In late April 2025, Microsoft unveiled its latest European Digital Commitments—a set of measures aimed at reinforcing digital sovereignty for European customers. These are timely and welcome, especially in light of the sovereignty challenges I recently highlighted in my blog “Why US Isolationism is Now a Global Cloud Risk.” But do they go far enough?
In this blog I will compare how these commitments measure up against the four categories of sovereignty risk that increasingly concern European governments and organizations.

Figure 1: Cloud Sovereignty Risks
Data Sovereignty: Privacy and Confidentiality
Microsoft’s Commitment
Microsoft has extended its EU Data Boundary initiative to include more services (such as Teams, Exchange Online, and OneDrive), offering European customers the ability to have their data stored and processed in Europe. Microsoft completed the project by extending the EU Data Boundary to include professional services data from technical support interactions. In addition, Azure Confidential Compute offerings can ensure that customer data being processed within a trusted environment cannot be accessed by Microsoft. Customers can also create a “lockbox” around their data across Azure, Dynamics 365, and Microsoft 365. Microsoft already enables customers to secure their data with encryption keys that they, not Microsoft, control with Azure Key Vault and Microsoft Purview Customer Key.
Residual Risk
Despite this, Microsoft remains a US-headquartered company—and therefore subject to US laws like the CLOUD Act, which allows extraterritorial data requests. Microsoft says it will challenge such demands when they conflict with EU law, but legal protection is not equivalent to legal immunity. Therefore, the cloud customer must make use of the controls provided by Microsoft where this is a concern.
Operational Sovereignty: European Partnerships
Microsoft’s Commitment
Microsoft Cloud for Sovereignty is a package of technologies and configurations to help governments and other customers run on Azure in Microsoft public cloud datacenters with greater control over data location, encryption, and administrative access. Microsoft has partnered to create sovereign clouds in France and Germany offering them the capability to deliver a broad range of Microsoft Azure cloud services and Microsoft 365 productivity tools. This is further extended through collaboration with European cloud providers to enable them offer Microsoft applications and services on their infrastructure.
Microsoft also announced that going forward their European datacenter operations and their boards will be overseen by a European board of directors that consists exclusively of European nationals and operates under European law.
Residual Risk
It remains to be seen whether the partner operated clouds can provide the same functionality, performance, and cost of the Microsoft public cloud. The extent to which European oversight could override US laws is a legal question which can only be answered by lawyers.
Infrastructure Sovereignty: Operational Continuity
Microsoft’s Commitment
Microsoft commits to set up contingency arrangements for operational continuity through European partners to cover the situation where they were legally obliged to suspend services. They are already enabling partners in France and Germany. These include Capgemini and Orange, who formed a joint venture named Bleu that provides a trusted cloud platform operated under French control. There is a similar sovereign cloud initiative in Germany through a partnership between Microsoft, SAP, and Arvato Systems (a Bertelsmann IT subsidiary)
Microsoft have also committed to store back-up copies of their code in Switzerland, with the legal rights needed to access and use this code if needed for this situation.
Residual Risk
While these commitments are welcome, the knowledge and effort required to restore and make operational the whole technology stack involved should not be underestimated.
Technology Sovereignty: Avoiding Digital Lock-In
Microsoft’s Commitment
Microsoft commits to better interoperability through open APIs and open-source integration. Customers will increasingly be offered modular service options that blend Microsoft capabilities with regional software and platforms. This includes their set of AI Access Principles which Microsoft say will be enhanced in the coming months. This has led to the development of many open-source models from European-based AI developers such as Mistral and Hugging Face. These are all available via public APIs to facilitate interoperability.
Residual Risk
These modular offerings are helpful, but proprietary cloud architecture and development tools like Microsoft Graph, Azure Resource Manager, or Copilot for Microsoft 365 still create high switching costs. True portability remains elusive without common standards.
Opinion: Progress, but Not Yet a Sovereign Cloud
Microsoft’s European Digital Commitments mark significant progress in aligning cloud services with EU values of privacy, autonomy, and transparency. But they remain constrained by the geopolitical and legal realities that surround US cloud providers.
While Microsoft’s new commitments are a positive development organization operating in Europe must balance the functionality provided by US owned cloud services, the cost, and the wide availability of skills in these services with the risks that depending upon them bring.
These announcements bring opportunities for European service organizations to collaborate with Microsoft to provide sovereign versions of their cloud services and for European cloud user organizations to support the European delivery of these services.
To learn more about this and other cyber security development register for Identity-Centric Cybersecurity Impact Day 2025 in Frankfurt November 6th, 2025.