decrypted · 2 july 2026 · digital sovereignty
The quiet shift to sovereign hosting
For a decade the default answer was "put it in the cloud", meaning one of a handful of American hyperscalers. That default is now being questioned, quietly but seriously, in boardrooms and government departments across Europe.
What changed
Nothing single. Several currents arrived at once, and together they moved the conversation from cost to control.
- Jurisdiction. Data can sit physically in Europe and still be reachable by a foreign government through extraterritorial law such as the United States CLOUD Act. Where your data lives and who can compel access to it turn out to be different questions, and only the second one matters in a crisis.
- Trust after incidents. A run of high-profile intrusions, and unusually pointed official scrutiny of at least one major vendor's security culture, made "too big to fail" sound less like reassurance and more like concentration risk.
- Licensing shocks. Sharp changes to pricing and licensing across cloud and virtualisation, several of them following large acquisitions, reminded everyone how much leverage a single supplier quietly holds once you depend on it.
- Regulation. Sovereignty requirements are creeping into procurement rules and certification schemes, so for a growing set of buyers this is no longer optional.
Why Microsoft keeps coming up
Because many organisations are Microsoft-shaped from end to end: identity, email, documents, the desktop, and now the assistant sitting on top of all of it. That concentration is convenient right up until it is a single point of dependency, cost and risk. The reaction is rarely a dramatic exit. It is a rebalancing: keep what genuinely works, but pull identity, sensitive data and regulated workloads back under direct control, so that no one supplier owns the whole estate.
What "sovereign" has to mean
This is where the word gets abused. A "sovereign cloud" that is still operated by, or legally reachable through, a foreign parent company is sovereignty theatre. Real sovereignty is about control, and it is testable:
- You own, or fully control, the hardware, the data and the encryption keys.
- You can operate the system without a foreign entity's cooperation or permission.
- You can leave. Open standards and open source are how you keep that exit open.
If a platform fails those three tests, the label is marketing.
It is not all or nothing
The sensible pattern is not to rip out the cloud and self-host everything out of principle. It is to decide, workload by workload, what truly must stay under your control, such as identity, secrets, regulated data and any AI trained or run on sensitive material, and what can sit anywhere at all. Hybrid, chosen deliberately rather than by inertia.
The organisations doing this well are not making a political statement. They are treating dependency as a risk to be managed, the same as any other, and deciding for themselves which of their systems they are no longer comfortable renting.
Sources
- Eurojust: The CLOUD Act explained
- CISA: Cyber Safety Review Board report on the 2023 Microsoft Exchange Online intrusion
- CIO: VMware licensing and pricing hikes after Broadcom
- Hogan Lovells: EUCS sovereignty requirements continue to drive debate
Sovereign architecture and infrastructure is part of what d4 works on. If it is on your mind, get in touch.
More like this
- The SD-WAN orchestrator that needed no login, and the one before it 29 july 2026
- A mislabelled maintenance job, and the outage it exported to Britain 27 july 2026
- The Zimbra bug that needed no click, and the year it went unpatched 24 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.