Sovereign cloud vs. a hyperscaler EU region

They look similar on a map. They behave very differently in a crisis.

On a normal operating day, an “EU region” of a global hyperscaler and a genuinely sovereign cloud can look almost identical: low latency, in-country data, a European address on the invoice. The difference only becomes visible under stress — a jurisdiction dispute, a sanctions regime, a supply-chain compulsion, a vendor decision. That is precisely when defense and critical public infrastructure cannot afford surprises.

Where they diverge

Jurisdiction

An EU region operated by a US-headquartered provider remains subject to US law, including the CLOUD Act, which can compel data production regardless of storage location. A sovereign cloud you self-host is subject only to your own jurisdiction.

Control plane

The EU region runs on the hyperscaler’s global control plane, operated by the hyperscaler’s staff and tooling. A sovereign cloud’s control plane runs on your infrastructure, operated by your (cleared) people. Whoever operates the control plane holds effective root.

Disconnection

A sovereign platform can run air-gapped and keep functioning with no external dependency. A hyperscaler region depends on the provider’s global fabric — identity, billing, management planes — that is not designed to be severed.

Continuity of capability

A sovereign, open-source stack cannot be repriced, relicensed, geofenced, or withdrawn out from under you. A managed region can change terms, and you inherit the change.

Side by side

DimensionHyperscaler “EU region”Sovereign cloud
Data locationIn-countryIn-country
Jurisdiction over the vendorForeign (e.g. CLOUD Act)Yours
Control-plane operatorThe hyperscalerYou
Runs fully disconnectedNoYes
Source auditableNoYes
Can be repriced / withdrawnYesNo

The crisis test

The honest way to evaluate the two is to ask what happens on the worst day, not the average one:

  • A diplomatic or sanctions dispute puts the vendor’s jurisdiction at odds with yours. Who can compel access?
  • Connectivity to the provider’s global fabric is severed. Does the system keep running?
  • The vendor is acquired and changes commercial terms. Can you continue on your own?

For a marketing site or a retail app, a hyperscaler EU region may be exactly the right, pragmatic choice. For a command system, a classified workload, or critical national infrastructure, the crisis answers are the whole point — and they favour a sovereign, self-hosted architecture.

Not a binary — a spectrum named honestly

This is not an argument that every workload must be fully sovereign. It is an argument for naming the dependency. A sovereign posture is a deliberate choice with real trade-offs (you operate more yourself). The failure mode is buying a foreign-controlled region under a “sovereign” label and discovering the dependency in the middle of the crisis it was supposed to survive.

See how the platform delivers the sovereign side of that choice in Secure Operations, or read the underlying definition.

← All sovereignty articles Talk to an expert