WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Sovereignty

Your data stays in the region. The instruction that moves it arrives from somewhere else.

Residency is a claim about bytes at rest. Identity, build artefacts, telemetry and the break-glass rota are four separate systems, and most datasheets give them one row.

A sealed glass case of documents on a plinth, with a painted line running across the floor and up the walls to mark the room as a territory. A long mechanical arm enters through a narrow slot high in the wall, crosses the line, and rests one finger on the case’s latch.

Draft, not yet edited. Written by Iris Valdés, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

Ask a vendor where your data is and you get a city. Ask where the console sits that can move it and the sentence gets longer.

Both answers can be true at once. They are answers to different questions, and only one of the questions is on the datasheet.

Residency is a commitment about rest

A data residency commitment says something narrow and checkable: the records live on media inside a named territory and they are processed there. It is a good commitment. It is warrantable, it is auditable, and the industry has had a decade of practice writing it down.

What it does not describe is the channel by which the machines holding those records are told what to do. That channel is a separate system with its own geography, and it has never been the subject of the sentence.

Under the GDPR the processor acts on the controller's documented instructions. The whole architecture of the relationship is built on the instruction as its unit. Which makes the useful question about any large platform not where the records are kept, but how many other instruction channels reach the same machine and where each one begins.This is not an argument that those channels are sinister. It is an argument that they exist, that they are load-bearing, and that a document about storage is silent on all of them.

A region is four systems, and the datasheet counts one

A cloud region is not a single thing that is either here or not here. It is a data plane, which holds and serves your records, and a set of other planes that the data plane obeys. At minimum, four.

Identity. Something validates a credential before storage does anything at all. In the large clouds that something is usually a global service with a regional front door, and the trust runs outward.

Build and release. The software on the racks is compiled, signed and published somewhere else, then pushed in. A region does not write its own operating system.

Telemetry. Operational metrics and logs leave by design, because the people who keep a fleet alive look at the fleet, not at one region of it.

Operational access. A named human role that can act on infrastructure when the normal path is broken. Its geography is a rota question, and rotas follow the sun.

None of the four carries your records. All four carry instructions.

A region boundary. Storage and processing loop inside it. Identity assertion, signed build artefacts and break-glass sessions cross inward from outside; telemetry crosses outward.Region boundaryData planeYour records, at rest and in flightStorage and processingIdentity assertionSigned build artefactBreak-glass sessionTelemetry
Storage and processing are the only things that stay inside. The four that cross the boundary are the ones the sentence about residency is not a commitment about.
The sentence on the pageWhat it is a commitment aboutWhat it leaves open
Data stored and processed in the EUBytes at rest and in flightWho can issue an instruction to the machines holding them
Operated by EU-resident personnelEmployment contractsWhether a non-EU role can act without a person
Physically isolated sovereign regionThe data planeIdentity, release, telemetry, operational access
Customer-managed encryption keysKey custodyWhose process the key is used inside
Support delivered from within the EUThe tier-one rotaThe escalation path past tier three

Every cell in the middle column is true. None of them is false advertising. They are precise answers, and the imprecision arrives later, when five precise answers get summarised into one word on a slide.

Three questions, and the second one is the slow one

If the global identity service were unreachable from this region for an hour, what stops working? If new sessions stop, identity is not in the region. If the answer is that nothing changes, the follow-up is who validated the last token and how long that validation stays good for. Both answers are useful. Only one of them appears in any marketing material.

Who signs the binaries, and can a signed change reach this region without anyone inside it approving it? The answer is usually yes, and usually for a reason you would endorse if it were explained to you, which is that you want Tuesday's security patch on Tuesday and not after a local review board has met. That is a defensible engineering decision. It is also a standing inbound instruction channel from wherever the build system lives, and it is not mentioned in the residency clause because the residency clause is about your records and this is about their code.

Which role outside the region can act on infrastructure inside it, under what trigger, and where is its use logged in a place I can read without asking you? The last clause is the one that changes the answer. Break-glass access that is logged to the provider's own systems, disclosed on request, is a different control from break-glass access that lands in your tenant within the hour.

Three is what a reader can carry. There are more — whose process the key material is used inside rather than where it is stored, the escalation path past tier three, the firmware and hypervisor supply chain — and the shape is the same every time.

A region that built its own identity service, its own compiler and its own on-call rota would not be a region of that cloud. It would be a different cloud with the same API.

Which is why the real ones are expensive, and say so

The gap is architecture before it is anybody's marketing. These planes are shared because sharing them is how a global platform stays coherent, patched and affordable, and the engineers who built it that way were solving a problem, not hiding one.

Which tells you what a genuine sovereign offering has to have paid for: a separate identity plane, a release gate that a person inside the perimeter can hold shut, operations staff whose access does not route outward, and telemetry that is scrubbed and kept local. Every one of those is slower and dearer than the alternative, and where a provider has actually built them, the documentation tends to be specific to the point of tedium — because at that price, the detail is the product.

Vagueness, here, is information. So is the direction of the vagueness. Ask which plane moved and the providers who moved one will answer in build numbers, and the providers who moved none will answer with the address of a building.

The clause you want is in almost no agreement, partly because the thing it would commit to has no agreed name yet. Ask for it anyway. The redline that comes back is a more accurate architecture diagram than anything on the website.

Primary The document itself. Claims in this piece rest only on these.

  1. Placeholder: the published architecture and shared responsibility documentation for at least two sovereign or dedicated cloud region offeringsEverything in the middle of this piece — that identity, release, telemetry and operational access are separate planes with their own geography — is read from how these documents are built rather than from any one vendor's wording. No provider is named anywhere in this piece and no configuration is described as fact for any named region. An editor must open the current documentation for each offering the piece implies before it runs, and should expect at least one provider to be an exception on the identity plane, because at least one has spent real money on being one.
  2. Placeholder: the data residency and data location clauses of the same providers' current data processing addendaThe claim that the contractual commitment is drafted about storage and processing location, and not about the origin of administrative instructions, is the hinge of the first half. It is standard drafting and we are confident of it in general. It has not been verified clause by clause against a current addendum from this desk. If a provider's addendum does commit on administrative access origin, the piece is wrong about that provider and should name it as the exception rather than soften the sentence.
  3. Placeholder: Regulation (EU) 2016/679 (GDPR), Article 28(3), documented instructionsOfficial Journal of the European UnionUsed for one proposition only: that the relationship between controller and processor is built on instructions, which makes any other instruction channel into the same machine worth naming. We have quoted the operative words and nothing else. Read the point off the consolidated text before this prints; if the characterisation of the instruction as the legal unit does not survive, cut the sentence rather than hedge it.
  4. Placeholder: the European cybersecurity certification scheme for cloud services, on operational autonomy and immunity criteriaENISA / European CommissionReferred to obliquely and deliberately without a status, a level name or a date. We could not establish from this desk what the current published criteria say about operational autonomy as at September 2026, and the piece says so rather than assuming. Do not let an editor tighten that sentence into a claim about what any scheme requires.
  5. Placeholder: Regulation (EU) 2022/2554 (DORA), contractual content for ICT services supporting critical functionsOfficial Journal of the European UnionCited in one clause, for the proposition that the locations of provision and processing must be stated in the contract. No article number is printed because we have not read the article for this piece. If the reference survives editing it needs the location as well as the sentence, per house rule.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Placeholder: Brussels reporting on the sovereignty requirements in the cloud certification schemeMLex / EuractivAttributed if used. No claim in this piece rests on it, and the piece deliberately reports no negotiating position and no timetable.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: vendor launch material and partner blog posts for sovereign region tiersPointed us at the shape of the claim — that a single sentence about where data resides is being offered as an answer to a question about control. Not cited, not relied on, and nothing here should be edited into a statement about an identified vendor's architecture without documentation in hand.

Iris Valdés

Sovereignty

I track the platforms, the algorithms and the culture wars they trigger, from content moderation rulings to the latest app everyone downloaded this week. I read the comments so you don't have to.