Your UK cloud region still answers to Washington

October 6, 2026

Your UK cloud region still answers to Washington

October 6, 2026
Your UK cloud region still answers to Washington

TL;DR

  • UK MPs warn that the US CLOUD Act gives Washington a "kill switch" over public sector cloud, where AWS and Microsoft take up to 80% of the spend.
  • A UK region does not change who the provider answers to, because the CLOUD Act covers handing over data and US sanctions cover switching services off, which the ICC has already lived through.
  • You can't leave the hyperscalers overnight and most of you shouldn't, but you should know what breaks if your account disappears, hold your own encryption keys and keep a copy of your data outside US jurisdiction.

Over the weekend Bloomberg ran a piece quoting Chi Onwurah, who chairs the Commons Science, Innovation and Technology Committee, on what MPs are now calling "a strategic and economic vulnerability" in Britain's dependence on American cloud providers. The UK government spends around £1 billion a year on cloud and by her estimate AWS and Microsoft take up to 80% of it, and in her words the US CLOUD Act gives Washington a legal "kill switch".

I wrote about this back in February when I showed how easy it is to route traffic between two European cloud providers, and the contracts have carried on going to the US providers regardless. In the past year HMRC gave AWS a £473 million, ten year deal to move its tax systems out of its old data centres after a tender in which AWS was the only bidder, the Ministry of Defence signed a £400 million contract with Google Cloud and NHS trusts have been moving patient records as well. When Bloomberg asked, all three departments said their data sits in UK data centres, although none of them answered the question about the CLOUD Act.

Does a UK region protect you from the CLOUD Act?

It does not, because the CLOUD Act lets US authorities compel a US provider to hand over data in its "possession, custody, or control" no matter where it is stored (18 U.S.C. § 2713). The Act has been in force since 2018 and what matters under it is who owns the company running the data centre.

The French worked this out some time ago with their national Health Data Hub, which was built on Azure in 2019 and, after years of pushback from their data protection regulator, is moving to Scaleway in a migration that should finish by early 2027. The HMRC contract goes the opposite way, as it was signed with AWS's Luxembourg subsidiary for UK data held in UK data centres, and none of that changes the fact that the parent company is American.

Is "kill switch" the right word?

I'm going to be the pedantic engineer here and say not quite, because the CLOUD Act is about disclosure and on its own it doesn't let anyone turn off your servers. That power comes from the sanctions regime, which was used in February 2025 when the US sanctioned the chief prosecutor of the International Criminal Court, and by May his Microsoft email account had stopped working. Microsoft says it never suspended services to the court, only to the sanctioned individual, but the ICC still decided to move roughly 1,800 workstations off Microsoft 365 and onto an open source suite.

That leaves us with two separate risks, where one is that someone reads your data without telling you and the other is that someone takes your service away. Both of them come from the same place, which is why a UK region doesn't fix either.

Which sectors depend most on the cloud?

To get a feel for how exposed each sector is I looked at Eurostat, which regularly asks EU companies what they buy from cloud providers. The survey doesn't ask which provider they use, but with three US companies holding around 70% of the European market I think it's a fair proxy.

Bar chart of cloud use by sector for EU enterprises with 10 or more employees in 2025, showing the share that buy any paid cloud service and the share that run their own software on cloud compute. Information and communication 83% and 48%. Energy supply 71% and 28%. Professional and technical 67% and 24%. Real estate 62% and 20%. Water and waste 59% and 12%. Manufacturing 54% and 11%. Admin and support services 52% and 15%. Wholesale and retail 51% and 15%. Construction 47% and 10%. Transport and storage 47% and 11%. Accommodation and food 40% and 9%. All sectors excluding finance 53% and 15%
Cloud use by sector across EU enterprises with 10 or more employees. Data: Eurostat isoc_cicce_usen2, 2025

The number I didn't expect was energy, where 71% of suppliers buy cloud services and 28% run their own software on cloud compute, which puts a piece of critical national infrastructure second only to the tech sector itself. Banks aren't covered by the survey, but UK regulators answered that one for us in July when they put AWS, Google, Microsoft and Oracle under direct oversight as critical third parties.

What breaks if your US cloud account is switched off?

When I talk to customers about this, most of them tell me they're multi-cloud or that they "could move if we had to", and then we sit down to list what runs on the provider and the answer usually turns out to be everything. I always start that exercise with the bill because it's the most honest inventory you have, and on AWS you can pull last month's spend by service straight from Cost Explorer.

aws ce get-cost-and-usage \
  --time-period Start=2026-09-01,End=2026-10-01 \
  --granularity MONTHLY \
  --metrics UnblendedCost \
  --group-by Type=DIMENSION,Key=SERVICE \
  --query 'ResultsByTime[0].Groups[].[Keys[0],Metrics.UnblendedCost.Amount]' \
  --output table

The billing exports from Azure and GCP will give you the same list, and once you have it you can go through it line by line asking whether the same thing could run somewhere else. In our experience these are the ones that hurt:

  • Identity. If your engineers log in through Entra ID or IAM Identity Center, losing the provider means losing the login to everything else as well.
  • Encryption keys. If the provider's KMS holds them then the provider holds your data, whatever the contract says.
  • Proprietary data stores. DynamoDB, Cosmos DB and Spanner have no drop-in replacement, whereas Postgres, Cassandra and Kafka run anywhere.
  • Backups. A backup kept in the same account goes when the account goes, so it doesn't count as a backup for this scenario.
  • The glue. DNS, CI/CD, secrets and observability SaaS are often US-owned too and nobody remembers them until they're gone.

What we would do about it

I don't expect anybody to move their whole estate off AWS next quarter, and for a lot of workloads I wouldn't recommend it anyway. What I would aim for is being able to leave if you ever have to, and making sure the data you care about most can't be held hostage in the meantime.

I would start by classifying what you run, because most of it isn't sensitive and it's only things like tax records, patient data and anything regulated that deserve a sovereign home or at the very least a sovereign copy.

After that I would take the encryption keys back using the External Key Store in AWS KMS or External Key Manager in Google Cloud, both of which keep the key material in a key manager you control outside the provider. It isn't perfect, because the provider still sees plaintext while it processes your data, but a disclosure order against stored data returns ciphertext and the decision to switch the keys off becomes yours.

I would also build on things that can move with you, and Kubernetes, Terraform and open source data platforms like Postgres, Cassandra, Kafka and OpenSearch all run the same on OVHcloud, Scaleway, Hetzner or IONOS as they do on AWS. The managed version of each is more convenient, but the open source version is the one you can take with you when you leave.

The last thing I would do is ship backups to a European provider on a schedule and, once a year, restore one of them there and bring a real service up on it so that you know the copy works before you need it.

Where this leaves us

Onwurah also said the UK is unlikely to build its own AWS and should work with France and Germany instead, which sounds realistic to me when OVHcloud made about €1 billion last year against AWS's $128 billion. Engineering teams don't need to wait for governments to sort that out though, because Kubernetes, Terraform, the open source data platforms and the European providers to run them on are all available today.

At Digitalis we run open source data platforms 24x7 on whichever cloud our customers choose, European ones included, and we help them plan the exit before they need it. If you'd like to talk it through, get in touch.

And if anyone in Washington is reading this, please don't switch off my email.

Frequently asked questions

Does storing data in a UK region protect it from the US CLOUD Act?

No, because the CLOUD Act, which has been in force since 2018, lets US authorities compel a US provider to hand over data in its "possession, custody, or control" no matter where it is stored (18 U.S.C. § 2713), so what matters is who owns the company running the data centre. HMRC's contract was signed with AWS's Luxembourg subsidiary for UK data held in UK data centres, and the parent company is still American.

Can the US government switch off a cloud service used in the UK?

Not through the CLOUD Act, which is about disclosure and on its own doesn't let anyone turn off your servers, but the US sanctions regime can. It was used in February 2025 when the US sanctioned the chief prosecutor of the International Criminal Court, and by May his Microsoft email account had stopped working, although Microsoft says it never suspended services to the court, only to the sanctioned individual.

What breaks first if a US cloud account is switched off?

The quickest way to find out is to start with the bill, which is the most honest inventory you have, and ask of each line whether the same thing could run somewhere else. The ones that hurt are identity (Entra ID or IAM Identity Center), encryption keys held in the provider's KMS, proprietary data stores such as DynamoDB, Cosmos DB and Spanner, backups kept in the same account, and the glue of DNS, CI/CD, secrets and observability SaaS.

Does holding your own encryption keys stop a cloud provider handing over your data?

Only partly, because the provider still sees plaintext while it processes your data. AWS KMS External Key Store and Google Cloud External Key Manager do keep the key material in a key manager you control outside the provider, which means a disclosure order against stored data returns ciphertext and the decision to switch the keys off becomes yours.

Do you need to leave AWS, Azure or Google Cloud to reduce the risk?

No, you can't leave the hyperscalers overnight and for a lot of workloads it isn't the right move. A more realistic aim is being able to leave if you ever have to, which means classifying what is sensitive, taking the encryption keys back, building on Kubernetes, Terraform and open source data platforms such as Postgres, Cassandra, Kafka and OpenSearch that run the same on European providers, and shipping backups to a European provider with a restore rehearsed once a year.

References and related reading

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Ready to Transform 

Your Business?