent suggests a formal reversal would take one to three years even if it comes. But "formally in force" and "actually sovereign" are exactly the two things this essay has been arguing apart from each other since the opening paragraph. If it succeeds, it will not be the first time a framework built substantially on an executive order proved exactly as durable as the administration that signed it.

The technical detail matters here as much as the legal one. Under the CJEU's own Schrems II reasoning, a GDPR risk assessment must consider the legal authority to compel access, not merely how often that authority has historically been exercised. For FISA Section 702 specifically, exercise is by design invisible — directives are classified, providers are gagged by statute, and no transparency report can disclose what the law forbids disclosing. A hyperscaler can report, accurately, that CLOUD Act requests for European enterprise data are "exceptionally rare." That statistic describes disclosed requests. It says nothing about what the law authorizes, and Schrems II says the authorization is what matters.

This is the frame the zero-day scenario sits inside. The CLOUD Act and FISA already establish, as settled US law, that a court order or executive directive can reach into an American parent company's global operations regardless of where the affected infrastructure sits. Whether that authority has ever been used to compel withholding, delaying, or restricting a security patch specifically is a separate, empirical question — and the honest answer is that it hasn't happened yet, publicly. But "hasn't happened yet" is a description of restraint, not a description of incapacity. The legal architecture for it already exists. The only missing element is the specific exercise.


The Precedent That Already Happened

Europe does not need to imagine executive coercion of hyperscaler operations. It has already watched a live case study, run not by Washington against Europe, but by the West against Russia — and it demonstrates the mechanism works exactly as this essay describes, just aimed in a different direction.

Following Russia's 2022 invasion of Ukraine, Microsoft and AWS suspended new customer sign-ups, then progressively withdrew existing services under EU and US sanctions pressure. By March 2024, under the EU's twelfth sanctions package, Microsoft was shutting down more than fifty cloud products for Russian businesses — not through Russian infrastructure being seized or nationalised, but through the American and European parent companies simply deciding, under legal compulsion, to stop serving the region. Russian distributor Softline warned its clients the suspension would bring "functional limitations in the operation of cloud products and services from Microsoft, Amazon and Google" — the exact texture of degraded, cascading service failure this essay's realistic scenario describes, running not through a dramatic single order but through a sanctions package working its way down the corporate chain over eighteen months.

The mechanism is proven. What is not yet proven — what remains, for now, the illustrative hypothetical — is the mechanism running in the other direction, against a European ally rather than a designated adversary. But the infrastructure that would carry that instruction, should it ever be given, is identical. It is the same parent company. The same global operations chain. The same legal levers, differing only in which government is pulling them and which customer sits on the receiving end.

Europe has no equivalent leverage over Amazon.com Inc. or Microsoft Corporation that Washington holds over their compliance departments. That asymmetry — not any specific hostile intent — is the actual sovereignty gap.


Why the Hyperscalers Cannot Fix This — Even If They Wanted To

Here is the part of the argument that does not depend on any government ever issuing any order, and it is the part that should worry the sovereignty debate most, because it means the problem is not political. It is structural to the hyperscale business model itself.

A genuinely sovereign security operation — one immune to the scenario above by design, not by promise — would require a European entity capable of independently discovering vulnerabilities, developing patches, validating them, and deploying them without dependency on the parent company's global threat-intelligence pipeline, global engineering teams, or global patch-development infrastructure. That is not a governance change. It is a second, fully redundant security research and engineering organisation, maintained permanently, contributing nothing to the economies of scale that make the hyperscale model profitable in the first place.

The hyperscaler business model exists because a single global fleet, a single global threat-intelligence pool, and a single global engineering organisation can defend billions of endpoints more efficiently than any fragmented alternative. Microsoft says this explicitly and correctly: 84 trillion signals a day is a capability that exists because it is global. The moment you genuinely bifurcate that pipeline — not rebrand it with a European advisory board and an EU-resident SOC director, but actually sever the dependency — you have built a second, smaller, less capable security organisation operating at a fraction of the detection power, funded entirely by the European customer base alone rather than amortised across the planet.

No hyperscaler will build that voluntarily, because building it is close to admitting the global model was never sovereign anywhere, for anyone, including American customers relying on the same architecture. And no hyperscaler can build it as a side offering, because a security operation that is sometimes global and sometimes sovereign, depending on which product tier a customer purchased, is not actually two operations — it is one operation with a marketing partition drawn across it, which is precisely what a Security Operations Center "under European management" that still depends on a shared global signal pool actually is.

This is the sentence AWS, Microsoft, and Oracle all need but none of them can honestly write into a sovereignty framework: our security operations are sovereign except for the parts that make them work.

Microsoft's own justification — disconnecting systems creates blind spots, the global pool is what makes detection work — is not actually a hyperscaler-specific argument. It is the standard natural-monopoly argument for a balancing or coordination function: a single synchronised grid area needs one system operator keeping frequency and voltage stable in real time, not two competing ones, because duplicating the coordination function doesn't produce redundancy, it produces conflict. Global threat-signal correlation genuinely may work the same way — there may be a real efficiency case for one pool rather than many. But that is precisely the argument for why it belongs under public, accountable ownership rather than a single foreign private balance sheet, not an argument against sovereignty concerns. Europe has already run this experiment twice with infrastructure of exactly this character, and the results were not ambiguous. Finland sold its national power distribution network to a private consortium in 2014; within two years the buyer was structured to pay 1.6% tax on tens of millions in profit while raising customer tariffs to cover its own acquisition debt, prompting the sitting Prime Minister to call the arrangement "repulsive" on the record. The United Kingdom privatised water in 1989; UK water companies have since paid out £85.2 billion in dividends while accumulating £65 billion in debt, and Thames Water alone now carries close to £20 billion in debt against year-on-year increases in raw sewage discharge, with special administration — temporary renationalisation — openly discussed in Parliament this year. Both cases share the same architecture this essay has described for cloud security operations: a function with genuine natural-monopoly characteristics, handed to a private owner whose economic incentive is extraction rather than resilience, with the customer base holding no real exit option because the infrastructure cannot be meaningfully duplicated. Cloud security operations are not yet a scandal on the scale of Thames Water. The mechanism that would produce one is already in place.


What This Means for Procurement

None of this is an argument that European institutions should abandon hyperscale cloud entirely — an argument this site has not made and does not make here. It is an argument for pricing the actual risk rather than the marketed one.

The ownership-and-control criterion developed on this site in May applies with full force to security operations specifically, not only to data residency. A European public institution evaluating a "sovereign cloud" offering should ask a narrower and more useful question than "where is my data stored": can this provider's European security operation independently discover, develop, validate, and deploy a critical patch with zero dependency on any process, system, or signal originating outside EU jurisdiction — and can that independence be demonstrated, not merely asserted? Every hyperscaler currently on the market will answer no, because the economics of the business make yes impossible, not merely inconvenient.

For the systems where the answer matters most — critical infrastructure, defence procurement, health records, financial supervision — that gap is not a compliance footnote. It is the entire risk. Sovereignty in cloud has, since May, been a data-residency conversation. It needs to become a security-operations conversation, because the CLOUD Act, FISA 702, and the 2022 Russia precedent all point at the same conclusion: the parent company's jurisdiction reaches wherever the parent company's operational dependencies reach, and today, for every major hyperscaler, that is everywhere.

Europe's own emerging sovereign stack — Mistral's infrastructure build-out, the SecNumCloud-certified providers, OVHcloud's in-house manufacturing — remains smaller, less mature, and more expensive than the hyperscale alternative. That gap is real and this site has not pretended otherwise. But smaller and genuinely sovereign is a different category of risk than large and sovereignty-washed. Procurement decisions for Europe's most sensitive systems should be made with that distinction in view, not obscured by it.

We can't rent sovereignty. We especially can't rent it in the one layer — security operations — where the vendor's own summit stage has already told us, on the record, that the global pool is non-negotiable.


JP Ahonen is a transformation director, Finnish defence reservist, and independent analyst based in Porto Rafti, Greece. He previously worked as an advisor within a major hyperscaler's public sector professional services organisation.

Audit: Digital Sovereignty Package vs. CLOUD Act Exposure
The flagship EU programme that counts these offerings toward its sovereignty targets. Verdict: FAIL.
Lexicon: Ownership-Control Criterion
The test this essay extends from data residency to the security pipeline itself.
Star Five: Public Ownership of Natural Monopolies
Why a coordination function with no possible competitor belongs in public hands.