On June 10, 2025, under oath before the French Senate, Anton Carniaux, Microsoft France's Director of Public and Legal Affairs, was asked whether he could guarantee that French citizens' data hosted on Microsoft's EU cloud would never be handed to US authorities without French authorisation. His answer, verbatim: "No, I cannot guarantee it." (Heise coverage; The Register).
That sentence is the entire sovereign-cloud thesis. Every serious CTO planning a GPU workload for the EU market in 2026 has to grapple with what it means for the stack they pick.
TL;DR
- EU AI Act enforcement powers activated August 2, 2026, with fines up to EUR 35m or 7% of global turnover (Commission press IP/26/1714).
- BYOK on a US-hyperscaler EU region does not neutralize the CLOUD Act. Once the key touches a US-controlled KMS, the provider can be compelled (CMS Feb 2026 white paper).
- Sovereign EU GPU compute is CHEAPER than hyperscaler, not more expensive. OVHcloud, Scaleway, and Nebius run H100 at roughly 1/3 the AWS on-demand rate. The cost premium is at the certification layer (SecNumCloud, BSI C5), not the infrastructure.
- Only a few clouds meet true legal sovereignty: OVHcloud Bare Metal Pod (SecNumCloud March 2025), S3NS PREMI3NS (SecNumCloud late 2025). Microsoft EUDB and AWS European Sovereign Cloud reduce operational exposure but do not eliminate CLOUD Act reach.
The three tiers of "sovereign"
Marketing language conflates these deliberately. A CTO evaluating vendors has to distinguish them explicitly:
- Data residency . data physically located in EU regions. Baseline offered by every hyperscaler EU region. Does not satisfy GDPR Chapter V by itself.
- Operational sovereignty . admin and support access restricted to EU-resident personnel. Reduces third-country access risk during ordinary operations. Does not survive a lawful order from that personnel's home jurisdiction.
- Legal sovereignty . immune from non-EU jurisdiction, especially the US CLOUD Act (18 U.S.C. § 2713) and FISA §702. This is the bar the French SecNumCloud scheme requires and the bar the removed EUCS "High+" tier would have codified.
The EDPB Recommendations 01/2020 on supplementary measures make this concrete. Use Case 2 requires encryption keys held solely by the data exporter in the EEA. Use Case 6 finds that no effective supplementary measure exists when the importer needs cleartext for processing. Since a GPU inference server has to see cleartext prompts, this is the load-bearing legal finding for AI workloads specifically.
The 2026 regulatory stack a CTO has to reason about
EU AI Act, Regulation (EU) 2024/1689. Prohibited practices since Feb 2, 2025. GPAI obligations since Aug 2, 2025. General enforcement and Article 50 transparency requirements activated August 2, 2026 (AI Act Service Desk timeline). Annex III high-risk system rules apply Dec 2, 2027. Article 26 mandates deployer obligations including automatic-log retention "of at least six months." Chapter V (Articles 51-55) classifies a GPAI model as "with systemic risk" above the 10²⁵ FLOP training-compute threshold.
GDPR Chapter V plus Schrems II. Article 44 governs transfers; Article 46 permits SCCs. The Schrems II judgment (C-311/18) held SCCs valid but requiring case-by-case supplementary measures where third-country law does not provide "essentially equivalent" protection. The 2023 EU-US Data Privacy Framework restored adequacy for certified US importers, but the framework is under active legal challenge and prudent buyers are architecting for Schrems III.
EU Data Act, Regulation 2023/2854, Chapter VI. Applies since September 12, 2025. Mandatory 30-day cloud-switching window; full elimination of switching charges by January 12, 2027 (EUR-Lex 2023/2854). We covered this in depth in our EU Data Act post.
Saudi PDPL, Royal Decree M/19. Article 29 permits cross-border transfer only when it does not prejudice national security, uses minimum data, and the destination provides adequate protection or an appropriate safeguard applies. SDAIA's Regulation on Personal Data Transfer requires a Transfer Risk Assessment for non-adequate destinations. Sector overlays from SAMA (financial), CST (telecom), and MoH (health) apply on top.
UK. European Commission renewed the UK adequacy decisions on December 19, 2025, valid until December 27, 2031, accommodating the new UK Data (Use and Access) Act 2025.
NIS2, Directive (EU) 2022/2555. Cloud and data-centre services are Annex I "essential entities." Article 21(2) mandates ten risk-management measures including cryptography and MFA. Management can be personally liable.
US CLOUD Act, 18 U.S.C. § 2713. The pivot point. A US-jurisdiction provider is compellable to disclose data "regardless of whether such communication, record or other information is located within or outside of the United States." Every debate about "sovereign hyperscaler EU regions" turns on this statute.
What EUCS, Gaia-X, and SecNumCloud actually mean in 2026
EUCS (EU Cloud Certification Scheme) was ENISA's opportunity to codify legal-sovereignty as a certification tier. The controversial "High+" tier requiring EU headquartering and CLOUD Act immunity was removed in the March 2024 draft (ENISA EUCS page). As of August 2026, EUCS is not adopted. France, Germany, Italy, and Spain pushed for sovereignty requirements; Ireland, Sweden, the Netherlands, and the US industry lobby pushed against. The result: sovereignty remains a national-implementation question, and buyers have to look to national schemes.
Gaia-X Trust Framework, Compliance Document 24.06. Defines Labels 1, 2, and 3. Label 3 is reserved for European-only providers "where immunity to non-European laws is possible" (gaia-x.eu). This is the label a serious sovereign RFP asks for by name.
ANSSI SecNumCloud 3.2 (France). The strictest legal-sovereignty bar in Europe. Requires EU-only shareholding and CLOUD Act immunity. Qualified providers as of August 2026:
- OVHcloud Bare Metal Pod . qualified March 2025 (OVH press)
- S3NS PREMI3NS . qualified late 2025, the first Google-technology-based offering to clear SecNumCloud (S3NS press)
- Outscale, Cloud Temple, Oodrive, Worldline, Orange Business
BSI C5:2020 (Germany). 121 criteria across 17 subject areas. Not itself a sovereignty scheme but the German baseline before sovereignty discussions begin (bsi.bund.de).
What hyperscaler sovereign offerings actually cover
Named products, current shipping status, and what the fine print excludes:
Microsoft EU Data Boundary. Phase 3 completed February 26, 2025. Storage and processing of customer data + professional-services + system-generated logs stays in the EU. Does not cover Defender, Sentinel, Front Door, Security Copilot, or default support-operations access. Microsoft remains CLOUD Act compellable (EUDB excluded services; Microsoft blog).
AWS European Sovereign Cloud. General availability January 14, 2026 in Brandenburg, Germany. EUR 7.8 billion investment. German legal entities, EU-resident directors, EU-citizen advisory board. Sovereign Local Zones planned for Belgium, Netherlands, Portugal (AWS blog). Reduces operational exposure meaningfully but the ultimate parent remains US.
Google Sovereign Cloud. S3NS (Thales JV) achieved SecNumCloud in France late 2025. Germany JV in Preview, GA end of 2026 targeting BSI C5 and the new C3A framework (Thales press).
Oracle EU Sovereign Cloud. Live since July 31, 2023 with Frankfurt and Madrid regions 1,500 km apart for DR. By 2026 has 1,500+ EU-resident staff (Oracle blog).
BYOK does not save you
The most common architectural mistake we see is BYOK on a US-hyperscaler EU region, on the assumption that customer-held keys neutralize the CLOUD Act. They do not. Once a key touches a US-controlled KMS, it is within "possession, custody, or control" per 18 U.S.C. § 2713. Provider infrastructure performs the crypto operations, so the provider can be compelled to disclose either the key or the plaintext.
Consensus across law-firm analysis: CMS Feb 2026 white paper, WilmerHale on EDPB Recommendations. Only true Hold Your Own Key (HYOK) with an external key store the provider never sees clears the EDPB "unintelligibility" bar in Recommendations 01/2020 Use Case 6.
Confidential compute (Intel SGX, AMD SEV-SNP, NVIDIA H100 Confidential Compute) closes the runtime-memory attack surface. It does not change legal jurisdiction. Azure NCC H100 v5 is GA in East US2 and West Europe only (Azure Confidential Computing blog). No EU-native sovereign cloud has published an H100 CC SKU as of August 2026.
The sovereign RAG stack
The most common enterprise AI pattern is retrieval-augmented generation. A naive RAG pipeline crosses the sovereignty boundary at every arrow:
- documents → OpenAI
text-embedding-3-large(US API endpoint) - embeddings → Pinecone (default US region)
- query → GPT-4 API (US endpoint by default)
Every arrow is a Chapter V transfer. Every step where the importer holds cleartext falls under EDPB Use Case 6. Sovereign equivalent:
- Embeddings: BGE-M3, E5-multilingual, or Mistral Embed self-hosted. Or Mistral La Plateforme regional endpoints (French HQ, no default CLOUD Act exposure).
- Vector store: Qdrant self-hosted, or Qdrant Cloud EU (operated by Qdrant Solutions GmbH, Berlin-domiciled). Weaviate Shared Cloud in AWS Frankfurt is a residency solution but not a jurisdiction solution.
- Inference: Mistral Large or self-hosted Llama 3.3 70B on OVHcloud, Scaleway, or Nebius EU regions running vLLM or KServe (see our post on vLLM vs TGI vs KServe on Kubernetes).
Fine-tuning sovereignty. LoRA is preferable to full fine-tuning for sovereignty because training data never crosses to a third-party API. Only the small adapter (typically 10-200 MB) leaves the boundary if distributed downstream.
The Ireland problem. AWS eu-west-1 in Dublin satisfies GDPR territoriality but the parent AWS Inc. remains CLOUD Act compellable. The Irish DPC has issued EUR 4.04 billion cumulative GDPR fines, most against those same US tenants (DLA Piper GDPR Survey January 2026). Ireland is a data-residency answer, not a sovereignty answer.
The vendor matrix, with real 2026 prices
EU-native GPU cloud (jurisdiction-safe):
| Vendor | HQ | H100 | H200 | Regions | Sovereignty |
|---|---|---|---|---|---|
| OVHcloud | France | Yes | Yes | Gravelines, Strasbourg, Warsaw, London | SecNumCloud (Bare Metal Pod, Mar 2025) |
| Scaleway | France (Iliad) | Yes (~EUR 2.73/GPU/hr) | No (offers B300-SXM) | Paris, Amsterdam, Warsaw | EU jurisdiction; DC5 Paris positioned sovereign |
| Nebius | Netherlands | Yes (H100 SXM $3.85/hr on-demand, $2.15 preemptible) | Yes ($4.50 / $2.45) | Finland (310 MW Lappeenranta live Mar 2026), France (120 MW Béthune end-2026), UK, Iceland | EU jurisdiction |
| IONOS | Germany | Not itemized | Yes (dedicated) | Multiple DE | German jurisdiction |
| Open Telekom Cloud | Germany | Yes (p5s flavor since Dec 2024) | Not confirmed | EU-DE | Deutsche Telekom parent; C5 lineage |
| STACKIT | Germany (Schwarz Group) | Not explicitly named | No | DE only | Sovereign positioning; hosts Llama 3.1 with no-training/no-storage guarantee |
| Exoscale | Switzerland | Not confirmed | No | CH + EU | Swiss adequacy |
US-parented (residency yes, jurisdiction no):
- CoreWeave EU . H100 + H200 (Barcelona: 10,224 H200 GPUs live May 2025). US parent, CLOUD Act exposure remains.
UK sovereign:
- OVHcloud UK (London)
- Civo . H100 PCIe from $1.99/hr, Kubernetes-native, UK sovereignty guarantee
- Nscale . UK-based, GBP 2B UK commitment, GB200/H200/H100
Saudi Arabia + PDPL:
- Oracle Cloud Jeddah and Riyadh . bare-metal H100.8 and A100-v2.8 shapes live
- Google Cloud Dammam (me-central2) . live since November 2023, gated to CNTXT-purchased KSA-based customers under CST Class C license
- Azure Saudi Arabia Central . construction complete on three AZ sites, Q4 2026 GA
- HUMAIN (PIF-backed) + Nvidia partnership expanded November 2025 to 600,000 GPUs over 3 years including GB300
Object storage: Scaleway Object Storage (PAR/AMS/WAW from EUR 0.012/GB-month One Zone IA), Cloudflare R2 with EU jurisdiction bucket keeping data + replicas in-region, Wasabi EU (Amsterdam, Frankfurt, London), MinIO self-hosted.
PostgreSQL and vector DB: Aiven (Frankfurt, London, Amsterdam), CloudNativePG self-hosted on Kubernetes, Neon EU Frankfurt, Qdrant Cloud EU.
Cost reality: sovereign is CHEAPER at the compute layer
The narrative that sovereign equals expensive is wrong for GPU compute:
| SKU | US hyperscaler EU region | Sovereign EU |
|---|---|---|
| H100 SXM per GPU-hour | AWS p5.48xlarge eu-west-2 at ~$8.94/GPU/hr on-demand (cloudprice.net) | OVHcloud ~EUR 2.80/GPU/hr; Scaleway from EUR 2.73/GPU/hr; Nebius H100 SXM $3.85/GPU/hr |
Sovereign EU H100 pricing is roughly 1/3 to 1/2 the AWS on-demand rate in the same region. The premium flips at the certification layer: SecNumCloud-qualified capacity carries an estimated 30-100% markup over standard OVH (Scalingo SecNumCloud guide); BSI C5:2020 attestation projects run 3-6 months (Type 1) or 6-12 months (Type 2) (Securance C5 guide).
Enforcement is real
- Italian Garante v. OpenAI, December 20, 2024 . EUR 15 million fine plus mandatory 6-month public information campaign for training-data lawful-basis and transparency failures (Garante press)
- Italian Garante v. DeepSeek, January 30, 2025 . definitive limitation order blocking Italian data processing after DeepSeek denied EU law applied
- CNIL 2025 annual report . 323 investigations, 83 sanctions, EUR 486.8m in fines (CNIL 2025)
- DLA Piper GDPR Survey January 2026 . EUR 1.2 billion in fines in 2025, EUR 7.1 billion cumulative, 443 breach notifications per day
What we help with
Eprecisio deploys production sovereign-cloud GPU workloads for clients across EU, UK, and MENA. See our on-prem GPU Kubernetes reference architecture, our on-prem Kubeflow deployment for a UK research lab (2 years, 100% uptime), and our LoRaWAN IoT platform on Kubernetes for healthcare. For the buyer-side framing on picking a DevOps consultancy for regulated industries, see our compliance buyer guide.
If you are architecting a sovereign AI cloud for an EU-facing workload and want a second opinion on your vendor shortlist, or want a written architecture review before you sign a multi-year commitment, book a free 30-minute call.
Honest caveats
Two items I flag in the research rather than skate over: no publicly-visible SDAIA sanction decisions have surfaced post-14 September 2024 grace period. No public 2024-2026 CLOUD Act §2713 order against EU-hosted data of a US provider is visible (such orders are typically sealed). Both areas will update as primary sources land.
