Sovereignty washing is selling a US-owned cloud as "sovereign" because it sits in an EU datacentre. It isn't. Jurisdiction follows the company, not the disk, so the US CLOUD Act still reaches the data. Real sovereignty needs EU ownership plus zero-knowledge encryption: the only claim that survives a subpoena.
Let me be precise about what I'm attacking, because the word "sovereign" has been doing a lot of dishonest work lately. In January 2026 AWS switched on its European Sovereign Cloud in Brandenburg, Germany. A roughly 7.8-billion-euro buildout. A German parent entity. EU-resident-only operations, the whole kit. A month later Microsoft shipped M365 Local and Foundry Local, wrapped in an EU Data Boundary, a European board, and a "Data Guardian." Both are real engineering efforts by people who are clearly trying. Both are also, in the word the EU itself is now using, sovereignty washing. Not because the datacentres are fake. Because the legal thing they claim to deliver isn't in the box.
What "sovereign" is actually supposed to mean
Strip the marketing and sovereignty is two properties, not one.
The first is control: you decide who can access your data, and nobody can quietly change that from outside. The second is protection from extraterritorial law: no foreign government can compel disclosure through a court your country never voted for. You need both. A provider can give you a gorgeous dashboard of access controls (that's control) and still be legally obligated to hand your files to Washington (that's no protection). The second property is the whole ballgame, and it's the one a green pin over Germany says exactly nothing about.
Residency, where the bytes physically rest, is real and worth something. It shortens the distance for an EU regulator and keeps latency low. But residency is a fact about hardware. Sovereignty is a fact about power. The disk doesn't know who owns the company operating it, and the law doesn't care where the disk sits. It cares who controls the company.
The law nobody has repealed
The US CLOUD Act, signed in 2018, compels a US-incorporated company to produce data it controls on a valid US demand, no matter where on Earth that data lives, even when producing it breaks a foreign country's law. It binds the company, not the server. An AWS eu-central-1 region operated by an American corporation is not, by that fact alone, beyond US reach. The order is served in the US, the company goes and fetches the bytes from Frankfurt, and the location defence, the one Microsoft tried in the Ireland email case, is dead in US law.
So ask the only question that matters about any "sovereign cloud": is there a US-incorporated entity anywhere in the chain that controls this data? A German subsidiary doesn't sever that chain if a US parent can direct it. A joint venture built on US technology doesn't sever it either. This is exactly why CISPE, the trade body for European cloud providers, went after the European Commission for recognising S3NS, a Google-technology joint venture, as "sovereign." Their secretary general Francisco Mingorance called it "an own goal that institutionalises sovereignty washing." When the institution writing the rules blesses a borrowed-technology JV as sovereign, the word stops meaning anything at all.
And you don't have to take a privacy company's word for the gap. Take Microsoft's. In June 2025, before the French Senate, Microsoft France's legal chief, Anton Carniaux, could not guarantee that French citizens' data would never be handed to US authorities. Not "we'd resist." Not "it hasn't happened." Could not guarantee. That's the most senior legal voice in the room telling a national parliament that the protection property isn't there. A French operation. EU-resident staff. People who genuinely intend to protect you. And still no guarantee. Corporate ownership sank it.
"But the Data Privacy Framework fixed transfers"
Two different questions, and people keep collapsing them into one. The EU–US Data Privacy Framework governs whether a transfer is lawful under GDPR. The CLOUD Act governs whether a US company must comply with a US warrant. The Framework does nothing to the second. And the Framework itself is shaky: Schrems II already killed its predecessor, the General Court dismissed the Latombe challenge in September 2025, an appeal landed in October 2025, a Schrems III is in preparation, and most of the lawyers I read expect the Framework to fall within two to four years. Building your sovereignty on a legal instrument with that life expectancy is not a plan. It's a bet you'll have moved on before the bill comes due.
Why an EU datacentre run by a US company isn't enough
Here's the scenario I'd put to anyone evaluating a hyperscaler's sovereign tier. A US federal prosecutor serves a CLOUD Act order on the American parent for data held in its European Sovereign Cloud. The order can carry a gag clause that legally forbids telling you it happened. So: the European board, the Data Guardian, the EU-resident ops staff, what do they actually do? If the parent controls the keys or can direct the subsidiary, the answer is one word: comply. The governance theatre raises the cost and the friction. It does not change the legal obligation. Friction is not a wall.
This is the difference between trusting a jurisdiction and not having to. Governance, boards, guardians, residency commitments, these are all promises you have to trust. They depend on people keeping their word against a court order. A subpoena is precisely the moment trust gets tested, and it's precisely the moment governance theatre has nothing left to offer.
The market has noticed. Gartner pegs worldwide sovereign-cloud spend at around 80 billion dollars in 2026, up roughly 36% year over year, with Europe specifically growing about 83%. France is moving 2.5 million civil servants off Microsoft and onto Linux. All 27 EU states signed a digital-sovereignty declaration in November 2025, and the Commission presented its Tech Sovereignty Package in May 2026. The demand is real and it's accelerating. The supply is mostly hyperscalers selling residency with "sovereign" printed on the side, at roughly a 15% premium and with a fraction of the services you'd get from the main region. AWS's sovereign cloud launched with about 90 services against the main platform's 240-plus. You pay more, get less, and still don't get the one property the label promised. Quite the deal.
The only sovereignty claim that survives a subpoena
There are exactly two moves that close the gap, and the strong posture uses both.
Non-US jurisdiction. If no US-incorporated entity sits anywhere in the chain that controls your data, there is no American company for a US court to compel. That's a structural fact about who owns the business, not a promise about how it behaves.
Zero-knowledge encryption. Jurisdiction settles who can be ordered. Encryption settles what can be produced. If the server only ever holds ciphertext, then a valid order, from any government, yields nothing readable. This is the part that survives a subpoena, because it doesn't depend on anyone resisting anything. The capability to decrypt simply isn't there to compel.
Either move alone leaves a seam. A European provider that holds your keys can still be compelled to decrypt under its own jurisdiction. A US provider with client-side encryption removes file-content exposure but still answers US orders for everything else it holds: metadata, logs, account records. You want both seams closed. That combination is the actual definition of a sovereign cloud, and notice it has nothing to do with how many guardians sit on a board.
This is the bar we built Beebeeb to. We're operated by Initlabs B.V., a Dutch company, with data stored in Falkenstein, Germany, under EU law. No US parent. No US entity to serve. And it's end-to-end, zero-knowledge by default: your files are encrypted on your device with AES-256-GCM before they leave it, keys derived from your passphrase with Argon2id and never sent to us. We hold ciphertext we cannot read. If a German court served us a valid order tomorrow, we could produce account metadata. We could not produce readable files, because we have never been able to read them. That cuts both ways, of course: lose your passphrase and recovery phrase and we can't recover your files either. Our clients and encryption core are open source, so this is checkable rather than promised. An independent audit is planned, not yet done, and I'd rather say that plainly than imply otherwise. "Verify, don't trust" only works if you don't lie about the verification.
How to actually tell if a provider is sovereign
Forget the badge. Run four checks, in order, on anyone. Us included.
- Who owns the company? Not which datacentre. Which legal entity controls the data, and is there a US parent anywhere in the chain? If yes, the CLOUD Act applies regardless of region.
- Can they read your files? If the provider can decrypt your data, so can anyone who can compel the provider. Zero-knowledge, client-side encryption is the only architecture where the answer is structurally no.
- Is it open source? Encryption claims you can't inspect are marketing. Open clients and an open crypto core let you, or a researcher, verify that the keys really never leave your device.
- What happens under a subpoena? Ask it straight: "If a court orders you to hand over my files, what can you actually produce?" If the honest answer is "readable files," it isn't sovereign, whatever the brochure says.
Genuine peers pass parts of this. Proton Drive is open-source, audited, and gives you zero-knowledge encryption on a 5 GB free tier. Good product, and Swiss rather than US-owned. Tresorit offers real zero-knowledge with EU regions and a free Basic plan. I'm not here to knock either of them; they clear the bar that matters. Our edges sit on different ground: EU (not Swiss) jurisdiction, fully open clients, a CLI and WebDAV mount for the people who live in the terminal, scale up to 99 TB self-serve with a custom quote beyond, and a single-product focus instead of a bundle. You can read the whole pricing picture without booking a sales call.
The enemy here was never Proton or Tresorit. It's the category lie. The one where a 7.8-billion-euro datacentre with American ownership gets sold as sovereignty, and the EU has to coin a phrase to call it out. "Sovereign cloud" should be a legal claim you can verify, not a sticker you can buy. If a provider can be handed a subpoena and produce your readable files, it failed the only test that counts. Everything else is washing.