Defence Officials Resist Brussels' Push for Domestic-Only Cloud
European defence officials and arms-industry contractors are publicly resisting the European Commission's Cloud and AI Development Act, a law presented in June 2026 that would grade public-sector services by sensitivity. The Act's stated goal is to cut the European Union's structural dependence on American hyperscalers, but officials across several member states argue the timeline moves faster than domestic alternatives can mature.
Only the highest sensitivity tier would require "solely domestic" technology, and the Commission's own estimate puts that tier at roughly one percent of public-sector services. Defence officials and contractors warn that a fast retreat from Amazon Web Services, Microsoft Azure and Google Cloud, which together hold around 70 percent of the EU cloud market, risks leaving armed forces with inferior systems, wider cyber gaps and harder coordination with NATO allies. The F-35 fighter jet is the example officials keep returning to: its digital infrastructure runs embedded on American cloud services rather than bought as a swappable subscription, exactly the kind of dependency the top tier is meant to end.
Two senior EU defence officials and several European defence companies estimate the US lead in cloud and AI defence platforms at eight to ten years, a gap they say cannot be closed on the Act's own schedule. Not every contractor is waiting to find out: Airbus announced in July 2026 that it would migrate some critical applications from AWS to the French provider Scaleway, ahead of any legal requirement to do so.
Four Stages, One Top Tier: What 'Solely Domestic' Actually Requires
The Cloud and AI Development Act sets out four escalating stages of sovereignty, and only the last one demands a fully domestic stack. Stage one requires physical data location inside the EU, a bar most existing hyperscaler contracts already clear. Stage two adds independence from third-country law and transparent supply chains, closing off arrangements where a foreign government could compel data access. Stage three requires EU ownership and control of the provider itself, not just its data centres. Stage four, reserved for the roughly one percent of services judged most sensitive, demands complete software transparency and no third-country influence at all.
| Stage | Requirement | Scope |
|---|---|---|
| Stage 1 | Physical data location inside the EU | Broad, most public-sector workloads |
| Stage 2 | Independence from third-country law and transparent supply chains | Sensitive but not top-tier services |
| Stage 3 | EU ownership and control of the provider | High-sensitivity services |
| Stage 4 | Complete software transparency, no third-country influence ("solely domestic") | About 1 percent of public services |
Finland's Foreign Minister Elina Valtonen framed the underlying worry in blunt terms, saying Helsinki is preparing for the risk of a foreign-supplier "kill switch" being used against it. NATO Deputy Assistant Secretary-General James Appathurai countered from the interoperability side, stressing that allied militaries need to exchange battlefield data seamlessly and at speed, a requirement that gets harder every time a member state's cloud stack diverges from its neighbours'.
Beyond the Backlash: A Two-Speed Compliance Problem in the Making
The headline fight is over how fast the European Union should cut its cloud dependency, but the more useful question for a business owner is what happens once stage four actually applies to only one percent of services. Sovereignty as a policy goal and sovereignty as an operational risk are being treated as the same problem in the debate; they are not. The policy goal is reducing structural leverage a foreign government could hold over European public services in a crisis. The operational risk is that forcing the switch on a fixed timetable, before domestic alternatives have closed an eight-to-ten-year capability gap, could itself create the cyber and interoperability failures the law is meant to prevent.
That split produces a two-speed compliance problem that has had almost no attention next to the sovereignty headlines. Ninety-nine percent of covered services stay on largely unchanged hyperscaler arrangements under stages one and two, which mostly formalise practices AWS, Azure and Google Cloud already support. The remaining one percent needs a wholly separate, much smaller supply chain of domestic providers, and it is not obvious that supply chain exists yet at the scale or maturity the Act assumes. Contractors who serve that top tier, from the Scaleways of the market to defence-specific cloud vendors that barely exist today, are being asked to scale up against a deadline set by policy rather than by their own capacity. Contractors who serve everyone else face a much lighter compliance lift dressed up in the same "sovereignty" language, which makes it easy for both groups, and their public-sector customers, to misjudge which rules actually apply to them.
What an EU Defence-Adjacent Business Owner Should Watch
A business owner selling into EU public-sector or defence-adjacent contracts should first find out which of the four stages its own contracts will fall under, since stage one and two obligations are close to current practice while stage four is a different business entirely. Ask whether current cloud or software vendors have a credible path to stage three or four certification, or whether that work has not started, because a vendor caught flat-footed on a contract inside the top tier becomes the buyer's problem too.
Watch how individual member states transpose the Act, since the eastern and Nordic states most focused on NATO interoperability are also the ones most likely to seek exemptions or slower timelines for defence-linked services, which could open a second, national-level two-speed pattern on top of the EU-wide one. Finally, track whether a genuine domestic-only cloud and AI supply chain forms at all in the next two to three years; if it does not, the one-percent tier risks becoming a compliance category with no vendors able to fill it, which is its own kind of operational risk.
Read next: EU Ties AI Data Centers to Grid Planning | The Commission Hired US AI to Vet Its Own Staff



