The quote arrives, and the debate changes. As long as the discussion was about “regaining control of data,” everyone agreed. Once line items for migration, application rewrites and parallel operations appear, sovereignty becomes a budget trade-off. For European businesses, the question is no longer just where to host their information, but how much to pay to preserve their freedom to act. Looking ahead to September 2026, established trends point to a market where that freedom is likely to be negotiated application by application, far from any wholesale replacement of American clouds.
A European flag is not enough
The first misunderstanding concerns terminology. A data centre located in France does not, on its own, guarantee legal or operational independence. Businesses need to examine who owns the provider, who administers the infrastructure, which entities can access the data and which laws apply to them. Location matters, but it does not settle the question.
The US CLOUD Act crystallises this concern: under certain conditions, American authorities can ask a provider subject to their jurisdiction to disclose data under its control, even when stored abroad. This means neither automatic access nor the disappearance of procedural safeguards. But for a company handling trade secrets, this exposure can weigh on its risk assessment.
In France, ANSSI’s SecNumCloud qualification provides a demanding benchmark, combining security with conditions designed, among other things, to protect against certain forms of extraterritorial interference. It applies to specific offerings within a defined scope, not indiscriminately to all of a provider’s activities. Above all, it does not relieve customers of the need to secure their own applications: qualified hosting does not fix poor access management.
Regulation adds pressure without imposing a single model
The GDPR does not prohibit the use of an American cloud in principle. Among other things, it requires safeguards for processing and, where applicable, international transfers of personal data. Confusing compliance, location and sovereignty therefore leads to costly decisions that are sometimes poorly justified. Obligations vary according to the data, sector, contracts and risks involved.
In finance, the DORA regulation, applicable since January 2025, strengthens requirements for digital resilience and oversight of IT providers. It places dependencies, contracts and exit strategies at the heart of governance. It does not prescribe a wholesale shift to European providers. Its message is more operational: an outsourced critical function must remain manageable.
Another major piece of legislation, the Data Act, has applied since September 2025. Among other things, it regulates switching between providers of data processing services and provides for the removal of switching charges from January 2027. This timetable should make switching easier. It does not, however, eliminate migration work or technical incompatibilities: leaving without a penalty does not mean leaving without a bill.
The real dependency lies hidden in applications
Moving standardised virtual machines can be relatively straightforward. Replacing a proprietary database, an analytics pipeline or functions executed on demand is far less so. This integration is precisely what the major cloud providers sell: services that can be deployed quickly, connected to one another and supported by monitoring and security tools.
Consider a European manufacturer. Its document archives could move to a local hosting provider with few changes. Its predictive maintenance application, built around several specific managed services, might require a new architecture. The cost is then no longer about storage: it involves months of development, testing and teams diverted from other projects.
Containers, Kubernetes and open formats reduce certain dependencies without making every environment interchangeable. Identities, networks, security logs and backup mechanisms remain sources of lock-in. Multicloud, meanwhile, can help spread risk, but it can also multiply the skills required. Two poorly managed providers are not necessarily better than one properly governed provider.
Who will accept the extra cost?
The first candidates are organisations for which a loss of control would have disproportionate consequences: defence, government bodies handling sensitive information, critical infrastructure and strategic research. In these cases, paying more can be a form of insurance. The offering must still meet actual needs and deliver the expected levels of availability.
Next come businesses whose customers demand specific safeguards. A software vendor working with financial institutions or public bodies can turn its hosting choice into a commercial advantage. Sovereignty then becomes a means of accessing certain markets. That benefit must, however, be verified in calls for tenders, not assumed by marketing teams.
For an SME selling online, the trade-off will often be different. Speed to market, available skills and the quality of tools will carry considerable weight. It could reasonably retain its current cloud while strengthening its backups, contractual provisions and data export capabilities. Meaningful independence does not always require an immediate migration.
Calculate the full cost, not just the subscription
Comparing two monthly prices is not enough. A robust project must account for several items:
- Transformation: auditing dependencies, adapting code, transferring data and validating performance.
- Transition: running environments in parallel, training and any additional external support.
- Operations: support, on-call coverage and tasks previously handled by managed services.
- Risk avoided: disruption, contractual lock-in, legal exposure or price increases that are difficult to circumvent.
Nor is a sovereignty premium inevitable. For simple, predictable uses, a European provider can be competitive. Conversely, an apparently inexpensive offering can become costly if the business has to rebuild its tools. A sound comparison spans several years, with explicit assumptions about growth and staffing needs.
Europe must sell more than protection
European providers will not secure lasting success on the regulatory argument alone. They must offer robust interfaces, usable documentation, responsive support and services suited to development teams. Offerings that combine American technology with European governance, meanwhile, seek to reconcile extensive functionality with local control. Their credibility depends on concrete safeguards and qualifications actually obtained, not announcements.
The rise of artificial intelligence could intensify this tension: maintaining control of sensitive data matters, but so does access to computing capacity and the most powerful tools. One plausible response would be selective sovereignty, focused on strategic assets, with monitored connections to other environments.
What next? Ahead of their next budget decisions, businesses would do well to map their dependencies before choosing sides. Identifying critical data, testing an export and costing an exit will deliver more than an abstract commitment to independence. The most credible scenario is not a single European cloud replacing all the others, but deliberate segmentation. Those willing to pay will be those who can explain what freedom they are buying — and demonstrate that it works when they need it.


