Blog Cloud Sovereignty in Europe: NIS2, DORA & AI Act

 

Blog:

Cloud Sovereignty & Compliance in Europe: How NIS2, DORA and the EU AI Act Are Reshaping Cloud Strategy

 

 

By  Lee Wilkinson / 14 Sep 2026  / Topics: Compliance , Cloud , Data protection

Summary

Three EU regulations now shape every cloud compliance decision in Europe. This article covers:

  • What NIS2, DORA and the EU AI Act each require of your cloud infrastructure in 2026
  • Why data residency no longer equals data sovereignty and why that distinction decides your compliance posture
  • How the three frameworks overlap and where a single control gap triggers multiple obligations
  • A five-principle sovereign architecture that satisfies all three regulations without a permanent cost premium 


Why physical location no longer guarantees compliance

Choosing a data centre inside the right national border used to be enough to call a workload "compliant." That assumption has quietly stopped holding. A server sitting in Frankfurt or Amsterdam tells you nothing about who can be legally compelled to hand over the data on it, which is exactly the gap regulators have spent the last three years closing.

Three frameworks now converge on the same question: not just where does the data sit, but who can reach it, and can you prove that in an audit. NIS2 covers more than 160,000 entities across 18 sectors, and EU data protection authorities have issued over EUR 5.9 billion in GDPR fines since May 2018, according to Vision Compliance's tracking of GDPR Enforcement Tracker data. DORA applies to EU financial entities and their critical ICT suppliers. The EU AI Act adds infrastructure obligations for high-risk AI systems on top of that.

The commercial argument is moving just as fast. Insight's Digital Sovereignty Trilemma survey, fielded by Coleman Parkes between December 2025 and January 2026 among 900 senior decision-makers at organisations with 500+ employees across nine European countries, found that 67% of organisations already treat digital sovereignty as a critical strategic consideration, rising to 78% within one to two years and 82% within three. Fifty-five percent named regulatory complexity as one of their biggest strategic challenges, and 43% had already used strong sovereignty credentials to win or retain business. These are vendor-commissioned survey findings rather than official statistics, so treat them as directional industry sentiment rather than settled fact.

What follows maps the regulatory landscape as it stands in 2026, what each framework actually requires of your cloud architecture, and how organisations building on Azure, AWS or Google Cloud can get to a sovereign-ready posture without absorbing a compliance premium they can't justify internally.

The European regulatory stack, and why it behaves like one system

GDPR, NIS2, DORA and the AI Act didn't arrive as four unrelated checklists, even though most compliance teams still manage them that way. By 2026 they push toward the same three outcomes: know exactly where data lives, control who can touch it, and be able to prove, with evidence rather than assurances, that you can keep operating through a fault or an audit.

The overlap is heaviest for organisations in finance, healthcare, energy and the public sector, where a single control gap can trigger obligations under two or three regimes at once.

NIS2: cybersecurity obligations across 18 sectors, with personal liability attached

NIS2, the revised Network and Information Security Directive introduced by the EU in 2023, replaces a narrower predecessor with mandatory obligations covering more than 160,000 entities. It brings in risk management requirements, board-level accountability, incident reporting deadlines, and supply chain security mandates, with personal liability for senior management where non-compliance is established.

The directive splits obligated organisations into two tiers:

  • Essential entities: large operators in energy, transport, banking, healthcare and digital infrastructure, facing proactive supervision and the strictest enforcement.
  • Important entities: mid-size organisations in the same sectors, subject to the same technical bar but reactive rather than proactive supervision.

Four things NIS2 expects a board to be able to demonstrate:

  1. Risk ownership. The board approves cybersecurity measures and oversees implementation; failing to do so can carry personal liability.
  2. Security requirements. Article 21 of the NIS2 Directive sets out baseline measures, including incident handling, business continuity and crisis management.
  3. Supply chain security. Vendors and service providers need their own cybersecurity practices assessed, not just your own.
  4. Incident reporting. Essential entities must notify their national CSIRT within 24 hours of a significant incident, with a fuller report due within 72 hours.

In practice, NIS2 pushes identity rigour, tamper-evident logging, supplier governance and time-bound incident reporting straight into the platform layer. The operative word is demonstrable: an auditor needs to be able to trace your controls through telemetry and change records, not take your word for it.

The penalties are real and tiered: essential entities face fines of up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher, while important entities face up to EUR 7 million or 1.4% of turnover. These figures apply per member state, so an organisation with subsidiaries in several EU countries faces separate exposure in each one.

DORA: operational resilience as something you have to prove, not just plan for

The Digital Operational Resilience Act (DORA) mandates operational resilience standards for EU financial entities and their ICT providers, and became enforceable in January 2025. It requires documented and tested exit strategies from critical providers, contractual audit rights, controls on ICT concentration risk, and ongoing monitoring of third parties.

Scope is set by activity, not headcount. A 50-person FinTech processing payments sits under the same obligations as a major bank.

DORA standardises ICT risk management across the sector: tested failover, measured recovery time and recovery point objectives, threat-led testing where it applies, and a register of third-party ICT arrangements that actually matches what's running in production. Resilience has effectively become a product requirement rather than a line item in a disaster recovery plan.

The architectural implication is the sharpest part. Article 28's mandatory exit strategy requires financial entities to maintain a documented, tested, auditable plan to move away from any critical ICT provider without disrupting service. If your platform is tightly bound to one vendor's proprietary APIs, that "exit plan" may in practice be a multi-year migration: not a contingency plan, but lock-in wearing a compliance badge.

What European financial organisations should be doing now:

  1. Audit every existing cloud contract against Article 28's exit-strategy requirements.
  2. Classify workloads by criticality and flag which ones depend on single-provider managed services.
  3. Start documenting exit-strategy architecture at the enterprise level, before a crisis forces the decision.
  4. Make sure the ICT third-party risk register covers every cloud provider, with ongoing monitoring rather than a point-in-time review.

The EU AI Act: an infrastructure obligation hiding inside an AI regulation

The EU AI Act (Regulation 2024/1689) is the first comprehensive AI-specific regulation of its kind, classifying AI systems by risk and imposing data governance, auditability and infrastructure requirements on high-risk systems. It reaches full application on 2 August 2026, and penalties can reach 7% of global annual turnover.

A lot of SaaS products don't realise they're in scope: creditworthiness assessment tools in FinTech, CV screening in HR tech, and medical-device-adjacent features in HealthTech can all fall under Annex III's high-risk categories. The infrastructure problem is direct: SaaS platforms running on shared hyperscaler-managed AI services often can't produce the infrastructure-level provenance the Act requires. Self-hosted or sovereign environments make full data lineage documentation possible in a way shared multi-tenant services typically don't.

For infrastructure teams, this translates into segregated training and inference environments, dataset documentation, evaluation artefacts and rollback paths, all of which are considerably easier to deliver when your data perimeter and key management sit inside a single, simple jurisdiction.

Data residency vs. data sovereignty: the distinction that decides your compliance posture

The most expensive misunderstanding in European cloud compliance right now is treating residency and sovereignty as the same thing. They aren't, and the gap between them is where most regulatory exposure actually lives.

 Data ResidencyData Sovereignty
DefinitionServers physically located within a geographic boundaryData subject to the laws and governance of a specific jurisdiction
Protection from the US CLOUD ActNoYes, with a certified sovereign provider
NIS2 / DORA compliancePartialFull
Encryption key controlNot guaranteedGuaranteed
EU public sector eligibilityLimitedFull
Foreign government access riskRemainsEliminated

A US hyperscaler running servers on EU soil gives you residency. It does not give you sovereignty: US law can compel disclosure irrespective of where the hardware physically sits. According to SoftwareSeni's analysis of the European Commission's October 2025 Cloud Sovereignty Framework, US hyperscalers control more than 70% of the EU cloud market and remain subject to extraterritorial US laws, namely the CLOUD Act and FISA, that can compel data access regardless of server location. Most regulated workloads now need sovereignty, not just residency, to satisfy their obligations.

The "kill switch" scenario: why location alone doesn't protect you

Insight's Digital Sovereignty Trilemma research puts this precisely: 67% say maintaining digital sovereignty is a critical consideration when making strategic business decisions today, rising to 78% in one to two years and 82% in three or more years. The public sector leads the shift, with 73% viewing digital sovereignty as critical to their strategic decisions, reflecting a heightened focus on national security and jurisdictional safety.

Operational resilience, in practice, now rests on digital sovereignty: the ability to keep technical control over your systems and encryption keys regardless of outside interference. Insight's own framing of this is direct: imagine a foreign jurisdiction exerting authority over your cloud provider and effectively pulling a kill switch on your enterprise systems. That isn't an IT scenario; it's a business continuity threat with no easy workaround once it happens. The same research found that 32% of organisations now prioritise supply chain resilience and continuity when evaluating cloud strategy, ahead of cost control (20%) and speed to market (16%).

Even where legal transfer mechanisms exist on paper, most boards now prefer to narrow their exposure directly: keep sensitive workloads and telemetry inside the EEA, hold keys under EU jurisdiction. It's a posture that reduces risk, simplifies audits and makes accountability much easier to explain after the fact.

What non-compliance actually costs

The financial consequences here aren't theoretical anymore. Per Vision Compliance's tracking of enforcement data, EU data protection authorities have issued roughly EUR 5.9 billion in GDPR fines since the regulation came into force in May 2018 (with the top 10 fines alone accounting for over EUR 4.5 billion), and IBM's Cost of a Data Breach Report 2025 puts the average cost of a breach in the EU at EUR 4.57 million. Worth flagging: IBM's global figures for the same report are quoted in USD elsewhere (a global average of $4.44 million, and $4.18 million specifically for public-cloud breaches), so make sure you're comparing the EU-specific euro figure and not mixing it with the global dollar one. Eight years into enforcement, only around a third of organisations (34%, per the Cisco Data Privacy Benchmark Study 2025) report full GDPR compliance.

The waste side of the ledger is better documented. Insight's Digital Sovereignty Trilemma research puts European cloud capacity waste at 24% annually, driven mainly by inactive or orphaned resources, poor visibility across environments, and weak governance. AI has driven a 12% increase in hosting costs in a single year, and 56% of organisations are not conducting a Total Cost of Ownership assessment before significant workload placement decisions, according to the same survey.

Building one sovereign architecture instead of four parallel compliance streams

The most common failure isn't a missing control: it's running GDPR, NIS2, DORA and the AI Act as separate checklists that never actually converge, even though they overlap in controls, reporting chains and the risk models regulators expect to see. Map the shared intent, which is limiting systemic risk, enforcing auditable controls, and protecting European citizens' data, and most of the architecture decisions become fairly obvious.

Five principles define the pattern that tends to survive a European regulatory audit:

  1. EU-only multi-region with verifiable failover. Use at least two independent EU locations. Keep production, snapshots and DR copies inside the EEA. Run controlled failovers on a schedule and retain the evidence with the same rigour as financial records.
  2. Deterministic key management. Adopt an EU-resident KMS with explicit ownership. For material workloads, use bring-your-own-key or hold-your-own-key backed by hardware roots of trust and split custodianship.
  3. Network egress governance. Close default egress. Enumerate allowed destinations by policy, and document the reason each one exists.
  4. Evidence-centric operations. Centralise logs, configuration history and privileged access trails in immutable, lifecycle-managed stores. The platform should be able to answer who, what, when and where without ad hoc scripting mid-incident.
  5. Exit and portability by design. Model your exit strategy at the start, not after signing a contract. Use standard VM images and open data formats. Keep restore and migration playbooks in version control, and actually rehearse them: you're only as portable as the last time you proved it.

Turning compliance into a competitive advantage

Sovereignty doesn't have to come with a permanent price premium. The organisations that come out ahead on compliance across Europe are generally the ones treating it as a design principle from day one, rather than something bolted on after a regulator asks questions.

Insight's approach architects sovereign compliance frameworks that keep operations running around the clock without being held hostage to vendor licensing shifts or regional data law changes. Through FinOps and Hybrid Cloud Assessments, Insight repatriates high-intensity workloads to whichever environment is genuinely most cost-effective. Insight cites clients typically recovering around 12% of their hosting budget to reinvest in AI and R&D, a figure from Insight's own client engagements rather than an independently audited industry average.

Avoiding the sovereignty tax with FinOps

Insight's Digital Sovereignty campaign page attributes the underlying claim to Gartner: with 56% of organisations failing to conduct a TCO assessment before moving workloads, most are unknowingly paying a 15-30% price premium for "compliant" infrastructure. Insight's FinOps and Hybrid Cloud Assessments identify savings in that same 15-30% range as an internal benchmark from client engagements, worth validating against your own workload profile rather than treated as a guaranteed outcome.

Insight's FinOps services meet organisations wherever they are in that journey: identifying waste and unused resources, aligning teams, optimising costs and tightening governance, with the aim of better governance, lower costs and closer collaboration between finance and engineering.

Explore Insight's FinOps Services to see where your organisation might be quietly subsidising compliance inefficiency.

NIS2 readiness: from gap assessment to board-level confidence

Insight's approach to NIS2 compliance builds on existing processes and accounts for overlapping EU directives, rather than treating NIS2 as an isolated exercise, prioritising risk management and incident reporting from the outset. Insight offers a NIS2 Awareness Workshop to prepare senior management teams, plus a NIS2 Assessment Service to identify gaps and produce a tailored compliance roadmap.

Where this leaves European cloud strategy

NIS2, DORA, the EU AI Act and the broader European data sovereignty agenda aren't upcoming concerns to plan around. They're live business risks, with enforcement activity, financial penalties and reputational fallout already playing out across the continent.

The organisations best positioned for the next few years are the ones treating operational resilience, agility and cost efficiency as one strategic framework rather than three competing priorities: designing for sovereignty from the outset while keeping enough flexibility to adapt as the regulatory landscape keeps shifting, because it will keep shifting.

Organisations that build for sovereignty from the start don't just weather the next regulatory shock better. They tend to win more business because of it. Resilience has stopped being a defensive line item; it's a commercial argument.

Headshot of Stream Author

Lee Wilkinson

EMEA Technology & Strategy Lead – Cloud & On Prem, Insight

As EMEA Technology Lead for Cloud and On-Prem Solutions, Lee is responsible for the Cloud and On-Prem & Intelligent Edge practice area as part of Insight's EMEA solutions business. This includes defining the Hybrid Cloud technology strategy EMEA wide, evaluating and helping the business adopt Hybrid Cloud Technology from Insights Alliance and Partner Managed vendors. Lee has 19 years experience working in the technology industry, the past ten years of which he has worked at Insight.