EU Overview
Last reviewed: August 2026
Overview
Section titled “Overview”This section is a regulatory guide for global enterprise architects who are deploying cloud workloads into the EU (European Union) market or dealing with EU customers and financial institutions. While the earlier vendor-neutral documents covered globally common architecture, this guide focuses on the EU’s distinctive legal and regulatory environment and its implications for landing zones, data placement, and vendor selection.
Topics Covered
Section titled “Topics Covered”- GDPR and Data Sovereignty — Covers the GDPR cross-border transfer framework (SCCs, adequacy decisions), the EU Data Boundary, a comparison of sovereign cloud options (AWS European Sovereign Cloud, Microsoft Bleu/Delos, OCI EU Sovereign Cloud, Google’s sovereignty partnerships), and the state of the EUCS certification scheme.
- DORA (Digital Operational Resilience Act) — Covers the scope of DORA, which has applied since January 2025, the status of CTPP (Critical ICT Third-Party Provider) designations, and ICT risk management and exit strategy requirements.
- NIS2 + EU AI Act — Covers NIS2’s cybersecurity and incident-reporting obligations and the EU AI Act’s implementation timeline (including the 2026 Digital Omnibus deferral of high-risk AI obligations).
- EU Member-State Cloud Security Schemes — Covers country-specific certification and procurement schemes such as Germany’s BSI C5, France’s ANSSI SecNumCloud, Spain’s ENS, and Italy’s ACN, their relationship with EUCS, and hyperscaler compliance status.
- Europe’s Sovereign AI and Model Landscape — Covers the EU AI Continent Action Plan and AI Factories, European FM providers such as Mistral AI and Aleph Alpha, and the scope of AI services offered by hyperscaler sovereign clouds.
Why EU Regulation Has Surged Now
Section titled “Why EU Regulation Has Surged Now”Between 2025 and 2026, the density of EU cloud- and AI-related regulation increased markedly. DORA began to apply (January 2025) and CTPPs were designated (November 2025); Microsoft completed the EU Data Boundary (February 2025); AWS European Sovereign Cloud went live (January 2026); and the EU AI Act took effect in stages (prohibited practices in February 2025, GPAI in August 2025) — all in quick succession. At the same time, matters that remain unsettled, such as the EUCS certification scheme and the proposed Cybersecurity Act 2 (CSA2) amendment (January 2026), are progressing in parallel. This is the result of the “Digital Sovereignty” policy stance that strengthened after the war in Ukraine converging with a wave of framework legislation enacted in the early 2020s (DORA, NIS2, and the AI Act, following GDPR) that has, after transition periods, entered its application phase all at once. For global companies, it is important to track and distinguish which regulations are already finalized and in effect from those that remain in flux.