# Cloud Sovereignty, Provider Risk, and Migration Options for EU Companies

DevFeed: [Cloud Sovereignty, Provider Risk, and Migration Options for EU Companies](<https://devfeed.tech/articles/beyond-the-hyperscalers-what-actually-protects-you-31468.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/beyond-the-hyperscalers-what-actually-protects-you/>)

Author: Adam Gordon Bell

Published: 2026-09-16T13:00:00Z

Content type: opinion

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [migration](<https://devfeed.tech/topics/migration.md>), [pulumi](<https://devfeed.tech/topics/pulumi.md>), [Security](<https://devfeed.tech/topics/security.md>), [scaleway](<https://devfeed.tech/topics/scaleway.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [customers](<https://devfeed.tech/tags/customers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [pulumi](<https://devfeed.tech/tags/pulumi.md>), [scaleway](<https://devfeed.tech/tags/scaleway.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This recorded discussion examines cloud sovereignty, legal and cost concerns for EU companies using major US cloud providers, and the practical tradeoffs of moving to European providers. Three guests discuss provider exposure, encryption and account shutdown risks, migration costs, and whether Pulumi and agentic infrastructure can make future moves easier.

## Source excerpt

Recorded September 3, 2026. Quotes are lightly edited for clarity. Maybe this sounds familiar. You run infrastructure at a company that isn't American. Your workloads are on AWS, Azure, or Google Cloud, probably more than one, because that is what everyone picked. Until recently nobody asked you where the data lives or who can reach it. Now you're getting questions. Legal wants to know what NIS2 means for where your systems run. Someone on the leadership team read that the US government locked the cloud accounts of judges at the International Criminal Court and wants to know if that could happen to you. Finance wants to know why the bill went up again. A customer's security review asked, in writing, which country your data sits in. So now you have questions of your own: If a US court or agency wants my data, can they get it from my provider without involving me? Does putting everything in an EU region change that? The big providers now sell "sovereign cloud" in Europe. Is that different, or a rename? If I encrypt everything and hold the keys myself, am I covered? Could my account be switched off one day? What would I do? Are Hetzner, OVH, and Scaleway usable for real workloads? How much cheaper are they once you count the migration? What should I be building on now so I can leave later if I need to? A migration like this used to be a multi-year project. Does Pulumi and agentic infrastructure change that? Is any of this worth the disruption, or should I leave what works alone? I put those questions to three people who have each dealt with this for real. One of them helps EU companies work out their exposure and builds the tooling to leave. Another has spent fifteen years sizing what cloud actually costs, and thinks most people should stay put. The third moved his company off AWS and onto a European provider. They don't agree on how big the risk is. The full hour is below. Don't just default to the hyperscalers Waldemar Kindler co-founded Think Ahead Technologies, whe