On January 15th, 2026, in Potsdam Germany AWS Announced their AWS European Sovereign Cloud. This is welcome, especially in light of the sovereignty challenges I previously highlighted in my blog “Why US Isolationism is Now a Global Cloud Risk.” The recent escalation of geopolitical tension over Greenland have emphasized these concerns.
It is no surprise that AWS chose Potsdam and the HPI institute for this announcement. In Germany the government and public services have been very reluctant to use cloud services from US based organizations. For this offering to be successful AWS needs to convince the Germany government as well as German organizations of their sovereignty claims. The HPI institute in Potsdam, where the announcement was made, was established by one of the founders of SAP and Brandenburg, the region around Potsdam, is a technology incubator area in Germany.
What was announced
AWS announced the general availability of their first AWS European Sovereign Cloud Region in Brandenberg, Germany, together with a commitment to invest 7.8 Billion Euros the AWS European Sovereign Cloud in Germany through 2040. (To put this in perspective the EU cloud market is estimated to be worth 70 billion to 80 billion Euros per annum.) This announcement included several key sovereignty capabilities:
- The AWS European Sovereign Cloud is physically and logically separate from other AWS Regions and is operated exclusively by EU residents.
- It supports the complete set of capabilities provided by the AWS public cloud.
- It provides customers with full control to keep their data, including all metadata they create entirely in the EU.
- AWS has established a dedicated governance structure in Europe, with a new parent company and three local subsidiaries incorporated in Germany (GmbH).
- It also includes an advisory board, which will provide expertise and accountability in sovereignty-related matters and is made up of European citizens and residents.
In this blog I will compare how these announcements measure up against the four categories of sovereignty risk that increasingly concern European governments and organizations.
Data Sovereignty: Controlling Data Within Europe
The AWS European Sovereign Cloud is provided from data centers and infrastructure exclusively within the EU. The customer data which includes all the metadata they create (such as the roles, permissions, resource labels, and configurations) is held in these entirely within the EU. It also provides encryption options where customers can use their own keys, including integration with AWS KMS and AWS CloudHSM, which are also available within the Sovereign Cloud.
Residual Risk
This is the risk that AWS could be forced under US laws like the CLOUD Act to override all the EU legal governance and controls. If this remains a concern customers must use all the available technical controls to protect their data.
Operational Sovereignty: Local Control Over Cloud Operations
AWS has established a new European organization and operating model for the AWS European Sovereign Cloud, with a new parent company and three subsidiaries incorporated in Germany. This operates the European Sovereign Cloud independently with support and billing infrastructure managed by EU-resident staff. It has separate governance and operational autonomy from existing global AWS operations.
Only EU-resident AWS employees located in the EU have control over the operations and support of the environment. The operating model is based on the AWS European Sovereign Cloud: Sovereign Reference Framework (ESC-SRF). This framework aligns sovereignty criteria across multiple domains such as governance independence, operational control, data residency and technical isolation.
In addition, AWS Nitro systems architecture also separates AWS’s operational control plane, preventing AWS operational access to customer data during processing.
The ESC-SRF is published in AWS Artifact which provides customers with on-demand access to AWS security and compliance documents and AWS agreements.
Residual Risk
Unlike other vendors’ approaches which involve partnerships with local European entities, AWS has opted to maintain direct control while relocating operations to the EU. This may be advantageous for customers seeking consistency with global AWS tools and APIs but depends upon trust in the local EU governance structures.
Infrastructure Sovereignty: Contingency and Continuity
AWS claim that the AWS European Sovereign Cloud is physically and logically separate from other AWS regions and has no critical dependencies on non-EU infrastructure, and is designed to continue operations indefinitely, even in the event of a communications disruption with the rest of the world. AWS also announced plans to expand across Europe with new AWS Local Zones in Belgium, the Netherlands, and Portugal.
AWS Local Zones allow customers to store their data in a specific geographic location to meet data residency requirements or run latency sensitive applications. Customers also have the option to use AWS Dedicated Local Zones, AWS AI Factories or AWS Outposts in locations they select, including their own on-premises data centers.
Residual Risk
While this is a positive development, true infrastructure sovereignty requires not only isolation from foreign influence but also verifiable local control over all layers of the cloud stack—including personnel, supply chains, and operational processes. It is essential that customers check the third-party verification and legal safeguards published by AWS meet their sovereignty needs.
Technology Sovereignty: Avoiding Cloud Lock-In
AWS services support a wide range of international and de facto technology standards. The AWS European Sovereign Cloud customers will have access to those as well as to AWS APIs, tools, and service catalogues, and can leverage open-source integrations to build modular, portable applications.
Residual Risk
The AWS ecosystem remains deeply integrated with proprietary tooling such as AWS Lambda, CloudFormation, and IAM policies. Customers often choose AWS because of value these capabilities provide. However, this could create significant switching costs should they choose to move to another provider. True portability would require broader standardization across cloud providers, something AWS has not committed to.
Opinion: Organizations must define their sovereignty needs
Concerns over cloud sovereignty have evolved from data privacy and confidentiality to continuity of service. Not all organizations have the same need for data and workload sovereignty, but all organizations need cyber resilience.
Public services, manufacturing and commerce have all become dependent on using cloud services to operate with a highly optimized and just in time approach. Any loss of access can have a significant impact as was illustrated by the recent cloud service outages. The increasing worldwide geopolitical tensions mean that organizations must consider not only the risks to their data from the use of cloud services but also the impact of loss of access to the service.
The AWS European Sovereign Cloud is a strong response to European demands for more control over digital infrastructure. It provides a clear pathway for EU organizations with strong needs for EU data residency, EU operation control and EU physical infrastructure to leverage AWS services to meet local compliance and autonomy requirements. When choosing a cloud service organizations should consider their exit strategy, business continuity. and compliance, as well as sovereignty. There are several technical mitigations that organizations should consider:
Define an exit strategy and use standards to reduce lock-in. For example, use standard development orchestrations tools like Kubernetes and OCI container image standards. However, beware since each cloud vendor provides their own proprietary security, management, and optimization capabilities and APIs.
Data backup is a critical defense against digital impact of geopolitical shocks. Make sure the backup format is portable and that the backup data is held outside of the protected cloud.
Evaluate cloud service provider sovereignty claims. These include creating a data boundary to restrict access, operating as an EU sovereign legal entity with local data centers and staff, as well as offering a cloud in a box.