Photo by Brett Sayles on Pexels
The Cloud Dependency Problem No One Wants to Talk About
Europe has made no secret of its ambitions to become a leading force in artificial intelligence. The EU AI Act, Horizon Europe funding programs, and a wave of national AI strategies from Paris to Berlin signal a continent serious about competing with the United States and China on the global technology stage. But beneath the optimism lies a structural vulnerability that threatens to undermine every euro invested: Europe’s AI ecosystem is being built on top of cloud infrastructure it doesn’t own.
The numbers are difficult to ignore. Amazon Web Services, Microsoft Azure, and Google Cloud collectively control an estimated 65–70% of Europe’s cloud market. When European startups train large language models, when hospitals run AI-powered diagnostics, or when telecom operators deploy AI-driven network optimization tools, the overwhelming majority of that compute flows through servers owned and operated by American corporations — subject to U.S. law, U.S. export controls, and ultimately, U.S. strategic interests.
For a region that has staked much of its regulatory identity on data privacy, digital rights, and technological self-determination, this is more than an economic inconvenience. It is a geopolitical risk hiding in plain sight.
Why Sovereign Cloud Is the Missing Link in Europe’s AI Stack
The conversation around European AI competitiveness has rightly focused on access to advanced chips, with significant concern over export restrictions limiting access to NVIDIA’s H100 and A100 GPUs. But compute hardware is only one layer of the problem. Sovereign cloud infrastructure — data centers physically located within European borders, operated under European law, and governed by open, interoperable standards — is the connective tissue that makes AI development scalable, secure, and strategically independent.
Without it, European AI developers face a paradox: they may comply with GDPR and the EU AI Act at the application layer while simultaneously routing sensitive training data and model weights through infrastructure governed by the U.S. Cloud Act, which grants American authorities potential access to data stored by U.S.-headquartered companies regardless of physical server location.
This isn’t a theoretical concern. The invalidation of the EU-U.S. Privacy Shield in 2020 — and the ongoing legal fragility of its successor, the EU-U.S. Data Privacy Framework — demonstrates just how tenuous data sovereignty guarantees can be when infrastructure ownership remains foreign.
GAIA-X and the Open Standards Imperative
Europe’s answer to this challenge, at least in concept, has been GAIA-X — the federated cloud initiative launched in 2019 by France and Germany with ambitions to create a European data infrastructure ecosystem built on open standards and interoperability. In practice, GAIA-X has struggled to gain commercial traction, partly due to governance complexity and partly because the very hyperscalers it was designed to counterbalance became founding members of the initiative.
The lesson here is not that GAIA-X has failed, but that open standards alone are insufficient without corresponding investment in domestic cloud capacity and political will to mandate their adoption. For European AI to be genuinely sovereign, the infrastructure layer must prioritize vendor-neutral APIs, portable data formats, and federated architectures that prevent lock-in — regardless of who builds the underlying hardware.
Telecom operators, interestingly, are emerging as unexpected protagonists in this story. Deutsche Telekom, Orange, Telefónica, and others have the physical infrastructure, the spectrum assets, the enterprise relationships, and increasingly the edge computing capabilities to serve as credible sovereign cloud alternatives — particularly for latency-sensitive AI workloads that align naturally with their distributed network architecture.
The Telecom Angle: Operators as Sovereign Cloud Champions
Network operators are uniquely positioned to bridge the gap between raw connectivity and cloud-native AI services. With 5G standalone deployments accelerating across Europe and Multi-access Edge Computing (MEC) becoming commercially viable, telcos can offer something hyperscalers structurally cannot: compute embedded within sovereign national network infrastructure, with data residency guarantees that are legally and physically enforceable.
The European Commission’s Connected Continent legislative package and the forthcoming European Chips Act II both create policy openings for telcos to position themselves as preferred infrastructure partners for public sector AI deployments — healthcare, defense, smart cities, and critical national infrastructure — where data sovereignty is non-negotiable.
Several operators are already moving in this direction. Deutsche Telekom’s Open Telekom Cloud, built on OpenStack, and Orange’s Flexible Engine platform represent tangible steps toward telco-anchored sovereign cloud. The challenge is scale: these platforms remain a fraction of the capacity offered by AWS or Azure, and without aggressive public procurement policies or regulatory incentives, enterprise customers will continue defaulting to hyperscaler convenience.
Regulatory Levers and the Path Forward
Policymakers have tools available that remain underutilized. The European Data Act, which came into force in 2024, includes provisions designed to make cloud switching easier and reduce vendor lock-in. Combined with the Cyber Resilience Act and targeted public procurement requirements that favor European-operated infrastructure for sensitive workloads, regulators could meaningfully shift market dynamics without resorting to protectionist overreach.
Investment is the other critical variable. The EU’s proposed AI Gigafactories — large-scale AI compute clusters to be deployed across member states — represent a significant commitment, but only if paired with the sovereign cloud platforms needed to make that compute accessible, interoperable, and commercially viable for European developers.
Industry Outlook: A Narrow but Real Window
Europe has approximately a two-to-three year window to establish credible sovereign cloud infrastructure before AI model development and deployment patterns calcify around existing hyperscaler dependencies. After that point, switching costs — technical, contractual, and organizational — will make meaningful diversification exponentially harder.
The continent’s AI ambitions are real, its regulatory frameworks are among the world’s most sophisticated, and its talent pool remains world-class. But ambition without infrastructure sovereignty is a strategy built on sand. For European AI to succeed on its own terms, the cloud layer cannot remain an afterthought. It must become the foundation — and Europe must build it itself.
