Data Sovereignty Starts at the Hardware Layer
Table of contents
The Paperwork Layer
Europe spent 2026 writing sovereignty into law. On June 3, the European Commission adopted the Cloud and AI Development Act, a four tier framework that effectively bars US hyperscalers from the most sensitive government workloads. Worldwide sovereign cloud spending is forecast to hit $80 billion this year, with European spending up 83% year over year. In April, Brussels awarded a €180 million cloud contract with explicit sovereignty criteria for the first time in procurement history.
All of it is built on a premise nobody wants to say out loud: that sovereignty is something you can write into a contract.
It is not. Data sovereignty starts at the hardware layer, and almost nobody in this market controls the hardware layer. Not the EU. Not the sovereign cloud vendors. Not you. Until that changes, most of what is being sold as sovereignty is jurisdiction theater with a data center address.
One Email Account Ended the Debate
If you want to know where control actually lives in the stack, look at what happened to Karim Khan.
In February 2025, the US sanctioned the ICC chief prosecutor by executive order. Shortly after, Khan lost access to his Microsoft email account and moved to Proton. Microsoft disputes who pulled the trigger, but the mechanics are not in dispute: an American legal instrument reached into the digital life of an international court officer in The Hague and switched it off. The Dutch government started reassessing its entire digital infrastructure within weeks. The ICC began moving away from Microsoft.
Notice what did not matter in that story. Where the data was stored did not matter. GDPR did not matter. The ICC's legal immunities did not matter. What mattered was who controlled the account plane, the identity plane, and ultimately the machines underneath them. Control sits at the lowest layer someone else operates for you. Everything above it is a permission you have been granted, and permissions can be revoked.
Sovereignty Washing Is a Business Model
The hyperscalers read the room and responded with products. AWS European Sovereign Cloud, run from Germany. Microsoft, Google, and Oracle followed with regional structures, EU staff, EU boards, EU logos. CISPE, the European cloud association, has a name for this: sovereignty washing. Their argument is the correct one. Sovereignty is defined by control, not by presence. A US headquartered company operating an EU sovereign region is still subject to the CLOUD Act, which compels US providers to produce data regardless of where it physically sits.
This is not a hypothetical reading of the law. Microsoft's own representatives testified before the French Senate in 2025 that they could not guarantee French data would never be handed to US authorities. That is the honest answer, and credit to them for giving it under oath. Every sovereign branded offering from a US provider carries the same asterisk, whether the marketing admits it or not.
The industry lobby's response to the EU framework tells you the rest. The CCIA called the strict tiers a market shutdown dressed up as policy. Translated: the only tiers that provide real sovereignty are the ones we structurally cannot satisfy. That is not an argument against the framework. That is the framework working.
Now Go One Layer Down
Here is where it gets uncomfortable for Europe, because the same logic that demolishes sovereign cloud marketing also demolishes the EU's own plan.
The EU is putting €20 billion into AI gigafactories, part of a €200 billion InvestAI ambition. Per CEPS analysis, every planned gigafactory runs on Nvidia chips. Nvidia powers roughly 80% of global AI training workloads. The gigafactories will sit on European soil, behind European law, operated by European entities, and every single one of them boots on silicon designed by an American company, manufactured by TSMC in Taiwan, lithographed on ASML machines, and updated by firmware signed with keys Europe does not hold.
A sovereign data center full of someone else's silicon is a colony with good intentions.
And the silicon itself is not neutral. The current kill switch debate in Washington is the most clarifying policy discussion in years. US lawmakers have proposed mandatory location verification for export controlled AI chips. Nvidia has publicly insisted there are no backdoors, no kill switches, and no spyware in its GPUs, while simultaneously shipping an optional location verification service to fight smuggling. I take Nvidia at its word. But step back and look at what the debate itself proves: the question of whether a vendor or a government can reach into your accelerator fleet is being negotiated in a legislature you do not vote in. Whether the answer today is no is almost beside the point. The decision is not yours, and sovereignty is precisely the question of whose decision it is.
The Root of Trust Is Someone Else's Root
Go down one more layer and the picture gets worse, not better.
Modern platforms anchor their security in a hardware root of trust. On Intel systems, that anchor is CSME, which loads and verifies all other firmware before your operating system exists as a concept. SGX attestation, the technology underpinning confidential computing, chains back to root secrets controlled by Intel. When a confidential computing vendor tells you not even the cloud provider can see your data, the full sentence is: not even the cloud provider can see your data, assuming you trust the chip vendor's keys, signing infrastructure, and microcode pipeline, none of which you can audit and all of which answer to a foreign legal system.
This is not paranoia about hidden backdoors. Documented vulnerabilities in Intel's boot ROM have shown that whoever compromises the lowest layer can forge everything above it in ways the authenticity checks cannot detect. The lesson is not that the hardware is malicious. The lesson is that the hardware is decisive. The root of trust is exactly what it says: the root. Whoever holds it holds the tree.
China internalized this a decade before Europe did. The export controls of 2022 did not push Beijing toward better contracts; they pushed it toward CXMT, SMIC, and Huawei silicon. I covered the cost of that path in my CXMT HBM3 teardown: China is years behind and burning billions, and it is doing it anyway, because it concluded that sovereignty you cannot fab is sovereignty you do not have. You do not have to admire the regime to recognize the engineering logic. Meanwhile, as I wrote in the PCB resin supply chain teardown, a single missile strike on one resin plant rippled through the global electronics supply chain in weeks. The hardware layer is not an abstraction. It has coordinates.
What Sovereignty Actually Requires
So what would taking the premise seriously look like? Not autarky. Nobody fabs alone; even TSMC stands on ASML, Zeiss optics, and Japanese photoresists. Sovereignty at the hardware layer is not about making everything yourself. It is about holding the decisive points: the keys, the firmware, the attestation roots, and credible second sources for the silicon.
Concretely, for Europe, that means procurement rules that score who signs the firmware, not just where the data sleeps. It means RISC-V and European accelerator programs funded like they matter, because an open ISA is the only path to silicon whose roadmap is not a foreign policy variable. It means attestation infrastructure where the root keys are held by European entities, so confidential computing stops being a trust-me product. And it means treating the gigafactories' Nvidia dependency as a bridge with an explicit exit, not a foundation.
For everyone else, the checklist is shorter and harsher. Map your stack from the account plane down to the boot ROM and mark every layer where someone else holds the keys. That mark is your actual sovereignty boundary. Everything above it is yours on sufferance. The Khan case showed how fast sufferance evaporates: one executive order, one switched off mailbox, no appeal.
Physics Beats Paperwork
The sovereign cloud market will hit $80 billion this year selling the idea that law can overrule physics. It cannot. Jurisdiction is a layer, and it sits far above the silicon. When the layers disagree, the lower one wins. It always wins.
Data sovereignty starts at the hardware layer. Not because the hardware is where the data lives, but because the hardware is where the decisions live: what boots, what attests, what updates, what switches off. Own those decisions or be honest that someone else does. The contract you signed does not change the answer. It just changes how surprised you will be when you find out.