Sovereign Cloud Gives You a Data Center. Identity Governance Gives You Control.
European enterprises spent two years and real money on sovereign cloud deployments. Data residency turned out to be the easy part. AI agent identities are the part nobody governed.

Key points
- Data residency and operational sovereignty are not the same thing, and European deployments under DORA and NIS2 proved the difference.
- The CLOUD Act of 2018 lets US authorities compel US-headquartered companies to produce data stored abroad, whatever the server location.
- Germany's BSI published its C3A framework in April 2026, the first to define cloud sovereignty in operational terms including staff residency and federal takeover provisions.
- Identity governance, not infrastructure location, is where AI sovereignty holds or breaks down.
- Agentic AI systems generate non-human identities that most enterprise IAM platforms were never designed to manage.
Data residency is not sovereignty. That distinction, which should have been obvious from the start, is now the uncomfortable consensus among practitioners who deployed sovereign cloud infrastructure under live regulatory pressure.
Europe ran the experiment first. DORA came into full force in January 2025, NIS2 enforcement spread across EU member states, and the EU AI Act's high-risk provisions take effect in August 2026. Financial services firms and critical infrastructure operators spent two years migrating workloads, renegotiating hyperscaler contracts and writing sovereign cloud commitments into board-level risk frameworks.
The hyperscalers responded on schedule. AWS launched its European Sovereign Cloud in January 2026. Microsoft and Google followed. The market arrived. Clarity on what customers actually purchased did not.
What did you actually buy?
At the European Identity and Cloud Conference in Berlin this past May, practitioners weren't debating whether to adopt sovereign cloud. They were dissecting the gap between marketing decks and operational reality. Martin Kuppinger, co-founder of KuppingerCole, put it plainly: "Sovereignty is not a value in its own right, the required level depends on the use case and a proper risk assessment. There is no binary model for sovereignty."
The CLOUD Act of 2018 complicates the picture. US authorities can compel US-headquartered companies to produce data stored abroad, regardless of server location. European sovereign cloud offerings from US hyperscalers address this through operational separation and customer-managed keys, but those structures are new, partially tested and inconsistent across providers.
Germany's BSI raised the bar in April 2026, publishing its C3A framework, the first to define cloud sovereignty in operational terms: disconnect scenarios, staff residency requirements, and a provision allowing federal takeover of cloud operations in defense scenarios. Formally non-binding, it is widely expected to set the procurement benchmark for German federal contracts. We first reported on both the CLOUD Act exposure and the C3A criteria on 15 June 2026.
Should you worry about AI agents specifically?
The conference's clearest signal wasn't about infrastructure. Jason Keenaghan, who leads identity management strategy at Thales, framed the shift: "Identity is shifting from an IT function to a regulated infrastructure. The most important question for the next decade will be: Who is in control?"
Agentic systems, models that make API calls, provision resources and schedule workloads without human prompting, create non-human identities that most enterprise IAM platforms were never designed to manage. A deployment agent with standing access to production Kubernetes clusters doesn't care where its data center sits. If its credentials, permissions and audit trail aren't governed, the sovereign cloud boundary is irrelevant.
Sebastian Rohr, an IAM consultant and IDPro member, listed the minimum viable controls: assigned non-human identities, a defined on-behalf-of delegation model, SIEM-integrated audit trails, ephemeral credentials, context-based authentication and real-time revocation. Most enterprises aren't there. That gap, not data residency, is where AI sovereignty actually breaks down.


