How DORA Made Sovereignty a Bank Problem

A green circuit board shaped like Europe represents bank cloud sovereignty. Copper traces mark borders, and electronic components mark cities.

I’ve heard variants of the same line from probably a dozen people in the last six months. A consultant I know has done more US-to-EU migrations this calendar year than in his entire career before. A founder on LinkedIn wrote the other day: Trump effectively has a kill-switch to our highly digitalised society, and the thought of that is frightening. None of those people would have used the word “sovereignty” in 2023. All of them now use it without explanation. For European banks, the Digital Operational Resilience Act (DORA) turns that language into an operating requirement.

Schleswig-Holstein is a German state with 2.9 million residents. By late 2025, it had moved roughly 80% of about 30,000 state workstations from Microsoft Office to LibreOffice. Linux pilots were also running, and the state targeted full migration for 2026 (The Register, 15 Oct 2025).

Airbus opened a tender for a sovereign EU cloud in December 2025. The system would host software for planning, manufacturing, customer management, and product development. The potential contract is worth more than €50M and could run for 10 years. Airbus’s executive vice president for digital gave herself only an “80/20” chance of finding a qualifying provider (heise online, 19 Dec 2025).

The International Criminal Court (ICC) left Microsoft Office for openDesk in October 2025. Germany’s ZenDiS developed the open-source suite (The Register, 31 Oct 2025). The move came about six months after the US government effectively cut access to the chief prosecutor’s Microsoft email under Executive Order 14203. A Just Security analysis traces the sequence. In February 2026, Microsoft asked the UK Parliament to “correct the record”.

The Dutch parliament passed five separate motions in March 2025 (Computer Weekly; Euronews, 20 Mar 2025). The first would remove DigiD from Kyndryl after its planned acquisition of Solvinity. The second called for a review of Amazon Web Services (AWS) hosting the .nl domain. The other motions would prioritise EU providers, require exit plans for all US-hosted systems, and tender a Dutch-controlled national cloud.

Microsoft responded with a datacenter expansion worth more than €40B. The plan would increase capacity by 40% across 16 EU countries. Microsoft also offered a contractually binding “court-fight clause.” Brad Smith pledged that Microsoft would sue the US government rather than comply with an order to suspend EU operations. Microsoft described the clause in its one-year update to the European Digital Commitments, published on 29 April 2026.

The European Commission is reportedly preparing a Tech Sovereignty Package for 27 May 2026. The package would combine the Cloud and AI Development Act (CADA) with a Chips Act 2.0. It would restrict member-state governments from using US cloud providers for sensitive public-sector data. The restrictions would cover healthcare, finance, and judicial systems (CNBC, 7 May 2026).

I also see the change in my day-to-day work. Every data or artificial intelligence (AI) project we ran with DACH banks in the last 12 months included digital sovereignty. DACH covers Germany, Austria, and Switzerland. Sometimes sovereignty was the agenda.

On 18 November 2025, the European Supervisory Authorities published their first list under the Digital Operational Resilience Act (DORA). It named 19 Critical ICT Third-Party Providers (CTPPs). Here, ICT means information and communication technology. The list includes AWS, Microsoft, Google Cloud, IBM, Bloomberg, London Stock Exchange Group, Tata Consultancy Services, and Orange (EBA press release). Each provider now faces direct EU oversight. Lead Overseers can impose a daily fine equal to 1% of average daily global turnover for up to six months.

Sovereignty has therefore become a regulatory deliverable with a last-test date. Two forces drove that change: four converging legal pressures and a shift in how decision-makers price political risk.

Diagram of selected DORA Critical ICT Third-Party Providers by headquarters. Five US providers are shaded orange, while three European and Asian providers use blue or grey.

DORA, cloud sovereignty, and the policy shift

The sovereignty debate in 2026 is no longer mainly about the General Data Protection Regulation (GDPR); that battle is six years old. Four legal pressures now collide. The market was willing to ignore that collision until 2024.

US laws reach EU-hosted data

The Clarifying Lawful Overseas Use of Data (CLOUD) Act compels US-headquartered providers to disclose data (18 U.S.C. § 2713). The duty applies “regardless of whether such communication, record, or other information is located within or outside of the United States.”

Microsoft’s transparency report for the second half of 2024 records 5,587 US law-enforcement demands for consumer data. Of those demands, 115 were warrants for content stored outside the US (Microsoft CSR Government Requests). In late 2024, Microsoft France told the French Senate that it could not guarantee non-transfer of EU-hosted data under a CLOUD Act order. Microsoft France had now put the conflict on the record.

Executive Order 14203 sanctioned ICC officials, including Chief Prosecutor Karim Khan. The order appeared in the Federal Register on 12 February 2025; Winston & Strawn published a separate legal analysis. Khan then lost access to his Microsoft email (Computer Weekly). Microsoft denied that it had actively cut him off. The ICC moved to openDesk anyway. The sequence remains disputed, but banks now have a concrete case to examine.

Congress reauthorised Section 702 of the Foreign Intelligence Surveillance Act (FISA) in April 2024. The Reforming Intelligence and Securing America Act (RISAA) extended it until 20 April 2026 (CRS R48592; Brennan Center §702 resource). Section 702 still allows warrantless collection from US “electronic communication service providers.” Those surveillance powers helped invalidate Privacy Shield in Schrems II (CJEU C-311/18, 16 Jul 2020).

The privacy group noyb plans a broader challenge to the EU-US Data Privacy Framework (DPF). It would bring the case before the Court of Justice of the European Union (CJEU). Its argument is that Executive Order 14086 supports the transatlantic data system. Any later US administration can rescind that order. The General Court upheld the DPF in Latombe (T-553/23, 3 Sept 2025, Hogan Lovells). An appeal filed on 31 October 2025 remains pending.

EU law pushes back

The Data Act applies from 12 September 2025 (Regulation (EU) 2023/2854). Article 32(1) requires data-processing providers to take “all adequate technical, organisational and legal measures… to prevent international and third-country governmental access and transfer of non-personal data held in the Union where such transfer or access would create a conflict with Union law.” Article 32(2) recognises a third-country order only when it is based on an international agreement in force with the EU or relevant Member State.

No EU–US CLOUD Act executive agreement exists. On paper, a US warrant for non-personal banking transaction metadata hosted in Frankfurt therefore creates a conflict that the provider must resist. A ban on switching charges begins in January 2027 and removes one source of structural lock-in.

The EU AI Act entered into force on 1 August 2024 (Regulation 2024/1689). Obligations for general-purpose AI (GPAI) applied from 2 August 2025. The threshold for a systemic-risk designation is 10²⁵ floating-point operations (FLOPs). Commission enforcement begins on 2 August 2026, and fines can reach 7% of global turnover. Meta declined to sign the GPAI Code of Practice, while OpenAI, Anthropic, and Google signed it. The European Commission has not yet settled compliance rules for the next generation of frontier models.

EU cloud certification remains unresolved

The European Union Agency for Cybersecurity (ENISA) drafted the European Cybersecurity Certification Scheme for Cloud Services (EUCS). Under industry pressure, it removed the “high+” sovereignty requirements in March 2024. Those rules required EU headquarters, staff, and jurisdiction. ENISA has not formally adopted a successor (ITIF analysis, May 2025). Hogan Lovells reports that France, Italy, and Spain are seeking to restore the requirements.

France’s national SecNumCloud standard already requires immunity from extraterritorial laws. S3NS, a joint venture between Thales and Google, received SecNumCloud 3.2 qualification on 17 December 2025. It was the first US-tech-backed sovereign cloud to receive that qualification.

DORA turns the issue into bank operations

The Digital Operational Resilience Act applied from 17 January 2025 (Regulation 2022/2554). The 19-provider CTPP list is its most visible operational result. Article 28 requires contractual exit strategies, while Article 30 specifies contracts for critical functions. Articles 31–44 give Lead Overseers direct EU-level authority. Lead Overseers can impose a daily fine equal to 1% of average daily global turnover for up to six months.

The European Central Bank (ECB) published its Guide on Outsourcing Cloud Services on 16 July 2025. It clarifies the expectations of the Single Supervisory Mechanism (SSM) for concentration risk and exit testing. It also treats audit rights as a continuous obligation rather than contract boilerplate.

The German Federal Financial Supervisory Authority (BaFin) uses several national rules. Its Supervisory Requirements for IT in Financial Institutions (BAIT) align German supervision with DORA. So do the Minimum Requirements for Risk Management (MaRisk), section AT 9. The ninth MaRisk amendment dates from June 2024.

The Swiss Financial Market Supervisory Authority (FINMA) has applied Circular 2018/3 since 2018. The technology-neutral circular permits foreign outsourcing only when inspection rights are enforceable in the host jurisdiction. BaFin’s March 2024 cloud guidance update sets the same expectations in German national practice.

Across DACH, DORA, the ECB Guide, BAIT and MaRisk, and FINMA Circular 2018/3 converge on three operational requirements. Banks need a documented and tested exit strategy. They need contractually enforceable audit access in the actual jurisdiction and a measurable concentration metric for ICT third-party providers. That combination has put sovereignty on every chief information officer’s agenda.

Flow diagram of US and EU laws that affect cloud services. Arrows lead to three bank requirements: an exit plan, enforceable audit rights, and a provider-concentration metric.

Opinion shift

The opinion shift is harder to quantify, and I think it is also harder to undo. The consultant I mentioned earlier put it plainly. These migrations are not about trusting Brussels more than Washington. They respond to a US administration that repeatedly showed it would weaponise commercial dependencies against allies.

Two political events drove that response. The Microsoft and Karim Khan episode put a precedent on the record. The second was the threat to Greenland’s sovereignty. It included the January 2026 tariff escalation against Denmark (House of Commons Library CBP-10472). The Center for Strategic and International Studies (CSIS) called the Greenland crisis “the catalyst for European digital awakening” (CSIS, 2025).

In August 2025, Trump threatened substantial tariffs and export restrictions. He targeted countries with digital services taxes, the Digital Markets Act (DMA), or the Digital Services Act (DSA). A December 2025 Bloomberg report named Accenture, Siemens, and Spotify as possible targets for Section 301 retaliation. Together, those events removed the remaining doubt about whether Washington would use the lever.

The well-meaning “Europe isn’t a sanctuary” objection misses the structure of the decision. On its own terms, the objection is correct. The EU has its own surveillance expansion. Examples include the European Parliamentary Research Service study on virtual private networks and recurring Chat Control proposals. They also include German Impressum rules, French identification rules, and the UK’s age-verification regime.

Stripe was founded by Irish brothers, but it is structurally a US company. ASML is technically Dutch. Yet its supply chain and intellectual property (IP) exposure put it within the US Foreign Direct Product Rule. In September 2024, the Dutch government moved to take over licensing for the NXT:1970i and 1980i deep ultraviolet (DUV) systems. The licensing decision shows that Dutch ownership does not remove US influence.

Proton, a Swiss privacy provider, has publicly threatened to leave Switzerland over the revised Ordinance on the Surveillance of Post and Telecommunications (VÜPF). It has also started moving physical infrastructure to Germany and Norway. Europe is not clean, but its marginal exposure remains lower than that of a US-controlled stack.

Europe in 2026 is trying to distance more than it is trying to grow. The sovereignty drive could produce fragmented and slightly worse versions of every layer in the stack. It might still fail to produce a competitive EU technology sector. The Airbus-A380 jibe captures the risk: “database in France, frontend in Belgium, ops in Spain.”

Airbus is doing fine. Schwarz Digits, the IT arm of Lidl and Kaufland, won the Dutch Central Bank’s cloud business from AWS. OVHcloud passed €1B in fiscal year 2025 revenue, with 9.3% like-for-like (LFL) growth. In September 2025, Mistral closed a €1.7B Series C led by ASML. It plans a Swedish datacenter worth more than $1B. The fragmentation critique is valid, but it does not justify stopping.

What I’d hold: DORA makes cloud sovereignty operational

I keep coming back to two extreme facts that coexist.

First, sovereignty is not a values play. It is a rational response to the US legal apparatus and the EU statutory framework. In 2025, the US showed that it would weaponise commercial dependencies. EU law now makes inaction increasingly non-compliant. The policy shift forces the conversation, while the opinion shift makes it stick.

Second, the supply side is underfunded by two orders of magnitude relative to the hyperscalers it is meant to replace. The EUCS process still cannot agree on what “sovereign” means. Most organisations will therefore move one partition at a time. The first contested CLOUD Act warrant against an EU-resident hyperscaler subsidiary will test that legal structure.

These migrations are not a bet that the EU is a sanctuary. They lower the conditional probability that a foreign government can use a provider to unplug a bank. That government answers to a different electorate. I see this as a structural risk, not a directional call. It has quietly made sovereignty the #1 agenda item of 2026.

№ 081 11 min AI, Investing Updated