Why Cloud-First Has Meant Sovereignty Last – And How To Fix It

Concentration means convenience. It also brings lock‑in, geopolitical exposure and spiraling costs.

Editor’s note: Amid tense relations between the Trump administration and the EU, several reports have surfaced that European nations are increasingly looking at moving away from their overdependence on U.S. technology. John Leonard, research editor at MES Computing’s sister site Computing, delves into how Europe is seeking more tech sovereignty and less dependency on American technology.

Whoever thought it would be a good idea to rely on a handful of companies from a single country to maintain the UK’s digital infrastructure?

Well, the government for one. Guidance from the department of Department for Science, Innovation and Technology (DSIT), published a year ago, suggests that the risk of concentration is worth it for the extra goodies on offer. “Organizations should consider the best place to store and process data as non-UK services can be more cost effective, more sustainable or have additional features available,” it says.

Indeed, “cloud-first” has been government policy since 2013. At one time cloud-first embraced domestic players such as UKCloud - which had had contracts with the NHS, the Ministry of Defence, local and central government and private businesses before it was forced into administration in 2022 - as well as a broad ecosystem of local MSPs. More recently, however, by accident or design, it has come to mean AWS and Microsoft, Google and to a lesser extent Oracle and IBM; all U.S. companies, each, not uncoincidentally, with significant lobbying clout.

Long-term deals with U.S. tech giants have been a big part of the post-Brexit “Global Britain” narrative with the UK seeking to position itself as an AI and tech center of excellence, which has seen Microsoft and Google announcing billion-dollar investments in new datacenters and AI hubs in the UK.

But progress on a multi-billion-pound "tech prosperity deal", announced with some fanfare by Donald Trump and Keir Starmer last September, has ground to a halt, with the U.S. accusing the UK of a lack of movement on trade barriers.

Coercive and aggressive actions by our supposed ally have led more people to question - somewhat belatedly - whether being so tightly bound to the interests of one country, however “special” the relationship, is actually wise. And it’s not just local providers and rights campaigners who have been vocal on this topic. Calls for “digital sovereignty” have been growing steadily louder during Trump’s second term, and from some surprising sources.

Matt Harris is senior VP and Managing Director EMEA at HPE – a major U.S. tech company – is deeply critical of the UK’s strategy, or lack thereof. “If we look at say mobile or cloud, where did the UK play? Well, we made a choice [to get] strategically dependent on some large U.S. companies.”

Cloud-first has meant that “we put all of our data, all of our infrastructure, with some US corporations,” he went on. And have we benefited, have we lowered our costs? “No. It's the U.S. hyperscalers who made a huge amount of money out of that and are now as powerful as sovereign governments.”

Though its multi-year, multi-billion contracts with Big Tech, the UK has painted itself into a corner, says Nicky Stewart, senior advisor at the Open Cloud Coalition.

“Government is massively locked in,” she commented in a recent documentary series The UK AI Revolution.

Part of this lock-in is due to a lack of accountability for procurement decisions. “Within government and within the public sector mistakes get made. Mistakes get made all the time, and people's feet very rarely get held to the fire.”

This situation has allowed two players in particular, Amazon and Microsoft, to dominate the UK cloud space. Mark Butcher, a digital sustainability advocate, calls it negligence.

“We basically wrote a strategy which said we're going to give all of our money to two big American hyperscalers. Neither of those hyperscalers contribute to UK society. They pay as little tax as possible and they don't contribute back whatsoever, to any meaningful effect. And we're now repeating exactly the same exercise with AI adoption.”

Green Party MP Siân Berry has tabled an early day motion calling on the government to devise a UK digital sovereignty strategy. She told Computing: “Successive UK governments have created huge risks by sleeping on the issue of digital sovereignty while boosting the influence of the biggest US- and China-based tech companies.”

Recent examples of this boosting include a £400 million MoD contract with Google and a £1.5 billion defence AI partnership with Palantir.

A Lack Of Leadership

The UK is not alone in its over-reliance on non-domestic tech to support critical infrastructure. A similar bind exists across most of Europe, Canada, the Nordic countries and India. Antitrust investigations are launched, but they are delayed, challenged, pushed into the long grass and quietly dropped. Inaction is the easier path, the status quo the easier choice.

According to the European Parliament, AWS, Azure and Google Cloud control around 70% of the European market, while Synergy Research puts European cloud providers’ share at just 15 percent.

Scott Robertson, principal enterprise architect, foundation technology at the Co-op, is frustrated by the political inertia. "I'm not seeing any great leadership from the politicians - not just in this country but across Europe,” he commented.

“There is no joined up thinking between people in our own government, let alone across EU government collaboration.”

Reducing reliance on a single source of tech will require joined-up thinking and accountability at government level as a bare minimum. But even given that lets not kid ourselves it will be easy. The relatively straightforward multi-million-pound process to remove Huawei hardware from sensitive UK telecoms networks, which began in 2020, is not due for completion until 2027. (Europe is now embarking on a similar venture.)

There’s also the question of how far digital sovereignty can realistically go. After all, cloud services, even local ones - run on servers - and servers are almost all made in the U.S. or China.

Moreover, we must not throw the baby out with the bathwater. The problem is concentration of power, not the quality of the technology. It’s fine to use the hyperscalers for everyday duties, but not exclusively, and certainly not for critical infrastructure without a great deal of prior due diligence.

The hyperscalers offer global reach, cutting-edge functionality, resilience, consistent operating models, familiarity and - to a degree - standardization which may be difficult to replicate with local alternatives. This has made them attractive to businesses and governments alike as they pursue digital transformation and modernization programs.

If every country or bloc were to establish its own cloud infrastructure, that could make cross-border operations complex and expensive for organizations, slow innovation, and also open up new security holes, says Gary Barlet, public sector CTO at cybersecurity vendor Illumio. “I worry that if we start to fragment too much we may actually inherently reduce security,” he told Computing.

“If [nations] can define good standards that everybody can work towards that makes it easier. But as far as developing their own capabilities goes, they need to be very cognizant strategically about which capabilities they should have in house versus which they can afford to source from another friendly nation.”

What Does The Way Forward Look Like?

A focus on open standards and open source is essential if we are to increase independence on single sources while avoiding Balkanization. “We need policies that plan for and switch to open standards, user control of data, and strict regulation of dominant platforms,” said the Green Party’s Siân Berry.

Regulations do exist but they are not always rigorously applied. Set against that, excessive restrictions can stifle innovation. There’s a balance to be struck but the goal should be to establish a stable framework and a level playing field.

HPE’s Matt Harris welcomes the government’s efforts to get ahead on AI regulation. “At least we have a plan. We've got to see that through, and I would like to see almost a national unity around this to put us on the map. I don't remember what the cloud plan was for the UK economy at the time, or the mobile plan. We didn't have one.”

As part of a plan for greater autonomy, the government could invest more in R&D in key technology sectors such as AI, quantum computing, cleantech and cybersecurity, providing grants, tax incentives and low-interest loans to encourage the growth of domestic startups, many of which currently relocate to the US to scale .

It could redouble efforts to form alliances and share technologies with other countries, particularly those with similar values and technological goals, to create a more balanced landscape while ensuring that UK tech companies retain access to global markets.

Government procurement could prioritize domestic tech solutions for public projects, setting an example for the private sector.

Public awareness campaigns could explain the benefits of local tech solutions, encouraging consumers to support UK companies while educating them about data privacy and the risks of heavy reliance on foreign providers.

It is not only government and the public sector that need to reconsider their approach, says Mark Butcher.

“Large enterprises ... need to be willing to take that bag of cash they're currently giving to Microsoft or Amazon and put it over here instead. If I put it over here, I'm going to be giving the money to a UK-based company with UK-based people supporting the UK community.”

Distributing The Risk

Removing eggs from a single basket and distributing them more widely needn’t be part of some grand patriotic gesture. In almost every part of life, distributing risk is common sense. Why should tech be different?

Edwin Moraal is CISO at Veiligheidsregio Noord en Oost Gelderland (VNOG), a Dutch government organization responsible for managing fire and safety services in North and East Gelderland, the Netherlands. Five years ago, a cyberattack took out some of VNOG’s Microsoft Azure services, severely disrupting operations. “Restoring was a difficult and slow process,” Moraal remarked.

As a result, VNOG put in some contingency measures, including maintaining portable encrypted replicas of all important data with local control of all keys. Now, even if they were to be locked out of Microsoft 365 - a fate reportedly suffered by a prosecutor for the International Criminal Court (ICC) prompting fears of a kill switch - “we have some processes for that in place. We also have some things on prem, downloaded. It's about people and processes around it. If technology fails, we can depend on the process and take an alternative path.”

As Mark Butcher points out above, organizations have a choice. There are local alternatives to most of what the international hyperscalers provide, which in many cases are cheaper, better suited, or at least perfectly adequate for most needs. Admittedly, though, they are not always at innovation’s cutting edge, and services are often not interoperable, which is a particular problem when multiple partners are sharing a system.

“You have to think about that portability,” said Edwin Weijdema, field CTO EMEA at backup service provider Veeam. “From a service perspective, it's much harder [than data] because of the lack of second options.”

But there’s certainly an appetite for strategic independence. In recent Computing research, one-third of respondents said they had moved or were moving workloads off U.S. or Chinese cloud services. And according to a customer survey by Veeam, 46 percent of global customers rate digital sovereignty as extremely important, with 30 percent seeing it as moderately important. That's 76 percent in total.

If serious, those organizations will need to decide what data and services they simply could not do without and prioritize shifting or replicating them elsewhere.

The Alternatives

Despite initial appearances, and while the task remains daunting, there’s quite a lot happening on the sovereignty front in Europe.

Several European organizations are making a bid to break free of U.S. cloud providers, including the state of Schleswig-Holstein in Germany, which is replacing Microsoft Office, Exchange and Windows with open-source alternatives including LibreOffice, Open-Xchange and Linux.

DNS Belgium, the organization responsible for managing the country's internet domains, announced plans to move away from AWS, citing “the geopolitical reality”.

On the company side, Finnish technology company Vertics announced last week that it will terminate all maintenance and production environments from American cloud services and move its entire infrastructure to the Finnish provider UpCloud.

Meanwhile, MEPs (Members of the European Parliament) last week backed a report on measures to reduce the EU’s dependency on foreign technologies.

Government organizations in France, Germany, the Netherlands, and Italy are working to coordinate national efforts to develop open, interoperable and reusable digital solutions that can be shared across borders.

The European Commission has published a Cloud Sovereignty Framework with a scoring methodology for assessing the sovereignty of cloud services, while a coalition of European cloud providers introduced the Sovereign European Cloud API (SECA), a new open standard for cloud infrastructure management, as a foundational element of the EuroStack sovereign cloud initiative.

In Germany, the Centre for Digital Sovereignty of Public Administration (ZenDiS) has a mission of eliminating critical dependencies on individual technology providers, including supporting openDesk productivity software for public administration employees, which the ICC is now using to replace Microsoft 365 after its kill-switch scare.

Gaia-X is a European data‑infrastructure initiative launched in 2020 aiming to build a federated alternative to centralized cloud platforms continues, but progress has been disappointing.

Meanwhile, industry and advocacy groups like Open Cloud Group and CISPE are pushing hard for changes in procurement practices that favor the incumbents, and activist groups are urging governments to go further, including adding specific sovereignty provisions to legislation like the UK Cybersecurity Bill.

And of course, a market has opened up for sovereign cloud services. SAP plans to invest €20 billion in expanding services that guarantee residency and data access, and all the big US players have sovereign cloud offerings too, although they cannot guarantee protection from the US government. These cost 10%-30% more than their regular equivalents and are aimed at sensitive workloads in regulated industries and government.

Alternatively, UK providers like Civo avoid the complications of crossing jurisdictions for British firms.

Will History Repeat With AI?

The recalculation on sovereignty has become even more urgent in the face of AI. AI is finding its way into everything, and, for the most part, it’s exactly the same US tech giants who are driving it. It’s another one-way door, said Mark Butcher.

“The cloud was sold as inevitable and costly missteps followed. Now AI is being cast in the same light, but this time, the stakes are much, much higher.”

“What happens if we're dependent on a few suppliers that are providing AI tools that may not have any accountability, and that's where it gets really worrying,” said Open Cloud Coalition’s Nicky Stewart.

The UK needs to find a way to coordinate its universities, companies, startups and public bodies in some sort of national program, otherwise history looks set to repeat.

“AI is being pushed rather than pulled,” said the Co-op’s Scott Robertson. “And I think we'll end up as a society sleepwalking into something that is sold as an inevitability, when we've not had a chance to shape it.”

HPE’s Matt Harris said: “We must not make the same mistake with AI that we made with cloud.”

This article originally appeared on MES Computing’s sister site Computing.