Europe Built a €180M Sovereign Cloud. It Runs on Google. — June 3 it's law
The EU's Tech Sovereignty Package arrives June 3. Probably. It was due in March, then April, then late May, and has now been rescheduled more times than a dentist appointment I keep meaning to…
The EU's Tech Sovereignty Package arrives June 3. Probably. It was due in March, then April, then late May, and has now been rescheduled more times than a dentist appointment I keep meaning to cancel. When the white smoke finally goes up over Brussels, we will have a Cloud and AI Development Act, a Chips Act with a sequel number like it's a Marvel film, and an open-source strategy. Three years of work. €150-200 billion earmarked. A continent's worth of political capital.
And they fixed the wrong layer.
Let me walk you through how I know that, because the EU was kind enough to demonstrate it themselves, on camera, six weeks before the legislation even existed.
The €180 million teaching moment
In April, the Commission ran its flagship sovereign cloud tender — €180M, the showcase, proof that Europe can do this without the Americans. Four winners. Triumphant press release. Henna Virkkunen's name on it.
One of the four winning "sovereign" clouds runs on Google.
I'll give you a moment.
It's a venture called S3NS, in which Thales holds the controlling stake and Google Cloud provides — and I cannot stress enough that I am not making this up — the underlying infrastructure. The body that wrote the sovereignty rules procured, as its example of sovereignty, a cloud built on the precise thing sovereignty exists to get away from. This is the regulatory equivalent of launching a Buy Local campaign from inside a Costco.
CISPE, the trade body representing 38 actual European cloud providers, described this as "clearly an own goal" that "threatens to institutionalize sovereignty washing at the highest levels." Which, for a trade association, is roughly the prose temperature of a flamethrower.
The Commission's defence was the part that really sang. Non-European technology, it explained, can be sovereign provided it is "operated within a strict and appropriate framework." The technology isn't sovereign. The operation is sovereign. The hardware is American but it's being supervised very sternly by Europeans, and apparently that's the whole trick. Sovereignty as a vibe. Sovereignty as management style.
Schrödinger's subpoena
Here is my favourite sentence in the entire affair. When Forrester was asked whether the Thales majority stake actually shields S3NS from the US CLOUD Act, the analyst conceded it offers "much better legal insulation" — and then added the immortal words: "yet to be tested in court."
So the keystone example of European digital sovereignty is a legal hypothesis that has never survived contact with a courtroom. It's sovereign in the way my fantasy football team is undefeated in the pre-season. It's sovereign until someone files a motion. It's Schrödinger's cloud: simultaneously sovereign and not sovereign until a US judge opens the box.
You cannot put "sovereign (pending litigation)" in a procurement contract and call it a win. Well. You can, evidently. They did.
The scoring is magnificent
To their credit, the Europeans have not skimped on rigour. The framework grades sovereignty across eight weighted objectives. There are five SEAL levels, zero through four. CADA layers four cloud sovereignty tiers on top. Supply chain is weighted at twenty percent. There is a formula. There is almost certainly a colour-coded spreadsheet, and somewhere a very tired civil servant who knows in their heart it doesn't matter.
Because all of it — every objective, every tier, every weighting — measures who is allowed to stand next to the data. None of it changes the fact that the data is sitting there, intact, in one place, waiting to be asked for. They have built an exquisite scoring system for the guards and left the vault door propped open with a fire extinguisher.
CISPE actually named the two questions the framework can't answer: what happens when a foreign government wants to switch your infrastructure off, and what happens when it wants your data. Both questions assume the same thing — that somewhere there's one complete, reconstructable copy and one switch attached to it. The entire EU debate is just an argument about who gets to hold the switch. Nobody's asking why there's a switch at all.
The Dutch, bless them, were the one adult in the room. They blocked the Kyndryl-Solvinity deal — Solvinity runs the platform behind DigiD, the national login — because a US owner could be compelled under the CLOUD Act to hand over Dutch identity data. They didn't consult a sovereignty score. They looked at where a subpoena could land and locked the door. First block their screening agency has ever issued. No formula required.
The part where I'm insufferable about architecture
Here's the bit the eight objectives forgot. If you shred data into erasure-coded shards, encrypt them, and scatter them so no single site and no single operator ever holds enough to rebuild anything, both of CISPE's questions evaporate. The subpoena arrives at a custodian holding mathematical confetti. The kill switch turns off one node and the data shrugs and carries on from the others. There's no intact copy to seize, no chokepoint to grab, no ownership percentage to argue about in front of a judge who hasn't been born yet.
Compelled disclosure stops being a risk you manage with strict and appropriate frameworks and becomes a thing you have made impossible. Not unlikely. Not well-insulated. Not pending litigation. Impossible, in the way that asking me to reconstruct a document from one-fifth of its encrypted fragments is impossible.
Sovereignty by geography is a sticker. Sovereignty by ownership is a contract you hope holds up. Sovereignty by architecture is a property of physics, and physics does not have a legal department.
Europe is about to spend two hundred billion euros getting the sticker and the contract exactly right.
So fix the layer they skipped
This is the part where, by LinkedIn law, I'm supposed to be coy about the fact that I run a company that does exactly this. I won't be.
SkyeConnex is Data Sovereignty as a Service. Not a sovereign-themed region. Not a strict-and-appropriate framework with a colour-coded scorecard. The architecture I described above is the product: CloudRAID erasure-codes your data into encrypted shards and distributes them so that no single location, no single operator, and no single jurisdiction ever holds enough to reconstruct a single byte. AES-256-GCM on the payload, Reed-Solomon for the erasure coding, ML-KEM-1024 standing in front of the day quantum stops being a slide in someone's keynote.
What that buys you is the thing the eight objectives can't:
A subpoena lands somewhere holding fragments that decrypt to nothing. There is no intact copy to compel, because there is no intact copy. Anywhere.
A foreign government's kill switch turns off a node. The data reconstitutes from the shards it can't reach. Nobody phones you to apologise.
No JV ownership percentage to litigate, because your sovereignty was never resting on who the majority shareholder is. It was resting on math.
The EU spent three years asking who is allowed to stand next to your data. SkyeConnex asks a better question and then answers it in code: why is there a single copy of your data for anyone to stand next to?
The CLOUD Act doesn't get a vote. The court date never gets scheduled. The white smoke stays in the chimney where it belongs.
If your sovereignty story has a pending lawsuit attached to it, we should talk before June 3 makes it expensive.
Sources
Innocenzo Genna, Habemus Tech Sovereignty Package (quasi) — radiobruxelleslibera.com (29 May 2026)
EU Tech Sovereignty Push Adds Chip Powers, US Cloud Curbs — implicator.ai (June 3 date; Kyndryl-Solvinity / DigiD block)
Europe picks 4 sovereign cloud providers, but one has Google — The Register (CISPE "own goal" / "sovereignty washing"; S3NS structure)
EU awards its €180 million sovereign cloud contract — The Next Web (sovereign "operation" vs sovereign "technology")
EU Tech Sovereignty Package Debuts… — TechTimes (Forrester: "much better legal insulation… yet to be tested in court"; market-share figures)
EU SEAL Framework 2026 — innobu (SEAL-0 to SEAL-4, eight SOV objectives, supply chain weighted 20%)
Don't let hyperscalers hijack digital sovereignty, EC told — The Register (CISPE open letter; sovereignty defined by control, not EU presence)
EU weighs restricting use of U.S. cloud platforms… — CNBC (CLOUD Act jurisdiction over US providers)
Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.
Published May 30, 2026 · More from the SkyeConnex blog
More from the blog
Your Grocery Bill Now Comes With a Browser History
SkyeConnex - SkyeBucket (S4)
Every sovereign cloud pitch eventually asks you to do the same thing: rip out your stack and adopt theirs.
Read → Commentary · 2 min read89% Say Sovereignty Matters. 10% Paid For It.
BARC's Data Sovereignty 2026 is out. The headline: 89% of organizations rate data sovereignty as important. 51% say…
Read → Architecture · 2 min readCanada Needs a Sovereign Dependency Test, Because “Trust Us” Is Not an Architecture
Canada has become very good at buying platforms from other countries and then convincing ourselves we are in control…
Read →