sovereign-header.png
  1. Home
  2. Insights

Sovereign on paper. Fragile in practice.

08 Juli 2026

ShareShare the article

In brief 

  • Thales and Google Cloud launched the first pan-European sovereign cloud with cross-border disaster recovery. Sovereignty has moved from regulatory concept to live infrastructure. 
  • Financial institutions have built a solid compliance foundation. The next step is testing whether that foundation can withstand a real disruption, not just satisfy a reporting cycle. 
  • A 30-day self-assessment can reveal your resilience posture. Start with your crown jewels, not an enterprise-wide overhaul. 

Meet the Interviewee

Antonina Skrypnyk

Antonina Skrypnyk

Financial Services Industry Success Leader

Antonina brings more than 20 years of experience across banking, financial services, business consulting, and digital transformation. Prior to joining SoftServe, she held leadership roles in corporate and investment banking and private banking, managing portfolios across Europe and advising clients on complex financing and transformation initiatives. At SoftServe, she helps shape financial services strategy, solution development, and go-to-market initiatives, combining deep industry expertise with a strong background in technology-enabled business transformation. Antonina is a frequent speaker and thought leader on financial services innovation, emerging technologies, and industry trends. Antonina holds Master of Science in Financial Services, Law, Technology Management, and a Strategic Management Executive Program mandate with honors from University of Oxford Said Business School.

LinkedIn
Oleksandr Mykhalchuk

Oleksandr Mykhalchuk

Vice President of Critical Services

Oleksandr Mykhalchuk is Vice President of Critical Services at SoftServe, overseeing DevOps, Cloud Services, cybersecurity, and managed services worldwide. With over 17 years of experience, he built and scaled SoftServe's global DevOps and cloud practice into a cross-regional organization of more than 800 experts and engineers. He drives modernization, reliability, and security programs, develops technical leadership across the US, LATAM, and Europe, and regularly contributes to industry events and publications. Oleksandr studied mechanical engineering and computer science and holds an Executive MBA.

LinkedIn

What the Thales-Google sovereign cloud deal signals for financial services

On May 20, Thales and Google Cloud announced a sovereign cloud partnership in Germany. A new German entity, owned and controlled by Thales, will operate dedicated infrastructure independent from Google Cloud. Combined with the PREMI3NS sovereign region in France, this creates the first sovereign cloud that works across both countries. If one goes down, the other keeps running.

The announcement signals that sovereignty has moved from a theoretical regulatory concept to live infrastructure. You should watch this shift closely.

 

The gap between compliance and resilience

Financial institutions have made genuine progress. Multi-cloud and hybrid configurations with global hyper-scalers, sovereign partnerships with local independent providers (Thales with Google Cloud, Stackit with AWS, among others), and EU-hosted infrastructure are now part of the landscape.

These are sound steps. They do not, on their own, complete your sovereignty strategy. Your strategy must go beyond infrastructure. You need a recovery plan that works across providers and workloads that shift without disruption. You need tested exits, not just contractual ones. Your infrastructure gives you optionality. Your strategy decides whether you survive it.

You have likely seen this in your boardroom: the sovereignty presentation earns a round of nods and the meeting moves to the next agenda item. The resilience question often gets deferred to the next review cycle. It is the enterprise equivalent of a smoke detector that has not yet been tested against a real alarm. The device is installed. The drill has not been scheduled.

Data residency is necessary, however, is not sufficient on its own. Without recoverability, your compliance posture does not match your operational reality.

sovereign-image-1.png

Is sovereignty market disruption or hype?

The regulatory pressure is genuine, and it no longer arrives in one framework at a time. DORA, the EU Data Act, and the EU AI Act form what the Cloud Security Alliance describes as a compliance cascade: an interlocking regulatory architecture in which each framework presupposes and amplifies the others.

DORA, in force since January 2025, mandates ICT risk management, incident reporting, and third-party oversight for all EU financial entities. The EU Data Act grants cloud switching rights: 2-month notice periods, 30-day transition periods, elimination of switching charges from 2027. The EU AI Act reaches full application in August 2026. The compliance deadlines carry enforcement teeth. The disruption is regulatory, not technological.

Your risk is not taking the wrong steps. Relocating data to a European region, encrypting it, and reporting compliance to the board are good measures. The risk is that these steps, conducted in isolation, leave resilience untested. Your strategy should ask harder questions:

  • Can you recover critical operations within the timeframe you committed to your board?
  • Can you move a core workload to an alternative provider within 30 days?
  • Do you have the contractual, technical, and operational capability to change your current cloud arrangement without catastrophic cost?

If any answer falls short, you have identified exactly where your strategy can be strengthened.

What financial firms miss about sovereignty readiness

You may have two blind spots.

First: legacy systems built on decades-old platforms cannot be made portable. You cannot achieve cloud flexibility if your core systems cannot be moved from their current setup. Modernization is a prerequisite for sovereignty, not a separate initiative.

Second: sovereignty extends to AI, not just infrastructure. Your AI models, training data, and automated decision systems may sit outside the perimeter entirely. As the EU AI Act takes full effect in August 2026, that gap becomes a regulatory exposure.

What it means for your business

Full sovereignty across every system likely exceeds your budget reality. The cost premium runs 2-3 times higher than standard cloud configurations.

Protect your crown jewels first. And then attend to the next ones in line. Your top three critical systems (core banking, payment processing, customer data platforms) represent at least 20% of your workload portfolio. Securing sovereignty for those assets delivers 80% of your resilience benefit at a fraction of the total cost.

Your path depends on where you start. Tactical sovereignty applies targeted controls to your sensitive workloads, delivering protection with the least investment. A fast-path approach secures the crown jewels first and expands from there. Strategic transformation rebuilds your enterprise architecture for cloud flexibility and resilience by design.

How to find your gap in 30 days

One question reveals whether your sovereignty posture is tested:

If your cloud provider became unavailable tomorrow, how long would it take to restore this system on an alternative platform?

If you don’t know the answer, that is your gap. Run that question against your top five systems. Identify the platforms whose failure would halt operations. Compare the realistic restoration time to the recovery commitment you made to your board. Where a gap exists between the promise and the reality, you have found your starting point. This assessment takes weeks, not months, and can start with your existing team.

Read the case study: Accelerate Performance, Reduce Risks, and Optimize Cloud Investments

Opportunities and hurdles

The EU Data Act now gives you regulatory backing to demand portability from cloud providers, and switching charges disappear in 2027. The European Commission's Cloud Sovereignty Framework defines sovereignty as "effective control, not technological isolation," which validates hybrid approaches and removes the false binary of all-or-nothing sovereignty.

You will face hurdles. The cost premium remains significant, and cloud architects with regulatory expertise are scarce. Multi-year hyper-scaler contracts create switching barriers that are economic, not technical. Legacy infrastructure compounds the challenge for institutions still running decades-old core systems.

Learn more

Regardless of how legacy your core systems are or how robust your current cloud setup appears, your most valuable next step is an objective assessment of your existing infrastructure and recovery terms. The gap between your stated recovery commitments and your actual recovery capability is the clearest measure of your sovereignty posture. That assessment is the starting point, whether you are three years into a cloud transformation or just beginning.

SoftServe brings certified expertise across AWS, Google Cloud, and Microsoft, combined with deep regulatory experience in financial services.

Learn more: Accelerate modernization across banking, insurance, fintech, and payments with Agentic AI

Frequently Asked Questions

European regulators keep tightening cloud rules. Should financial firms view sovereign cloud as an urgent priority or a long-term transition?

The urgency is real, but the approach should be phased. DORA enforcement started 17 months ago. The EU Data Act already grants cloud portability rights. The EU AI Act reaches full application in August 2026. Financial leaders who treat sovereignty as a future initiative will find themselves behind institutions that started with their highest-risk systems and built outward. Protect what matters first, then expand deliberately.

Many banks have already placed workloads in EU cloud regions. What risk remains after that step?

Location addresses one layer of the challenge. The deeper question: can the institution keep running if that cloud region becomes unavailable? A provider outage, a sanctions event, or a contractual dispute could disrupt access regardless of where servers sit. Recovery drills, not just location audits, reveal the real posture. Institutions should test their recovery capabilities against realistic disruption scenarios.

Sovereign cloud deployments carry a steep cost premium. How should a CIO justify this investment to the board?

Enterprise-wide sovereignty is prohibitively expensive for many firms. The stronger case: identify the three to five systems whose failure would halt the business. Securing those assets first captures the vast majority of resilience value at a manageable cost. That framing converts a board conversation from "we need a multi-year transformation" to "we can protect our critical operations within a defined budget and timeline."

How does AI governance connect to the sovereignty conversation?

Sovereignty rules typically cover infrastructure and stored data. Few institutions extend those principles to AI models, training datasets, or automated decision systems. As the EU AI Act mandates governance for high-risk AI applications in regulated industries, that gap becomes a compliance exposure. Financial institutions should evaluate where their AI systems run, what data trains them, and whether those components fall under the same controls as their core platforms.

If a financial institution wanted to evaluate its sovereign cloud readiness this quarter, where should it start?

Choose your single most critical system. Ask how long it would take to restore that system on a different cloud platform if the current provider became inaccessible. If the answer exceeds your stated recovery window, that is your sovereignty gap, and your starting point. Run the same test on your next four critical systems. The result maps exactly where your posture is tested and where it remains untested.

ShareShare the article

Don't want to miss a thing?

Subscribe to get expert insights, in-depth research, and the latest updates from our team.
Subscribe

Our Insights

white paper
Generic agentic AI

Generative and Agentic AI Trends for 2026

Explore more
white paper

The Economics of AI: Cost Dynamics and New Value Streams

Explore more
white paper
AI Embodied

Humanoids: AI Embodied in Physical Form

Explore more
white paper

Cloud Modernization: The AI Catalyst No One Can Ignore

Explore more
guide

AI and the Cost of Certainty

Explore more
Softserve company logo
KarriereSearchContact Us

Hot Links

  • Home
  • Branchen
  • Services und Kompetenzen
  • Ressourcen
  • Presse
  • Über Uns
  • Kontakt
  • Karriere
  • Subscribe to Updates

Kontakte

  • Hauptsitz Austin

    201 W 5th Street Suite 1550 Austin, TX 78701

    +1-512-516-8880

    Toll Free:
    +1-866-687-3588

  • Privacy Notice - 
  • Terms and Conditions - 
  • Information Security - 
  • Sitemap - 
  • Search - 
  • Accessibility statement - 
  • LInkdn Link with Icon
  • Youtube Link with icon
  • Facebook Link with Icon
  • Instagram Link with icon

© Copyright 2026 SoftServe Inc.

hero-icon.svg
TikTok Link with icon
  • Twitter Link with icon
  • Soundcloud Link wiht icon
  • Bluesky Link with icon