Industry News

Jan. 16, 2026

From sovereign cloud to interoperable cloud: Europe's compromise in the face of American hyperscalers

From sovereign cloud to interoperable cloud: Europe's compromise in the face of American hyperscalers
In the absence of a true sovereign alternative, European companies are adopting hybrid strategies. The goal: to protect sensitive data while retaining the technological power of U.S. cloud leaders.

The facts are clear. Despite all the talk about the need for a sovereign European cloud, the sector remains overwhelmingly dominated by American giants. According to estimates by Synergy Research, Amazon Web Services, Microsoft Azure, and Google Cloud alone account for nearly 70% of the European market. European providers, on the other hand, are struggling to gain a foothold and hold no more than 15% of the market share.

While the illusion of a fully sovereign cloud has quickly faded, multi-cloud strategies are now emerging as a pragmatic compromise. They make it possible to meet the—often regulatory—requirements for protecting sensitive data in certain applications, while continuing to benefit from the performance and software ecosystems of U.S. hyperscalers for other uses.

This trend toward hybridization is expected to be further reinforced by new European legislative initiatives, starting with the Data Act. This regulatory framework, which took effect in September, aims in particular to remove the major barriers erected by U.S. cloud giants that hinder migration to another provider. It specifically targets data transfer fees—which are often prohibitively high—and can discourage companies from switching providers.

Interoperability Requirements

The Data Act also introduces interoperability requirements among different cloud platforms. However, these requirements have not yet been established. They will be the subject of a study conducted by the European Commission with the aim of harmonizing—or even strengthening—existing standards. No specific implementation date has been announced at this time.

In the meantime, some national regulators have taken the initiative. This is particularly true of Arcep in France. Last summer, the agency launched a public consultation under the SREN Act, which aims to secure and regulate the digital space. It seeks to require cloud providers to publish detailed information on the level of portability of their services, so that “potential customers can make informed choices.” 

Arcep also intends to ensure the availability and stability of API documentation—these application programming interfaces are essential for managing applications in multi-cloud environments.

“Trusted Cloud”

By relying on interoperable architectures, European companies can therefore balance two imperatives: the need to ensure the security of sensitive data—which is protected from U.S. extraterritorial laws—and the need for performance, thanks to the computing power and advanced software of the industry’s giants.

One factor, however, could shake things up: the rise of “trusted clouds.” Launched in 2021 by the French government, this certification applies to hybrid offerings that bring together a national provider and a U.S. provider, with the goal of offering “the best of both worlds”: data sovereignty and access to cutting-edge technological innovations.

Two platforms have already established themselves in this segment: S3NS, the result of a partnership between Thales and Google, and Bleu, born of a collaboration between Microsoft, Orange, and Capgemini. In mid-December, S3NS reached a key milestone by obtaining SecNumCloud certification from the National Cybersecurity Agency (ANSSI), an essential credential that opens the door to government agencies and companies handling sensitive data.

View All Industry News
Loading