How US juridical architecture locked European autonomy by design, and how Europe signed the lock itself.
In December 2013, a federal magistrate in New York signed a warrant for a set of emails. The account belonged to a suspect in a narcotics case. The emails themselves sat eight kilometres east of Dublin, on a server inside a Microsoft data center in Ireland. The United States government said the location did not matter. Microsoft said it mattered absolutely. What followed was a five-year legal war that climbed all the way to the Supreme Court of the United States, and it ended not with a ruling but with a sentence buried in a spending bill.
That sentence is the reason a hospital in Lyon, a bank in Frankfurt, and a ministry in The Hague can have their most sensitive records read by a government they did not elect, under a law they never debated, through infrastructure they chose themselves. The story everyone tells is about surveillance. The determining variable was never surveillance. It was ownership of the layer beneath the market.
There is a sharper move inside this case than ordinary lock-in, and it is the part worth holding onto. Dependence on a dominant supplier is familiar, the slow trap of switching costs that catches anyone who buys from the cheapest provider at scale. What happened here was different in kind. A constitutional question, whose law governs data held abroad, reached the highest court in the United States, and before the court could answer it, the legislature removed the question from the court's hands and decided it by statute overnight. The outcome was not reasoned. It was sequenced. Whoever controls the order in which events are allowed to happen can decide an outcome without winning the argument, and that is what makes this more than a story about a big company and a captive market.
The European Commission called the resolution a victory. That is where the real story begins.
The Warrant That Could Not Be Refused
The Microsoft Ireland case, formally United States versus Microsoft Corporation, turned on a question that sounds technical and is in fact constitutional. When an American company stores data abroad, whose law governs it? Microsoft argued that a US warrant stopped at the water's edge, that reaching into a Dublin server was an extraterritorial act requiring Irish cooperation. The Department of Justice argued that the company was American, the company controlled the data, and control was all that mattered. Location was a detail of engineering.
For five years the question moved through the courts. Microsoft won at the Second Circuit in 2016. The government appealed. By February 2018 the case stood before the Supreme Court, and the justices seemed genuinely divided, aware they were being asked to write the rule for a borderless technology using a statute drafted in 1986, before the web existed.
Then Congress removed the question from the court entirely. On March 23, 2018, the Clarifying Lawful Overseas Use of Data Act, the CLOUD Act, became law. It was not passed as a standalone bill. It was inserted into the Consolidated Appropriations Act of 2018, a 2,232 page omnibus spending package assembled in the final hours before a government shutdown. The provision that resolved one of the most consequential data sovereignty questions of the century rode into law inside a bill that almost no member had time to read in full. There were no dedicated hearings on the floor. The mechanism arrived the way these mechanisms always arrive, wrapped in something too large and too urgent to stop.
The text amended the Stored Communications Act to say what the Justice Department had argued all along. A provider subject to US jurisdiction must produce data in its possession, custody, or control, regardless of where that data is stored. On April 17, 2018, with the new law in hand, the government obtained a fresh warrant, and the Supreme Court vacated the Microsoft case as moot. The question was never answered. It was overwritten.
The principle that survived is simple enough to state in one line. If an American company holds your data, the American government can compel it, anywhere on earth, without a warrant in your country, without a court order in your jurisdiction, without telling you. Amazon Web Services runs data centers in Frankfurt that process European payrolls, medical records, and government correspondence. Under the CLOUD Act, that data is reachable from a courtroom in Virginia. The servers are in Germany. The jurisdiction is not.
The Victory That Was a Surrender
While the warrant fight played out, a parallel drama ran in Europe, and it ended in the same place by the opposite road.
In 2015, the Court of Justice of the European Union struck down Safe Harbour, the legal bridge that allowed personal data to flow from the European Union to the United States. The case was brought by an Austrian lawyer named Max Schrems, who had argued that American surveillance law made a mockery of European privacy guarantees. The court agreed. Five years later, in the judgment known as Schrems II, decided on July 16, 2020, the court struck down the replacement framework too, the Privacy Shield, for the same reason. American law permitted bulk surveillance. American law offered Europeans no meaningful path to challenge it. The two systems were not compatible, and no amount of paperwork could make them so.
The court left one door open. Transfers could continue if supplementary safeguards closed the gap. Brussels understood the arithmetic. There was no safeguard a private company could build that would override an act of the United States Congress. A clause in a contract cannot defeat a federal warrant. The gap the court described was not a gap in procedure. It was the CLOUD Act.
So the United States manufactured a safeguard. On October 7, 2022, the White House issued Executive Order 14086, introducing the words necessity and proportionality into American signals intelligence, and creating a new redress body, the Data Protection Review Court, where Europeans could in theory complain about surveillance. The body sits inside the executive branch. Its proceedings are not public. A complainant is never told whether they were surveilled, only that their complaint was reviewed and that any necessary remediation, if any, has occurred. It is a court in name, designed to satisfy a foreign court's requirement for the appearance of one.
On July 10, 2023, the European Commission accepted it. It issued an adequacy decision certifying that data transfers to the United States now met European standards. Buried in the analysis around the decision was an acknowledgement that the CLOUD Act remained a concern the framework did not resolve. The Commission certified adequacy while documenting inadequacy. In September 2025 the EU General Court, ruling on a challenge brought by the French parliamentarian Philippe Latombe, upheld the framework. The machine kept running.
This is the part that resists the conspiratorial reading and is more damning for it. Nobody was tricked. The Commission knew. The court knew. The lawyers knew. The certification was not a failure of understanding. It was a decision that the cost of telling the truth, severing the data link between two of the largest economies on earth, was higher than the cost of signing a document everyone present knew to be a fiction. That is not corruption. That is architecture deciding for people who still believe they are deciding.
What the Court Actually Saw
To understand why no contract could close the gap, it helps to see what the European judges were actually looking at, because the incompatibility was not abstract. It had statute numbers.
The first was Section 702 of the Foreign Intelligence Surveillance Act. It authorises American agencies to compel electronic communication providers to hand over the communications of non Americans located outside the United States, in bulk, for foreign intelligence purposes. A French citizen emailing through an American service is, by definition, a non American outside the United States. They are the target population the statute was written for. The second was Executive Order 12333, which governs intelligence collection conducted abroad, including the interception of data as it crosses the cables and switches of the global internet, with even fewer constraints than the statute. The third was not a law at all but a revelation. In 2013 the documents released by Edward Snowden exposed PRISM, the program through which the agencies drew directly on the servers of the largest American technology companies, and UPSTREAM, which tapped the internet backbone itself.
When the Court of Justice ruled in Schrems II, it named these authorities explicitly. It found that surveillance under Section 702 and Executive Order 12333 did not meet the minimum safeguards European law requires, that it could not be regarded as limited to what is strictly necessary, and that Europeans subject to it had no actionable remedy. That was the finding. Not that America might abuse its power, but that its ordinary, legal, openly authorised collection was structurally incompatible with European rights. A clause in a corporate contract cannot repeal Section 702. This is why every safeguard proposed since has been a negotiation over appearances. The underlying statute was never going to be amended to protect foreigners, and everyone at the table knew it.
The Health of Ten Million People
The abstraction acquires a body when the data is medical.
In 2019 France created the Health Data Hub, a central platform meant to pool the health records of the nation for research, drawing on data covering much of the French population. The government hosted it on Microsoft Azure. There was, at the time, no French platform certified at the required scale, so the most sensitive category of personal information a state holds, the medical histories of its citizens, was placed on infrastructure owned by an American corporation, subject to American law.
The challenge was immediate. In 2020 the Conseil d'État, the highest administrative court in France, examined the arrangement and reached a conclusion that captured the entire dilemma in a single posture. It could not exclude that American authorities might demand access to the health data under American law. It nonetheless declined to order the platform shut down, instructing the government instead to find, in time, a solution beyond the reach of that law. The court saw the trap clearly and ruled, in effect, that the trap was for now unavoidable. Over the following years the authorisation was challenged again and validated again, each time with the same acknowledged risk attached, the sovereignty always deferred to a future date.
The future arrived slowly. French negotiators, according to reporting on the decision, concluded what Brussels had concluded and what Schrems had proven in court, that no contractual addendum could override the obligations the CLOUD Act imposed. The only fix was to leave. France selected Scaleway, a domestic provider owned by the Iliad group, to host the Health Data Hub in place of Azure. The migration off American infrastructure was scheduled years after the dependency was created, at a cost and a delay that exist precisely because the exit was built last instead of first. The records of millions of French citizens sat under foreign jurisdiction for the entire interval, legally exposed, while the institutions that knew it worked out how to undo a decision that had been simple to make and enormously expensive to reverse.
Why Europe Built Its Own Trap
The CLOUD Act did not create European dependence on American infrastructure. It arrived to formalise a dependence that was already total. The choice that mattered was made decades earlier, not in any parliament, but in ten thousand separate procurement decisions, each of them individually rational.
Amazon Web Services entered Europe in earnest after 2007. The economics were not subtle. AWS could build and run a Frankfurt data center at a margin no European competitor could match, because it spread the cost across a global business that was already profitable. A European challenger would have had to justify enormous capital expenditure to investors with no path to comparable scale. The investors said no, correctly, every time. The European champion was never built, not because Europe lacked engineers, but because the return did not exist for whoever moved second into a market the first mover had already saturated.
The scale of the result is measurable. By the mid 2020s the three American hyperscalers, Amazon, Microsoft, and Google, held roughly seventy percent of a European cloud market worth around sixty one billion euros a year. The share belonging to European providers had fallen from nearly thirty percent in 2017 to about fifteen percent, where it has since flattened, with much of even that capacity rented from the same American giants. The continent that wrote the world's strictest privacy law runs that law's enforcement on infrastructure it does not own.
By the middle of the 2010s the dependence was structural. Deutsche Bank ran critical systems on the American cloud. SAP, Europe's one true software giant, built its strategy around Microsoft Azure. The German federal administration ran on Microsoft. The French state ran workloads on AWS. Hospitals, utilities, insurers, and tax authorities across the continent had migrated their operations onto platforms owned in Seattle and Redmond. Each had chosen well for itself. Together they had handed the substrate of European economic life to three American companies.
Once the dependence was structural, reversal became almost unthinkable, and the reason is the most important sentence in the whole story. The cost of leaving was not technical. It was competitive. Around 2018 Deutsche Bank examined what it would take to move off Microsoft and restore European data residency. The finding was unambiguous. Migration would cost billions, would impose eighteen months of operational risk, and would land the bank on European infrastructure that did not exist at the scale it required. Nothing moved. The board understood the sovereignty problem perfectly. It also understood that any bank migrating alone would bleed billions while its competitors consolidated their advantage on the cheaper American platform. The rational choice for each institution produced the irrational outcome for the continent. Sovereignty was not taken by force. It was surrendered by spreadsheet.
Europe did try to build the exit. In 2020 it launched GAIA-X, a Franco German initiative meant to create a sovereign European cloud ecosystem governed by European law. It had political backing, corporate members, and real ambition. Within a year it had something else. By 2021 the American and Chinese hyperscalers, Amazon, Microsoft, Google, Huawei, and Alibaba, had all joined as members. Microsoft, initially sceptical, executed what one study of the project called an apparent 180 degree reversal. The summits filled with presentations from the very companies the project existed to escape. A sovereignty initiative had been colonised by the thing it was meant to replace, and it produced governance frameworks and standards documents rather than a single commercial scale alternative. The exit was built, and the incumbents moved in and took the keys.
There is a lesson in lock-in that GAIA-X learned too late. The moment to prevent a dependency is always years before anyone can see it. By the time the danger is visible, the cost of reversal has already grown larger than the danger. The window does not announce its own closing. It simply closes, and the alarm rings afterward.
The Day the Architecture Spoke Aloud
For years the constraint stayed abstract, a matter of statutes and adequacy decisions and clauses most citizens would never read. Then, on June 10, 2025, it was spoken in plain language under oath.
A committee of the French Senate, investigating the dependence of French public services on foreign technology, summoned Microsoft France. Anton Carniaux, the company's director of public and legal affairs, sat before the senators. They asked him a direct question. Could he guarantee that the data of French citizens, held by Microsoft under public contracts, would never be handed to the American government? His answer was four words. Non, je ne peux pas le garantir. No, I cannot guarantee it. He swore he could not lie, and then he confirmed the thing the whole apparatus had spent a decade phrasing carefully enough to avoid confirming.
He added, accurately, that Microsoft fights. The company analyses each request, challenges those it finds unfounded, has won concessions from the American government over years of litigation. All of that is true, and none of it changes the answer. A company that must fight a foreign government for permission to protect its customers is not sovereign over that data, and neither are its customers. The fight is the proof. You do not fight a power you are free of.
That sentence in the Senate did what a thousand pages of analysis could not. It removed the deniability. The data of a French hospital is subject to the law of the United States, and the company that holds it says so to a parliament, on the record, because it could not say otherwise without perjury.
The admission is sharper still when set against the product Microsoft had built to answer exactly this fear. In 2025 the company finalised its EU Data Boundary, a commitment to store and process European customer data for its major cloud services entirely within the European Union. It is real engineering and it was expensive to build. It is also the wrong lock. The Data Boundary controls residency, where the data physically sits. The CLOUD Act controls jurisdiction, who can compel the company that holds it. A US corporation remains subject to a US legal order wherever its servers stand, so a record kept in a Frankfurt data center inside the Data Boundary is exactly as reachable as one kept in Virginia. The boundary moves the data and leaves the jurisdiction untouched. It answers a question no one was really asking, and the executive who could not guarantee protection had that very boundary already in hand when he said so.
The Settlement Rests on a Signature
The fragility of the whole arrangement became visible within months of a change of administration in Washington, and it revealed how little the European safeguard had ever been worth.
The adequacy decision stands on Executive Order 14086 and the redress machinery it created. An executive order is not a statute. It is the standing instruction of one president, and the next president can revise or revoke it with another signature. The redress system also depends on a small federal body, the Privacy and Civil Liberties Oversight Board, which is meant to monitor surveillance and issue the reports the framework treats as evidence of American good faith. In late January 2025 the new administration removed the board's three Democratic members by one sentence emails, dropping it below the quorum it needs to function. A board that cannot reach quorum cannot issue the reports the Data Privacy Framework relies on. A federal court ruled in May 2025 that the removals were unlawful and ordered reinstatement, but the point had already been made. The mechanism Europe had accepted as its protection could be disabled, for months at a stretch, by a single administration acting in its first week.
This is the deepest weakness of the settlement and the clearest proof of the thesis. The European Commission certified that American safeguards were adequate. Those safeguards rested not on law but on the revocable preferences of the American executive, and the executive demonstrated, almost immediately, that it could switch them off. The data kept flowing throughout. A protection that the protector can withdraw at will was never a protection. It was a posture held just long enough for a foreign court to accept it.
The Infrastructure Rule
There is a principle that operates beneath politics and economics, invisible until the moment it turns catastrophic. Whoever owns the layer beneath the market eventually governs the market. This is not metaphor. It is the observed behaviour of every system in which a technical substrate consolidates into a single set of hands.
Consider SWIFT, the messaging network that moves money between banks. When it became the global standard in the 1970s it was a cooperative headquartered in Belgium, neutral by design, owned by no government. For four decades that neutrality held, and no one imagined it could be otherwise. Then the centrality itself became the weapon. Beginning in the 2010s, the United States discovered that a network this essential, even one based in Brussels, could be made to obey Washington. Iranian banks were removed. They could send money nowhere, because there was no alternative at scale. The neutral pipe had become an instrument of statecraft, and nothing about the pipe had changed except the willingness to use it.
Consider GPS, built by the United States Department of Defense as a military system and then opened, generously, to the world. Every phone, every ship, every tractor now navigates by American military infrastructure. The signal is free. The dependence is not. The owner retains the capacity to degrade, to restrict, to switch off by region, and the existence of that capacity is itself a form of power that no treaty constrains. No rival was built for years, because the barrier was too high and the first mover had already won the world.
The same shape recurs across the entire base of modern life. Chip fabrication concentrated in Taiwan. Chip design concentrated in America. Rare earth processing concentrated in China. The dollar as the currency of settlement. Cloud as the substrate of computation. In each case the concentration arrived through ordinary market logic, whoever invests first and reaches scale first wins, and in each case the winner's dominance looked temporary right up until it was revealed as leverage. Law follows infrastructure far more often than infrastructure follows law. The CLOUD Act did not invent American jurisdiction over European data. American companies had already built that jurisdiction out of fibre and concrete and capital, and Congress merely wrote down what the market had already settled.
The Pattern Beneath the Pattern
Strip the CLOUD Act of its specifics and a sequence appears that has run, identically, through finance, navigation, energy, and computation. It runs in five movements, and at every movement the outcome still looks avoidable.
A market creates a dependency. American infrastructure reaches a scale competitors cannot match, and the standard becomes inevitable. The dependency hardens into lock-in, as systems integrate around the standard until migration becomes technically and financially catastrophic. The lock-in produces jurisdiction, because once the infrastructure is essential its owner can attach conditions to its use, and a technical choice quietly becomes a legal architecture. The jurisdiction becomes power, as the owner gains the ability to impose sanctions, demand access, and extract value, so that a private company's commercial reach becomes a state's strategic reach. And finally the power is presented as law. Congress passes a statute, the Treasury invokes a sanction, the regulator issues a rule, and what was always leverage is dressed, after the fact, in the language of legitimacy.
At each stage reversal looks possible. Europe could build its own cloud. Europe could fund a SWIFT alternative. Europe could subsidise chip fabrication until it reached scale. The technical possibility is real at every step. And yet, step after step, none of it happens, not because Europe is weak but because the cost of reversal outruns the political will to bear it precisely when reversal would still work. The trap is never locked with force. It is locked with economics, and economics does not feel like coercion while it is happening. It feels like the sensible thing to do.
This is why the words digital sovereignty, financial sovereignty, technological sovereignty are not slogans. They name concrete control over the layer beneath the market. Lose that layer and no later assertion of political will can recover it, because the infrastructure has by then become the real constitution, and the owner of the infrastructure has become the real sovereign, whatever the parliaments still say.
The Next Layer
If the pattern holds, and the argument here is that it is structural rather than accidental, then the place to watch is not cloud storage but the layer now consolidating above it. This is the forecast, and it should be read as a marked hypothesis rather than a settled fact.
Artificial intelligence runs on two scarce things, vast quantities of specialised compute and a handful of frontier models trained on it. Both are concentrating in the same hands that already hold the cloud. The largest training runs happen on infrastructure owned by Amazon, Microsoft, and Google, the last of which also fund or host the leading model laboratories. Europe regulates this technology ambitiously through its AI Act, governing how models may be used, by whom, under what risk tier. It does not own the compute the models are trained on, and it has no frontier laboratory at comparable scale. The shape is identical to the cloud, one stage earlier. Europe is writing the rules for a substrate it does not control, exactly as it wrote the world's strictest privacy law and then ran it on American servers.
The continent has begun, late again, to notice. The 2024 Draghi report on European competitiveness named the failure to seize the digital transition as a central reason the continent risks becoming an economic laggard. In early 2025 the EuroStack initiative gathered more than a hundred partners to pool European infrastructure and build a sovereign technology stack. It is the right idea, and if the cloud is any guide it is arriving at the moment the lock-in is already forming rather than years before it. The window for AI compute may be closing now, quietly, while the regulation of AI use absorbs all the political attention. If a statute attaching government access to AI infrastructure appears within a few years of that consolidation, the way the CLOUD Act appeared after the cloud consolidated, the pattern will have completed another full turn.
The Honest Objection
The strongest case against this reading does not dispute a single fact. It disputes the finality. The CLOUD Act exists, yes. American companies control the substrate, yes. But this is policy failure, the objection runs, not structural fate. Congress could amend the CLOUD Act tomorrow. It could require a warrant in the host country. Europe could mandate hard data residency the way China does. European states could subsidise European infrastructure until it stood on its own. Microsoft itself fights the warrants and sometimes wins, so the constraint is negotiable, not absolute. None of the mechanism is written in stone.
Every word of that is correct, and it is the right objection to raise. The reading here is narrower than the objection assumes. It does not claim reversal is impossible in principle. It claims that reversal requires something the objection never supplies, which is an institution capable of absorbing the transition cost while its competitors do not. That is the wall the Deutsche Bank study hit. The bank had the awareness, the analysis, and the motive, and it still could not move, because moving alone was competitive suicide and moving together required a coordination no market produces on its own. Political will can mandate the destination. It cannot, by itself, pay the price of arriving, and the price is structured so that whoever pays it first loses.
So the objection is logically sound and institutionally weightless. Yes, Europe could override the market that built the lock-in. But overriding that market means overriding the same force, capital flowing to the lowest cost provider, that created the dependence in the first place and that reasserts itself the moment the political pressure relents. The architecture does not survive because reversal is forbidden. It survives because the system that produced it is still running, and that system rebuilds the trap faster than any parliament dismantles it. Microsoft fighting the occasional warrant is not the counterexample. It is the architecture's most honest witness, a company demonstrating, every time it litigates, that the data was never under European control to begin with.
The Sovereignty That Was Never Real
European digital sovereignty was lost long before the debate over it began. It was lost when the procurement decisions chose convenience over control. It was lost when European capital declined to build the alternative. It was lost when the integration grew too deep to unwind without rupture. By the time the word sovereignty entered the conversation, the thing it described was already gone.
The CLOUD Act did not defeat that sovereignty. The law merely arrived to record what the market had already decided, that the layer beneath European politics would be governed from outside Europe. Schrems won twice in court and the data kept flowing. The Commission certified what it had already documented to be false. A Microsoft executive told a parliament the truth and the contracts renewed anyway. At each step the institution chose the running machine over the rupture, and called the choice compliance.
The reader arrives at the recognition late, the way everyone does, after the integration is complete and the alternatives have vanished and the reversal has become catastrophic. That lateness is not an accident of attention. It is the design. An infrastructure becomes invisible exactly when it becomes total, and politics, arriving to govern what it can no longer see, governs only the surface while the substrate governs everything else.
The architecture accounts for every actor except one. The person who realises it is too late.
Evidence Map
Facts, interpretations, forecasts, and disconfirming signals.
Core claim. European loss of control over its own data was produced by infrastructure consolidation and switching costs, not by the CLOUD Act; the 2018 law formalised a dependency that decades of procurement had already made structural, and European institutions ratified it because rupture cost more than the fiction of compliance.
Evidence level. Facts (high): the Microsoft Ireland case and its April 2018 vacatur; the CLOUD Act signed March 23, 2018 inside the Consolidated Appropriations Act; Schrems II (July 16, 2020); Executive Order 14086 (October 7, 2022) and the Data Protection Review Court; the adequacy decision (July 10, 2023) and its acknowledged CLOUD Act concern; the General Court upholding the framework (September 2025); the Microsoft France Senate testimony (June 10, 2025); the 2021 entry of US and Chinese hyperscalers into GAIA-X. Interpretation (medium, marked): that the redress court is designed for the appearance of remedy; that the certification was a knowing choice rather than an error. Forecast (speculative): that the same five step pattern will recur in AI compute and model infrastructure.
What would confirm this. A future critical infrastructure layer (AI training compute, foundation models) consolidating in a few US firms, followed within years by statutory access powers attached to it. Continued renewal of European public cloud contracts despite the 2025 admissions.
What would disprove this. A European cloud reaching genuine commercial scale and capturing major sovereign workloads without state coercion; or US reform requiring host country warrants that materially ends extraterritorial compulsion; or European states absorbing migration costs and exiting at scale.
Watchlist. EuroStack and sovereign cloud procurement mandates; any Schrems III challenge to the Data Privacy Framework reaching the Court of Justice; AI compute concentration and the first access statute attached to it.