
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
June 18, 2025. Anton Carniaux, Microsoft France's director of public and legal affairs. French Senate inquiry into public procurement and digital sovereignty. Senators asked him point-blank whether he could guarantee that data stored in Microsoft's sovereign cloud offering would never reach US authorities.
He said no. Under oath.
The reason is the US CLOUD Act from 2018. American companies have to comply with valid US legal requests for data regardless of where the servers physically sit. Microsoft, Amazon and Google all lobbied for that law back then. Same three now running the "European sovereign cloud" campaigns — Microsoft's "European Digital Sovereignty Commitments" launched early 2025, AWS and Google with their own variants right after. Doesn't matter what the product is called. The legal pipe runs back to Washington.
Simon Uzenat, who chaired the Senate committee, called Microsoft's transparency reports on US data requests "purely declarative." No external verification, no oversight. Marketing kept running anyway.
Carniaux is the cleanest public admission but not the only one. The Commission just awarded a €180M sovereign cloud tender in April 2026 — one of the four winners is S3NS, a Thales/Google Cloud joint venture. Commission's stated position now: non-European tech can meet sovereignty requirements with the right contract. They've redefined the word to fit the vendors.
Then there's the Solvinity/Kyndryl deal in the Netherlands. American IT services company buying the Dutch provider that runs DigiD, the national digital ID every resident uses for tax filings, pensions, healthcare. Solvinity's own chief privacy officer told parliament the proposed risk mitigations couldn't actually shield against the CLOUD Act. He was fired. Government extended the DigiD contract through 2028 anyway, before the national security review concluded.
Counter-example exists. Schleswig-Holstein moved 80% of 30,000 state employees off Microsoft Office to LibreOffice by December 2025. €15M annual licence savings against €9M one-time investment. Payback under 12 months. The French Gendarmerie has been running 100,000+ workstations on its own Linux distribution for over a decade. Not theoretical.
Wrote the full piece up here, with the Gaia-X collapse and the Digital Omnibus lobbying paper trail: https://thevisibleinvisible.substack.com/p/the-stolen-word
Honest question — at what point does a US hyperscaler selling "sovereign cloud" to an EU government, after admitting under oath it can't deliver sovereignty, stop being marketing and start being something a prosecutor cares about? Or never?