techwiki
LinkedIn·Tuesday, 11 August 2026·15d ago

Storing your data in the EU doesn't mean it's sovereign. We see this mix-up a lot: teams assume that because their cloud region is set to…

ML6
24,333 followers
Storing your data in the EU doesn't mean it's sovereign. We see this mix-up a lot: teams assume that because their cloud region is set to "EU-only," they're covered on sovereignty. Residency and sovereignty are not the same thing. Residency is about where your data physically sits. Sovereignty is about who can legally be forced to hand it over, no matter where it sits. The US CLOUD Act, passed back in 2018, can still compel a US-based provider to produce data stored abroad. That distinction is exactly what Europe's new cloud rules are trying to sort out. The upcoming Cloud and AI Development Act sets four assurance levels, from self-assessed basics up to full EU-only control. And here's the part that is most surprising: it's not designed to push the big hyperscalers out. The European Commission expects around 70% of public contracts to land at the lowest level and another 20% at the second, both of which hyperscalers can reach with the right setup. Google's partnership with Proximus is a good example: Google's infrastructure stayed in place, but all encryption, operations, and legal accountability moved to the European partner. So before anyone assumes they need to migrate away from their current provider, it's worth checking which level your workloads actually need. Most won't require a full rebuild. Read more in Sean Osawa McElhenny's blog 👉 link in comments. #EUSovereignty #CADA #Cybersecurity
39💬 3
View on LinkedIn

Cross-referenced

Related on the wire