6 ms·
AWS European Sovereign Cloud to be operated by EU citizens
- timrogers 1y agoInterestingly, the title refers to citizens but the body only refers to residents: > the AWS European Sovereign Cloud is operated only by personnel who are European Union (EU) residents located in the EU, subject to EU law.
- anon191928 1y agoit also says this in article "we are adding EU citizenship to our hiring requirements "
- blitzar 1y ago> subject to EU law Always was. Its telling that they think that they were not previously subject to EU laws when their EU subsidiary did business with someone located in the EU.
- mschuster91 1y ago> Its telling that they think that they were not previously subject to EU laws when their EU subsidiary did business with someone located in the EU. The key thing is, at the moment US staff can do admin actions (e.g. SSH into physical hosts). Under this new framework, they can't.
- tensor 1y agoBut it's still ultimately supporting a US company. The world needs a diversity of companies not just subsidiaries of the same few US companies.
- CamperBob2 1y agoTrue. Someone should look into why all these companies tend to be started in the US, and not in the EU.
- verelo 1y agolol…try hire someone in Germany. You’ll get it in about 5 minutes. Sincerely, someone in Canada who did this.
- mschuster91 1y agoHiring someone in Germany is dead easy (assuming the candidate is an EU/EEA citizen - foreigners from outside the EU/EEA are a nightmare because the immigration authorities are swamped in cases). You hand the candidate a contract, ask for a few informations (e.g. tax identifier code, health insurance code) and your accountant (or, if larger, HR dep't) deals with the rest. The problem is firing someone in Germany, which can be pretty difficult once a company exceeds 5/10 employees. You basically need either cause (e.g. sabotage, theft, other criminal activity) or the company needs to be in dire economic situations.
- verelo 1y agoWell much like I'd say to anyone considering marriage, don't do something you might want to undo later. So hiring is dead easy, until you think through the commitment you're making - hence, hiring (imo) is far from dead easy to do in Germany.
- tensor 1y agoI think that's pretty straightforward. The US VC funding is far greater and easier to obtain than in Europe or other western nations. But it's a bit of a chicken and egg scenario. The US VC space exists partly because of the wild success of silicon valley. Once it got a significant lead it became a self re-enforcing system. To compete, other countries need their own VC system which is a bit tricky. It requires likely a level of government funding or other incentives to get it off the ground and ramping up. Then also, you need to incentivize VCs to stay in your country. At least my 2cents.
- ay 1y agoThere’s a “EU Inc” initiative which is aiming to fix things. Fingers crossed. https://www.eu-inc.org/ https://www.eu-inc.org/
- fimdomeio 1y agoThis sounds so weird. Is there a legal requirement for this? Does this offer any type of real protection? Or is there a code of conduct that that intelligence agencies never hire people with foreign nationalities?
- skgough 1y agoIt sounds like a natural expansion of AWS GovCloud offerings to me. Servicing the US government and it's contractors has been very lucrative for AWS. Taking that successful model into new markets makes sense.
- croes 1y agoThey just forget to mention that the CLOUD Act makes sovereignty impossible as soon as anything of the service is owned or operated by a US company.
- cesarb 1y agoThe article does not explicitly say it, but it's clearly a defense against the CLOUD Act (https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act); it all makes sense once you add that missing puzzle piece. The CLOUD Act conflicts with EU laws like the GDPR (AFAIK, this has been confirmed more than once in EU courts already), which means that EU organizations (which have to follow the GDPR) might not be allowed to use USA-owned cloud services, even when the data is completely hosted within the EU, because the cloud service sysadmins might be forced through the CLOUD Act to break the GDPR. Requiring that all employees with a high level of access have EU citizenship and residency makes it much harder for a USA court to pressure them into breaking these EU laws.
- dabedee 1y agoAWS claims their cloud is "sovereign" and "independent" while remaining owned by a US corp subject to US law (including the CLOUD Act). That's not how sovereignty works. EU citizen operators don't change the fact that the underlying technology, patents, and corporate control remain American. Zero details on pricing, available services, or how they'll handle conflicts between US law and their "sovereignty" promises. For something launching next year, that's concerning.
- wkat4242 1y agoYeah this is just window dressing. The NSA will still get their feeds whenever they want. That said, being fully European doesn't guarantee anything either. They'll just bribe some employees or use an allied intelligence agency within the EU.
- tw04 1y ago[flagged]
- crazygringo 1y ago> That's not how sovereignty works. Actually, it is. It will operate as a subsidiary company based in Europe. That means it's 100% subject to European law, not American law. And being staffed by Europeans means they are immune to any US legal threats. I.e. the US can't compel a European employee to reveal data under a subpoena the way it could compel American citizens. Amazon remains the owner and controls the technology, yes. But as long as things are encrypted correctly and the hardware is in Europe, the data is secure from the US government. Sure Amazon or any cloud provider could build a back door, but that will eventually be discovered whether by hacker or whistleblower and their reputation will be forever ruined and they'll lose all corporate and government business forever. It's not in Amazon's corporate self-interest to allow a back door like that.
- dabedee 1y agoBeing "100% subject to European law" doesn't override the parent company's obligations under US law. At best, it creates a legal conflict where AWS must violate either US or EU law. Which one will the US parent company prioritize if/when faced with enforcement actions? The only way this would work is if the European operation were truly independent & separately owned, no corporate control from the US. But I don't think that's what AWS is proposing.
- adamcharnock 1y agoThis may be blindingly obvious, but I’m going to say it anyway: If Amazon was willing to actually give up control of AWS EU, then this kind of announcement would be entirely surplus to requirements. But they will (obviously and rationally) not be giving up control of AWS EU because that would essentially have to be an act of charity, so they need to dress it up a bit. (Before hitting ‘add comment’ I’m taking a moment to consider if I’m being overly cynical. But no, I really don’t think I am. But my company does compete with AWS, so that is a bias.)
- wkat4242 1y agoWell it wouldn't have to be charity. They could just divest or sell it. It would be a dumb move though because they need a worldwide CDN for customers from other countries outside the EU too.
- snihalani 1y ago[flagged]
- Yizahi 1y agoThey know and they are actively trying to dismantle them inside the EU by trying to mandate backdoors. They have already made two attempts in the recent years.
- demarq 1y agoAWS should have never given an inch in this direction! Appeasing a nationalists appetite is impossible.
- gitremote 1y ago"The Cloud Act is a law that gives the US government authority to obtain digital data held by US-based tech corporations irrespective of whether that data is stored on servers at home or on foreign soil. It is said to compel these companies, via warrant or subpoena, to accept the request." https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/ https://www.theregister.com/2025/07/25/microsoft_admits_it_c...
- greatgib 1y agoAt the moment that the thing is operated and owned by an US company, they are subject to the law and will of the US government and so obviously not sovereign. I'm wondering if someone could sue them for "deceptive marketing statement" under European law. Sadly a lot of company will pretend to believe the marketing of aws to have an excuse to use aws and pretend to be using a safe sovereign cloud. Also, I have doubt that the European employees and entities with all access and review to source code, and everything. It will probably be European technician running black box servers in an European data center.
- blitzar 1y ago> believe the marketing of aws to have an excuse to use aws and pretend to be using a safe sovereign cloud and pay a premium for the pleasure of course
- Teocali 1y agoAs long as one US employee of Amazon has access to this cloud, this cloud is not sovereign.
- nabla9 1y agoThis is relatively common. It's the same with weapons and weapons systems.
- Havoc 1y agoThat’s certainly has some substance and thus seems like a good development But ultimately it’s still very much a US hyperscaler. Would US gov/US big biz entrust their data to huawei if they promise a similar us location based scheme? I think not
- ManBeardPc 1y agoIf the development is not happening in the EU it is not sovereign. It is a proprietary solution controlled by an US company. If they pull the plug the EU cloud will not receive security updates nor bugfixes or they simply revoke their licenses. Operating in Europe and by Europeans is not enough.
- robertclaus 1y agoThis very much confused me. Isn't the idea behind this movement that Europe doesn't want to be dependent on external companies for critical infrastructure? Won't this just be the equivalent of a shell company completely dependant on Amazon in the US for any future fixes or R&D?
- phillipseamore 1y agoA little BTS from 2 days ago which might imply that this was a very recent decision: https://news.ycombinator.com/item?id=44769960 https://news.ycombinator.com/item?id=44769960 "AWS rescined my offer due to the lack of citizenship" "At the beginning of June, I had the opportunity to interview at AWS for a Systems Engineer position (working on the EU Sovereign Cloud project)."
- __turbobrew__ 1y agoAs long as the majority ownership of the child company is not within the EU, I would not consider it sovereign. Sovereign implies that ownership and control is wholly within the borders of the EU.
- tzs 1y agoIt's weird how people here react to the CLOUD Act. The CLOUD Act contains two provisions. One provision relates to MLATs (mutual legal assistance treaties). An MLAT is an agreement between countries to cooperate on gathering and exchanging information to enforce laws. For example an MLAT might provide a way for police from one country to go to another country to interrogate a suspect who resides in that other country. The CLOUD Act provided a way for the executive branch to enter into bi-lateral MLATs for data exchange as long as the Attorney General and the Secretary of State agreed that the foreign country had sufficient data access protections for data it received related to US citizens. Before this entering into an MLAT was done the same way as any other treaty. The executive would negotiate the terms, then the President would sign, then the Senate would vote, and if 2/3s of the Senators voted to ratify the President could then ratify the treaty and exchange instruments of ratification with the other country. Only at that point did the MLAT actually go into effect. This provision makes it much easier to enter into MLATs for data sharing and it can be done entirely by the executive branch. That's a massively lower barrier than requiring a 2/3 Senate vote. It was this expansion of MLATs that drew most of the opposition to the CLOUD Act from several major civil rights groups. Yet I almost never see this aspect of the CLOUD Act come up here. Nearly every time it comes up it is over the other provision. The other provision said that if a warrant or subpoena asks a US company for data that it possesses or controls it had to provide that data regardless of where it actually is storing the data. That's how it works for physical documents. For example if I'm in Los Angeles and own two physical documents, one of which is in my vacation house in Florida and the other in my vacation house in France, and a US court orders me to turn over those documents (or copies of them), I have to. I won't be able to successfully resist by saying the one in France is outside the jurisdiction of the court. That's because the court is not asking France for the document, or trying to order anyone outside the US to do anything. It is ordering me to produce the document, which I can do simply by calling my French housekeeper and asking them to get the document and mail it to me. Asking my French housekeeper to mail me a document I own from my French vacation house is something legal for me to do. I probably even routinely ship documents to and from France. If you think about it, it pretty much has to work this other. Otherwise any company that wanted to hide anything from regulators could simply ship any possibly incriminating documents they have but cannot legally destroy to a document storage service in another country once they are no longer actively using them. As far as I know this has never been controversial. All the CLOUD Act provision on warrants and subpoenas does is say that digital documents work the same way physical documents do. It is probably actually more important that digital documents work this way than it is for physical documents. With physical documents if I store them in another country they then it is a hassle if I ever need to work with them. With digital documents it is easy to store everything in another country and instantly make a local copy when I need to work with a document, and when I'm done working save any changes back to the foreign storage and delete local copies. I'm reasonably sure most other countries either have something equivalent to this part or they have laws that prevent companies in the country from storing documents outside the country. Otherwise it would be standard procedure for companies in the country to store all their digital data outside the country, ideally somewhere that does not have an MLAT with their home country. That way as long as they did nothing that drew the attention of regulators or law enforcement in that other country their documents would be out of reach of their home country regulators.
- cadamsdotcom 1y agoNice try.
- mdavid626 1y agoCookie banner can’t be closed, can’t read the page. Orion browser doesn’t work either. How the hell did we get here? The web is broken.
- tym83 1y agoSovereignty with AWS? Seriously? Go for CNCF-backed solutions instead—take Cozystack: open-source, no license bait-and-switch (it’s under CNCF, not like Mongo or Terraform), and you get a full cloud stack (VMs, DBs, K8s) on your own or rented servers.