When the CLOUD Act passed in 2018, most European CTOs treated it as a legal abstraction - something for the compliance team to worry about, somewhere between cookie banners and printer procurement. Eight years later, with the Schrems II ruling, NIS2 transposed into national law across the EU, DORA in force for financial services, and the Data Act's egress-fee provisions approaching, it's a board-level concern. Not because lawyers won an argument, but because the risk stopped being theoretical.

Let's define terms, because "sovereign cloud" has been marketed into mush. Real sovereignty means three separate things: data residency in EU jurisdictions, operational control by EU-headquartered companies, and legal protection against extraterritorial subpoenas. The marketing departments of US hyperscalers will tell you their European regions tick the first box. They are right. The other two are harder - and they're the two that matter when things go wrong.

What this looks like in practice: a hospital in Munich runs PACS imaging on AWS Frankfurt. The data never leaves Germany. Encryption at rest, EU support staff, the whole compliance package. But the operating company is a US Delaware corporation, subject to US law. A US court order can compel disclosure regardless of where the bytes physically sit. The hospital's lawyers know this. The hospital's board, increasingly, knows this too. This is the gap NIS2 and the Data Act are closing - slowly, imperfectly, but in one clear direction.

The regulatory timeline tells the story. Schrems II (2020) invalidated Privacy Shield and put every EU-to-US data transfer on legally shaky ground. NIS2 (national transpositions landing 2024-2025) made supply-chain accountability a board obligation with personal liability - you're now answerable not just for your own security, but for your vendors'. DORA (January 2025) did the same for financial services with teeth. The Data Act (with egress-fee provisions from 2027) attacks lock-in directly: the exit costs that made "we'll migrate later" a fantasy are being regulated away.

None of this means "stop using AWS." That's the strawman version of the sovereignty argument, and it fails on contact with reality - the hyperscalers are excellent at what they do, and most European companies will keep workloads on them for years. The serious version is about optionality: knowing exactly which of your workloads could move, where they could move to, and what it would cost - before a regulator, a customer's procurement team, or a geopolitical surprise forces the question on someone else's schedule.

That's where the European provider landscape gets interesting, because it's genuinely good now and mostly unknown. Hetzner offers price-performance that makes US-cloud bills look like a prank. OVHcloud runs one of the largest footprints in Europe with its own fiber and data centers. Scaleway ships a modern, developer-friendly stack from France. UpCloud delivers reliable compute from Finland. None of them is a drop-in AWS replacement across every service - but for the compute, storage, and network layers where most infrastructure spend actually lives, they are credible, often cheaper, and answer to EU law alone.

The honest obstacle isn't capability. It's operations. Every provider means another console, another API, another billing export, another set of security quirks to learn. A 30-person company can't staff a platform team per cloud - so they consolidate on one hyperscaler, and sovereignty quietly becomes something to revisit "next year," every year.

This is the actual problem Sencai exists to solve. A multi-cloud strategy - including a sovereignty strategy - is only real if a small team can operate it without drowning. One control plane across hyperscalers and EU-native providers, one place to see every resource and every euro, one audit trail that holds up when NIS2 evidence is requested: that's what turns "we should look at European providers" from a slide into a migration plan.

So here's the practical checklist we'd give any EU CTO for 2026. One: map which of your workloads are jurisdiction-sensitive - personal data, health, finance, government-adjacent - and which are commodity compute that could run anywhere. Two: ask your providers who legally operates each service, not where the servers are; the answers will surprise you. Three: price an exit for your top three workloads, because the Data Act is about to make that number negotiable. Four: run one real workload on one EU provider this year - not as a statement, but as an option you've actually exercised, with monitoring and backups and everything you'd demand anywhere else.

Sencai's position is simple: we ship a control plane that works across hyperscalers and EU-native providers (Hetzner, OVHcloud, Scaleway, UpCloud), and we let you decide where every workload lives. The control plane itself runs in the EU, operated by an EU company, with no US dependencies in the critical path. That's what sovereignty by default looks like: not a badge on a slide, but the freedom to put every workload exactly where it belongs - and to prove it.