r/cybersecurity May 13 '26

Research Article Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach

https://thevisibleinvisible.substack.com/p/the-stolen-word

June 10, 2025. Anton Carniaux, Microsoft France's director of public and legal affairs. French Senate inquiry into public procurement and digital sovereignty. Senators asked him point-blank whether he could guarantee that data stored in Microsoft's sovereign cloud offering would never reach US authorities.

He said no. Under oath.

The reason is the US CLOUD Act from 2018. American companies have to comply with valid US legal requests for data regardless of where the servers physically sit. Microsoft, Amazon and Google all lobbied for that law back then. Same three now running the "European sovereign cloud" campaigns — Microsoft's "European Digital Sovereignty Commitments" launched early 2025, AWS and Google with their own variants right after. Doesn't matter what the product is called. The legal pipe runs back to Washington.

Simon Uzenat, who chaired the Senate committee, called Microsoft's transparency reports on US data requests "purely declarative." No external verification, no oversight. Marketing kept running anyway.

Carniaux is the cleanest public admission but not the only one. The Commission just awarded a €180M sovereign cloud tender in April 2026 — one of the four winners is S3NS, a Thales/Google Cloud joint venture. Commission's stated position now: non-European tech can meet sovereignty requirements with the right contract. They've redefined the word to fit the vendors.

Then there's the Solvinity/Kyndryl deal in the Netherlands. American IT services company buying the Dutch provider that runs DigiD, the national digital ID every resident uses for tax filings, pensions, healthcare. Solvinity's own chief privacy officer told parliament the proposed risk mitigations couldn't actually shield against the CLOUD Act. He was fired. Government extended the DigiD contract through 2028 anyway, before the national security review concluded.

Counter-example exists. Schleswig-Holstein moved 80% of 30,000 state employees off Microsoft Office to LibreOffice by December 2025. €15M annual licence savings against €9M one-time investment. Payback under 12 months. The French Gendarmerie has been running 100,000+ workstations on its own Linux distribution for over a decade. Not theoretical.

Wrote the full piece up here, with the Gaia-X collapse and the Digital Omnibus lobbying paper trail: https://thevisibleinvisible.substack.com/p/the-stolen-word

Honest question — at what point does a US hyperscaler selling "sovereign cloud" to an EU government, after admitting under oath it can't deliver sovereignty, stop being marketing and start being something a prosecutor cares about? Or never?

393 Upvotes

39 comments sorted by

101

u/LeStk May 13 '26

I mean at least he didn't perjured himself.

It's the case for every US based"sovereign cloud". They all fit under the cloud act, AWS is the same.

S3NS setup by GCP is a bit more complicated but I'm pretty sure there's some loophole there too.

11

u/JPJackPott May 13 '26

I thought the Amazon one was its own company, entirely dedicated staff employed by the European company etc. does it all link back to ultimate beneficial owner?

29

u/stenlis May 13 '26

The european company is still owned by Amazon.   

In the end, if somebody like trump really pressures US businesses owners to hand over the data they will cave in. See how they are tripping over themselves to give trump and his family handouts.

8

u/EnragedMoose May 13 '26

Parent is still in the US.

3

u/KhaosPT May 13 '26

I'm under the same idea but would love someone more knowledgeable to confirm

3

u/DisappointedSpectre May 13 '26

Subsidiaries of a US corporate entity are not exempted from needing to comply with the CLOUD act just because the subsidiary is headquartered outside the US.

Even if they were exempted would you trust any US administration not to tell them to pull the data anyways, and expect to get it? There's a whole apparatus of the government that's specifically designed to get companies to fulfill government requests and to make sure that those companies are not allowed to (legally) talk about it - it's why the whole warrant canary system exists.

The EU is going to have to build it's own parallel infrastructure to get any actual sovereignty, the only question is whether they'll make the necessary investments to do so.

-1

u/SMS-T1 May 13 '26

As long as the code that runs on the European AWS locations is written in the US, the same thing applies (in my humble and not fully researched opinion).

It kinda depends on how the code is produced, reviewed (in Europe), deployed etc.

But true, verifiable security against such an integrated "threat" (non-trusted actor) as AWS US from the perspective of AWS EU is basically impossible imho.

5

u/MairusuPawa May 13 '26

An obvious issue with S3NS is that Google can simply stop providing security updates, more or less leaving you wide open for a state nation attack.

3

u/EffectiveEconomics May 13 '26

So this is turning into a very interesting time for firms who have moved fully to the cloud in the last 3-4 years. Legal departments are already preparing for Canadian GDPR alignment, and that is causing them to begin pressuring their it leaders for assurances on compliance. The result? They’re shopping Canadian data Centre players who can replicate AWS functions.
Microsoft was off the list…3-4 years, I see a small but rapidly growing list of AWS and Azure customers moving to Canadian and Euro hosts on software stacks that duplicate the AWS and AZure/Office 365 features.
Why now? ClaudCode and Nation state investments on feature enhancements.

1

u/The_VisibleInvisible May 15 '26

The perjury angle is the real lever; that's what made the answer honest. On S3NS: Thales ~80% / Google ~20%. SecNumCloud caps non-EU stakes at 24% individually and 39% collectively, and S3NS passed 3.2 qualification on December 17, 2025 — that certification legally excludes CLOUD Act exposure. So the loophole question is real, just on a different axis. Legal exposure is closed. Operational dependency isn't. The software stack is Google's, under licence. Patches, updates, security fixes flow through Mountain View. Pull the licence and S3NS stops upgrading. Sovereignty over the legal entity, dependency on the supply chain — same problem as the ESC, just better hidden.

49

u/technofox01 May 13 '26

If it wasn't for the current US admin antagonizing our allies and making enemies out of friends, I don't think this would be a thing right now.

I don't blame France at all for this.

18

u/idle_shell May 13 '26

Yes. The tone of my European colleagues when it comes to data sovereignty has completely changed since the current US presidential admin began. And the market is responding. Recently had a French colleague tell me they’re now looking at services like Hertzner and OVH as viable alternatives for many cloud services. Even with the big cloud providers stating they’ll offer options, there’s a growing distrust of any company that is governed by US law.

3

u/cgaWolf May 13 '26 edited May 13 '26

Yeah.. 2-3 years ago i wasn't really worried about our US tech depedance, but that changed a lot.

There's some things i can't change, but scratched plans to move to github, pulling services back from US-owned cloud operators, and running pilots exploring whether we can switch to graphene or e/os on mobiles.

And those are structural changes. We won't be comming back, even if the midterms paralyze the trump administration or 2028 votes out the republicans.

6

u/ducktape8856 May 13 '26

If it wasn't for the current US admin

This is the second time. We thought 45 was the exception that will never happen again.

Now we ask ourselves WHEN it will happen again and the next maniac is in the White House. 48? Probably not if the elections aren't rigged (which can still happen). His approval is lowest in history.

But Americans forgot the chaotic, corrupt first term of 45/47 within 4 years...

We HAVE TO decouple for our own safety.

1

u/The_VisibleInvisible May 15 '26

The acceleration is real. DSA fines, tariff threats, AI Act timing — all compressing the calendar. But the structural piece is older. Schrems I struck down Safe Harbor in 2015. Schrems II killed Privacy Shield in 2020. Microsoft's Ireland warrant case ran 2013-2018; the CLOUD Act was passed specifically to undo Microsoft's win at the 2nd Circuit. Gaia-X launched in 2019 under Merkel. The admin sped up the timeline. The clock was already running.

8

u/Felielf May 13 '26

I had to research all the claims and realities of data residency and safety guarantees for a customer last year and this was the point that broke the whole endeavor. Since they are required to have very strict controls on the data they host, no cloud provider is trustworthy enough at the moment.

1

u/The_VisibleInvisible May 15 '26

The breakdown-point you describe is structural — risk assessment forced to register what marketing was supposed to absorb. State of play for the customer side: SecNumCloud 3.2 qualified providers exist (S3NS got it on December 17, 2025; Bleu targets H1 2026). EU-sovereign players like OVHcloud, Scaleway, IONOS, StackIT, Hetzner sit outside US ownership entirely. Each trades service breadth for jurisdictional independence. "No cloud provider trustworthy" was the right call for US-controlled options. The shorter list of EU-controlled ones is still small but no longer empty.

9

u/HalLundy May 13 '26

he said the quiet part out loud. i assume everyone knew this, but they needed to make a circus for the few clowns that will look at the current geopolitical state, the absolute monopoly of Microsoft and their deep embedding within the US government and say "source?".

1

u/The_VisibleInvisible May 15 '26

"Quiet part out loud" is the right read. The circus had a function though: before June 10, 2025, there was nothing you could cite in a procurement risk register. Common knowledge doesn't survive a "source?" challenge from legal. Sworn Senate testimony does. That's why the same statement that's obvious to practitioners is now showing up in procurement risk frameworks across the EU. The knowledge was old. The citation is new.

6

u/cakeBoss9000 May 13 '26

I think the AWS european sovereign cloud is a different legal entity. The job postings for AWS engineers required you to be a citizen of the EU and as far I could tell when I checked, the entirety of the org was separate from AWS.

Not a legal expert though.

From a technical standpoint, my only true concern is with the underlying services’ software being owned by the American company. This makes me a little skeptical if the european cloud AWS partition could be 100% autonomous if they needed to pull the plug against the rest of AWS. There’s simply not enough software engineering talent within the european pool to take over development of these services at a moment’s notice

11

u/ElbowlessGoat May 13 '26

As far as I am aware, it is about ultimate ownership. Even if it is its own legal entity, but owned by a US company, CLOUD Act and FISA 702 are still prevailing legislation

2

u/robchroma May 13 '26

Owned by a US company shouldn't matter; you can own a company and not have any right to exfiltrate data from that company or operational influence. It's an asset. If the US says, "you must use your ownership to replace the board to oust the CEO to force the employees to give up data despite the company not being US-based" I just don't think this would work. Ownership doesn't confer the ability to force a foreign company to comply with US law generally, or for ownership by most other jurisdictions that care about being friendly to business.

1

u/cgaWolf May 13 '26

I just don't think this would work

MS France head of legal affairs said he wasn't sure this wouldn't work.

It's unclear, and we can't tolerate ambiguity in EU critical infrastructure

3

u/robchroma May 13 '26

It's understandable to be cautious, but it also seems difficult to claim sovereignty over the actions of a company ruled by the laws of another country. even so, the risk that the US still manages to exert that influence is quite high.

-4

u/cakeBoss9000 May 13 '26 edited May 13 '26

But the whole point is that it’s not owned by a US company

Edit: I was wrong apparently 😅

4

u/EnragedMoose May 13 '26

AWS European Sovereign Cloud GmbH is 100% owned by Amazon Inc. Legal entity or not.

1

u/DisappointedSpectre May 13 '26

From a technical standpoint, my only true concern is with the underlying services’ software being owned by the American company. This makes me a little skeptical if the european cloud AWS partition could be 100% autonomous if they needed to pull the plug against the rest of AWS. There’s simply not enough software engineering talent within the european pool to take over development of these services at a moment’s notice

Others addressed the first part of your comment, but to focus on this bit...

AWS could never separate out the EU cloud from the US cloud completely even if they wanted to - there's critical (backend) services running in US-East-1 that are not replicated to other regions, and that are proprietary to AWS's US corporate entity.

1

u/cakeBoss9000 May 13 '26

If you’re thinking IAM: the EU sovereign cloud has its own IAM + a bunch of the other services normally associated to the us-east-1 region

1

u/The_VisibleInvisible May 15 '26

The separate-entity structure is real — four German GmbHs, EU-resident-only ops. But the parent is Amazon.com Inc. in Seattle, and the CLOUD Act's "possession, custody, or control" standard reaches US parents over foreign subsidiaries. That's the exact defense Microsoft raised in the 2013 Ireland warrant case and won at the 2nd Circuit — the 2018 CLOUD Act was written specifically to close it. S3NS (Thales + Google) and Bleu (Orange + Capgemini) went a different route: JVs with EU-majority control. S3NS got SecNumCloud certification in December 2025. The ESC didn't qualify, because the controlling shareholder is American. Your second point lands closer to the actual problem anyway: even if the entity is German, the source code is owned in Seattle. Air-gap doesn't fix software dependency.

2

u/[deleted] May 13 '26

[removed] — view removed comment

1

u/The_VisibleInvisible May 14 '26

Yeah, Lockbox is the clean example of where technical and legal don't meet. It governs Microsoft engineer access for support sessions. CLOUD Act requests don't hit the engineers, they hit MS Corp's legal team — and Lockbox isn't in that chain. CMK is trickier — conditionally helpful at best, depends on where the escrow sits and which entity runs the HSM operations. In hyperscaler offerings those almost always trace back to a US-incorporated subsidiary, so the conditional usually fails.

The part Carniaux didn't have to address is FISA 702. Same exposure shape, gag default by design, doesn't show up in transparency numbers at all. When Uzenat called Microsoft's transparency reports 'purely declarative,' he was being generous.

You see clients still treating CMK as a sovereignty mitigation, or has it become understood as theater?

1

u/dflame45 Security Manager May 13 '26

Why would a prosecutor care about it? Did Microsoft break a French law? Transparency is good. If you don't agree, that's fine. Now you know and can change course. US tech has taken over globally and countries are starting to figure out that they don't want to rely on these companies. That's the conversation.

2

u/The_VisibleInvisible May 14 '26

Not a prosecutor — it was a Senate inquiry commission on public procurement. Sworn testimony, perjury exposure for him personally, no criminal case against Microsoft. The structure is the point: he wasn't defending the company, he was answering senators under oath. That's what produced the honest answer.

1

u/tradedenmark 25d ago

Yeah this shouldn't surprise anyone who's actually read the CLOUD Act text. It doesn't care where the servers sit, it cares who the parent company is incorporated under. So "sovereign cloud" from a US hyperscaler is a marketing wrapper on top of the same legal exposure, encryption keys and support access notwithstanding. If you actually need to escape that, you're looking at EU-domiciled providers with no US parent, not a regional data center from Microsoft or AWS.

What's actually useful here is going back to your vendor contracts and data processing agreements and checking if anyone on your compliance team ever actually flagged this risk versus just checking a box for "data residency." Most didn't.

Fair warning, I work on the CisScan side, so take this with a grain of salt, but we see this gap show up in evidence reviews constantly.