On a normal operating day, an “EU region” of a global hyperscaler and a genuinely sovereign cloud can look almost identical: low latency, in-country data, a European address on the invoice. The difference only becomes visible under stress — a jurisdiction dispute, a sanctions regime, a supply-chain compulsion, a vendor decision. That is precisely when defense and critical public infrastructure cannot afford surprises.
Where they diverge
Jurisdiction
An EU region operated by a US-headquartered provider remains subject to US law, including the CLOUD Act, which can compel data production regardless of storage location. A sovereign cloud you self-host is subject only to your own jurisdiction.
Control plane
The EU region runs on the hyperscaler’s global control plane, operated by the hyperscaler’s staff and tooling. A sovereign cloud’s control plane runs on your infrastructure, operated by your (cleared) people. Whoever operates the control plane holds effective root.
Disconnection
A sovereign platform can run air-gapped and keep functioning with no external dependency. A hyperscaler region depends on the provider’s global fabric — identity, billing, management planes — that is not designed to be severed.
Continuity of capability
A sovereign, open-source stack cannot be repriced, relicensed, geofenced, or withdrawn out from under you. A managed region can change terms, and you inherit the change.
Side by side
| Dimension | Hyperscaler “EU region” | Sovereign cloud |
|---|---|---|
| Data location | In-country | In-country |
| Jurisdiction over the vendor | Foreign (e.g. CLOUD Act) | Yours |
| Control-plane operator | The hyperscaler | You |
| Runs fully disconnected | No | Yes |
| Source auditable | No | Yes |
| Can be repriced / withdrawn | Yes | No |
The crisis test
The honest way to evaluate the two is to ask what happens on the worst day, not the average one:
- A diplomatic or sanctions dispute puts the vendor’s jurisdiction at odds with yours. Who can compel access?
- Connectivity to the provider’s global fabric is severed. Does the system keep running?
- The vendor is acquired and changes commercial terms. Can you continue on your own?
For a marketing site or a retail app, a hyperscaler EU region may be exactly the right, pragmatic choice. For a command system, a classified workload, or critical national infrastructure, the crisis answers are the whole point — and they favour a sovereign, self-hosted architecture.
Not a binary — a spectrum named honestly
This is not an argument that every workload must be fully sovereign. It is an argument for naming the dependency. A sovereign posture is a deliberate choice with real trade-offs (you operate more yourself). The failure mode is buying a foreign-controlled region under a “sovereign” label and discovering the dependency in the middle of the crisis it was supposed to survive.
See how the platform delivers the sovereign side of that choice in Secure Operations, or read the underlying definition.
