In June 2025, AWS unveiled its independent European governance structure for the AWS European Sovereign Cloud. This follows from other previous announcements on how AWS plans to support EU sovereignty for customers that require it. This is welcome, especially in light of the sovereignty challenges I recently highlighted in my blog “Why US Isolationism is Now a Global Cloud Risk.” But do they go far enough?

Figure 1: Cloud Sovereignty Risks
To satisfy customer requirements for the AWS European Sovereign Cloud, AWS says that they are introducing their Sovereign Requirements Framework (SRF). This is a set of technical, legal, and operational sovereignty controls that are intended to meet the sovereignty expectations of their customers, and regulatory requirements.
In this blog I will compare how these announcements measure up against the four categories of sovereignty risk that increasingly concern European governments and organizations.
Data Sovereignty: Controlling Data Within Europe
AWS’s Commitment
The AWS European Sovereign Cloud promises to store all customer data exclusively within the EU. AWS already provides capabilities for customers to store data within specific geographical regions. The AWS Nitro systems architecture also separates AWS’s operational control plane, preventing AWS operational access to customer data during processing. It also provides encryption options where customers can use their own keys, including integration with AWS KMS and AWS CloudHSM, which will also be available within the Sovereign Cloud.
Residual Risk
AWS, as a US-headquartered company, remains subject to US laws like the CLOUD Act. While AWS can design technical controls to reduce access risks, it cannot fully exempt itself from potential extraterritorial obligations. Legal uncertainties remain until tested in court, and customers concerned with these risks must use all available encryption and access control options.
Operational Sovereignty: Local Control Over Cloud Operations
AWS’s Commitment
AWS plans to establish a new European organization and operating model for the AWS European Sovereign Cloud, with a new parent company and three subsidiaries incorporated in Germany. This will operate the European Sovereign Cloud independently with new support and billing infrastructure managed by EU-resident staff. It will provide separate governance and operational autonomy from existing global AWS operations.
Only EU-resident AWS employees located in the EU will have control over the operations and support of the environment. Services will be physically and logically separate from existing AWS Regions, starting with the first region in Germany (planned availability by end of 2025).
Additionally, AWS will enable customers to meet requirements for compliance, including data residency, auditability, and oversight.
Residual Risk
Unlike other vendors’ approaches which involve partnerships with local European entities, AWS has opted to maintain direct control while relocating operations to the EU. This may be advantageous for customers seeking consistency with global AWS tools and APIs but may fall short of expectations for independent local governance by third-party European stakeholders.
Infrastructure Sovereignty: Contingency and Continuity
AWS’s Commitment
By designing the EU Sovereign Cloud as a standalone infrastructure, AWS aims to ensure that service availability and continuity are not impacted by legal decisions outside the EU. The German region is the first step, with expansion into other EU member states under consideration.
The AWS European Sovereign Cloud will also have its own dedicated networking infrastructure and connectivity from European providers, as well as sovereign Points of Presence for direct network connection via AWS Direct Connect. This will provide customers with an autonomous connection to the AWS European Sovereign Cloud.
Residual Risk
While this is a positive development, true infrastructure sovereignty requires not only isolation from foreign influence but also verifiable local control over all layers of the cloud stack—including personnel, supply chains, and operational processes. It is essential that AWS supports its claims with third-party verification or legal safeguards.
Technology Sovereignty: Avoiding Cloud Lock-In
AWS’s Commitment
AWS services support a wide range of international and de facto technology standards. AWS says its services in the Sovereign Cloud will remain interoperable with those in the existing global AWS regions. Customers will have access to AWS APIs, tools, and service catalogues, and can leverage open-source integrations to build modular, portable applications.
Residual Risk
The AWS ecosystem remains deeply integrated with proprietary tooling—such as AWS Lambda, CloudFormation, and IAM policies—which can create significant switching costs. True portability would require broader standardization across cloud providers, something AWS has not committed to.
Opinion: A Calculated Balance Between Compliance and Control
AWS’s European Sovereign Cloud announcements signal that US cloud providers are responding to European demands for more control over digital infrastructure. The initiative provides a clear pathway for EU organizations to leverage AWS services while aiming to meet local compliance and autonomy requirements.
However, AWS cannot fully escape the limitations imposed by its US origin. While technical and organizational safeguards are evolving, legal sovereignty, especially in the face of potential extraterritorial demands, remains unresolved.
Organizations operating in Europe must weigh the benefits of AWS’s global platform against the residual risks tied to jurisdiction and legal control. For some, AWS’s Sovereign Cloud may be “good enough.” For others, especially in government or defense, it may still fall short of full sovereignty.
To learn more about this and other cyber security development register for Identity-Centric Cybersecurity Impact Day 2025 in Frankfurt November 6th, 2025.