While digital sovereignty and strategic autonomy are top priorities, most European organizations remain structurally dependent on US cloud hyperscalers. How can you reconcile security and compliance imperatives (like NIS2) with the urgent need for AI adoption and technological innovation?
In this exclusive webinar, INCYBER and KuppingerCole deliver a comprehensive macro-economic and technical analysis of the European cloud market. Our featured expert, Mike Small (Senior Analyst at KuppingerCole), breaks down the current landscape, geopolitical threats, operational resilience, and the 4 critical control zones you need to know.
Mike Small, Senior Analyst at KuppingerCole Analysts
Hosted by Antoine Sauvageau-Audet, Head of International Public Affairs at INCYBER Forum
Hi, everybody. Good afternoon, everyone, and welcome. I'm delighted to welcome you all to this very first quarterly briefings that we're organizing with KuppingerCole Analysts. So my name is Antoine, and I will be your host for today's session. And this is Mike, who's going to be the analyst that will speak right after me. So this briefing is a direct follow-up of our discussions at the Insider Forum. I don't know, for those of you who were there, you might recall that our central focus this year was European Digital Sovereignty and how do we master our digital dependencies.
So as we emphasized back during the forum, our objective was not to isolate ourselves or point fingers. We want to address a highly practical and constructive challenge. How can we co-construct and secure digital future alongside major American tech players while preserving and nurturing our own strategic resilience? So in other words, it's how do we turn inevitable dependencies into balanced, sovereign partnerships to help us move past high-level theory and discussions and forums and bring concrete, real-world facts to your daily operations.
We are launching, in partnership with KuppingerCole, the Strategic Research and Insights Partnerships. So through this regular briefing, so this is the first one, our goal will be simple. It's to bridge the gap between hard cyber realities on the ground and the independent analytical depth of Europe's leading analyst firms.
And regarding these partnerships, I'm also proud to announce that the goal will be to strengthen independent European expertise, deliver deep market intelligence, and foster much tighter connections between the French, the German, and broader European tech and security communities. So there will be three core activities that we're going to be doing with KuppingerCole. The first one will be these quarterly briefings. So we will address challenges and cybersecurity challenges and regulatory challenges.
Then there will be an annual reference report that will provide a comprehensive yearly analysis of European market dynamics to guide you into making strategic decisions. And then the third one will be analysts from KuppingerCole, so an active analyst engagement during the forum. So during our event, we will have more and more KuppingerCole analysts coming throughout the year. And so this is my absolute pleasure today to welcome our first speaker, our first expert, Mike Small, which is a senior analyst at KuppingerCole.
So just a quick bio, Mike is a widely recognized authority in cloud security, data privacy, and risk management. He has authored extensive research and provided strategy consulting to enterprises worldwide. He's a chartered engineer, a fellow of the British Computer Society, and a member of leading professional organizations and the Institution of Engineering and Technology. So recently, Mike has published a fantastic paper titled From Digital Sovereignty to Economic Competitiveness, where he argues that digital sovereignty isn't a barrier to innovation or a bureaucratic headache.
When it's managed through co-constructions, it is actually the ultimate driver for economic competitiveness and resilience. So over the next 30 minutes, Mike is going to break down where the European market stands today, the reality of our dependencies, the impact of AI, and what the next five years will look like. And also I would like to add that if you have any questions during the webinar, don't hesitate and please feel free to put them in the chat, because at the end of the discussions, there will be a live Q&A session.
So Mike, the floor is yours. Thank you.
Okay, well, thank you very much for inviting me to give this presentation. And I've been researching the cloud for getting on for 15 or 16 years. And it's been interesting to see how the perspective on the cloud has changed.
Now, what has basically happened is that we started off worrying about the security of the cloud, then it became a question of compliance. And now, with the global shocks that came from COVID, and from other wars and other things, we've started to realize that the global economy, whilst it presented many benefits, has also come with certain costs and risks associated with it. And in particular, what we now have found is that whilst Europe is thriving, it's actually become very dependent upon US or external cloud services, which has caused some new risks.
And we have had to reassess those risks in the context of the changing geopolitical landscape. So what I'm going to talk about in this presentation is the reality of these risks, how we assess the risks, and what we see customers, companies, enterprises are doing, and look at the future. So the first step is really to understand where we are, we have to understand where we are in order to understand where we're going.
Now, what is interesting here is that the cloud market or the market for cloud services is enormous, $70 billion, it is estimated, and it's interesting that the estimate has come from the US. And the US is interested because 70% of the share of that market is taken by US vendors. And although Europe is highly technically and technologically advanced, we don't have a very large share of our own market for cloud services.
In fact, it's put at around 15% coming from Europe. So we have become very dependent upon US-based cloud services. And to understand that, what I would like us to do is to just simply step back a moment and remember what happened at the end of 2025. So I'm based in the UK. And in late October, I found that I could not use my banking app.
In fact, it turned out, although many people would not be very sad about that, the inland revenue or Her Majesty's Inland Revenue in the UK, cloud services or their IT services were no longer working. And all of this had happened because of a technical problem, not a deliberate problem, but a technical problem that had affected one of the major cloud services on the east coast of the US. And I think that the impact of that was very strongly illustrative of the fact that we have become very dependent upon those services.
And losing access to one of those services has become a very, very potentially impactful event. So why is it that people or organizations choose cloud services? And the simple answer to that is that they choose them because they currently offer the richest and the most comprehensive ecosystem that the US cloud services have grown and are reinvesting to the extent that they have a wide range of services out of the box. They're investing heavily and continuously innovating.
They have many, many different scalability capabilities through lots of different lots of different data centers around the world. And not only that, but if you were an IT professional, it would pay you to get qualified to understand and to be able to deal with one of those clouds. So there are lots of talent around that can help you to administer and to run those services. At the same time, there has been a lack of a unified EU strategy. And I will touch upon this when we come to the end, because this is more than just a question of technology.
So let us just sort of give as a proof point of what I've just really been saying. This chart here gives you an idea of the richness comparative for the different services. And I think everyone is aware that AWS, Google, and Microsoft are all US-based, US-owned cloud services. And what I have done in this chart is to compare the number of out-of-the-box services in total and the services which are to do with AI for those services versus what is probably the largest European cloud, which is OVH cloud.
So this shows, if you will, one of the reasons why it is that organizations tend to choose a US-based cloud service over the other ones. So this has taken us to the paradox that what we are calling the cloud sovereignty paradox, which is that this, the choice of these US-based cloud services is actually creating a new kind of dependency and a new kind of strategic risk. So let us go back to that example that we talked about of the problems with the cloud services that we all met at the end of October in early November 2025.
I would say that there are two lessons that we can learn from this, and there are two dimensions. The first lesson is that however we want to deny this, the US cloud is now part of European critical infrastructure. And that then leads to the question of, is our resilience good enough? And this is interesting because most of the discussion previously has been around compliance and data privacy and other things. Now in terms of dimensions, there are basically two dimensions that I see. One is a political dimension, and the other is organizational.
Now the political dimension is way above my pay grade, that how we manage these things politically is down to the European Parliament and our representatives in this. But for the majority of Europe, the question is how can an organization organize itself? How can it manage these questions? And that is really what I'm going to focus the rest of the presentation on. And at the end, I will come back to some of the wider questions.
So when you look at what the threats are from our use of US clouds, there has been an awful lot of discussion which has gone on for many years over our legal exposure to US laws. And I'm sure that all of you that have followed this will have followed the various legal interventions by Dr.
Schrems, which led to changes in the law and changes in the contracts. But whilst loss of data and loss of privacy and loss of confidentiality are important, loss of the service which you depend upon is, shall we say, higher up the chain in terms of the impact that it can have on you. So in terms of organizations, dependent upon a service that could not be guaranteed or could be withdrawn becomes a more important threat to consider. At a political level, then there is also the strategic potential for the loss of our technological autonomy.
And that is something which we also need to take account of. But I'm going to look at what we can do when we look at this from the perspective of an organization. So I believe that there are four principal organizational risks. And these risks are basically shown on here. The geopolitical risks become something that you have to put to a side and to deal with in a different way. But if you are running a business, if you are running an agency, if you are running a service that is delivering things to your customers or to your citizens, then these are the four things that you have to manage.
And the four things are basically the data sovereignty, where the risk is to do with legally unauthorized access. And the same is true of operational sovereignty, where the concerns over the U.S.
Cloud Act, which can demand that an operator of these systems can be required by U.S. law to hand over data, that is also legal unauthorized access. There is also the question of infrastructure sovereignty, that if in fact you find that the cloud service is delivered from a European location, even if that location is within Germany or something, if it is owned by a foreign third party governance, a third nation state, then could you be denied access to that, even if it was there, or even if you could get access, would you have the competence to be able to run and restore the service?
And finally, all of these non-European services depend upon a complex and very highly developed technology stack, which again you could legally be denied access to, if in fact there was the right kind of, shall we say, geopolitical instability. So those are the risks that we really, as an organization, need to deal with. And so how is the market responding to the concerns? Because these risks are well known now, and many customers are in fact, many enterprises are in fact raising those risks with the cloud service providers.
And so what I would like to say is that from the perspective of an organization, there are really four critical control areas that you have to consider. And you can see these quite clearly on the slide, which is that there are various techniques that you can use and engage to increase the protection of your data. And I can talk about those in more detail if people are interested. But in terms of resilience, the first question is to make sure that you do have your data secured, so that were you to lose your access to that service in any way, you would have an ability to continue.
And there are three basic approaches to this. An obvious one is to be able to back your data up, but it's more complicated than that. There is also the capability for many of the clouds for you to have what I would describe as a cloud in a box that you can run a version of that cloud may or may not be disconnected, but you can put it in your own data center and run it. And then there is the question of, would you be able to move to an alternative cloud? And that then opens the question of, could you move, which is to do with exit.
And if you were going to exit, how would you be able to move to another one, which is to do with openness? And so, one of the big questions is that standards are an enormously powerful capability.
And so, having the standards that would allow you to do that would be good. Now, moving on to how we would map those things, I will not dwell upon that, but here is how, if you were concerned about these four areas, that you could map those controls to those areas, and you will see that most of the cloud service providers provide controls. For example, you can run things regionally, you can use different kinds of encryption and so forth.
So, looking at that, you can see that there are capabilities that allow you to do that. So, that's to do with those risks.
Now, the other dimension to this is the dimension of sovereignty. So, how do you measure sovereignty? When a cloud service provider says they are sovereign, is it in fact? How true is it? And to help with that, at the EU, in last October, published a thing called the Cloud Sovereignty Framework, together with a set of assessments, where you are able to or an organization or an assessor is able to make a quantified assessment of whether or not a cloud that claims to be EU sovereign really is EU sovereign, or whether it is in fact, simply a marketing claim that has no substance.
And so, if you look, you can see that there is this framework, and I would advise anyone who is concerned about these things to understand what that means, because it gives you a tool to assess sovereignty. Now, so what can we see here?
This, so something seems to be missing from my slides, but there we are. So, let's just pass on from that.
So, what we can actually see is happening is that there have been a series of announcements recently by the US-based cloud service. And in the positive thing from this is that the strength of the EU market is sufficiently important to the US cloud providers, that they have been taking action to help to assuage the concerns of European customers.
And so, one of the approaches to this has been to set up a set of partnerships. And what you can see here is these different partnerships, and the two partnerships in particular are that Microsoft has come up with a partnership with Blue in France, and with Delos in Germany, where they will host the various services in data centers, in the country, in the EU, operated by the staff from the country, and with personnel under the law, and the actual infrastructure owned by the European organizations.
And the same is true in France for SANS, which is a subsidiary of Thales in France, and Telefonica in Spain, who provide a pretty comprehensive set of Google services hosted in the EU, managed by personnel in the EU.
Now, that is a different approach to the approach which was taken by AWS, and I'm afraid that is what was missing from the previous slide, that AWS has taken a different approach, and AWS has actually set up a German company with German ownership, with a German governance body, with the data center owned by this German organization, and they have put that in Brandenburg, which is near to Berlin, Potsdam, and they are delivering their services in Germany through that, and they claim they're going to repeat that process in other parts of the EU.
So, that is the approach that the US cloud providers have taken to this, which is basically two approaches. One is through partnerships, which is Microsoft and Google, and the other is through local entities, local legal entities that own and run the service, which is the approach taken by AWS.
So, what is happening in Europe?
Well, there are quite a large number of small, some small and some much larger, EU sovereign clouds that grew up independently of the US, which are, in fact, owned and run in Europe, and of these, you can see the main and the largest ones are shown in here, and you can see there are three clouds run from Germany, EONOS, StackIt, and T-Systems OpenTelecom cloud, and the French cloud, OVH cloud, and this slide gives you an idea of the technology, the target market, and the number of services that they provide, and basically, the most common technology is OpenStack, which is open source.
The common focus has been on Kubernetes and on container-based developments, and the target market has mainly been to do with public sector and other EU enterprises that are particularly concerned with sovereignty issues.
There is this larger number of smaller, but numerous EU cloud service providers, and there are too many of these to me to go through, but this is for you, if you wish to come back and have a look, you can see which those are, and interestingly, there is another complementary set of providers, which have specialized on providing AI infrastructure as opposed to a complete cloud service, and again, interestingly, one of the common themes behind all of these has been to foster the development of not, if you will, enterprise use, but also to foster the use or the creation of EU-based software as a service, SAS applications, so that's an overview of those services and how the market has responded in Europe.
Now, so what is it that is driving the market in this area? So, let's look both at the drivers and the constraints, and I'm sorry to say that I have lost all of this in my thing, but what I will do is talk about it.
So, what we can say is that the EU market is currently assessed to be growing at 43 percent per annum, which is absolutely significant. This is not only a large market, but it is a market which is growing at a very, very high rate, and that is for the market for generative AI.
The other driver, apart from generative AI, is EU defense spending, and all of the various geopolitical shocks that we have seen over the past couple of years have led to a very large increase in this, with EU defense spending growing and UK defense spending growing, and this rearm Europe, which is causing another strong need for reliable, sovereign, and controllable services that can be used for those kinds of applications. So, the gen AI market and EU defense are key things.
On top of that, these are basically coming from the problem of geopolitical uncertainty and the increasing need for resilience in our supply chains. So, those are the drivers for growth.
Now, let us look at what are the constraints for growth.
So, the constraints for growth are really an interesting one, is that gen AI uses an enormous amount of energy, and currently, the EU, in the EU, 2.5 percent of all of the electricity that is used in the EU is for running data centers, and you can easily see that doubling or quadrupling if we are going to have a large push into using generative AI, because at the state of the art at the moment, generative AI demands enormous amounts of energy, and to give an example of that, 20 percent of all of the electricity that is consumed in Ireland is consumed by data centers.
Now, that's an amazing statistic when you think about it. One-fifth of all of the electricity in Ireland is dedicated to using data centers.
The second problem, which is constraining things, is how we invest in Europe, and this comes back to multiple different factors, but you can see this because if you take the average, and this is from a study by the IMF, so this is a pretty good fundamental study of the economy of Europe versus the economy of the US, that an EU technology organization invests something like 3.5 percent of their sales turnover into research development and product improvement.
That is a quarter of what is invested by a US technology organization, and so you can see that that US technology organizations invest more heavily, and not only that, they have access to the kind of venture capital which is prepared to take the kinds of risks on technology, and furthermore, we see that the actual market share of the largest EU cloud service provider is something like only two percent of the total market, so we have a structural problem which is making it difficult for us to be able to do that, so I apologize for whatever has happened to the slides, and what I would like to say as a kind of closing note is that we need to not just own the cloud, but we need to be able to use the kind of technology that these cloud services provide to be able to get ahead.
It is not sufficient to try and recreate what has already been recreated. We need to stand on the shoulders of giants and to use the best of what there is to actually make Europe great again, to parody a certain person from the US.
So, with that, I'm going to say I'm open for questions and hand it back to Antoine. Thank you, Mike, for this really interesting intervention, really nice numbers that you showed there. Maybe to start off, since there's one or two questions in the chat, but I do have one small question, which is do all use cases for cloud services require the same level of sovereignty, in your sense?
Yes, well, I think that's actually a very good question, and this is that organizations need to take a risk-based approach to using this, and it has been interesting to see. Let me give you an example that I came across a local government organization in the UK, and they had a simple strategy which said, we never use the cloud. It's too dangerous. We're not going to use the cloud.
So, it turned out that the publishing department within this wanted to use the cloud, and there was a long debate about what was actually going to be used, but it turned out that the local government had to produce paper posters to advertise services that were public, and that in order to produce those posters most economically, they needed to post the data which was going to be used by the printer through the cloud to the printer.
So, we had an organization that was taking public information that was going to be published and was refusing to use the cloud to do that because they had a simple, we won't use the cloud because it's too dangerous. Now, that is clearly a ridiculous extreme, but lots of different organizations have different risk appetites. They're doing different kinds of work, and they have different levels of dependency upon the cloud services, and so what you really need to do is to take a risk-based approach. How confidential is the data?
What would be the impact in terms of compliance if this data were compromised? What steps can I take to mitigate that? How important would it be to my business if I were to lose access to that service or lose access to that data, and then to make a judgment?
So, there is no one size fits all, and it's certainly true that some business cases, and I earlier talked about ones such as, for example, defense, where there may be a much stronger need for sovereignty than others. Okay.
Thank you, and there's a question also from Vincent Rombouts, which is, what do you think about the DeepOVH cloud and Clever Cloud consortium initiative? Sorry, could you repeat that? What do I think about the DeepOVH cloud and Clever Cloud consortium initiative?
Well, all of these initiatives are good, and so I encourage all of this. It is good for us to, in Europe, to collaborate, and I think this has been one of the challenges that the European market is still incredibly fragmented, that it is still difficult for a French service to sell something in Germany, and for a German service to sell something in Spain, and so this is a disadvantage that we have in Europe, that sovereignty is not yet really seen, if you will, in the same way across the whole of Europe as being European.
Sovereignty is often seen as being, well, it's only really sovereign if it's in my country, and that's not the same attitude. If it's, you know, we are competing with a company that in California has the same level playing field in New York or in Georgia, and so we have to be better at collaborating and working together.
Okay, then there's another question of Rick, which is, how much of a constraint it is that the majority of frontier AI models are either US-owned and closed sources or Chinese and open source? Well, so I think this is another one of these areas where we have not yet figured out exactly what the risks are, and this is an emerging area that there are truths and there are concerns and there are falsehoods around gen AI. So the fact of the matter is that, as I said earlier on, we are linked almost inextricably to a lot of technology that has its foundation in the US.
If you really are concerned about that, then open source tends to at least give transparency as to what is going on. But at the moment, AI gen AI is really still the Wild West, and you need to be careful about everything that you do with that and to make sure that you assess the risks of all of the things that you're doing. And there is a whole separate presentation that we could give you just on that. So that is, in the famous words, another story.
And just to bounce on this, for you, following the question of Rick, looking at the next five years, for you, what would be the most critical move European providers must make to close this AI gap that is becoming more and more, well, bigger and bigger?
Well, so I think that the reality is that the US cloud providers will make their products adequately sovereign to remove most of the concerns for most of the use cases, so that the different approaches, whether it be partnership or local ownership, will, in fact, mean that the next five years, the cloud providers that we're all used to will continue. And that the most significant thing that we can do in Europe is to make sure that we have a significant thing that we can do in Europe is to make sure that we actually exploit the capabilities of these things to do new stuff, to add value.
And that's where, again, if you look again at the IMF and the IMF projections, that the potential for Gen AI is enormous. And what we mustn't do is, shall we say, get stuck in a rut of trying to recreate in Europe what has already been created in terms of fundamental services. What we need to do is to find ways to exploit what is new in terms of the Gen AI in a way that is better and more productive to make our manufacturing and our services and everything that we do more efficient, more effective and better.
And that is a better approach than trying to simply recreate a local version of something that is already existing. And to bounce back on what you just said, Mehdi said that, from what you understood, the major issue with a sovereign cloud is political. So how to push countries to collaborate and force them, just like you said, to how do you see, like, do we need to do another NIS2, another law?
Like, how do we, let's say, how can cloud architects move from beyond mere paper compliance, European paper compliance, and build through operational resilience? For example, just like you said, the AWS, when it went down, like, how can cloud architects move beyond mere paper compliance to operational resilience for when a major cloud region physically go down, for example?
Well, that's an interesting question. And so one of the things is that I'm not sure that many organizations have done a very good job of architecting their clouds. And to give you an example of this, one of the, there is a startup company in Holland, in the Netherlands, which is very interesting, because this is an example of what I was just talking about a moment ago. Because what they are doing is they have a sovereign European technology using using Gen AI to help people to design their use of cloud services to achieve various forms of regulation, or of policy, or of resilience, or whatever.
And so here is an example of using this technology to actually achieve something that would have been very difficult and possibly flawed in the first place. And they are using, and that is going to be incredibly important when we are deploying Gen AI. Because nobody, nobody, Gen AI is again, the Wild West, people are creating agents, they don't know where they are, but they're all somewhere in the cloud, and they're all doing things.
So being able to bring this, to use these technologies, to be able to do things that are better, to do them in a more controlled way, and to get better results is the critical message that I want to keep getting across to people. Okay.
And also, maybe you have another question, but is there any solutions that help migration in between cloud services, for example? Well, yes.
And so, first of all, many of, first of all, that if you are using a cloud service, then you should be working very hard to make sure that you use all of the standards that that cloud service supports. And by that, I mean the international standards. And so there are standards for backups, there are standards for container images, there are standards for all kinds of different data. So where there are standards, use them. And then when it comes to taking snapshots or backups of what you've got, make sure that they are taken in these standards.
Now, some of the backup providers, and indeed there are some of the cloud services themselves, contain capabilities that allow you to migrate infrastructure as a service, VMs, between VM environments. And so those are things that can help you to move things. And there is a potential for Gen AI to also help with this, so that it becomes easier to move between proprietary clouds, as well as to move to standard clouds.
So standards are your friend, and some of the tools that are available in the cloud services themselves, and there are some other services often offered by the backup and disaster recovery capabilities to do that. Okay. And there's another good question from Nedi, which is, what do you think about the AI Act and cloud sovereignty? Do you think these two should progress together or separately?
Well, what we have to be careful about is to make sure that where regulation, where there is regulation, that we use that regulation to create a level playing field, but not to suppress innovation. And so the important thing is that regulation is good because it, if you will, kind of helps to protect and control things, but it can also, at the same time, shall we say, prevent innovation.
And again, we go back to the tick box approach. Organizations need to understand what the risks are and to apply these regulations in a way which is within the spirit of regulation, rather than to try and gold plate what the regulation is trying to do in order to not use a technology, not exploit the benefits that it can bring. So use the technologies in a way which is ethical, but make sure that you do it in a way which is also going to give you growth and to grow Europe. Okay. And maybe if I can ask one last question before ending this fantastic webinar.
How should I factor sovereignty into the equation when choosing a cloud service, for example? Earlier you talked about risk management depending on what you are doing as an activity, but do you want to elaborate maybe a little bit on that? So how should I factor sovereignty? Okay.
Well, again, this is just another dimension of risk management, but basically sovereignty is a quality and that quality may be important. And I say it's a quality because if you look at the ISO standard for, if you will, architectures of cloud services, there is functionality. And most people, most organizations want to use something because of the benefits and the functionality that it delivers. And functionality though is not sufficient.
You want a service that is going to deliver the functions you want, but it also has to meet the qualities that you need to do with, does it actually continuously work? Is it reliable? Is it in fact legal and so forth? And so sovereignty is a quality which people need to take into consideration with all the other things that they take into consideration like security, resilience, and so on and so forth. And so sovereignty is just another quality that needs to be considered when you are planning your and choosing your cloud service. Okay.
Well, since there's no more questions and it's already 5.55, we're going to put an end to this webinar. I want to thank you all different participants from different European countries for being there. And thank you once again, Mike, also for your presentation. It was really, really interesting. And I don't know if you have maybe one last word for the participants on your side.
Well, I'd just like to say thank you very much for your attention. And I do hope that you will look at our websites and read our research in this matter, because I'm sure it can help you in your everyday business. And I'd like to thank InCyberForum for inviting me to this presentation. Thank you very much. Yes. And I would like to add that Mike's paper also, which is really interesting is also on the Kippinger Call website. And there will also be the recording of this session on the Kippinger Call website also. And I will send you also the slides later on when the presentation is finished.
So thank you all and see you next time. Okay. Thank you. Bye-bye. Bye-bye. Bye-bye.
See All Locations
See All Locations