Explore how cloud sovereignty becomes a scored criterion for data protection.

Airbus has made protection from extraterritorial law a scored criterion in its cloud tender, signaling that sovereignty is now a technical requirement, not just a talking point.

3 min readInfoQ
Explore how cloud sovereignty becomes a scored criterion for data protection.

Airbus's decision to score protection from extraterritorial law as a formal criterion in its cloud tender is a quiet but significant signal. The company did not frame this as a rejection of hyperscalers; it explicitly positioned Scaleway as a complement to its existing multi-cloud strategy, which still includes AWS. What matters here is not the specific vendor choice, but the procurement logic. When a company of Airbus's scale builds legal resilience into its evaluation matrix, it stops being a niche concern and becomes a template. The lesson for practitioners is straightforward: sovereignty is no longer just about where data resides, but about which legal regimes can reach it. That distinction changes how you should be evaluating every cloud and SaaS vendor, not just the large ones.

The pattern is already spreading. Practitioners are seeing similar scrutiny extend beyond hyperscalers to smaller US SaaS vendors. That is a meaningful expansion of the threat model. Most teams have spent years assessing cloud providers on technical capability, compliance certifications, and price. Few have systematically asked whether a vendor's corporate structure or data flow agreements could expose them to non-European legal demands. Airbus just made that question a scored requirement. For our readers, the practical takeaway is to audit your own vendor list with this lens. You do not need to be a defense contractor to care. Any company processing personal data of EU citizens, or operating in regulated industries, faces the same exposure. The question is whether you want to discover that exposure through a legal notice or address it in your next procurement cycle.

What is refreshing here is the lack of overclaiming. Airbus is not calling this a revolution, and neither should you. The company is treating sovereignty as one variable among many, not as a magic switch. That is the right posture. The harder truth is that sovereignty claims require verifiable controls. A vendor can say it is sovereign, but you need to see the underlying architecture, the legal opinions, and the operational safeguards. The fact that Airbus scored this criterion alongside technical capability suggests they understand that trade-off. They are not asking for a binary choice between performance and protection. They are asking for both, and they are willing to build a procurement process that holds vendors accountable to that standard.

The specific detail to watch is how this scoring criterion evolves. Will Airbus publish its weightings or the exact legal scenarios it tested? Will other European industrial giants follow with similar language in their tenders? If this becomes a common clause, you will see vendors scrambling to provide verifiable evidence of legal isolation, and that is a healthy pressure. For now, the actionable step is to review your own vendor contracts and ask one direct question: if a non-European court issued an order for data access, what happens next? If your vendor cannot answer that with specifics, you have your answer. The future of cloud procurement is not just about speed and uptime. It is about knowing which laws can reach your data, and whether your architecture gives you a fighting chance to say no.

From InfoQ

Airbus selected Scaleway as its sovereign cloud provider after a tender that scored protection against non-European extraterritorial legislation alongside technical capability. Airbus frames it as complementing multi-cloud, not exiting AWS. Practitioners note the pattern is spreading past hyperscalers to small US SaaS vendors, and that sovereignty claims still require verifiable controls.

Read the original at InfoQ