What the Thales-Google sovereign cloud deal signals for financial services
On May 20, Thales and Google Cloud announced a sovereign cloud partnership in Germany. A new German entity, owned and controlled by Thales, will operate dedicated infrastructure independent from Google Cloud. Combined with the PREMI3NS sovereign region in France, this creates the first sovereign cloud that works across both countries. If one goes down, the other keeps running.
The announcement signals that sovereignty has moved from a theoretical regulatory concept to live infrastructure. You should watch this shift closely.
The gap between compliance and resilience
Financial institutions have made genuine progress. Multi-cloud and hybrid configurations with global hyper-scalers, sovereign partnerships with local independent providers (Thales with Google Cloud, Stackit with AWS, among others), and EU-hosted infrastructure are now part of the landscape.
These are sound steps. They do not, on their own, complete your sovereignty strategy. Your strategy must go beyond infrastructure. You need a recovery plan that works across providers and workloads that shift without disruption. You need tested exits, not just contractual ones. Your infrastructure gives you optionality. Your strategy decides whether you survive it.
You have likely seen this in your boardroom: the sovereignty presentation earns a round of nods and the meeting moves to the next agenda item. The resilience question often gets deferred to the next review cycle. It is the enterprise equivalent of a smoke detector that has not yet been tested against a real alarm. The device is installed. The drill has not been scheduled.
Data residency is necessary, however, is not sufficient on its own. Without recoverability, your compliance posture does not match your operational reality.

Is sovereignty market disruption or hype?
The regulatory pressure is genuine, and it no longer arrives in one framework at a time. DORA, the EU Data Act, and the EU AI Act form what the Cloud Security Alliance describes as a compliance cascade: an interlocking regulatory architecture in which each framework presupposes and amplifies the others.
DORA, in force since January 2025, mandates ICT risk management, incident reporting, and third-party oversight for all EU financial entities. The EU Data Act grants cloud switching rights: 2-month notice periods, 30-day transition periods, elimination of switching charges from 2027. The EU AI Act reaches full application in August 2026. The compliance deadlines carry enforcement teeth. The disruption is regulatory, not technological.
Your risk is not taking the wrong steps. Relocating data to a European region, encrypting it, and reporting compliance to the board are good measures. The risk is that these steps, conducted in isolation, leave resilience untested. Your strategy should ask harder questions:
- Can you recover critical operations within the timeframe you committed to your board?
- Can you move a core workload to an alternative provider within 30 days?
- Do you have the contractual, technical, and operational capability to change your current cloud arrangement without catastrophic cost?
If any answer falls short, you have identified exactly where your strategy can be strengthened.
What financial firms miss about sovereignty readiness
You may have two blind spots.
First: legacy systems built on decades-old platforms cannot be made portable. You cannot achieve cloud flexibility if your core systems cannot be moved from their current setup. Modernization is a prerequisite for sovereignty, not a separate initiative.
Second: sovereignty extends to AI, not just infrastructure. Your AI models, training data, and automated decision systems may sit outside the perimeter entirely. As the EU AI Act takes full effect in August 2026, that gap becomes a regulatory exposure.
What it means for your business
Full sovereignty across every system likely exceeds your budget reality. The cost premium runs 2-3 times higher than standard cloud configurations.
Protect your crown jewels first. And then attend to the next ones in line. Your top three critical systems (core banking, payment processing, customer data platforms) represent at least 20% of your workload portfolio. Securing sovereignty for those assets delivers 80% of your resilience benefit at a fraction of the total cost.
Your path depends on where you start. Tactical sovereignty applies targeted controls to your sensitive workloads, delivering protection with the least investment. A fast-path approach secures the crown jewels first and expands from there. Strategic transformation rebuilds your enterprise architecture for cloud flexibility and resilience by design.
How to find your gap in 30 days
One question reveals whether your sovereignty posture is tested:
If your cloud provider became unavailable tomorrow, how long would it take to restore this system on an alternative platform?
If you don’t know the answer, that is your gap. Run that question against your top five systems. Identify the platforms whose failure would halt operations. Compare the realistic restoration time to the recovery commitment you made to your board. Where a gap exists between the promise and the reality, you have found your starting point. This assessment takes weeks, not months, and can start with your existing team.
Read the case study: Accelerate Performance, Reduce Risks, and Optimize Cloud Investments
Opportunities and hurdles
The EU Data Act now gives you regulatory backing to demand portability from cloud providers, and switching charges disappear in 2027. The European Commission's Cloud Sovereignty Framework defines sovereignty as "effective control, not technological isolation," which validates hybrid approaches and removes the false binary of all-or-nothing sovereignty.
Regardless of how legacy your core systems are or how robust your current cloud setup appears, your most valuable next step is an objective assessment of your existing infrastructure and recovery terms. The gap between your stated recovery commitments and your actual recovery capability is the clearest measure of your sovereignty posture. That assessment is the starting point, whether you are three years into a cloud transformation or just beginning.
SoftServe brings certified expertise across AWS, Google Cloud, and Microsoft, combined with deep regulatory experience in financial services.
Learn more: Accelerate modernization across banking, insurance, fintech, and payments with Agentic AI
Frequently Asked Questions
European regulators keep tightening cloud rules. Should financial firms view sovereign cloud as an urgent priority or a long-term transition?
The urgency is real, but the approach should be phased. DORA enforcement started 17 months ago. The EU Data Act already grants cloud portability rights. The EU AI Act reaches full application in August 2026. Financial leaders who treat sovereignty as a future initiative will find themselves behind institutions that started with their highest-risk systems and built outward. Protect what matters first, then expand deliberately.
Many banks have already placed workloads in EU cloud regions. What risk remains after that step?
Location addresses one layer of the challenge. The deeper question: can the institution keep running if that cloud region becomes unavailable? A provider outage, a sanctions event, or a contractual dispute could disrupt access regardless of where servers sit. Recovery drills, not just location audits, reveal the real posture. Institutions should test their recovery capabilities against realistic disruption scenarios.
Sovereign cloud deployments carry a steep cost premium. How should a CIO justify this investment to the board?
Enterprise-wide sovereignty is prohibitively expensive for many firms. The stronger case: identify the three to five systems whose failure would halt the business. Securing those assets first captures the vast majority of resilience value at a manageable cost. That framing converts a board conversation from "we need a multi-year transformation" to "we can protect our critical operations within a defined budget and timeline."
How does AI governance connect to the sovereignty conversation?
Sovereignty rules typically cover infrastructure and stored data. Few institutions extend those principles to AI models, training datasets, or automated decision systems. As the EU AI Act mandates governance for high-risk AI applications in regulated industries, that gap becomes a compliance exposure. Financial institutions should evaluate where their AI systems run, what data trains them, and whether those components fall under the same controls as their core platforms.
If a financial institution wanted to evaluate its sovereign cloud readiness this quarter, where should it start?
Choose your single most critical system. Ask how long it would take to restore that system on a different cloud platform if the current provider became inaccessible. If the answer exceeds your stated recovery window, that is your sovereignty gap, and your starting point. Run the same test on your next four critical systems. The result maps exactly where your posture is tested and where it remains untested.




