Sovereignty Washing
Where sovereignty cannot be supplied, the word is redefined.
Three American hyperscalers hold approximately seventy per cent of the European cloud market. As American companies, they cannot meet the legal test for sovereignty established under Schrems II. They cannot change which government compels them. They cannot stop Europe from wanting sovereignty. What they can do is redefine the word.
Sovereignty washing is the strategic response. AWS European Sovereign Cloud, Microsoft Sovereign Cloud and S3NS market structurally identical architectures as sovereign offerings. The SEAL Framework replaces the binary legal test with a graduated score on which American providers always score sovereign-enough. The Cloud and AI Development Act is the legislative front on which the redefinition either becomes law or is refused.
Encode a binary sovereignty test in CADA. Apply the Schrems II essentially-equivalent standard, formalised by the European Data Protection Board as the European Essential Guarantees, using the five-position framework as the operational scaffold: Positions 1, 2 and 3 qualify; Position 4 does not. One clause. One question. Can someone else be compelled? One answer. The score is what produced the redefinition; the binary forecloses it.
“It was intended that when Newspeak had been adopted once and for all and Oldspeak forgotten, a heretical thought… should be literally unthinkable, at least so far as thought is dependent on words.”
— George Orwell, 1984, Appendix on the Principles of Newspeak
On 17 March 2026, twenty-five chief executives of European cloud and digital service providers wrote to Henna Virkkunen, Executive Vice-President of the European Commission for Tech Sovereignty, Security and Democracy, ahead of a roundtable on the EU Cloud and AI Development Act. The letter’s first principle named the structural test the legislation must meet: “Sovereignty must be defined by control, not simply by having EU presence or meeting cybersecurity standards.” Francisco Mingorance, Secretary General of the trade association CISPE, framed the broader stake in plain language: “CADA is a once-in-a-lifetime opportunity to put Europe back on the front foot in the digital economy, and we must not squander it by legitimising sovereignty-washing.”
Doublespeak is language constructed so that the words mean the opposite of what they describe. Peace prizes for warmongers. Human Rights Council seats for documented abusers. Sovereign clouds operated by the threats they were meant to exclude.
Sovereignty washing is incentivised doublespeak.
Europeans want sovereignty. Hyperscalers are redefining the word in front of us.
The strategic situation
The hyperscalers face a problem they cannot solve.
Three American companies hold approximately seventy per cent of the European cloud market.
The market reached €61 billion in 2024 and Synergy Research Group projects it will grow to over €74 billion in 2025. Seventy per cent of €61 billion is approximately €43 billion. That is the European cloud revenue currently flowing to American firms in a single year.
They invest approximately €10 billion every quarter, or €40 billion annually, in European capital expenditure to defend the position.
Over one hundred and forty hyperscale data centres are operational in Europe. The scale of the defensive investment is itself the measure of how much they have at stake.
This revenue cannot meet the legal test for sovereignty.
Paper 1 established the test using the language of the law itself. The CLOUD Act, codified at 18 U.S.C. §2713, requires American providers to produce data within their “possession, custody, or control,” regardless of whether that data is located within or outside the United States.
FISA Section 702 permits the targeting of non-US persons reasonably believed to be located outside the United States for foreign intelligence purposes. Executive Order 12333 governs signals intelligence activity.
None of these is contractual or displaceable by a data residency clause, a customer-managed encryption key, an operational handover to a European partner, or a national-cloud joint venture.
The legal reach follows the corporate chain, not the server rack.
The hyperscalers cannot escape this.
They are American companies. American law applies because they are American.
Reorganising into a European subsidiary does not change which entity has possession, custody, or control of the underlying infrastructure.
Anton Carniaux, Director of Public and Legal Affairs at Microsoft France, confirmed this on 10 June 2025 under oath at a hearing of the French Senate.
Asked whether Microsoft France could guarantee that European customer data would not be transmitted to United States authorities without explicit French authorisation, he answered: “No, I cannot guarantee that.”
The threat actor’s own representative, in a European parliamentary chamber, testifying under oath, confirmed that the structural fact cannot be met.
So the hyperscalers cannot meet the test.
They also cannot stop Europe from wanting it.
The European awakening is older than 2026 but the trajectory steepened in early 2025. The first Trump administration produced the Schrems II judgment.
The second has produced more. On 17 January 2026, ten per cent tariffs were announced on imports from eight NATO allies, escalating to twenty-five per cent on 1 June.
The International Criminal Court’s prosecutor Karim Khan was sanctioned by an American executive order in February 2025 and lost access to his Microsoft email account, demonstrating to every European institution that American jurisdiction reaches into European workflows when the American executive chooses.
Microsoft’s French Senate testimony followed in June 2025. The CISPE letter followed in March 2026.
Each event widened the gap between what European institutions thought they had purchased and what they had actually purchased.
The awakening is not reversible. It accelerated in 2025 because the threats became visible. The hyperscalers cannot un-publish the executive orders, un-sanction Khan, un-tariff the allies, or un-testify Carniaux.
What they can do is redefine the word.
The redefinition is the only move available to them.
They cannot change American law because they cannot change which government they answer to. They cannot stop Europe from wanting sovereignty because the events that produced the wanting are public, documented, and accumulating.
They can only change what European procurement, regulation, and law mean by sovereignty. If the word can be changed, the legal test the word originally encoded becomes inapplicable, and the same product can be sold without modification under a label that no longer requires the test it was created to fail.
The product cannot change. The label can.
This is the rational response of any economic actor facing the constraints these actors face.
Forty-three billion euros of annual European revenue is at stake in 2024, roughly fifty-two billion in 2025 if the projection holds.
Sovereignty rules under any binary definition would close a meaningful fraction of that market to them. Faced with that exposure and unable to alter the underlying legal position, redefinition is the only move available.
We see what they are doing.
The same pattern appears outside cloud.
Mastercard rebranded its European operations as “Mastercard Europe” with a Belgian licensing entity to address sovereignty concerns about payment data. Visa pursued similar arrangements.
The threats become the providers of protection from themselves. Sovereignty washing is the cloud-layer instance of a pattern visible across financial services, payments, identity, and platform infrastructure.
The frame is general; the cloud case is where the redefinition is being institutionalised through European law in 2026.
The redefinition in operation
“It was intended that when Newspeak had been adopted once and for all and Oldspeak forgotten, a heretical thought… should be literally unthinkable, at least so far as thought is dependent on words.”
George Orwell, 1984, Appendix on the Principles of Newspeak
The redefinition produces a sequence of products that share the same architecture, fail the same legal test, and arrive with new marketing language.
AWS European Sovereign Cloud.
Announced in 2023, generally available from 14 January 2026. The first region launched in Brandenburg, Germany. Amazon Web Services committed €7.8 billion in investment through 2040 and projects the regional contribution to European gross domestic product at €17.2 billion.
The marketing materials describe the offering as “operationally autonomous” and “operated exclusively by EU residents through entities incorporated in Germany.”
The legal reality is that those entities are subsidiaries of Amazon Web Services, Inc., a Delaware corporation, which is subject to the CLOUD Act, which requires production of data within the parent company’s possession, custody, or control regardless of where the operating entity is incorporated.
The operational autonomy is real, the jurisdictional position unchanged.
The product is Position 4 in the five-position framework (Paper 1), sold under a label that implies Position 1 or Position 2.
Microsoft Sovereign Cloud.
Brad Smith, Microsoft’s Vice Chair and President, posted a celebration of Microsoft’s status as a Leader in the Forrester Wave: Sovereign Cloud Platforms, Q2 2026.
The Wave names Amazon Web Services, Microsoft, Google Cloud, and Oracle as the global leaders in providing sovereignty to a region whose sovereignty problem is principally with American jurisdiction.
Microsoft’s European sovereign cloud architecture includes Bleu, a joint venture announced in May 2021 with Capgemini and Orange to wrap Azure infrastructure in a French operating entity, and Delos Cloud, a German partner-operated national cloud.
Both Bleu’s and Delos’s customer data sit on Azure infrastructure.
The wrapper changes the operating entity but leaves the corporate parent’s possession, custody, or control unchanged.
Carniaux’s Senate testimony, three years after Bleu was announced and several months before Delos’s full launch, confirmed that the wrapper does not address the legal test.
Google Cloud and S3NS.
S3NS is a joint venture of Thales and Google Cloud, announced in October 2021. It markets a “trusted cloud” offering.
On 17 April 2026, the European Commission’s Cloud III procurement awarded sovereign-grade contracts to four European consortia, including Proximus with S3NS, Clarence, and Mistral, applying the Commission’s Cloud Sovereignty Framework as the binding criterion.
The Proximus consortium was placed at SEAL-2 (Data Sovereignty), one level below the SEAL-3 reached by three other consortia.
Sovereign status was awarded. The threat to the data is Google. The framework score adjudicated this acceptable.
The pattern is consistent. A product is announced with sovereignty marketing on an unchanged American legal architecture. Forrester ratifies the marketing claim in the Wave, the Cloud Sovereignty Framework absorbs the ratification into its scoring, and Cloud III awards the contract on the basis of the score. By the time the procurement officer reads the documentation, the redefinition is operational and the legal test that produced the requirement is nowhere in the chain.
Improvements within Position 4 are real.
Each is better than the previous configuration: operational autonomy in place of remote operation, customer-managed encryption keys in place of provider-managed, EU staffing in place of American, a European data centre in place of Virginia.
Each individual improvement raises the cost of disclosure for the provider without changing whether disclosure can be compelled.
The legal test produces a yes or no.
Every offering documented above answers yes to the question: can someone else be compelled to share this data?
The sovereignty-by-control test the CISPE letter named on 17 March 2026 is the test the offerings fail.
Sovereignty is defined by control. The American parent retains control. Therefore the offering is not sovereign, regardless of how the controls within Position 4 have improved.
The improvements are real and irrelevant.
The institutional ratification
The redefinition becomes operational through institutional documentation that procurement officers rely on.
Standards bodies have been instruments of capture before.
In 2006 the United States National Institute of Standards and Technology published Special Publication 800-90A, which contained the Dual Elliptic Curve Deterministic Random Bit Generator algorithm.
The algorithm contained a kleptographic backdoor inserted by the National Security Agency through the standardisation process. The backdoor allowed the NSA to predict the random numbers generated by anyone using the algorithm.
RSA Security accepted ten million dollars from the NSA to make Dual_EC_DRBG the default in its BSAFE cryptographic library.
The standard remained in published form for eight years before the Snowden disclosures of September 2013 confirmed the backdoor; NIST withdrew the algorithm in April 2014.
The same NIST is now setting post-quantum cryptography standards (FIPS 203, 204, and 205, finalised in August 2024, the first two IBM-developed).
Germany’s BSI and France’s ANSSI have responded by hedging: both recommend FrodoKEM and Classic McEliece alongside the NIST standards, the European agencies refusing to follow NIST alone.
The European hedge admits what it cannot say openly: a standards body that produced Dual_EC_DRBG cannot be trusted unconditionally to produce uncompromised cryptography.
The four current cases below are sovereignty washing’s standards-body moment.
Europe hedged on the post-quantum standards. On cloud sovereignty, Europe has so far ratified.
The Forrester Wave. Forrester Research is a Cambridge, Massachusetts analyst firm. Its quarterly Wave reports are read by procurement, legal, and compliance functions across the European public and private sectors.
The Wave: Sovereign Cloud Platforms, Q2 2026 names Amazon Web Services, Microsoft, Google Cloud, and Oracle as Leaders. Tencent Cloud is named as the only Chinese hyperscaler with a deliberately consistent strategy.
The companies whose jurisdiction is the source of the European sovereignty problem are named as the leading providers of sovereignty to Europeans.
Microsoft and AWS celebrated the rating in their corporate channels; the Wave document and the celebrations are the artefact European procurement reads.
Forrester is doing what its clients pay for. Forrester is an instrument of sovereignty washing rather than its source.
Gartner, the other major analyst whose work procurement reads, has chosen not to publish an equivalent ranking. Its sovereign cloud framework forecasts hyperscaler workload loss to local providers as sovereignty pressures build, and projects European sovereign cloud spending to overtake North America by 2027. The institutional ratification of hyperscalers-as-sovereign-cloud-leaders is a specifically Forrester move.
The Cloud Sovereignty Framework. Published by the European Commission, the Framework specifies eight sovereignty objectives weighted across SEAL levels 0 to 4.
The objectives include data residency, supply chain control (the highest weighted objective at twenty per cent), encryption, operational autonomy, transparency, audit, incident response, and exit reversibility.
The Framework is an instrument designed to make sovereignty claims auditable. Auditable claims are useful when the underlying claim is true.
Auditable claims that average load-bearing tests with cosmetic ones are how the redefinition becomes operational.
CISPE’s public assessment of the Framework named the move precisely: “Rather than bringing clarity, the Framework muddies the waters by introducing a murky ‘sovereignty score’ that averages the impossible with the irrelevant.”
A score allows compensation. AWS European Sovereign Cloud scores well on data residency, encryption, operational autonomy, and EU staffing, which compensates for failing the foreign-jurisdiction test.
The score system was designed in such a way that compensation is possible.
That is the entire problem.
Cloud III and S3NS. The April 2026 procurement was the first time the Commission awarded sovereign-grade contracts using the Framework as a binding criterion.
Three consortia reached SEAL-3 (Digital Resilience): Post Telecom with OVHcloud and CleverCloud, STACKIT of the Schwarz Group, and Scaleway. The Proximus consortium with S3NS, Clarence, and Mistral reached SEAL-2 (Data Sovereignty).
S3NS is the Thales-Google joint venture documented in Section 2. The Commission, applying its own Framework in good faith and after industry consultation, certified a Thales-Google joint venture as adequate for the second-highest sovereignty level the Framework defines.
CISPE’s response was direct: the inclusion of S3NS is “a clear own goal” that “threatens to institutionalise sovereignty washing at the highest levels.”
The trade body of European cloud providers, watching the European Commission award sovereign status to a venture half-owned by Google, named the move while it was happening.
The procurement officer reading the Framework will not see CISPE’s objection.
The procurement officer will see the SEAL rating.
The CADA process. The Cloud and AI Development Act is being drafted in 2026, led by Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy.
The draft has been postponed twice. The European Commission plans the formal proposal for 27 May 2026.
CADA is intended to convert the SEAL Framework from a voluntary assessment into binding law. If CADA codifies the redefinition, if it ratifies the SEAL score as the test, if it accepts AWS European Sovereign Cloud and S3NS as sovereign, then the redefinition becomes law.
Once a sovereignty test is encoded in legislation, every procurement officer in DORA-regulated entities, NIS2 essential entities, and public administration will read CADA’s definition and apply it. The heretical thought that another definition might exist becomes literally unthinkable in the relevant procurement workflow.
The redefinition is the framework. The framework is the legislation. The legislation is the test.
The institutional layer is not the source of sovereignty washing.
The hyperscalers commissioned the redefinition; the institutions execute it. Forrester writes Wave reports because Wave reports are what its clients pay for.
The Big Four advise European governments and audit American hyperscalers because that is the structure of their professional services market.
The European Commission produced a Sovereignty Framework with eight weighted objectives because the consultation process was open to industry and industry includes the hyperscalers.
NIST sets standards under the authority of the United States government because that is what NIST is. None of these institutions is unusually corrupt.
All of them respond to the incentives they face. The redefinition succeeds at the institutional layer because the hyperscalers can shape the inputs to processes the institutions are designed to run.
The truth of the law
The legal test does not move when the marketing language moves.
The CLOUD Act says what it says. FISA Section 702 says what it says. The Court of Justice of the European Union has applied the test in Schrems II and arrived at its conclusion.
None of these has been amended in response to the redefinition. The hyperscalers cannot persuade the law to mean something different by persuading their analysts to write Wave reports. The law is not produced by Forrester.
In Schrems II, decided 16 July 2020, the Court of Justice invalidated the European Commission’s adequacy decision underpinning the EU-US Privacy Shield.
The reasoning was direct. United States surveillance under FISA Section 702 and Executive Order 12333 was found to be disproportionate; collection was bulk rather than particularised; oversight was inadequate; non-US persons had no judicial redress equivalent to US persons under the Fourth Amendment.
The Court formulated its test as “essentially equivalent” protection. To transfer personal data outside the European Union under standard contractual clauses or any other instrument, the third country must provide protection essentially equivalent to that guaranteed within the European Union under the General Data Protection Regulation and the Charter of Fundamental Rights.
The European Data Protection Board subsequently formalised the test as four European Essential Guarantees: processing must be based on clear, precise, and accessible rules; necessity and proportionality with regard to legitimate objectives must be demonstrated; an independent oversight mechanism must exist; and effective remedies must be available to the individual.
The Court’s application of these guarantees to United States surveillance produced a finding of inadequacy.
The hyperscaler response to Schrems II has been to argue that subsequent measures address the deficiencies.
Executive Order 14086, signed by President Biden on 7 October 2022, established a redress mechanism through the Data Protection Review Court.
The successor framework, the EU-US Data Privacy Framework, received a Commission adequacy decision in July 2023.
Both have been challenged. The EU General Court upheld the Data Privacy Framework on 3 September 2025 in Latombe v European Commission; that decision is now on appeal at the Court of Justice.
NOYB, the European Center for Digital Rights founded by Maximilian Schrems, is preparing a separate, broader challenge.
The Court of Justice has been consistently more sceptical of US surveillance arrangements than the General Court. Two prior frameworks have already been invalidated.
The third sits before the same body that invalidated the first two. The trajectory is consistent: each round of the case law has reaffirmed the test.
The hyperscalers cannot win at the legal layer because the legal layer is moving against them. The redefinition is their response to that fact.
The CISPE letter put the legal point plainly: “Cybersecurity certification alone does not ensure sovereignty, as it does not address exposure to extraterritorial legislation such as the U.S. Cloud Act.”
The operational test follows from Schrems II and the European Essential Guarantees.
If anyone else can be compelled to share your data, you are not sovereign.
The test is binary.
It produces a yes or no. The Cloud Sovereignty Framework’s eight objectives produce a score that allows compensation across objectives; the legal test allows none. A high score on data residency, encryption, or EU staffing leaves compellability untouched.
The legal test asks one question. The question has one answer.
Everything else is the institutional layer manufacturing the appearance that the question has many answers.
Apply the test to the products of Section 2.
Amazon Web Services, Inc., Microsoft Corporation, and Alphabet Inc. (parent of Google Cloud) are all American corporations subject to the CLOUD Act.
AWS European Sovereign Cloud’s German subsidiary remains within Amazon’s possession, custody, or control. Bleu and Delos sit on Microsoft’s infrastructure and remain within Microsoft’s possession, custody, or control. S3NS’s fifty per cent French shareholding does not relocate Google.
Each offering answers yes to the test question.
Each offering fails the test. The framework score has averaged the impossible with the irrelevant; the law has not.
The framework can be revised.
The law would have to be revised by the United States Congress, which has shown no intention of revising the CLOUD Act, FISA Section 702, or Executive Order 12333 in any direction that would produce European adequacy.
The structural position is permanent until the law changes, and the law will not change in the time frame of European procurement decisions.
The series prerequisite
Every paper that prescribes procurement-led sovereignty assumes “sovereign” can be applied to mean genuinely sovereign at the moment a procurement officer writes a specification.
Papers 2, 23, 24, 25, and 26 each prescribe a procurement instrument: seven-layer build-out, public procurement of European search (where the same redefinition risk applies to “sovereign search” the moment hyperscalers offer it), a European platform that activates Position 2 capability, anchor demand on the Airbus-Galileo-GSM precedent, and targeted procurement for European integrators and operators. The vision document on trustless sovereignty (emperorsnewcloud.eu) prescribes architectures where mathematical properties replace institutional trust.
Every prescription depends on the procurement officer being able to identify which providers count.
If the redefinition wins, the procurement officer cannot identify which providers count.
The procurement officer reads the Cloud Sovereignty Framework, which lists AWS European Sovereign Cloud at SEAL-3 and S3NS at SEAL-2 and was used in Cloud III.
CADA is expected to codify the Framework.
The procurement officer types “sovereign” into the procurement specification. AWS European Sovereign Cloud is the cheapest qualified bid.
The procurement is awarded. Dependency persists.
Anchor demand has gone to the hyperscalers and the €43 billion has remained American.
Capture the word and you capture the procurement. Capture the procurement and you capture the next decade.
The collapse is structural.
A procurement-led prescription that activates a redefined word activates the redefinition, not the prescription. The European bank reading DORA in 2028 looks for sovereign cloud services.
The Framework tells the bank that AWS European Sovereign Cloud, Microsoft Sovereign Cloud, and S3NS qualify.
The bank procures. The bank’s compliance is documented. The bank’s data remains compellable under the CLOUD Act.
The DORA compliance and the data sovereignty have come apart.
The regulation reads the artefact of compliance; the substance of sovereignty has been quietly excluded from the regulatory definition.
Every procurement signed under the redefinition compounds the dependency, every framework ratified extends the definitional capture, and every contract awarded to a hyperscaler under a SEAL rating becomes a precedent the next procurement cites.
The cost of accepting the redefinition is paid every year, in every contract, until the legal test is restored. The cost of refusing it is paid once, at the legislative layer, in the language of the law that follows.
The remedy is to restore the language so the existing prescriptions remain operational.
The prescription
Encode a binary sovereignty definition in European Union law. Apply the Schrems II essentially equivalent test, formalised as the European Essential Guarantees, as the operational test for sovereignty. Use the five-position framework (Paper 1) as the operational scaffold.
The framework has five positions.
Position 1 is national sovereignty: data and infrastructure controlled by the citizen’s own state.
Position 2 is European sovereignty: controlled by EU or EEA entities, no non-EU entity in the chain.
Position 3 is distributed: controlled by no single entity, jurisdiction, or consortium, where decentralisation is structural and protocol changes cannot be unilaterally compelled.
Position 4 is shared sovereignty with a foreign state: the dominant European reality today, where data sits on infrastructure operated by an entity subject to non-EU jurisdiction.
Position 5 is foreign-controlled, including captured systems that market themselves as Position 3.
Positions 1, 2, and 3 qualify as sovereign. Positions 4 and 5 do not.
The prescription is technology-agnostic. It does not specify a cryptographic architecture for Position 3 or a member-state arrangement for Position 1. It specifies the test the architecture must meet: can someone else be compelled? If yes, the architecture is not sovereign.
The legislative form is one clause.
Something close to: “Sovereign cloud services are those for which no entity in the operational supply chain can be compelled by a government other than that of an EU member state to disclose, modify, or restrict access to customer data; and for which the surveillance regime applicable to any extra-EU jurisdiction in the supply chain meets the European Essential Guarantees as established in Schrems II and formalised by the European Data Protection Board.”
The clause is binary, auditable in court.
Drafters of CADA can refine the language; the substance is the test.
Mandate Position 3 minimum for three categories of European entity.
DORA-regulated entities. The Digital Operational Resilience Act applies to financial entities and their information and communications technology third-party service providers. Financial entities operate critical infrastructure whose data is operationally consequential.
Compellability of that data by a foreign government is a structural risk to European financial stability. Position 3 minimum applies.
NIS2 essential entities. The second Network and Information Security Directive applies to approximately one hundred thousand European entities across energy, transport, banking, healthcare, water, public administration, digital infrastructure, and space.
These are the categories the European Union has already determined warrant the highest cybersecurity protection. The cybersecurity protection is undermined if the data is compellable by a foreign government.
Position 3 minimum applies.
Public procurement. Member-state government information technology procurement and European Union institutional procurement collectively account for hundreds of billions of euros annually. Public procurement spends public money to provide public services.
Sovereignty over the data those services produce is a public interest. Position 3 minimum applies.
The mandate creates anchor demand at the legal layer.
The anchor demand activates the procurement prescriptions in the rest of the series. Paper 25 documents the precedent: Airbus, Galileo, and GSM were activated through procurement instruments that mandated European supply for European demand.
The same instrument applied to cloud, AI infrastructure, and digital services builds the European market that currently does not exist at the necessary scale.
Five objections to the prescription deserve direct response.
The objection that the hyperscalers are improving sovereignty controls and that a binary test denies real progress.
The improvements are real. Customer-managed encryption keys, EU staffing, operational autonomy: each is better than the previous configuration.
None addresses the legal test.
The Carniaux testimony of 10 June 2025 is the threat actor’s own confession: under oath, in the French Senate, Microsoft France’s representative answered “No, I cannot guarantee” when asked whether European customer data would not be transmitted to United States authorities.
The improvements raise the cost of disclosure for the hyperscalers without changing whether disclosure can be compelled. The cost is irrelevant if the answer to the test question is yes.
The objection that Position 3 minimum is too restrictive and that European industry cannot deliver at the scale DORA, NIS2, and public procurement require.
The objection inverts cause and effect. European cloud providers hold fifteen per cent because European procurement has been buying American.
Gartner projects sovereign cloud spending from $6.7 billion in 2025 to over $23.1 billion in 2027. The prescription creates the anchor demand that builds the supply.
The same mechanism appears in Paper 25 (Airbus, Galileo, EURATOM, GSM at continental scale) and Paper 24 (open-source platform). The Galileo precedent ran twenty years from threat identification to operational signal; the cloud transition runs faster because the technology is mature.
Position 1 (national) and Position 3 (truly decentralised) do not require a European hyperscaler or a single corporate champion.
The objection that Schrems II is about personal data and the prescription overreaches by extending it to all cloud workloads.
The legal test in Schrems II is the floor, not the ceiling. The European Essential Guarantees are formulated as cross-cutting principles.
The categories the prescription covers are critical infrastructure: financial services, energy, transport, healthcare, water, public administration, digital infrastructure, space.
Critical infrastructure data is more strategically sensitive than individual personal data. The argument that Schrems II’s protections should not extend to critical infrastructure is the argument that operational data of European banks, hospitals, and energy grids deserves less protection than individual consumer messages. This inverts the public interest at stake.
The objection that a binary test cannot accommodate sectoral nuance.
Your data is secure or it is not. The CLOUD Act, FISA Section 702, and executive orders do not have low-risk exceptions.
Sectoral nuance does not override the legal compellability of data subject to American jurisdiction. The score-based approach is what produced the redefinition; a binary test forecloses the compensation.
The objection that the CADA process is well-intentioned and should not be undermined.
We need protection. CADA’s value depends entirely on what it codifies.
The Cloud III April 2026 outcome is the warning. The European Commission used its own Sovereignty Framework, in good faith, after industry consultation, and awarded sovereign status to a Thales-Google joint venture.
The Commission was well-intentioned. The output ratified sovereignty washing.
CADA can repeat this outcome at scale. The prescription is what CADA must encode to be worth passing.
The Cyber Resilience Act enters full application on 11 December 2027. The next Multiannual Financial Framework runs 2028 to 2034. The legal test should align with both.
Refuse the redefinition
Europeans want sovereignty. Hyperscalers are redefining the word in front of us.
The Cloud and AI Development Act, planned for proposal on 27 May 2026, is the legislative front.
The text the Commission proposes will be the basis on which procurement officers in DORA-regulated entities, NIS2 essential entities, and public administration apply the word “sovereign” for the next decade. Two paths follow.
If the text encodes the SEAL Framework’s score, the redefinition becomes operational at the law layer.
AWS European Sovereign Cloud, Microsoft Sovereign Cloud, S3NS, and the next product the redefinition produces all carry sovereign labels into 2030, and procurement defaults to sovereign-enough.
The €43 billion remains American. The European cloud market grows from €74 billion in 2025 toward €100 billion by the end of the decade and the same seventy per cent of it flows to American firms.
Every paper in this series that prescribes procurement collapses at the moment a procurement officer types “sovereign” into a specification.
If the text encodes the Schrems II essentially equivalent test, the redefinition is foreclosed.
DORA-regulated entities, NIS2 essential entities, and public procurement all migrate.
The European cloud market builds out behind the legal mandate exactly as Airbus, Galileo, and GSM built out behind their procurement mandates.
The €43 billion does not vanish; it redistributes. European Position 2 providers reach hyperscaler-relevant scale because the legal mandate creates the demand that builds the supply.
The 2030 European cloud is European because European law required it to be.
The defence is the legal test, encoded in law, applied in procurement, enforced in regulation.
The redefinition is rational and will continue. The hyperscalers will produce the next generation of “sovereign” products and the institutional layer the next generation of frameworks, the next CADA equivalent, the next analyst Wave.
Permanent vigilance is the framing because permanent capture is the threat.
If anyone else can be compelled to share your data, you are not sovereign.
This is the answer the Court of Justice gave in Case C-311/18 on 16 July 2020. The trajectory has been consistent since. Two prior data transfer frameworks have been invalidated; a third is on appeal at the Court of Justice; broader challenges are in preparation. The legal foundation is moving in one direction, and that direction is towards the test the redefinition is designed to evade.
This call is to the European policymakers drafting CADA, the Commission officials running procurement, the member states reviewing their own sovereignty frameworks.
It is also to the European industry that has begun naming sovereignty washing publicly, to the journalists investigating the institutional ratification, to the academics testing the SEAL framework against Schrems II, and to the European platform builders constructing the alternatives Position 2 and Position 3 require. Each role is needed.
The diagnosis is not contested by the law; the only question is whether European legislation, European procurement, and European regulation will follow the law or substitute the score.
Sovereignty washing is incentivised doublespeak. Capture the word and you capture the procurement. Capture the procurement and you capture the next decade.
Encode the test. Refuse the rest. The series operates only if the diagnosis is acted upon.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →