Why US Isolationism is Now a Global Cloud Risk
In recent weeks, the global landscape has been shaken by the ripple effects of renewed US isolationist policies—specifically through tariffs and technology restrictions aimed at strategic rivals. This intensifying stance is not just causing trade disruption; it is exposing a deeper layer of vulnerability in how cloud services are used and delivered around the world.
While the concept of “sovereign cloud” has been gaining traction for years—particularly in the EU and Asia—recent geopolitical moves underscore its urgent relevance. For non-US businesses, the risks go beyond economic uncertainty. They cut into the very infrastructure, operations, and legal frameworks that underpin the cloud computing services that businesses rely on.
What is the Problem?
The core issue is that governments can override legal contracts—especially during times of geopolitical tension. This makes cloud services, dependent on cross-border infrastructure and data flows, inherently vulnerable to unilateral state actions.
The US government, through legal instruments like the CLOUD Act, as well as executive actions, has repeatedly demonstrated its ability to reach beyond its borders to access data, compel service providers, and restrict technology exports. For foreign businesses using US-based cloud providers—or services hosted in US-influenced jurisdictions—this creates a fundamental problem of trust, continuity, and control.
Sovereignty Risks for Non-US Cloud Users
To understand the real-world impact, we can categorize the risks into four interrelated sovereignty domains. Each highlight how non-US organizations may face legal, operational, and technical exposure.

Figure 1: Four Cloud Sovereignty Risks
Data Sovereignty Risk
Even when data is physically stored outside of US borders, it may still fall under US jurisdiction. The US CLOUD Act enables U.S. law enforcement agencies to compel technology companies, through warrants or subpoenas, to provide data stored on their servers, regardless of whether the data is held domestically or internationally.
Ironically, one of the major concerns of the US government was the claim that foreign governments (notably the Chinese) were stealing US data. On 10 February 2020, the U.S. Department of Justice issued a statement concerning the indictment of individuals in connection with the theft of consumer data held by Equifax in 2017. This act sanctions similar actions by the US Government.
This undermines local compliance regimes, privacy expectations, and legal protections.
The EU–U.S. Data Privacy Framework has partially addressed these concerns. However, privacy advocacy groups, notably NOYB led by Max Schrems, have indicated intentions to challenge the DPF in the Court of Justice of the European Union (CJEU), arguing that it may not fully address the issues highlighted in previous rulings.
Operational Sovereignty Risk
Since cloud services are globally available, service administration may follow the sun. Unless the cloud service provider contractually agrees that the administrators are in the users’ home jurisdiction, they will be subject to foreign laws. If administrators are US citizens or employed by a US company, they can be legally required to access, monitor, or even disrupt services—without the knowledge or consent of the customer.
The administrative actions include those which could override customer security controls to alter system configurations or exfiltrate data. While cloud service providers include capabilities that they claim mitigate this risk, it still undermines trust.
Infrastructure Sovereignty Risk
Physical data centers, networking equipment, and other infrastructure elements may reside in or depend on US-based entities. In times of political conflict or sanctions, governments could seize, disable, or restrict this infrastructure— disrupting or severing access to critical business operations .
Cloud providers may offer a “cloud in a box” which can be in a physical location agreed by the customer. They also offer their services hosted in specific geographical locations to mitigate this concern. In some cases, a local non-US partner also administers the service to overcome these concerns.
However, while the service may run autonomously for extended periods, it will still connect from time to time for updates. Would this meet your business’s risk appetite?
Technology Sovereignty Risk
Cloud services are “software defined” and depend upon a complex technology stack. This involves proprietary hardware and software to deliver a proprietary user environment. While the basic capabilities of networking, storage and computing may support open standards, the user interfaces, tools, and APIs provided by the services are proprietary.
More importantly, the value of the services to the end user is increased through proprietary middleware and managed services. This is already the case for databases and development environments, it also includes Generative AI tools delivered as cloud services. This vendor lock-in reduces portability, making it challenging for businesses to maintain continuity if access is restricted.
If the US government were to legally oblige the cloud service provider to cease providing that service in certain geographies it would be difficult for organizations in those to maintain business continuity.
Opinion
Businesses in Europe and across the world have gone through digital transformation based on the use of cloud services. The value of this depends upon the free flow of data and computing power between countries and jurisdictions. Trust is supported by international trade agreements and contracts between end user organizations and the cloud service provider. Trust is hard to win and easy to lose. The actions of the US government to unilaterally overturn international trade agreements have called this trust into question.
Immediate actions that organizations can take include implementing multi-cloud strategies based on open standards. Exploiting data residency capabilities together with appropriate data protection technologies such as encryption. Requiring the cloud service providers to explain in depth how their service mitigates these risks. Demand independent assurance of any claims.
How can organizations best respond to these challenges? For more information on this and other key cyber security questions attend EIC in Berlin in May 2025.