GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
← Back to feed

EU's May 27 Tech Sovereignty Package Would Bar AWS, Azure, and Google Cloud From Government Health and Finance Data

Ten days from now, the European Commission is scheduled to adopt its “Tech Sovereignty Package” — and if the procurement preference clause survives intact, AWS, Azure, and Google Cloud face restricted access to Europe’s most sensitive government workloads.

The package, expected May 27, includes the Cloud and AI Development Act (CADA) and Chips Act 2.0. According to two Commission officials who spoke anonymously to CNBC, internal discussions are circling around a requirement that financial, judicial, and health data processed by public-sector organisations must use sovereign EU cloud infrastructure. US cloud providers could remain in government contracts for less sensitive work, but would be shut out of the high-value regulated tiers.

The Stakes

European government cloud is not a niche. Health, finance, and judicial workloads account for the bulk of EU public-sector IT spend — categories where AWS, Azure, and Google Cloud currently operate without restriction, provided they meet data-residency compliance rules.

The US Cloud Act complicates that picture. Under the 2018 law, American companies can be compelled to hand over user data regardless of where it is stored. European procurement rules have not previously treated this as a disqualifier. The CADA’s proposed framework would change that: sovereignty would be defined by who controls the infrastructure, not merely where the data sits.

Three sectors named explicitly in internal Commission discussions:

  • Financial data processed by public-sector organisations
  • Judicial records and case management
  • Health data held by government entities

What Clears the Bar

The CADA as drafted would introduce preferential procurement provisions for EU sovereign cloud providers — meaning governments would be required to choose European alternatives when they exist, or formally justify why they can’t. This is the commercially decisive clause.

For context: the Commission awarded €180 million in “sovereign” cloud contracts in April that included a Thales-Google partnership. European cloud providers immediately flagged this as “sovereignty washing” — a term borrowed from greenwashing, where the label applies but the underlying control does not. The CADA’s precision on control versus presence is meant to close that loophole.

The industry body CISPE, representing 29 European cloud providers, has published a framework demanding that sovereignty be defined by effective control, technology ownership, and protection from foreign jurisdiction — not cybersecurity certification alone.

The Risk: Package Could Arrive Declawed

The Tech Sovereignty Package has slipped twice. It was originally scheduled for March 2026, pushed to April, and is now logged for May 27. No Commission official has publicly explained either delay.

The substantive reason is a conflict between the CADA’s procurement preference clause and EU competition rules. The current competition commissioner has publicly opposed industrial-policy carve-outs that conflict with DG COMP sign-off requirements. If that interservice dispute is not resolved by May 27, the procurement preference clause will likely be dropped to meet the deadline — turning the CADA from enforceable industrial policy into a roadmap document.

The Chips Act 2.0 component faces a separate problem: Germany, France, and the Netherlands have not confirmed matched-funding shares for the proposed €10 billion Chips Manufacturing Fund. Without national commitments, the Commission cannot legally include state-aid amounts in the draft text.

Market Impact

AWS, Azure, and Google Cloud collectively hold the dominant share of European public-sector cloud contracts. If the CADA passes with its procurement preference clause intact:

  • Government health data systems requiring AI workloads (patient records, diagnostic inference, claims processing) would need to route through EU-certified providers
  • Financial supervisory bodies and central banks — already among the most regulated cloud buyers — would face mandatory European-first procurement
  • Judicial data, including case management systems where AI-assisted document review is growing fastest, would be restricted to sovereign infrastructure

The law would apply to public-sector organisations only. Private-sector companies are explicitly excluded from the current proposals.

Once presented by the Commission on May 27, the package requires approval from all 27 EU member states. Timeline to enforcement: likely 2027-2028 given the normal legislative cycle.

The European Cloud Landscape

The alternative to US hyperscalers remains fragmented. Providers like OVHcloud, Hetzner, IONOS, and national sovereign cloud initiatives vary significantly in capability, geographic coverage, and enterprise feature depth. The CADA’s procurement preference provisions are designed to accelerate consolidation and investment in that alternative stack — but only if the clause survives the political process.

The European Parliament had not assigned a rapporteur to the CADA as of late April, meaning Brussels enters May 27 without a formal Parliament counterparty in place. That institutional gap extends the timeline for any enforcement mechanisms to be finalised even after Commission adoption.


The Commission has a May 27 window. Every day the package slips further, the standards vacuum is filled by non-Commission actors — industry frameworks, bilateral national agreements, and US provider lobbying — that define sovereignty on their own terms.