Digital sovereignty just grew teeth: what the 2026 EU cloud rules mean for where you run your workloads
By Alec on
For years, digital sovereignty was the sort of phrase that sounded weighty in a keynote and changed nothing on the Monday morning after. You'd nod along, close the slide deck, and go back to your AWS console.
That stopped being true this year.
Three things moved through Brussels in 2026, and together they turn a slogan into decisions you now have to make on purpose. The deadlines are close enough that putting it off is itself a choice, and not a clever one. Here's what changed, and what it means for European cloud sovereignty in practice.

The EU Data Act: lock-in stopped being legal
Start with the change that hits your budget. The EU Data Act made moving cloud provider a right your supplier can't take away. Switching became enforceable on 12 September 2025, and from 12 January 2027 they won't be allowed to charge you a penny to leave. Germany has already named the Bundesnetzagentur as its enforcer, with fines of up to 4% of global turnover.
If you're an engineer, sit with that January 2027 date, because it changes how you should weigh your architecture. The exit is being built for you, in law. So the real question isn't "can we leave?" any more. It's whether you've built anything worth leaving for, and whether your data comes out in a shape another provider can actually take in.
Portability used to be a line on a vendor's slide. Now it's a right you can point at, backed by a fine. It's also the whole reason Cyso's public cloud runs on OpenStack with zero vendor lock-in: open standards mean your next move stays easy, not just your first one.
Explore Cyso's public cloud (zero lock-in) →Sovereign cloud got a score
In June 2026, the European Commission did something regulators often get wrong. It took a fuzzy idea and turned it into a scorecard.
The Cloud Sovereignty Framework is a way to grade a cloud provider on how European it really is. Instead of taking the vendor's word for it, a buyer can score them against 48 defined criteria, sorted into eight areas: strategy, legal and jurisdictional questions, data and AI, day-to-day operations, the supply chain, the technology itself, security and compliance, and environmental impact. Add it up and you get one sovereignty score, and a level that tells you how protected you are. (We unpacked the wider EU Tech Sovereignty Package and what it means for cloud in Europe separately, if you want the policy detail.)
There are four levels, and they climb from "kept in Europe" to "controlled by Europe":
Level 1 just means your data is processed and stored on infrastructure inside the EU. This is the floor.
Level 2 adds that the provider has to show real independence from countries outside the EU, and be open about who supplies its software.
Level 3 goes further. The provider must be EU-owned and EU-controlled, and some staff have to meet citizenship requirements.
Level 4 is the top rung: full control over the software supply chain, with no room for a foreign government to interfere.
Most organisations won't need the top of the ladder. The Commission reckons only about 1% of Europe's public services actually require Level 4, which is the tier you'd expect for the genuinely sensitive work.
The point is to match the level to the job, so you're not paying for sovereignty you don't need, or settling for less than the work demands. Member states have a year from adoption to decide which level applies where.
The Commission put a real €180 million contract behind the framework, and split it across four providers on purpose, so no single vendor could lock in the EU institutions themselves. When the regulator won't concentrate its own risk, that tells you plenty about how it expects everyone else to buy.
Business developers should read that twice. "Sovereign" is becoming something you can measure and prove, not just a word on a website. Before long your prospects will ask what level you meet, the same way they ask about ISO 27001 today. It's why we keep our certifications and EU-only data centres out in the open on our Trust Centre.
The rulebook got lighter, and that's easy to misread
At the same time, Brussels eased off on paperwork. The Commission proposed the Digital Omnibus on 19 November 2025, and it worked its way through the institutions during 2026. It softens parts of the GDPR: it narrows what counts as personal data, makes it easier to use data to train AI on a legitimate-interest basis, and trims cookie consent (single-click opt-outs, choices remembered for at least six months). It also stretches the breach reporting window from 72 to 96 hours. On the AI side, it pushed the hardest obligations for high-risk systems back from August 2026 to 2 December 2027.
There's a trap in reading "simplification" as "Europe is backing off, so relax." That's the wrong lesson. Europe isn't loosening its grip on where data lives or who controls it. It's clearing admin off the desk so the strategic questions, the ones about sovereignty and control, get more air. Friction is being taken out of compliance and put into your choice of provider.
The thread that ties it together
Step back and the shape is hard to miss. One law strips out the cost of leaving. Another defines what "good" looks like once you do. A third clears the bureaucratic undergrowth so the sovereignty conversation can take centre stage.
Underneath all of it sits a legal fact that hasn't changed and won't. The US CLOUD Act lets American authorities compel US companies to hand over data wherever in the world it's stored, and that runs straight into Article 48 of the GDPR. You can host European data, in a European data centre, on a US hyperscaler, and still not have solved that conflict.
That's why this is more than talk. European leaders are already rethinking their cloud strategy, and the trade press and analysts report that most European CIOs now want to lean more on local providers.
Nobody serious thinks AWS, Azure and Google Cloud get toppled in two years. They still hold most of the European market, and pulling live workloads apart is slow, costly, unglamorous work. But sovereign cloud has moved out of the defence-and-government corner and into ordinary infrastructure planning.
If you're weighing the two biggest hyperscalers specifically, we've written the honest side-by-side:
Cyso vs AWS comparison → Cyso vs Azure comparison →So what do you actually do?
If you're in the C-suite, treat 2027 as a near-term planning horizon, not a distant one. The fee ban and the sovereignty scorecard land within months of each other, so the cost of moving drops at the same moment the case for moving gets easier to defend to a board.
If you're an engineer, here's the honest test. If your provider vanished from your options tomorrow, how many weeks until you were running somewhere else? If the answer is "no idea," that's now a business risk with a legal deadline attached, not just backlog you keep pushing down the list.
And if you sell or build in this market, the question that wins European deals has shifted. Price and speed still matter. But "under whose jurisdiction, and can you prove it?" is what more buyers will ask first.
The rules took a long time to grow teeth. They've got them now. The winners won't be the ones who panicked, and they won't be the ones who ignored it. They'll be the ones who read the deadline, looked at their own stack without flinching, and started moving while moving was still their call to make.
Talk to our experts about a sovereign cloud move →Frequently asked questions
What is the EU Data Act?
The EU Data Act is a regulation that governs who can access and reuse the data generated by connected products and cloud services. For most IT teams, the part that matters is cloud switching. Since 12 September 2025 you have a legal right to move provider without contractual or technical roadblocks, and from 12 January 2027 providers can't charge switching fees at all. It applies directly across every member state, and enforcement sits with national authorities who can issue real fines. You can read the official overview on the European Commission's Data Act page.
What is sovereign cloud?
Sovereign cloud means cloud infrastructure that keeps your data, and the control over it, inside European jurisdiction and beyond the reach of foreign law. It's more than just hosting in an EU data centre. True cloud sovereignty covers who owns and operates the provider, who can be compelled to hand over data, and where the underlying technology comes from. The EU's 2026 Cloud Sovereignty Framework grades this on four levels, from Level 1 (data stored in the EU) up to Level 4 (full control, no foreign interference).



