In January 2026, Amazon Web Services launched AWS European Sovereign Cloud GmbH in Brandenburg, Germany. €7.8 billion invested. New corporate entity. EU-resident managing directors. Billing in euros. Separate operational partition. Separate certificates.

AWS CEO Matt Garman said at launch that it "unlocks a huge amount of business." That's not a sovereignty statement. That's a sales strategy.

The tell is in what AWS doesn't say. They say "strong legal protections." They say "designed to meet sovereignty needs." Carefully lawyered language. Conspicuously absent from every press release, every FAQ, every analyst briefing: "The US government cannot legally compel access to your data."

They don't say it because they can't.

The CLOUD Act Doesn't Care About Your GmbH

The US CLOUD Act, passed in 2018, permits US authorities to compel US-headquartered companies to produce data they possess, control, or can access — regardless of where that data is physically stored. A subsidiary is not a firewall. Courts have established that parent companies can compel subsidiaries to produce data. A German GmbH whose sole shareholder is Amazon, Inc. is a phone call away from a federal warrant.

This is not a speculative legal theory. It is the exact mechanism that killed the previous two EU-US data transfer frameworks.

Safe Harbour died in 2015 because US surveillance law overrides voluntary corporate privacy commitments. Privacy Shield died in 2020 because promises from two administrations are not laws. The current EU-US Data Privacy Framework — the third attempt — is now structurally undermined by the Supreme Court's June 2026 ruling in Trump v. Slaughter, which eliminated the FTC's independence from the President. The DPF's adequacy decision cites FTC independence 259 times. noyb has asked the Commission to withdraw it.

Three agreements. Two dead. The third on life support. The pattern is not that the EU and US keep failing to negotiate a good deal. The pattern is that the US legal system cannot provide the protections EU law requires, because those protections are incompatible with how US surveillance and executive power actually work.

A German subsidiary with a German name and a German board does not change this. The CLOUD Act reaches through corporate structures because it reaches through control, not just presence. AWS European Sovereign Cloud GmbH controls data that Amazon, Inc. can be compelled to produce. The sovereignty is operational theatre. The dependency is legal fact.

What "Sovereignty Washing" Looks Like

Sovereignty washing is the practice of wrapping a hyperscaler product in the language and aesthetics of sovereignty — national branding, local staff, separate billing entities, data residency commitments — without addressing the structural dependency that makes the product non-sovereign.

The AWS Brandenburg deployment is the textbook case. It has every surface-level attribute of a sovereign cloud:

  • Local entity. AWS European Sovereign Cloud GmbH, registered in Germany.
  • Local staff. EU-based executives and engineers.
  • Local billing. Invoiced in euros, under EU contract law.
  • Data residency. Data stored in German data centers, on German soil.
  • Operational separation. Separate partition, separate certificates, separate access controls.

And it has the one attribute that makes none of the above matter:

  • US parent company. Amazon, Inc. owns the GmbH. The CLOUD Act applies.

The Gaia-X CEO has been blunt about this. The highest level of sovereignty can only be achieved by providers headquartered on European soil. A US company with European staff and European data centers is still subject to US legislation. This is not a technicality. It is the difference between a compliance checkbox and a genuine answer to who can access your data and under what authority.

Microsoft made a parallel move in late 2025, committing to in-country data processing for Copilot in Canada and expanding Azure Local. Same pattern: localization of the visible layer, no change to the corporate control layer. The sovereignty is in the branding, not in the architecture.

What's Actually Moving

While the hyperscalers build sovereignty theatre, the actual sovereign infrastructure movement is crossing from policy into procurement. The shift is concrete and measurable.

Gaia-X reached operational maturity. The federated European cloud standards initiative now counts more than 15 operational data spaces — a noticeable difference from the long list of projects that were previously "in preparation." Trust Framework 3.0, released in late 2025, enabled federated trust structures across borders and sectors. Cloud Temple became the first provider certified at Gaia-X's highest sovereignty label. The framework is no longer a whiteboard exercise.

Procurement is following policy. Airbus issued a tender worth more than €50 million to migrate mission-critical environments to a sovereign European cloud. BMW continues expanding the Catena-X data-sharing network. The German armed forces signed a seven-year contract to replace Microsoft 365 with an open-source alternative. These are not pilot programs or innovation labs. They are production infrastructure decisions made on sovereignty grounds.

The European Commission introduced a Cloud Sovereignty Framework. Late 2025 saw the first formal scoring system to measure how exposed a given cloud service is to foreign legal jurisdiction. The Commission has begun applying that framework to actual EU procurement contracts worth hundreds of millions of euros. The framework creates a mechanism to distinguish between sovereignty claims and sovereignty facts — which is precisely the distinction the hyperscalers don't want scored.

The Bitkom survey confirms the demand. A large majority of German companies want to end technical dependence on US cloud providers. Trust in US providers among surveyed companies has fallen to well under half. The gap between intention and action — companies that want sovereignty but haven't migrated yet — is where rushed, expensive decisions under regulatory pressure come from.

The Recovery Question

Most sovereignty discussions focus on where data lives: which provider, which data center, which jurisdiction. These are legitimate questions, but they address only the visible layer of a deeper dependency.

Sovereignty also requires control over what an organization can recover from when infrastructure fails. If your backups are stored in a format you can't audit, on infrastructure you can't inspect, using tools that require a vendor license key to restore — your sovereignty claim has a hole in it. A business can be fully compliant on paper while remaining entirely dependent on a foreign vendor's proprietary backup infrastructure that it cannot fully audit, migrate away from, or recover from independently.

Regulatory frameworks like the EU Data Act, NIS2, and DORA establish requirements around data residency, access controls, and operational resilience — but they leave backup architecture and recovery sovereignty largely to individual organizations. This is the layer that gets the least scrutiny and carries the most hidden dependency.

What This Means for Community Infrastructure

The audience for this site is people who build infrastructure for communities they serve — fire halls, town offices, small businesses, community organizers, tribal utilities. The sovereignty washing phenomenon is not an abstract Brussels debate for these audiences. It directly shapes the procurement decisions their councils and boards are making right now.

Here's the practical framework.

If your cloud provider is a US company, you do not have sovereignty. You have a contract with a company that is subject to the CLOUD Act. The data center location, the billing currency, the staff nationality, and the subsidiary structure do not change this. AWS European Sovereign Cloud is subject to US legal compulsion. Microsoft Azure in any region is subject to US legal compulsion. Google Cloud Platform is subject to US legal compulsion. This is not an opinion. It is the CLOUD Act.

If your software requires a vendor license key to run, you do not have sovereignty. You have a dependency. The vendor can change the terms, raise the price, discontinue the product, or withdraw the license. Self-hosting proprietary software on your own hardware in your own country does not eliminate this dependency. The jurisdiction is closer, but the control is still external.

If you cannot inspect the source code, you cannot verify what the software does with your data. Proprietary software requires trust. Open source software enables verification. When a system handles sensitive community data — member records, financial transactions, health information, communications — the ability to audit is not optional. It is the difference between trusting a vendor's assurance and confirming the behavior yourself.

If your backups are in a vendor-proprietary format on vendor-controlled infrastructure, your recovery is not sovereign. You can be compliant on residency and still be unable to restore without the vendor's tools, on the vendor's timeline, at the vendor's discretion. Sovereign recovery means backups in open formats, on infrastructure you control, restorable with tools you own.

The Architecture That Actually Works

The sovereignty that holds up under legal pressure — the kind that survives a CLOUD Act warrant, a DPF invalidation, a vendor acquisition, a license change — is structural, not contractual. It looks like this:

  • Hardware the community owns or controls. Not a hyperscaler region. Not a vendor's data center. Servers in a building the community has authority over.
  • Open-source software with no commercial runtime license dependency. Proxmox for virtualization. Nextcloud for collaboration. Matrix for communication. Keycloak for identity. OpenStack for cloud. Software that runs without a license key, without a vendor-operated management plane, without permission.
  • Backups in open formats on infrastructure the community controls. Proxmox Backup Server with deduplicated backups to local or community-owned storage. Restorable without a vendor account.
  • Federation with other communities on the same terms. Keycloak Identity Brokering for cross-community SSO. Matrix federation for inter-community communication. Gaia-X-style federated trust for procurement. Federation without centralization — communities connect without ceding control to a hub.
  • Code that can be inspected, modified, and forked. AGPLv3 for the platform. GPL for the kernel. WTFPL for the content. When the community needs to understand or change how the software works, they can. When the vendor disappears, the software keeps running.

This is not a hypothetical architecture. It is the pattern we deploy. The Hoopa Valley Tribe built a version of it — they own the data center, the fiber, and the ISP. Gaia-X is building the procurement framework to make it easier to buy. OpenStack shipped its 33rd release this year, with 40% of contributions from European engineers building the sovereignty exit. The German military is replacing Microsoft 365 with an open-source alternative under a seven-year contract.

The sovereignty washing exists because the demand is real. The hyperscalers wouldn't be building German subsidiaries and painting flags on data centers if European institutions weren't serious about leaving. But the subsidiaries are not the answer to the demand. They are a strategy to capture it without meeting it.

The Question to Ask

When a vendor says "sovereign cloud," ask one question: can the US government legally compel access to my data?

If the answer is yes — and for every US-headquartered cloud provider, the answer is yes — then the sovereignty is in the marketing, not in the architecture. A €7.8 billion GmbH is still a subsidiary. A subsidiary is still under the parent's control. And control is what the CLOUD Act reaches.

The communities that own their infrastructure won't need to ask. The ones that rent it from US providers will spend the next two years finding out.


Sources: KumoMTA — Europe's burgeoning sovereign IT movement explained, Business Matters — Europe's Digital Independence Drive Is Finally Moving Beyond the Whiteboard, Piet Jan de Bruin — Why AWS's European Sovereign Cloud Is "Sovereignty Washing", noyb — US Supreme Court just blew up EU-US Data Transfers, Gaia-X Association, Osler — Canada's 2026 privacy priorities