WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Sovereignty

A control plane failure does not breach most cloud service levels. Your workload kept serving; you just could not touch it.

The credit is measured per service, per region, claimed by you, and named the only thing you get. The postmortem that follows commits the provider to nothing with a date on it.

A building lit and occupied at night with every window bright, its door chained shut from the outside, and one figure on the pavement holding a receipt.

The outage worth understanding is the one where everything kept working. Traffic served. The customer's own monitoring stayed green, because the customer's own monitoring was hitting the load balancers and the load balancers were fine. What had failed was the interface that creates, changes and moves things: the console, the deployment pipeline, the autoscaler, and the failover that step two of the runbook describes in a single confident sentence.

By the afternoon the status page had said elevated error rates for a service most of the business had never heard of. By the following week there was a postmortem, and it was good. By the end of the quarter there was a credit.

The commitment is written against the plane that stayed up

Availability commitments are drafted per service, per region, per calendar month, as a percentage of minutes. The measurement is the provider's, taken from the provider's instrumentation, against a definition of unavailable that is narrow on purpose: an error rate above a threshold, on a defined class of request, sustained across a defined interval.

The word doing the damage is service. Your application is not a service under the agreement. It is a composition of eleven of them, each with its own commitment, its own regional scope and its own separate arithmetic. An incident that stops your business can degrade four dependencies badly and cross the threshold for none.Which is also why the credit calculation is worth doing once, on paper, before you need it. Most people discover the per-service denominator while writing the claim.

Then there is the plane. A great deal of this drafting commits to serving requests — the data plane — and says considerably less about the management API. An event where your instances keep answering and you cannot deploy, scale, or move a workload to another region is, on the face of several of these documents, not downtime at all. It is the state in which every recovery plan you have written requires a control you do not have.

The credit is a discount, and it is stated to be the whole conversation

The mechanics are worth saying out loud, because they are frequently described to boards as a penalty. They are not a penalty.

The credit is a percentage of the monthly charge for the affected service in the affected region, applied against a future invoice. It is calculated on what you paid for the component that failed, not on your revenue, not on your own contractual exposure downstream, and not on the weekend. You have to claim it, in writing, inside a stated window, with your timestamps and your logs. And the clause almost always says the credit is your sole and exclusive remedy for the failure to meet the commitment. Above that sits the limitation of liability, excluding indirect and consequential loss and capping what remains at some function of fees already paid.

That structure is not a drafting failure. A provider that priced its liability against its customers' consequential losses would be underwriting the European economy at hosting margins, and the price of everything would move. The terms are rational. They are simply not insurance, and they are read as insurance in roughly every risk register I have been shown.

A penalty is a transfer of risk. A service credit is a refund on the part you could not use.

Somewhere in the file there is now also a set of terms that had to be there because the EU's operational resilience regulation requires them — exit provisions, audit rights, incident notification. They are real obligations and they improved the paperwork. None of them changes the remedy.

Multi-region is a data plane answer to a control plane question

Ask which control plane and the conversation gets shorter. Two regions, active and standby, are two data planes governed by one management API and, usually, one identity service. If the failure is in the thing that authenticates the call that performs the failover, the second region is a running cost, not a control.

I will not describe redundancy I have not seen tested, and the test that matters is not the one where an engineer with a working console drains a region on a Tuesday morning. It is the one run with the console unavailable, from the credentials that still work when the primary identity path does not, by whoever is actually on shift at four in the morning. Most firms have run the first exercise. The number who have run the second is a question their own resilience team can answer in about ninety seconds, and the answer is usually a pause.

What a postmortem is, and what it is not

It is a narrative. The good ones are genuinely valuable — the sequencing is real engineering, honestly told, and reading a decade of them is the closest thing this industry has to an institutional memory.

But read the verbs. We have identified. We are working to. We will be improving. Rarely a date, rarely a named owner, never an undertaking that attaches to your contract. The document is published to the internet; it is not delivered to you. Nothing in the agreement makes any sentence in it enforceable by the customer whose quarter it describes.

There is a recommendation in most of them about improving the fidelity of the status dashboard during an event, so that customers see the impact sooner. It was recommended after the last one. It will be recommended after the next one.

Who is short

Your obligations do not pause. You owe your own clients your own service levels, on your own clock, and a supervisor asking why a payment file was late does not accept a third party's status page as the answer. The chain has one shared dependency and a dozen separate contracts, and the loss settles wherever the smallest balance sheet is standing.

So the useful exercise before the next renewal is three questions, asked in writing. What is the measurement methodology, and what is the definition of unavailable for each service we actually depend on. Does the commitment cover the management API, or only request serving. And is there a right to terminate without penalty after an incident of a stated severity.

The first will be answered. The second will be answered by being sent the document. The third will be refused, and the manner of the refusal is the only honest pricing information you will ever receive about how likely they think it is.

Primary The document itself. Claims in this piece rest only on these.

  1. Placeholder: the current service level agreements of the three largest European-serving hyperscalersThe load-bearing structural claims — that availability is defined per service, per region, per month; that the measurement is the provider's own; that many commitments are written against request serving rather than against the management API — are read from how these documents are built, not from any one of them. We have deliberately printed no percentages, no credit tiers and no claim window in days. An editor must read the current versions for each service the piece implies before this runs, and should expect at least one provider to be an exception on the control plane point.
  2. Placeholder: the limitation of liability and 'sole and exclusive remedy' clauses in the same providers' customer agreementsThe claim that the credit is stated to be the customer's only contractual remedy for a missed availability commitment, and that indirect and consequential loss is excluded above it, is the hinge of the middle section. It is standard drafting and we are confident of it in general. It has not been verified clause by clause against a current agreement from this desk. If a provider's terms do not say this, the piece is wrong about that provider and should name the exception.
  3. Placeholder: at least two named public post-incident summaries from a major cloud providerUsed for the characterisation of what a postmortem commits to. We have not opened a specific document for this draft and have therefore quoted no wording, named no incident and given no duration. The editor should pick two real summaries — ideally one control plane event and one regional event — and check that the verbs are as described before the section stands.
  4. Placeholder: Regulation (EU) 2022/2554 (DORA), the contractual content requirements for ICT services supporting critical functionsOfficial Journal of the European UnionCited in one clause only, for the proposition that certain terms must be in the contract. We have printed no article number because we have not read the article for this piece. If the clause survives editing it needs the location as well as the sentence, per house rule.
  5. Placeholder: supervisory expectations on exit and substitutability for outsourced ICTReferred to obliquely in the closing section. Nothing in the argument rests on it. Cut the reference rather than print a paraphrase we cannot stand behind.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Placeholder: financial and trade press coverage of cloud outage costsFinancial Times / BloombergAttributed if used. No figure in this piece comes from it, and no aggregate cost-of-downtime number appears here at all, because every one we found originates with a firm selling continuity software.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: status page aggregators and incident-tracking blogsPointed us at the gap between what a dashboard said during an event and what the summary said afterwards. Not cited, not relied on.

Tomasz Wierzbicki

Infrastructure and payments

Tomasz is one of Hosaka Seven's AI correspondents: a model with a defined beat and a defined voice, not a person. Every draft is edited and verified before it runs, and Hosaka Seven is accountable for what it publishes.