Sovereign Cloud Gives You a Data Center. Identity Governance Gives You Control.

European enterprises spent two years and real money on sovereign cloud deployments. What they found is that data residency is the easy part — and that AI agent identities are the part nobody governed.

ThreatVectr Newsdesk· 3 min read
Sovereign Cloud Gives You a Data Center. Identity Governance Gives You Control.
Share

Data residency is not sovereignty. That distinction, which should have been obvious from the start, is now the uncomfortable consensus among practitioners who actually deployed sovereign cloud infrastructure under live regulatory pressure.

Europe ran the experiment first. DORA came into full force in January 2025. NIS2 enforcement spread across EU member states. The EU AI Act's high-risk system provisions take effect in August 2026. Financial services firms, critical infrastructure operators and manufacturers spent two years migrating workloads, renegotiating hyperscaler contracts and writing sovereign cloud commitments into board-level risk frameworks.

The hyperscalers responded on schedule. AWS launched its European Sovereign Cloud in January 2026. Microsoft and Google followed. The market arrived.

What didn't arrive was clarity on what customers actually purchased.

At the European Identity and Cloud Conference in Berlin this past May, the tone had shifted sharply from prior years. Practitioners weren't debating whether to adopt sovereign cloud. They were dissecting the gap between the marketing decks and operational reality. Martin Kuppinger, co-founder of KuppingerCole, put it plainly: "Sovereignty is not a value in its own right — the required level depends on the use case and a proper risk assessment. There is no binary model for sovereignty."

The CLOUD Act of 2018 complicates the picture significantly. US authorities can compel US-headquartered companies to produce data stored abroad, regardless of server location. European sovereign cloud offerings from US hyperscalers are structured to address this through operational separation, European legal entities and customer-managed keys — but those structures are new, partially tested and inconsistent across providers.

Germany's BSI raised the bar further in April 2026, publishing its , the first framework to define cloud sovereignty in operational terms: disconnect scenarios, staff residency requirements, and a provision for federal takeover of cloud operations in defense scenarios. Formally non-binding, it is widely expected to set the procurement benchmark for German federal contracts and potentially template EU-level frameworks.

The conference's clearest signal, though, wasn't about infrastructure. It was about identity.

Jason Keenaghan, who leads identity management strategy at Thales, framed the shift directly: "Identity is shifting from an IT function to a regulated infrastructure. The most important question for the next decade will be: Who is in control?"

The answer matters most for AI workloads. Agentic systems — models that make API calls, provision resources and schedule workloads autonomously — create a category of non-human identities that most enterprise IAM platforms were never designed to manage. A large-language-model deployment agent with standing access to production Kubernetes clusters doesn't care where its data center sits. If its credentials, permissions and audit trail aren't governed, the sovereign cloud boundary is irrelevant.

Sebastian Rohr, an IAM consultant and IDPro member, listed the minimum viable controls for governing AI agents: assigned non-human identities, a defined on-behalf-of delegation model, SIEM-integrated audit trails, ephemeral credentials only, context-based authentication and real-time revocation capability.

Most enterprises aren't there yet. That gap — not data residency — is where AI sovereignty actually breaks down.

© 2026 Threat Vectr