Digital sovereignty and AI: when the cloud provider goes silent

On 10 June 2025, before the Senate's committee of inquiry on public procurement, rapporteur Dany Wattebled asked the director of public and legal affairs of Microsoft France, Anton Carniaux, whether he could guarantee that the data of French citizens would never be passed to the American authorities without the agreement of the French authorities. Under oath, he answered: "No, I cannot guarantee it", specifying that the case had never occurred. The answer is legally accurate and holds for any provider subject to American law. It also concerns companies that entrust a growing share of their work to AI services hosted by others.

Three ways of losing access to a service

Dependence on a provider shows itself in three ways. A technical outage makes the service unavailable for a few hours. A political or regulatory decision restricts access for certain customers, certain countries or certain uses. A unilateral change withdraws a model, revises a price or alters terms of use. The causes differ, the effect is the same for the customer, who suffers a choice made elsewhere.

The question has long been asked for files or email. It becomes more pressing with AI, because assistants slot into everyday tasks: answering customers, preparing quotes, sorting mail, proofreading contracts. The more the tool is integrated into the work, the more its stoppage shows.

Outages: CrowdStrike in 2024, AWS in 2025

On 19 July 2024, a faulty update to the security software of the vendor CrowdStrike crashed Windows computers around the world. Microsoft estimated the number of affected devices at 8.5 million, less than 1% of Windows machines. The proportion was small, but these machines were in companies that provide critical services, and banks, transport operators and airlines were disrupted. The US cybersecurity agency CISA issued an alert the same day; CrowdStrike published its root cause analysis on 6 August.

The incident did not involve AI. It shows that an update pushed remotely by a single provider can immobilise millions of machines within hours, at customers who had changed nothing on their side.

The second case concerns the infrastructure on which many AI services run. On 19 October 2025 at 11:48 pm Pacific time, Amazon Web Services' US-EAST-1 region, in Northern Virginia, began to malfunction. According to the account published by AWS, a latent race condition, that is, a defect that is triggered only when two processes act in a precise order, left an empty DNS record for the regional endpoint of the DynamoDB database. DNS is the directory that translates the name of a service into a network address: without this record, applications could no longer find DynamoDB.

The record was restored at 2:25 am, but the effects had spread to EC2 virtual machines, network load balancers, Lambda and other services that depend on them. The last was restored only at 2:20 pm on 20 October, about fourteen and a half hours after the start of the incident. AWS then disabled the automation in question worldwide and announced fixes.

The account is detailed, which is to AWS's credit. It also establishes that the cause was internal to the provider. No customer could have prevented it; the only protection available on their side was not to depend on a single region, or a single provider.

Decisions taken outside Europe

The main cloud and AI model providers are American and apply American law, including export controls and sanctions. On 15 January 2025, the Biden administration published a so-called AI diffusion rule, which established a global licensing regime for the export of advanced chips. It was to apply from 15 May. On 13 May 2025, the Department of Commerce announced its abandonment and promised new regulation within four to six weeks. Within four months, the conditions of access to advanced computing were written and then withdrawn by decisions taken in Washington.

Providers also set their own limits. On 5 September 2025, Anthropic changed its terms of use to refuse access to entities more than 50% owned, directly or indirectly, by companies established in countries where its services are not authorised, including China, Russia, Iran and North Korea, wherever they are located. The company cited legal and security reasons. The merits of this choice are not the subject here. It shows that a provider can redefine the list of its customers by a simple update of its terms.

A third case remains contested. In 2025, the agency AP reported that Microsoft had blocked the email of the International Criminal Court's prosecutor, Karim Khan, after the American sanctions targeting the Court. Microsoft's president, Brad Smith, replied that the company had neither stopped nor suspended its services to the Court. A spokesperson did, however, confirm that the sanctioned official had been cut off from Microsoft's services. What is established is enough: when an American sanction targets a person, an American provider applies it, including at an organisation based in The Hague.

Product changes: the withdrawal of GPT-4o

The third category is the most frequent and the least visible. On 7 August 2025, OpenAI launched GPT-5 and removed several previous models from ChatGPT, including GPT-4o. Existing conversations switched automatically to the nearest GPT-5 equivalent. In the face of protests, Sam Altman announced the very next day the return of GPT-4o for paying subscribers. On 12 August, the model was again in the selector by default, with a promise of sufficient notice before any future withdrawal.

The episode concerned the consumer app and was settled in five days. It nonetheless illustrates a point that matters to a business. A process built on a specific model, with instructions written and tested for it, quality checks and sometimes internal validation, depends on the availability of that version. When the model is hosted by a third party, the date of the change belongs to the third party. When it runs on a company machine, the company chooses the moment of the update and can test the new version before switching.

Cloud Act and GDPR: two laws in conflict

The American Cloud Act, adopted in March 2018, allows the American authorities to demand from a provider subject to their jurisdiction the data it holds or controls, wherever it is stored. The text also provides for bilateral agreements to frame these requests. According to the Department of Justice, two have been signed, with the United Kingdom in 2019 and with Australia in 2021. Negotiations are open with Canada and the European Union.

In 2019, the European Data Protection Board and the European Data Protection Supervisor published a joint assessment of this text. They note a risk of conflict of laws. Article 48 of the GDPR, the European regulation on personal data, allows a request from an authority of a third country to be acted upon only if it is based on an international agreement, such as a mutual legal assistance treaty. An American provider that receives a request based on the Cloud Act may therefore find itself caught between two contradictory obligations.

This is what the answer given to the Senate described. Anton Carniaux added that, according to the transparency reports that Microsoft publishes twice a year, no European company had been affected by such a request, but that a regular and well-founded request would oblige the company to hand over the data.

Transfers of personal data to the United States have rested since 2023 on the Data Privacy Framework, an adequacy decision of the European Commission. On 3 September 2025, the General Court of the European Union dismissed the action brought by French member of parliament Philippe Latombe and confirmed the validity of this framework. The member lodged an appeal before the Court of Justice on 31 October 2025. To our knowledge, at the date of publication of this article, the Court has not yet ruled. The General Court recalled that the Commission must continuously monitor developments in American law and may suspend, amend or repeal its decision. The two previous frameworks, Safe Harbor and Privacy Shield, were invalidated in 2015 and 2020. A critical process that assumes this legal basis will no longer move relies on an assumption that recent history has not confirmed.

AI Act: a shifted timeline, a documentation obligation

The European AI regulation entered into force on 1 August 2024 and applies in stages. Prohibited practices have been prohibited since February 2025. The obligations of providers of general-purpose models, such as large language models, have applied since August 2025. For so-called high-risk systems, a simplification regulation, the AI omnibus, which entered into force on 27 July 2026, postponed the deadlines. According to the European Commission, they fall on 2 December 2027 for the uses listed in Annex III of the regulation, which covers employment, education and critical infrastructure among others, and on 2 August 2028 for AI built into products that are already regulated.

For a company that uses AI without developing it, the practical effect is documentary. It will need to know which system it uses, for what purpose, with what documentation from the provider, and be able to show it. Documenting a system that one operates oneself, whose version and activity logs one knows, is simpler than reconstructing this information from what a provider agrees to publish.

SecNumCloud and the European cloud sovereignty framework

France has the SecNumCloud standard of ANSSI, the national cybersecurity agency. It qualifies so-called trusted cloud offerings, with the stated aim of protecting sensitive data and processing against the cybercriminal threat and against the application of extraterritorial laws. Recommendations published by ANSSI on 9 July 2024 specify in which cases to use a qualified offering to host sensitive information systems.

At European level, the Commission announced on 10 October 2025 a tender of €180 million over six years, intended to allow the Union's institutions to buy sovereign cloud services from at most four providers. Bids are assessed against a cloud sovereignty framework with eight objectives, including legal sovereignty, supply chain transparency, technological openness and compliance with Union law.

These schemes target public administrations first. They nonetheless indicate the method adopted by the public authorities: sovereignty is broken down into verifiable criteria, applicable to any purchase. An SME can take inspiration from them for its own AI services without aiming for qualification.

What a local infrastructure changes, and what it does not

Running a model on a machine installed on one's own premises, or in a data centre that is chosen and under contract, does not remove the risks. A power cut, a disk failure or a configuration error remain possible. The point of failure changes place: it lies within the company's perimeter, covered by its backups, its uninterruptible power supplies and its service providers.

Four elements, however, cease to depend on a third party. First availability: an outage in an American region does not stop a tool that runs on the internal network, including when the internet connection drops. Then stability: the model version changes on the chosen date, after testing. Jurisdiction: data processed on a machine that the company owns and operates is not in the hands of a provider subject to a foreign order, and its location is easily demonstrated under the GDPR. Finally cost: a depreciated machine does not see its usage price revised by a third party.

The counterpart is well known. The models that can run on a local machine are smaller than the most powerful models offered by the large providers, and the company must handle operations or entrust them to a service provider. The choice is therefore made task by task.

Using the cloud without depending on it

The useful distinction contrasts depending on a service with using it. A company depends on a service when it can no longer work without it. It uses it when it does so because it brings something, knowing how to do without.

In practice, this means classifying tasks. Contracts, customer files, health data or manufacturing secrets are handled internally. Searches on public information and drafts with no sensitive data can go to a remote model, if the contract with the provider allows it. Everyday work runs locally, and calling an external model becomes an option.

Three mechanisms make this split workable. A single gateway to the outside applies the classification rules and keeps a record of every transfer. The architecture makes it possible to change provider or model without rebuilding everything. A degraded mode, tested at regular intervals, means that an outage of the external service results in less elaborate answers rather than a stoppage. This is the application to AI tools of an old rule of business continuity plans: every function judged critical has a fallback solution, whose operation is verified before it is needed.

Measuring your dependence

Outages, political decisions and changes of terms have one thing in common: the customer company can neither foresee them nor negotiate them when they occur. It can, beforehand, draw up the list of tasks entrusted to an external AI service, estimate what a day of interruption would cost for each, and decide which ones must be able to continue on a machine it controls.

HOMN builds boxes intended for this last category: machines installed on the company's premises, which run the models on site. Whatever equipment is chosen, the inventory takes a few days of work. The AWS outage of October 2025 lasted fourteen and a half hours.

Does the Cloud Act apply to data stored in Europe?

Yes, when it is held or controlled by a provider subject to American jurisdiction. The 2018 Cloud Act allows the American authorities to demand it wherever it is stored. On 10 June 2025, Microsoft France stated before the Senate that it could not guarantee that data of French citizens would never be handed over.

What does digital sovereignty mean applied to AI?

It is the ability of an organisation to decide where its data is processed, which model it uses and when it changes, without depending on an outside decision. It is assessed by criteria: the provider's jurisdiction, the location of processing, the possibility of changing provider, operation in the event of an outage. The cloud sovereignty framework published by the European Commission in October 2025 sets out eight.

When does the AI Act apply to high-risk AI systems?

Since the AI omnibus entered into force on 27 July 2026, the obligations apply on 2 December 2027 for the uses listed in Annex III and on 2 August 2028 for AI built into regulated products. Prohibited practices have applied since February 2025 and the rules on general-purpose models since August 2025.

How do you ensure business continuity if a cloud AI service goes down?

By listing the tasks that rely on this service, estimating the cost of an interruption for each and providing a degraded mode for the most critical. A model run on a local machine can provide this degraded mode. It must be tested regularly, and not only planned on paper.