The cloud has become as essential as roads and water. Why is it owned by commercial foreign actors? An invisible layer of cloud infrastructure underpins modern life.
Do you use the cloud? You probably do — even if you don’t realize it.
For most people not working in IT, the cloud is an intangible concept. The cloud is the foundational layer of modern society. Public services, government institutions, banks and public transport rely on cloud platforms, but also everyday technologies: your phone, laptop, website, apps, smart home devices—all constantly interacting with the cloud.
In essence, the cloud means renting someone else’s data center. Instead of each organization maintaining its own servers, companies now rent computing power from global platforms. Over time, this evolved further; you can now rent not just raw computing resources, but also the software and infrastructure that run on them.
That simple shift — from ownership to dependency — changed everything. Recently, this intensified with the rise of Generative AI — systems like ChatGPT, Gemini3, and Mistral all require enormous data centers to function. And it’s not just people using these tools anymore: much of the software we depend on is now quietly powered by Generative AI as well. Automation, personalization, and even decision-making are increasingly driven by AI models that live — and learn — in the cloud.
We don’t control that cloud. Almost all of the infrastructure we rely on runs on American cloud giants: American hyperscalers. These companies benefit from enormous economies of scale, and integrate open source innovations into cohesive, high-performance platforms. European cloud infrastructure is dominated by these hyperscalers, with 90% of EU data hosted on US-based providers (European Parliament, 2025). They are marvels of engineering — but they are not ours. They have commercial priorities, answering only to their shareholders, not to EU citizens. We lose not just technical control, but democratic oversight.
This dependence carries legal and political risks. The U.S. CLOUD Act (Clarifying Lawful Overseas Use of Data Act) gives American authorities the right to demand access to data held by U.S.-based companies, even when that data is stored abroad. Information hosted on American cloud platforms may fall under U.S. jurisdiction — regardless of European privacy laws (such as GDPR).
The United States allegedly pressured Microsoft to restrict access for the International Criminal Court — an example of how geopolitical leverage can extend deep into digital infrastructure (Politico, 2025, AP News, 2025). Control over data is not merely technical, but political.
If control over the cloud has become a question of power, then we should treat it like other critical infrastructure: as a public good.
Cloud infrastructure has reached the threshold where it requires democratic safeguards that commercial platforms cannot provide. Nearly every citizen interacts with cloud infrastructure, often unconsciously — mobile apps, online banking, healthcare portals, and government websites all run on cloud platforms. But today's cloud is fully operated by commercial actors with global reach and zero obligation to citizens. We wouldn't accept this from our road network or national archives. We shouldn't accept it for the digital infrastructure that underpins them all.
This concern is especially pressing with the rise of Generative AI. The Dutch Ministry of the Interior (BZK) recently released a national position that encourages experimentation with Generative AI in the public sector — but only with strong guarantees around public values, privacy and responsibility (government.nl). These guarantees mostly rely on legal contracts with commercial providers. A sovereign cloud platform would provide the technical foundation to enforce those guarantees, not just write them down.
The commercial cloud market works, but not in the interest of citizens, public agencies, or long-term resilience. We have no control over commercial conditions, and regulation alone cannot ensure autonomy. Public infrastructure also enables innovation: startups and SMEs often can't afford enterprise-grade cloud services. It could offer a discount in return for shares, thereby both fostering innovation and its own funding. This reinvests public-private success into shared digital infrastructure, similar to the Dutch academic patent model.
We do not need to reinvent the wheel. The industry standards for cloud computing — Kubernetes, Postgres, Apache Airflow — are already open source. The challenge is not invention, but operation. We need a European infrastructure that provides these standard tools as a reliable utility, stripping away the proprietary lock-in of American hyperscalers.
Sovereignty, fairness, and innovation aren't competing ideals — they are interdependent. Each guards a different dimension of resilience. Together, they form the rationale for treating the cloud as a public utility.
The EU consumes AI technology at scale, but produces little of the infrastructure that enables it. This infrastructure gap creates a structural dependency; Europe has strong AI adoption and research, but lags in developing foundational infrastructure. We pay for these services, funding further infrastructure development abroad, increasing our dependence.
The Netherlands is home to ASML, the world’s leading supplier to the semiconductor industry, yet Europe does not produce a relevant amount of the chips it needs. Even the presence of companies like Nexperia, with an HQ in the Netherlands (NOS, 2025), cannot alter the fact that large-scale semiconductor production remains external to the EU. This lack of domestic capacity extends to cloud infrastructure — so much so that Nvidia, the single largest producer of chips for AI workloads, did not list the EU as a separate category in its quarterly report (Nvidia, 2024).
In 2023, the EU held just 12.7% of the global semiconductor market. The EU Chips Act aims to double this share by 2030 to strengthen Europe’s technology ecosystem and reduce reliance on external suppliers. Yet, even with 53% of global AI leadership (mainly in B2B applications), the EU controls only a fraction of global semiconductor fabrication capacity—the hardware backbone of AI compute.
Almost half of companies spend between 6-10% of their revenue on cloud cost (CloudZero Cost benchmark), a cost split between infrastructure and software costs. This is only projected to get higher, with additional AI cost estimated at 5% of revenue for larger companies (Computer Weekly). These costs represent a structural drain; much of the economic value leaves the continent, via either the infrastructure it pays for or the software it runs on — representing capital flight and lost reinvestment capacity (DigitalEurope Critical Tech Gap Report, 2024; Frontier Economic Security Report, 2024).
National governments are increasingly integrating AI into public infrastructure. In the Netherlands, agencies now use Generative AI for administrative tasks such as permit approvals and citizen inquiries. However, with limited domestic infrastructure, many rely on international suppliers like OpenAI, often deployed via Microsoft Azure—the platform that also underpins most Dutch government cloud services (Rijksoverheid, 2025).
In response to sovereignty concerns, many American hyperscalers now offer "Sovereign Cloud" packages or promise that European data will stay in European data centers. This is a comforting illusion, but legally insufficient. In the world of cloud computing, geography is not jurisdiction. Even if your data sits physically in a data center in Eemshaven or Middenmeer, if the company managing that server is a subsidiary of a U.S. corporation, it falls under the extraterritorial reach of the U.S. CLOUD Act. The U.S. government can compel access to that data, bypassing European courts entirely. True sovereignty requires that the operator—not just the server—be under European jurisdiction.
Europe's regulatory approach has long centered on what technology may do, not where it runs. The EU must invest in the physical and digital backbone that allows those rules to function. New regulatory frameworks increasingly compel EU-based companies to localize their technology stacks. The AI Act, AI Liability Directive, Digital Fairness Act, and Digital Networks Act all introduce new compliance layers for organizations relying on international infrastructure.
While these regulations aim to foster data sovereignty and trust, they also create additional costs and operational burdens that U.S. and Chinese competitors do not face. From both an economic and fairness standpoint, if EU companies are required to comply with these localizations, the EU must provide the corresponding infrastructure to make compliance feasible and competitive.
Large-scale infrastructure development is both possible and necessary on an EU-wide scale. Data centers and compute resources directly improve Europe's capacity to develop and scale critical technologies. Public–Private Partnerships (PPPs) enable collaboration between industry and government while spreading financial risk. They become more than funding tools — they are the bridge between policy and practice, aligning public accountability with private capacity.
Existing EU initiatives demonstrate this model. EuroHPC, a joint undertaking composed of public and private members, coordinates supercomputing infrastructure. The EU Chips Act demonstrates PPP potential: of its €100 billion total, only €3.3 billion comes from EU-level funds, with the remainder contributed by member states — an effort intended to double Europe's chip production share to 20% by 2030. The EU's AI Factories Initiative aims to construct AI-specialized datacenters under the EuroHPC framework with a €1.5 billion budget for 2025, seeking €200 billion in total investments over seven years (European Commission, 2024).
At the national level, an opinion piece in de Volkskrant showed that localized AI infrastructure can shield academia and startups from economic uncertainty and dependence on foreign providers. The study proposed that an investment of €400 million—well above the current €45 million budget—would fund a national AI platform accessible to research, startups, and universities, reducing the long-term cost burden on the public sector (de Volkskrant, 2025).
The scale of investment elsewhere underscores the urgency. The U.S. Stargate Project pledges US$500 billion for AI infrastructure, building 20 datacenters through a PPP involving OpenAI, SoftBank, and Oracle—with no direct public funding (Washington Post, 2025).
The cloud is now critical national infrastructure. It's as vital as energy, water, or electricity. Relying on foreign platforms means exposure to policy shifts, pricing changes, sanctions or data access laws—as detailed earlier with the CLOUD Act and commercial dependency. Control, continuity and choice — those are the watchwords for digital sovereignty. The Netherlands already called for coordinated EU action on sovereign cloud technologies (Netherlands Digital Government, 2025).
The Dutch built flood defenses and energy grids for autonomy, for reliability, and for making sure everyone has access to critical infrastructure. The same is now true for cloud. Local control is required to reduce vulnerability to crises—cyberattacks, geopolitical tensions, or infrastructure failures.
Sovereign infrastructure underpins not just security, but trust. Citizens must know where their data lives—who controls it. The logic of the platform must be open, so that we can have our checks and balances. Scale from government and semi-public institutions will increase robustness across the entire system, something that the technology sector can then benefit from.
Critics might argue that a public cloud would lag behind hyperscalers in innovation and cost efficiency. That's true — at first. But public value isn't measured quarterly, and sovereignty compounds. By embracing open source software, innovation is kept at a level similar to what hyperscalers already do — embrace open source initiatives, integrate them into a cohesive whole, and market it as an innovation.
Sovereignty requires openness. Paradoxically, the most independent infrastructure will be built from global collaboration and open-source software — the very antithesis of national isolation. A sovereign cloud isn't about isolation — it's about accountability. Just as our dikes protect the land, an open, public cloud protects our data. This sovereignty requires more than openness—it requires technical autonomy.
Critics often worry about government surveillance. But unlike commercial 'black boxes,' a public cloud based on open source is a 'glass house.' The code, security protocols, and encryption standards are public. Trust isn't requested; it is verified. Citizens and watchdogs can audit the system to ensure the state provides the infrastructure, but the citizen retains the keys.
Legal safeguards can't enforce technical autonomy, because the data is still hosted on US servers. This autonomy is further undermined by the regulatory risks outlined earlier—the CLOUD Act and its geopolitical implications, as demonstrated by the International Criminal Court case. Regulation is reactive and slow; infrastructure should be proactive and strategic. You can't regulate your way into owning the electricity grid, you must build it.
Public infrastructure enables governance by design — not as an afterthought once regulation finally catches up with innovation. We need this technical layer of sovereignty, not just a legal declaration.
Sovereignty isn't achieved through paperwork — it's built, maintained, and shared. And we already have the tools to do it — open-source platforms, PPP frameworks, and the EuroHPC governance model.
Public clouds shouldn’t replace private ones — they should exist alongside them, giving citizens and governments a real choice. The goal isn't to dismantle hyperscalers, but to offer a transparent and accountable alternative. Public infrastructure benefits from healthy competition. If hyperscalers can do something better and cheaper, businesses should have that choice.
Democratically owned infrastructure protects long-term interests that markets, driven by quarterly incentives, often overlook. For hyperscalers, privacy too often feels like a hurdle rather than a principle. A public cloud would guarantee access to cloud infrastructure for our government and for our citizens. We want that access to be equal — no opaque deals between companies, but a clear and open structure.
Much like public libraries or public transport, this empowers the private sector by lowering cost and complexity of scaling new ideas. Through the innovation model outlined earlier, public infrastructure enables the government to share modestly in the success it helps create. That's different from the current model, where companies receive subsidies and later sell their innovations on the open market. Unlike past government investments in technology, this model ensures public returns.
But no country can achieve true digital sovereignty alone — our future cloud must be built on European collaboration. Reclaiming part of that public stake isn’t anti-market — it’s about ensuring that the next wave of innovation strengthens Europe’s digital foundations, not erodes them
Europe should lead the conversation on its own autonomous cloud infrastructure. The Netherlands can play a leading role — we are already home to open-source excellence. But we are not alone. France and Germany now host major European LLM developers such as Mistral and Aleph Alpha, while the EU funds pan-European model initiatives like OpenEuroLLM and OpenGPT-X. Both countries also have established cloud providers — OVHcloud, Open Telekom Cloud, and STACKIT — that offer a European alternative to the American hyperscalers. (Xomnia, 2025).
Even the European Court of Auditors has called for coordinated, EU-wide investment in shared AI infrastructure (ECA, Special Report 08/2024). A March 2025 joint declaration by the D9+ countries similarly urged the creation of shared digital infrastructure to support European startups (S9+ Declaration). "Without sovereign infrastructure, Europe experiences a steady value drain—public funds fuel private innovation abroad."
We are at a critical time in the evolution of data-related technology. We already handed control of our personal data to advertisers. Now we're facing the rise of Generative AI and text-based automation. If the time for the EU to lead on its own future isn't now—when?
EU and NL leadership must rest on a shared-ownership model — where public institutions and private innovators co-develop the foundations of digital sovereignty. A European public cloud should not only guarantee open, accountable access but also reinvest in the ecosystem it enables: government funding that earns its return through innovation, and innovation that strengthens the public infrastructure it relies on. The Netherlands can shape this reciprocal model, building on its open-source strengths and tradition of cooperative enterprise.
Europe's next research program should fund a federated public cloud prototype—governed under EU digital-sovereignty principles, co-managed by member states, and open-sourced by default. Just as we built dikes to protect our land from water, we can build clouds to protect our data—and our democracy—from dependence.
Author’s Note on AI Use
This post was conceived, researched, and argued by the author(s). Generative AI tools were used only for language refinement and structural editing. All factual claims, analysis, and conclusions are the author’s own, and all sources have been independently verified.
