“Sovereign cloud” means “not US owned cloud”

A slide split in two. On the left, under a US flag, an AI-generated image of a suited man whose head is a dark storm cloud. On the right, under an EU flag, a Magritte-style painting of a suited man in a brown coat and orange tie whose head is a white cloud, in a sky full of clouds, one of them wearing a bowler hat.
Two clouds, two jurisdictions. Source: AI-generated “Trump Cloud”; “The Cloud Man,” found on Whoopah, which does not appear to be an actual René Magritte painting.

For the most part, “sovereign cloud” is a code word for “not running on US based clouds.” What most people skip is that the geography doesn’t matter. If your stuff runs on a US owned cloud, not matter where it actually runs, the US government can probably compel the cloud provider to get your data.

Sovereignty is not a single property. When people use the word, they are usually mixing together at least five different ideas.

  1. Ownership is about who holds the asset – the data, the servers, the model.
  2. Control is about who can operate it, change it or switch it off.
  3. Jurisdiction is about whose laws apply and whose courts can compel access.
  4. Capability is about whether you have the skills to build or run it yourself.
  5. Optionality is about whether you can walk away and use something else without serious damage.

These are relatively independent. Storing your data in a UK datacentre may give you a sense of ownership, but it does not settle the question of jurisdiction. The US Cloud Act, passed in 2018, allows US authorities to seek data held by US-based providers wherever it happens to be located. That is not a theoretical concern.

This is why US-based companies and organizations using cloud never use the phrase “sovereign cloud.” To them, it’s just “the cloud.”

🔗 What do we mean by sovereign AI?

Comments

Leave a Reply

Categories:

Discover more from Coté

Subscribe now to keep reading and get access to the full archive.

Continue reading