• Blog
  • Quo Vadis Europe? A continent between hyperscaler cloud and the desire for digital sovereignty

Quo Vadis Europe? A continent between hyperscaler cloud and the desire for digital sovereignty

European providers now hold only around 15 percent of their home market. Why digital sovereignty is not a question of location but an architecture decision – and how organizations can approach it in practice.

Kommunikationstechnologie im globalem Internet
Jonathan Bauer

Jonathan Bauer

CEO FC-X

The article classifies the sovereignty debate: Why it cannot be answered with the question of server location, which regulations now apply, and how organizations come to a robust own position.

The article classifies the sovereignty debate: Why it cannot be answered with the question of server location, which regulations now apply, and how organizations come to a robust own position.

At a glance

  • European providers now hold only around 15 percent of their own cloud market

  • Sovereignty is not a state, but a property of architecture – to be decided in stages and per application

  • The practical benchmark is not the location of the data, but the actual ability to switch

An uncomfortable starting position

The numbers are clear. According to surveys by the Synergy Research Group based on numbers for 2024, the share of European providers in the European market for cloud infrastructure has fallen from 29 percent in 2017 to about 15 percent. The three major US providers account for around 70 percent of the European market; the largest European providers each account for around two percent. European providers have significantly increased their sales during this period – the market just grew much faster.

In parallel, the political assessment of this dependency has fundamentally changed. What was long considered a question of efficiency is now discussed as a strategic risk: access possibilities from third countries, geopolitical vulnerability, lack of negotiating position, price and license developments without a real alternative.

The regulatory framework is becoming more concrete

The European response has so far been less about their own providers and more about rules. Two developments are directly relevant for organizations.

Since September 12, 2025, the switching regulations of the EU Data Act apply. Providers of data processing services must actively facilitate switching: with a notice period of no more than two months, a subsequent transition period of basically 30 days, open interfaces, support for export, and the goal of functional equivalence. Switching fees may already only be charged on a cost basis; as of January 12, 2027, they will be completely eliminated.

In addition, there is the Cloud and AI Development Act, with which the EU Commission aims to strengthen European cloud and AI capacity. Among other things, it provides for a significant expansion of data center capacity, a joint procurement framework for public administrations and – particularly relevant in practice – a unified sovereignty framework with graded assurance levels. These range from pure data retention in European infrastructure to complete control without the influence of third countries.

This very gradation is the real progress in the debate.

Sovereignty is not a yes-or-no question

The widespread dichotomy "hyperscalers or sovereignty" is misleading. Sovereignty is not a label that a provider carries, but a property that is decided by concrete questions:

  • Where is the data located – and where is it processed and secured?

  • Who operates the service, and under which law does this organization fall?

  • Who owns the cryptographic keys, and who can access them administratively?

  • How transparent are the supply chain, updates, and subcontractors?

  • How quickly and at what cost could the service actually be replaced?

These questions can be answered differently per application – and that is precisely the pragmatic approach. A website, a development environment, and a professional procedure with personal or classified data have different requirements. A uniform level of sovereignty for the entire portfolio is expensive, slow, and usually unjustifiable.

Even the much-discussed sovereign offerings of international providers can be evaluated so soberly: They significantly raise the level in individual dimensions – such as location, operating personnel, or key management. Whether they completely exclude an access possibility from the country of origin is another and much more difficult question to answer. Separating the dimensions leads to a reliable decision, instead of trusting a promise.

What organizations should do now

Integrationsanleitung

Differentiate protection needs

Classify applications and data by criticality, instead of deciding across the board.

Icon Webhook

Map dependencies

Make services, subcontractors, license models, and proprietary interfaces transparent.

Icon medizinische Information

Set sovereignty goals

Define a target level per application – from data retention in the EU to full operational sovereignty.

Icon Schild

Test exit capabilities

Describe not only switching scenarios but also play them out with a real service.

Icon Datenbasis

Adjust contracts

Actively demand the rights from the Data Act regarding portability, deadlines, and fees.

Trainingsmodel

Embed architectural principles

Set open formats, standardized interfaces, and own key sovereignty as a standard.

Frequently asked questions

Conclusion

Europe will not quickly regain the market shares of the past ten years. But that is not the decisive factor. What matters is whether organizations know their dependencies, consciously accept them, and can dissolve them if necessary. Sovereignty does not arise from choosing a provider, but from architectures, contracts, and competencies that make a choice possible in the first place. Those who invest today in transparency and the ability to switch do not buy independence – but room for maneuver. And that is currently the scarcer commodity.

How we support

The FC-Gruppe helps organizations turn the sovereignty debate into a decision: taking stock of cloud and software dependencies, analyzing protection needs and target images, assessing sovereign operating models, exit and migration concepts, as well as contractual and technical implementation. Contact us if you would like to determine your position.

Written by Jonathan Bauer

More On This Topic

Realise projects with us?

Speak directly with our experts.

FC-Gruppe GmbH

Administration
Contact Data

Am Storrenacker 8 76139 Karlsruhe