Two Meanings of the Same Word
AWS and the European Commission are using the phrase 'digital sovereignty' to mean two different things at the same time. On 18 August 2026, AWS announced it will open a permanent Builder Loft developer space in Berlin from October 2026, with programming built around educational sessions on digital sovereignty, hackathons, and security-readiness workshops. The post, written by principal developer advocate Channy Yun on the AWS News Blog, describes sovereignty as a subject to teach, alongside AI upskilling in Hyderabad and community programming in Sao Paulo.
Four months earlier, on 17 April 2026, Brussels was using the same term with a very different purpose: as a graded procurement requirement. The Commission's Cloud Sovereignty Framework measures sovereignty across eight objectives, covering strategic, legal, operational, and environmental considerations alongside supply chain transparency, technological openness, security, and EU law compliance. That framework does not teach sovereignty; it audits it.
The gap between the two uses matters because only one of them carries consequences for a procurement bid. A developer who attends a Berlin hackathon on sovereignty leaves with knowledge. A company bidding for an EU public contract needs a certified SEAL rating, and knowledge of the term is not the same as holding one.
How Brussels Grades Sovereignty
The European Commission's Sovereignty Effectiveness Assurance Levels, or SEAL, run from SEAL-0 to SEAL-4, and the scale exists specifically because 'sovereign cloud' had become a marketing claim without a shared definition. SEAL-0 marks a complete lack of sovereignty; SEAL-4 marks a full EU supply chain, from chips to software, with no dependency outside the bloc.
For its own EUR 180 million procurement framework, the Commission set the bar at SEAL-2 as the minimum for eligibility. Most of the winning bids cleared that bar with room to spare, reaching SEAL-3 rather than settling for the floor, which suggests the scale is already separating genuinely deep sovereignty claims from shallow ones.
None of this scoring exists inside AWS's Berlin programming. A hackathon or a security-readiness workshop can explain what SEAL-2 means without ever positioning AWS to hold one, because the rating is assigned to a bidder's actual infrastructure and ownership, not to a company's willingness to discuss the concept.
The Four Winners, and the Absence
Four consortia won the Commission's framework contracts, and every one of them is EU-based. Post Telecom, based in Luxembourg and France, won together with OVHcloud and CleverCloud. STACKIT, the German cloud arm of the Schwarz Group that owns Lidl and Kaufland, won on its own. Scaleway, part of France's Iliad Group, won on its own. Proximus, spanning Belgium, France, and Luxembourg, won together with S3NS, Clarence, and Mistral.
AWS is not on that list, and neither is Microsoft Azure or Google Cloud. No US hyperscaler holds any share of the EUR 180 million awarded, even as American providers continue to handle roughly 80 percent of the EU's annual professional cloud spending, a concentration EU policymakers have called a strategic vulnerability.
| Provider | Headquarters | Partners | Outcome |
|---|---|---|---|
| Post Telecom | Luxembourg/France | OVHcloud, CleverCloud | Won |
| STACKIT | Germany | Schwarz Group (solo) | Won |
| Scaleway | France | Iliad Group (solo) | Won |
| Proximus | Belgium/France/Luxembourg | S3NS, Clarence, Mistral | Won |
| AWS | United States | - | Not awarded |
What a Classroom Cannot Certify
Attending a session on digital sovereignty at AWS's Berlin Builder Loft does not move a company toward SEAL certification, because the two systems are not connected. The Builder Loft is community programming aimed at developers; the SEAL framework is a procurement instrument aimed at infrastructure and ownership structure, and an organization needing to prove sovereignty for a public-sector or regulated contract has to go through the latter, not the former.
There is a further layer worth naming briefly: AWS, as a US company, remains subject to the US CLOUD Act's extraterritorial reach regardless of where its EU data centers physically sit or what data-residency claims it makes. That is a separate, well-documented legal fact, not a new finding from this framework, but it is the backdrop against which the SEAL system was built in the first place.
For a developer or IT lead in Berlin, the practical takeaway is a simple distinction to hold onto: use AWS's programming for what it is, a place to learn about cloud architecture and community, and use the Commission's SEAL rating for what it is, the actual bar an organization has to clear when a contract requires demonstrable sovereignty. Confusing the two does not change which one a procurement officer will ask for.
Read next: The Commission Hired US AI to Vet Its Own Staff | The EU Repair Law Took Effect as 27 Different Laws



