In June 2025, Microsoft announced a package of sovereignty solutions for European customers. One of them, called Data Guardian, restricts remote access to systems holding European data to the company's own Europe-based employees, with real-time approval and tamper-evident logging for every access.
Seven months later, in January 2026, AWS announced its own European sovereign cloud was operational: more than €7.8 billion invested, the first region running in the German state of Brandenburg, and a phrase that sums up the intent — "zero operational control outside of EU borders." In November 2025, Google Cloud had already opened its first hub dedicated to data sovereignty solutions in Munich, on the grounds, in the words of a company vice president, that "European organizations should have control over their own digital destiny."
Three of the world's largest cloud providers, within little more than a year, built entirely new legal and operational structures for a single purpose: to convince European customers that their data — and, increasingly, the way the AI agents using it operate — sit under rules the customer understands and can verify. This is not a regional marketing move. It's a signal of where the buying conversation is heading everywhere, including here.
The question that moved
For years, a buying committee's question about a vendor's cloud was geographic: which country the server sits in. All three companies treated that question as insufficient. Microsoft describes Sovereign Public Cloud as an environment where "customer data stays in Europe, under European law, with operations and access controlled by European personnel, and encryption under full control of the customer" — four conditions, not one.
AWS went in the same direction with a different emphasis: its European sovereign cloud is described as "physically and logically separate" from the company's other regions, "operated exclusively by EU residents," with no critical dependencies on non-EU infrastructure, and designed to keep running "even in the event of a communications disruption with the rest of the world." Governance includes a parent company and German subsidiaries led by EU citizens, plus an advisory board with independent members.
The pattern across all three is the same: physical data residency stopped being a sufficient answer. What matters now is who has operational access, under which law, with what record, and with what possibility of audit — stated with that precision, and preferably written into the contract.
This is why Google Cloud frames the whole move as a matter of the customer's "control over their own digital destiny," not just data location. And it's why AWS's European governance structure includes an advisory board with members independent of Amazon's own leadership: the intent is that oversight doesn't depend solely on the vendor's word.
Where the sovereignty promise still runs into practice

None of these three structures came from an engineering whim. They came from a question regulators, auditors, and European boards have asked for years and that became impossible to ignore once generative AI started handling contracts, internal policy, and customer data: if a foreign law compels disclosure of information stored in the cloud, who decides, under what process, what gets handed over?
Each provider's answer is a combination of technical architecture and local legal structure — not a "server in Europe" sticker slapped on a product still operated from elsewhere. And that's exactly where most AI contracts signed by companies outside Europe still fall short: data residency gets mentioned, but operational access, the approval chain, and the audit trail aren't specified in any verifiable clause. A server "in the right country" solves nothing if the vendor can access, move, or use that data with no record the contracting company can check afterward.
What has to be in place
The move by all three providers points to four elements any company — European or not — can already demand before signing a corporate AI contract.
Residency and architecture defined by contract, not by a verbal promise. Where data is processed and stored needs to be written down, with real audit capability — not just stated on a sales page.
Each company with separate data and rules. One customer's environment cannot mix with another's, technically or in terms of access policy. It's the same logic behind AWS describing its sovereign cloud as physically separate from its other regions.
Configurable retention with automatic purge. How long data is kept, and what happens to it afterward, need to be parameters the contracting company sets — not a generic vendor policy.
An audit trail of who accessed what, when, and why. Without that record, "sovereignty" is a word in a marketing sheet, not a verifiable guarantee.
This is how Skyller was designed: residency and architecture set per plan and contract for each customer, each company with separate data and rules, and configurable retention with automatic purge from day one.
What changes for anyone buying AI today

For a company in Brazil or Latin America, none of this is a Europe-only matter. The same question that led Microsoft, AWS, and Google to build dedicated structures — exactly which rules apply to this data, and who can prove it — applies to any corporate AI vendor hired here, regardless of where it was born.
The practical gain from treating this as a purchase criterion, not a technical footnote, is twofold. On the risk side, the company stops depending on the vendor's word and gets a clause it can invoke in an audit or an incident investigation. On the negotiation side, a board that knows exactly which questions to ask arrives at the table in a stronger position than one that only asks "is our data safe?" — a question too broad to produce any useful answer.
There's also an effect that tends to go unnoticed: once a company writes these four requirements into an internal procurement process, they apply to any new vendor, AI or not. The criterion stops being a one-off contract quirk and becomes part of how the company evaluates any service handling sensitive data.
Infrastructure entirely controlled by the customer, in a private cloud or a local environment, remains an additional possibility for those with that specific requirement — but for most companies, what actually solves the problem isn't where the server physically sits, it's the architecture and the contract that define who is in charge of that data.
Four questions to bring to your next purchasing meeting
Before signing the next AI contract, whether with a local or an international vendor, it's worth bringing these questions to the table:
- Where exactly is the data processed and stored, and is that written into the contract or only on a website page? A marketing statement doesn't count as a clause.
- Who, in practice, has operational access to the environment holding our data, and under what approval? A vague answer likely means the vendor doesn't know, or won't say.
- Is there an audit trail our own team can actually consult, or does only the vendor have access to that record? A record only the vendor can see is useless for an internal investigation.
- What happens to the data when the contract ends, and is that automatic or does it depend on someone remembering to ask? Retention with no defined term is risk accumulating silently.






