10.03.2026

⏱ 9 min Reading Time

61 percent of European CIOs plan to shift more workloads to local providers. With the production launch of Delos Cloud in early 2026, the EU Data Act, and Gaia-X as an interoperability framework, digital sovereignty is shifting from buzzword to concrete architectural decision. A roadmap for CIOs navigating the tension between innovation and control.

TL;DR

  • 🏛 Delos Cloud goes live in 2026, delivering Microsoft services under German law – with BSI oversight of telemetry data.
  • 📊 61% of European CIOs intend, per Gartner, to shift more workloads to regional providers.
  • EU Data Act + NIS2 make data localization and exit strategies mandatory by 2026.
  • 🌍 Gaia-X prioritizes interoperability over building its own infrastructure – avoiding the next vendor lock-in.
  • Five-step roadmap for CIOs: Classify, assess, migrate, contractually secure, continuously audit.

Growing Discomfort: Why Hyperscaler Dependence Has Become a Boardroom Issue

2024 was the year cloud dependence evolved from an IT concern into a strategic risk. The U.S. CLOUD Act, geopolitical tensions, and repeated legal challenges to the EU-U.S. Data Privacy Framework have accelerated the debate. What was once a compliance footnote now appears on supervisory board agendas.

The numbers tell a clear story: A Gartner study of 214 European CIOs reveals that 61% plan to shift workloads to local or regional providers. Fifty-three percent are actively planning to reduce reliance on global hyperscalers. Forty-four percent have already begun.

Behind these figures lies a tangible problem: Organizations running mission-critical IT on platforms subject to U.S. jurisdiction retain little control in a crisis – and that crisis is no longer theoretical.

61 % of European CIOs

plan, per Gartner, to shift more workloads to local or regional cloud providers – a clear signal against uncontrolled hyperscaler dependence.

Delos Cloud: Microsoft’s German Exception

In early 2026, Delos Cloud GmbH brought its second operations center online in the Leipzig region. With that, its georedundant infrastructure is fully operational for production use. Its promise: Microsoft Azure and Microsoft 365 delivered under German law, operated by security-vetted personnel, with telemetry data under BSI (Federal Office for Information Security) oversight.

“Europe’s cloud strategy must go beyond mere data localization. Real sovereignty means operational control, transparent supply chains, and the ability to switch providers.”

Gaia-X AISBL, Architecture Whitepaper 2025

Delos is a joint venture between Microsoft, SAP, and Arvato Systems. Its design aims to resolve a core dilemma: enterprises and public institutions want to harness a hyperscaler’s innovation power – without surrendering control over their data. According to Computerwoche, the premium over standard Azure ranges from 10 to 20 percent.

Critics like netzpolitik.org call this “label washing”: the underlying technology remains American; dependence on Microsoft’s product lifecycle persists; and no genuine exit scenario is built in. Sovereignty ends where Microsoft decides to deprecate a feature – or raise prices.

The Counterpoint: Why Purely European Alternatives (Still) Fall Short

Those rejecting Delos must confront an uncomfortable truth: As of today, European cloud providers do not offer the full functional spectrum enterprises require for their digital infrastructure. OVHcloud, IONOS, and Open Telekom Cloud deliver solid IaaS services – but a complete ecosystem with productivity suites, AI services, and enterprise-grade integrations? That remains the exclusive domain of U.S. hyperscalers.

That’s precisely where Delos delivers strategic value – not as an end-state solution, but as a transitional model. Companies gain time to build out their multi-cloud strategy while meeting regulatory requirements today. The question isn’t “Delos or Europe?” but rather: “How quickly can European providers close the functionality gap?”

Gaia-X: From Failed Megaproject to Interoperability Standard

Gaia-X has had a rocky history. Launched in 2019 as a Franco-German flagship initiative for a European cloud infrastructure, it quickly became synonymous with overambitious industrial policy: too many stakeholders, too little concrete output, too much bureaucracy.

By 2026, the assessment is more nuanced. Gaia-X has shifted focus – away from building its own infrastructure, toward interoperability standards and trust frameworks. Its Gaia-X Digital Clearing Houses (GXDCH) certify cloud services against uniform criteria. Less flashy than a European “supercloud,” this approach is strategically smarter.

Because the real problem with cloud dependence isn’t infrastructure itself – it’s lock-in via proprietary APIs, data formats, and integrations. Building to Gaia-X standards lets organizations move workloads between providers without rewriting half their architecture each time. Sovereignty doesn’t emerge from owning hardware – it emerges from choice.

10-20 % premium

is what Delos Cloud costs versus standard Microsoft Azure – the price tag for German data residency and BSI-controlled telemetry.

EU Data Act and NIS2: Regulatory Pressure Mounts

Alongside strategic debates, the regulatory landscape is tightening. The EU Data Act, fully applicable since September 2025, obliges cloud providers to enable genuine portability. Switching charges must be transparently disclosed – and starting in 2027, they will be banned outright.

Simultaneously, NIS2 has raised cybersecurity requirements for critical infrastructure. Companies must demonstrate that their cloud service providers meet appropriate security standards. For CIOs, this means cloud provider selection is no longer just a technical decision – it’s a compliance obligation carrying personal liability for executives.

Prof. Dr. Luise Hölscher, newly appointed State Secretary at the Federal Ministry of Finance and Chair of the IT Planning Council, sent a clear signal: away from consensus-seeking among federal and state governments, toward operational implementation. The German Government Cloud is set to scale in 2026 – proving sovereign operating models work in practice.

Five-Step Roadmap: How CIOs Navigate the Sovereignty Agenda

Digital sovereignty cannot be achieved through a single migration project. It’s a continuous process demanding both strategic foresight and operational discipline. This five-step roadmap gives CIOs concrete orientation.

Step 1: Conduct data classification. Not all data carries equal sensitivity. CIOs should establish a three-tier model: public, business confidential, and regulatory critical. Only the third tier requires a sovereign cloud solution. Everything else can be distributed based on cost-benefit analysis.

Step 2: Audit lock-in across existing workloads. Where do proprietary dependencies lie? Which services rely on vendor-specific APIs with no portability? This audit forms the foundation of any exit strategy – and should be updated at least annually.

Step 3: Build a multi-cloud architecture. The target architecture deliberately distributes workloads: hyperscalers for AI services and global scale; sovereign providers for regulatory-critical data; open-source platforms like OpenStack or Kubernetes as a portability layer. Container orchestration with Kubernetes makes workloads fundamentally movable.

Step 4: Embed contractual exit clauses. The EU Data Act empowers CIOs – but enforcement lives in the contract. Maximum notice periods, defined data export formats, transition timelines, and cost transparency belong in every cloud agreement. Those who omit them today will pay dearly tomorrow.

Step 5: Implement continuous sovereignty monitoring. Regulatory requirements evolve, providers change terms, new options emerge. An annual cloud sovereignty review must become a fixed part of IT governance.

What CIOs Should Do Now

The question is no longer whether digital sovereignty matters – it already does. The question is whether CIOs will shape it proactively – or be driven reactively. Delos Cloud proves sovereign operating models are possible on hyperscaler foundations – even if they’re no silver bullet. Gaia-X provides the interoperability framework that reduces lock-in long-term. And regulatory pressure from the Data Act and NIS2 makes action non-negotiable.

CIOs who begin data classification now – and structure their multi-cloud strategy – gain a strategic edge. Those who wait until regulation forces what strategy should have delivered long ago will face costly catch-up.

The wise path lies in the middle: leverage hyperscaler innovation where it creates value; build sovereign alternatives where control is decisive; and secure contractual flexibility to hold open the options you’re planning for today – three years from now.

Frequently Asked Questions

What exactly is Delos Cloud?
Delos Cloud is a joint venture of Microsoft, SAP, and Arvato Systems. It delivers Microsoft Azure and Microsoft 365 under German law. All customer data remains on German soil; telemetry data is overseen by the BSI (Federal Office for Information Security); and operations are conducted by security-vetted personnel adhering to German IT security standards.

How does Gaia-X differ from a standalone European cloud?
Gaia-X does not build its own cloud infrastructure. Instead, it defines interoperability standards and trust frameworks against which cloud services are certified. Its goal: make workloads portable across providers – and reduce lock-in.

Must all corporate data move to a sovereign cloud?
No. Classification is key: only regulatory-critical and highly sensitive data require a sovereign solution. Public and less-sensitive data may remain on global platforms, based on cost-benefit analysis.

What does migrating to a sovereign cloud cost?
Delos Cloud carries a 10-20% premium over standard Azure. Add migration costs, which vary depending on the complexity of your existing infrastructure. The EU Data Act caps switching charges – and bans them entirely from 2027 onward.

What role does NIS2 play in cloud strategy?
NIS2 tightens cybersecurity requirements for critical infrastructure. Companies must prove their cloud providers meet appropriate security standards. Executive leadership bears personal liability for compliance.

What Does “Digital Sovereignty” Mean Concretely for a German Mid-Sized Company?

Control over three dimensions: where your data resides (data locality), who can access it (access sovereignty), and whether you can switch providers (portability). The EU Data Act – effective September 2025 – grants you legal levers for the first time.

Has Gaia-X failed – or is it still worthwhile?

As an infrastructure alternative to AWS/Azure, Gaia-X has failed. But as a framework for data sovereignty and interoperability, it delivers value: standardized labels, compliance checks, federated catalogs. Pragmatic recommendation: use Gaia-X certification as a procurement criterion – not as a platform.

Further Reading

More from the MBF Media Network

Header Image Source: panumas nikhomkhai / Pexels

Share this article:

Also available in

More Articles

04.08.2026

Local AI: Governance Before Hardware Purchase

Benedikt Langer

10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...

Read Article
03.08.2026

AI Regulation: Up to 3 Percent of Corporate Revenue

Tobias Massow

5 min read Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations ...

Read Article
31.07.2026

You are paying for the R&D of the next competitor

Benedikt Langer

4 min read You are funding the R&D of your next competitor and calling it AI transformation. Frontier ...

Read Article
29.07.2026

Model Harness Instead of Model Marriage: Who Controls the AI Chain?

Eva Mickler

6 min read The lock-in is shifting from the individual model to the orchestration layer. Those who don’t ...

Read Article
28.07.2026

Washington decides which AI is allowed to run here

Eva Mickler

6 Min. read time In just eight days, Washington has shifted the dispute over Chinese AI models from ...

Read Article
23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
A magazine by Evernine Media GmbH