Microsoft has validated a €100 billion European market — by quietly admitting they cannot solve the sovereignty problem from inside their own product. EU procurement should now flow to EU vendors, the UK should follow, and both should bypass the proprietary stack for the boring open-source one that already does the job.

In April 2026, Microsoft shipped the result of serious engineering effort decoupling Azure Local from the Azure cloud management plane. Thousands of nodes. A local control plane. A new Local Identity service with Key Vault for air-gapped scenarios. Independent storage and compute scaling. That is not a feature release. It is a quiet admission that "the cloud" — as it has been sold to European procurement officers for a decade — has a sovereignty problem Microsoft cannot fix from inside their own product.

1

Read the admission carefully. Microsoft's product roadmap is now the strongest validation we have that the European sovereign infrastructure market is real, large, and growing fast. Microsoft does not engineer for thousands of on-prem nodes, rip out a core Arc dependency, and ship Local Identity for air-gapped key management unless their customers — European customers, primarily — are signalling, with budget attached, that the Azure-as-default era is closing.

Five months on, the engineering admission is on the record and has not been walked back; what happens to the budget behind it is still being decided. The numbers behind that signal are substantial enough that they deserve to be quoted in full.

The Market Microsoft Validated

$23.1B
European sovereign cloud IaaS spending projected for 2027 — up from $6.7B in 2025.
Gartner
€100B+
Projected annual European sovereign cloud market by 2031, from a base of ~€20B today.
Broadcom CIO research
60%
Western European CIOs who say they want to increase use of local cloud providers.
CIO survey, 2025
€1.5T
Forecast total European tech spending in 2026 — driven by AI, cloud, and sovereignty.
Forrester

European sovereign cloud spending is on track to more than triple in two years.2 The full European sovereign cloud market — including the on-prem and hybrid layers Azure Local is targeting — is forecast to grow roughly five-fold over the same horizon.3 This is the largest single budgetary realignment in European IT in a generation, and it is happening in plain sight.

Microsoft's response to that signal is, in itself, instructive. But it is not the answer Europe needs.

The €264 Billion Question

Behind the sovereign cloud forecast sits a much larger problem that the EuroStack initiative has been laying out, with increasing political traction, since late 2024.

European procurement runs an annual outflow estimated by the EuroStack initiative at €264 billion to foreign technology providers5. Eighty percent of European technology is imported. Seventy percent of foundational AI models in global use originate in the United States. European companies account for just seven percent of global research spending on software and internet technology.4

The €264 billion figure is an advocacy estimate from the EuroStack industry initiative and will be argued over by analysts who use narrower definitions. The directional case — that the outflow is structural, large, and politically significant — holds at a small fraction of it.

In cloud specifically: three US cloud providers hold roughly 70% of the European cloud infrastructure market. European providers hold 15%. AWS and Microsoft Azure alone each hold close to 40%.

10

The political response is now mobilising at scale. The EuroStack proposal — backed by the European Parliament's ITRE Committee in June 2025 and reinforced by the European Digital Sovereignty Declaration on 5 December 2025 — calls for €300 billion of investment over a decade, with a €10 billion European Technology Fund as the first tranche. The Cloud and AI Development Act entered the legislative process in Q1 2026. A new Executive Vice-President role for Technological Sovereignty, Security and Democracy was created in the December 2024 Commission. France has begun migrating government workstations from Windows to Linux. The 2026 EU budget allocates €1 billion to the Digital Europe Programme.

11

The political will is finally aligning with the budgetary reality. What has been left to vendor marketing departments — and is therefore in danger of being squandered — is the engineering question. How does sovereignty actually work?

Britain in the Same Bind

The European story has a British shadow that deserves naming, and it is not a smaller version of the same thing. The dependency is arguably deeper — AWS, Azure and Google Cloud supply more than 90% of UK public sector organisations, and AWS and Microsoft together take up to 80% of all UK cloud spending.12 The policy response is thinner at every level. The Competition and Markets Authority found both firms held significant market power, then declined to designate either and accepted voluntary commitments instead.13 The Government Digital Service’s National Cloud Strategy, expected in July 2026, has slipped to 2027.14 The lead department could not define data sovereignty when asked.

Britain has the same dependency. It does not yet have the plan. The UK picture, and what a buyer there can do about it without waiting for a strategy to be published, is a separate argument we will set out on its own.

15

The rest of this piece is about the engineering and the money, both of which apply on either side of the Channel.

The Competitiveness Objection

The strongest argument against this thesis has been put most clearly by Zach Meyers, writing for CEPA: that decoupling wholesale from US cloud risks hurting European competitiveness more than it helps sovereignty, because hyperscalers have economies of scale European alternatives cannot match.8 The objection deserves a direct answer, because it is the one EU and UK procurement officers will hear most often from their incumbent vendors.

The answer is that the objection assumes a definition of "hyperscaler" that no longer holds.

AWS in 2008 was infrastructure — pay-as-you-go compute and storage, sold as a utility. AWS in 2026 is a product platform with infrastructure as the entry-level tier. The same shift has happened at Azure and GCP, deliberately and explicitly. The revenue model has migrated up the stack from rented compute to proprietary managed services: Lambda, Cosmos DB, DynamoDB, Step Functions, EventBridge, App Service, Logic Apps, Glue, Athena, Cognito, IAM-as-application-glue. None of those have a drop-in open-source equivalent. The lock-in is the product strategy, not an unintended side-effect.

Once the platform layer is seen for what it is, the competitiveness argument inverts.

The 37signals Receipt

The cleanest empirical refutation comes from 37signals — the SaaS company behind Basecamp and HEY, run by Ruby on Rails creator David Heinemeier Hansson. Their cloud exit, executed across 2023–2025, is the most thoroughly documented hyperscaler repatriation on record.6 The numbers do the rebuttal work:

37signals · AWS Exit · 2023–2025
  • Annual AWS spend before the exit$3.2M
  • One-time Dell hardware investment (recouped during 2023)$700k
  • One-time Pure Storage purchase replacing a $1.5M/yr S3 bill$1.5M
  • Steady-state on-prem storage operating cost per year< $200k
  • Projected total infrastructure bill, on-prem< $1M/yr
  • Five-year savings projection$10M
  • Engineering headcount added to operate the new estate0
  • Database query performance change3–5× faster

DHH's own summary: "Cloud can be a good choice in certain circumstances, but the industry pulled a fast one convincing everyone it's the only way."7 AWS, for context, runs at roughly 30–40% operating margins on its infrastructure tier — the markup European customers are paying for elasticity they often do not need.

37signals is not a unique case. Dropbox's Magic Pocket repatriation saved an estimated $75 million.9 ReversingLabs, a software supply-chain security firm, has stated publicly that AWS would cost their business 10 to 15 times more than self-hosting, even after factoring in server rental and the salaries of the engineers required to operate the racks. These are not edge cases. They are the empirical baseline once you look past the marketing.

Same workloads. Same team count. Lower cost. Higher performance. That is the definition of a competitiveness gain, not a loss.

The Honest Trade-off

DHH himself is careful to note where cloud genuinely wins: nascent applications with low traffic, and workloads with unpredictable bursty demand. A startup with no idea whether it needs ten servers or a thousand should use AWS. So should an enterprise whose 95th-percentile demand is twenty times its median.

But that is not most workloads. It is certainly not the workloads European institutions, regulated industries, and established SaaS companies are running. Steady-state production traffic on predictable hardware is exactly where the hyperscaler markup hurts most — and exactly where European procurement budgets are concentrated.

The Skills Argument

The financial case largely stands on its own. The skills case sharpens it, with a caveat worth stating plainly.

Teams whose engineering capability is tied to one vendor's proprietary APIs are not building European competitiveness. They are building a renewable subscription liability for European balance sheets — denominated in dollars, priced by a foreign vendor, with no negotiating leverage at renewal time. A "senior Azure engineer" is not a senior systems engineer. The first is a vendor-trained dependency. The second is a transferable professional asset. The corporate training budgets that produce the first are not building European industrial capability; they are subsidising Microsoft's certification programme.

Self-hosting on the boring open-source stack is operationally different. You run your own Postgres. You plan your own patching. You hire your own SREs. Every euro spent on that builds transferable engineering capability: Postgres skills work everywhere, Kubernetes skills work everywhere, Linux skills work everywhere, and the team trained this year remains useful next year regardless of which vendor wins which procurement.

The honest objection is that this is easier to assert than to staff. 37signals had an unusually strong operations culture before it left, and a public body on a fixed pay band competing with hyperscaler salaries is not in the same position — which is precisely why a decade of “just use the managed service” was such an easy sell. We cannot evidence our way past that constraint and will not pretend to.

What we would say is narrower. The capability has to be built somewhere, by someone, or it is rented forever at a price you do not set. That does not mean every institution hiring its own platform team. It means the stack being commodity enough that the capability can come from a contracted supplier, a shared service across departments, or a European provider — and that whoever holds it can be replaced without rewriting the system. Proprietary managed services foreclose all three of those options at once. That is the difference worth paying for, and it is a smaller claim than “hire your own SREs”.

Rented competitiveness, denominated in dollars and set by a foreign vendor, is the weakest possible foundation for European industrial policy.

Sovereignty Is Not Geography

Sovereignty is not where the bytes physically sit. It is who can pull the lever.

Azure Local, even in its 2026 form, is still Microsoft's hypervisor, Microsoft's control plane (now hosted locally instead of in Redmond's datacentres), Microsoft's update cadence, Microsoft's licensing terms, and a US-domiciled vendor relationship subject to US legal jurisdiction. The CLOUD Act applies to Microsoft Corporation regardless of where the SAN sits. Geography of iron does not equal jurisdiction of vendor.

The Register itself, in covering the Azure Local upgrade, conceded the point in passing: it hears "different definitions of 'sovereign' infrastructure every week."1 The European Commission's October 2025 framework attempted to fix this with an eight-point definition and a sovereignty-score formula. The fact that such a formula was needed at all tells you how much the term has been hollowed out by vendor marketing.

The Honest Test

If the vendor's home government issues a legally enforceable order against the vendor's corporate parent, can the vendor's customer continue operating?

For Azure Local, the answer is no. Kernel updates stop. Licence renewals stop. Support relationships terminate. Your "sovereign" cloud becomes a stranded asset.

That is the sovereignty problem Microsoft cannot solve, because Microsoft is the problem.

The Complexity Tax

The technical case against Azure-Local-as-sovereignty is just as strong as the legal one.

AKS-on-Azure-Local layers an opinionated Azure-shaped control plane, Microsoft-specific networking and storage drivers (CNI and CSI implementations tuned for Azure's assumptions), Arc-shaped management surfaces, and a sprawling licensing model on top of what could be a vanilla Kubernetes cluster on commodity Linux. You pay a complexity tax for "feels like Azure" — at exactly the moment your reason for moving to your own iron was to escape Azure's operational model.

The actual sovereignty stack is already commodity FOSS, and has been for a decade:

Boring. Auditable. Yours. Every layer has multiple commercial European support providers. Every layer is built and maintained by global open-source communities not subject to a single jurisdiction's legal levers. Every layer can be inspected at the source level by your own security team or a contracted auditor.

Compare this to Azure Local, where the control plane is a binary blob whose roadmap is set in Redmond. The boring stack is harder to sell to a procurement committee that wants a single vendor on speed-dial. It is much easier to operate, audit, and survive geopolitical disruption with.

Cloud as a Component, Not a Commitment

The choice between proprietary lock-in and the boring stack is more than a vendor-selection question. It is an engineering discipline that has to be present in the codebase from the first commit, or it is not present at all.

At uRadical, our standing rule is that the cloud is an interchangeable deployment target, not an architectural assumption. Every system we build — MyWelcomeBook, SafeOps365, Music Bingo Live, every retainer engagement and architecture review — ships as a single Go binary that runs on any Linux kernel. SQLite handles per-tenant data on the same disk as the binary. Object storage uses an S3-compatible interface that points equally well at AWS S3, MinIO on-prem, Ceph, or a Hetzner box. The application has no opinion about whether it is running on AWS, Hetzner, a customer's air-gapped rack, or a co-located server in Belfast.

Which means it can be moved between any of those, in a weekend, without a rewrite.

Compare that to a typical "cloud-native" application built around proprietary managed services. The business logic invokes Lambda for compute, DynamoDB for state, Cognito for auth, EventBridge for events, S3 with vendor-specific bucket policies for storage, IAM for inter-service authorisation, and Step Functions for orchestration. None of those have drop-in equivalents. The application does not run on AWS — it is AWS, expressed as code. Migrating it does not mean changing a deployment target. It means rewriting the system.

This is the engineering reality behind every "cloud sovereignty" debate. If the codebase is cloud-neutral, sovereignty is a deployment decision and can be made tomorrow. If the codebase is hyperscaler-native, sovereignty is a multi-year migration project that most organisations will simply postpone forever.

That choice is made at the codebase level, by engineering teams, years before a procurement officer ever signs a sovereign cloud contract.

The Pivot Worth Seeing

Here is the pragmatic argument for any organisation already moving off the Azure public cloud.

If you are already buying your own hardware to run Azure Local, you have already paid the expensive part of the sovereignty migration. You have negotiated the capex. You have provisioned the rack space. You have hired the operations capability. You have re-platformed your network connectivity. You have rebuilt your runbooks for on-prem.

The leap from "Azure Local on your iron" to "k3s on your iron" is dramatically smaller than the leap you have already made.

So treat Azure Local as a stepping stone if you must. It is a viable short-term off-ramp from the Azure public cloud — a defensible choice for organisations that cannot move all the way at once. Use it to break the dependency on the Azure management plane. Use the local hardware as a beachhead.

But do not mistake the stepping stone for the destination. Every euro you continue to spend on Azure Local licensing, support, and tooling is a euro that does not flow to a European consultancy, a European hosting provider, a European Kubernetes distribution, or a European open-source maintainer. And every architectural lock-in you accept inside Azure Local is a future migration cost you have signed up for in advance.

Where The Money Should Flow

The case for European and UK procurement preference is structural rather than sentimental, and it follows the logic every other strategic sector already applies. It is also, unavoidably, a preference — so it should be argued on what it buys you rather than on whose flag is on the invoice.

Local consultancies pay local tax. They train local engineers. They participate in local open-source projects. Their roadmaps respond to local regulatory and political priorities. They are subject to local jurisdiction. When something goes wrong, you can sue them in your own courts — under your own laws.

Local hosting providers — OVHcloud, Hetzner, Scaleway, IONOS, UpCloud, Civo, Krystal, Mythic Beasts, Bytemark, and dozens of regional players across the EU and UK — already operate at scale on the boring open-source stack. They run Kubernetes. They run Postgres. They run Ceph. They publish their architectures. They compete on price and engineering quality, not on lock-in.

The European open-source ecosystem is genuinely thriving. Mistral on the AI side. Nextcloud for collaboration. Element and Matrix for messaging. PostgreSQL itself has deep European maintainership. The Linux Foundation Europe was established specifically to coordinate this work. The EuroStack directory project lists hundreds of European-built alternatives across every layer of the stack.

A European vendor still has a lever

This is the point at which the argument has to be honest about its own seam. Swapping AWS for OVHcloud does not remove a dependency; it relocates one. Hetzner can raise prices, change terms, suffer an outage or be acquired. A European consultancy can go under — UKCloud held NHS and MoD contracts and went into administration in 2022. “European” is not a synonym for “no lever”, and anyone selling it that way is doing the same trick with a different flag.

Two things follow. The first is that the lever-free position is not a vendor at all — it is the commodity open-source stack on hardware whose contract you hold, which is why that argument comes before this one rather than after it. Local vendor preference is the second-best answer, and it only works because the stack underneath it is portable. Buy a European provider running proprietary European software and you have bought the original problem in a nearer jurisdiction.

The second is that proximity of jurisdiction is a real and underrated good, not a patriotic one. A lever you can reach is categorically different from a lever you cannot. You can litigate against a supplier in your own courts, under law your own legislature can amend, in a timeframe measured in months. You can escalate to a regulator that answers to your parliament. You cannot do any of that about a US federal order served on a US corporate parent, and no amount of contractual assurance changes which court has jurisdiction. The dependency does not disappear. It becomes one you have standing in.

Two principles, taken together, would redirect tens of billions of euros and pounds annually from American shareholders to European balance sheets:

Defence procurement does not buy from foreign vendors first. Neither does energy infrastructure. Both pay for that preference in cost and occasionally in capability, and the trade is made anyway, deliberately, because a supply chain you cannot control is judged to be the larger risk. Digital infrastructure is treated as the exception to a rule every comparable sector applies — and it is the one sector where the switching cost compounds every year you defer the decision.

The Microsoft Move, Read Correctly

The Azure Local upgrade is genuinely useful information, but not in the way Microsoft's PR team intended. It is a confession that the cloud sovereignty problem is real, that European and UK procurement officers have noticed, and that the largest American software company in the world has decided to engineer around the problem rather than dismiss it. That is a market signal worth €100 billion a year by 2031.

The question is who captures that market.

If European and UK budgets continue to flow to American vendors merely wearing local jerseys — Bleu, Delos, S3NS, Azure Local, the various "EU Sovereign" hyperscaler offerings — then the sovereignty market becomes another channel for the same extraction. The €264 billion outflow continues. The 80% import dependency persists. The lever stays in foreign hands.

If those budgets flow to European and UK hands — to local consultancies, local hosting providers, locally-led open-source projects, and the boring auditable stack that already works — then the sovereignty market becomes the long-overdue rebalancing of European and British digital industrial policy.

Sovereignty is not a procurement checkbox or a Microsoft SKU. It is an engineering posture and a budgetary discipline. Both are within reach. Neither will adopt themselves.

Closing

Three Disciplines

Pick the boring stack. Hire the local team. Own the lever.

uRadical builds cloud-neutral production systems on the boring open-source stack. Single Go binaries. Embedded data stores. S3-compatible interfaces. Portable across hyperscalers, on-prem, and air-gapped environments — by design, from the first commit.

So when sovereignty becomes a deployment decision rather than a migration project, you are already there.

  • Sharwood, S., “Microsoft levels up Azure Local to make it fit for large-scale sovereign clouds”, The Register, 30 April 2026. Source for the Azure Local changes described here — support for thousands of nodes, a local control plane, the new Local Identity service with Key Vault for air-gapped scenarios, and independent storage and compute scaling — and for the observation that the publication hears “different definitions of ‘sovereign’ infrastructure every week”. theregister.com
  • Gartner sovereign cloud IaaS spending forecast 2025–2027, reported via TechRadar, “Europe is going all-in on sovereign cloud — investment to triple by 2027”. Source for $23.1B projected 2027 spending against $6.7B in 2025. Figures are a vendor-analyst forecast, not an outturn. techradar.com
  • Broadcom, “Three Predictions for Sovereign Cloud in 2026”. Source for the projected €100B+ annual European sovereign cloud market by 2031 from a base of roughly €20B. Published by a vendor with a commercial interest in the forecast, which is why it is quoted as a projection rather than a fact. broadcom.com
  • Bria, F., Timmers, P. & Gernone, F., EuroStack — A European Alternative for Digital Sovereignty, Bertelsmann Stiftung & CEPS, 2025. Source for the 80% technology import figure, the 70% share of foundational AI models originating in the United States, the 7% European share of global software and internet research spending, and for the €300 billion investment proposal with a €10 billion European Technology Fund as its first tranche. bertelsmann-stiftung.de
  • EuroStack Industry Initiative, €264bn annual outflow to foreign technology providers. An advocacy estimate from an industry initiative with a stated position, and contested by analysts using narrower definitions — quoted here on that basis. euro-stack.com
  • Heinemeier Hansson, D., Leaving the Cloud, 37signals, 2024–2025. Primary record of the 37signals AWS exit and the source for the figures in the table above: $3.2M annual AWS spend before the exit, the $700k Dell hardware investment, the $1.5M Pure Storage purchase replacing a $1.5M/yr S3 bill, under $200k/yr steady-state storage operating cost, the sub-$1M/yr projected total, the $10M five-year savings projection, no added headcount, and the 3–5× query performance improvement. basecamp.com
  • Sharwood, S., “37signals on-prem migration to save millions, abandon AWS”, The Register, 9 May 2025. Independent reporting of the same migration. theregister.com
  • Meyers, Z., “Decoupling From the US Cloud: A Step Backwards”, Center for European Policy Analysis. The competitiveness objection addressed in this section, stated in its strongest form by its own author. cepa.org
  • Dropbox’s Magic Pocket migration off AWS S3, begun 2015. Source for the roughly $75 million reduction in operating expenses across the first two years after the migration. Dropbox attributed a gross margin improvement from 33% to 67% between 2015 and 2017 primarily to the infrastructure project. builtin.com
  • Mordor Intelligence, Europe Cloud Computing Market Outlook 2026–2031. Source for the European cloud infrastructure market shares quoted here. mordorintelligence.com
  • European Commission, European Digital Sovereignty Declaration, 5 December 2025; and the Cloud and AI Development Act, in legislative process from Q1 2026. Source for the policy timeline, the Executive Vice-President role for Technological Sovereignty, Security and Democracy created in the December 2024 Commission, and the €1 billion Digital Europe Programme allocation in the 2026 EU budget.
  • Competition and Markets Authority, Cloud services market investigation — final decision, 31 July 2025. Source for the finding that both AWS and Microsoft hold positions of significant market power, for the recommendation to open Strategic Market Status investigations into each, and for the UK market shares quoted here: AWS and Microsoft at up to 80% combined, 30–40% each. gov.uk
  • Computer Weekly, “CMA to launch strategic market status investigation into Microsoft; Amazon Web Services off the hook”, 31 March 2026. Source for the CMA Board declining to open the cloud SMS investigations on 25 March 2026, the voluntary commitments accepted on 31 March, and the narrower business-software investigation commencing in May 2026. computerweekly.com
  • DSIT / Government Digital Service, Cloud Challenge Book 2026, 7 July 2026. Published in place of the expected National Cloud Strategy; source for the five “national-scale challenges” and the future National Cloud Infrastructure Programme. gov.uk
  • Further UK context: Computer Weekly, “Campaigners urge UK to develop digital sovereignty strategy”; TechPolicy.Press, “UK Regulator Probes Microsoft While Backing Voluntary Cloud Rules”; Computing, “Why cloud-first has meant sovereignty last”; Civo, “CMA Cloud Ruling: Why the UK Missed Its Big Opportunity”.