
The Sovereignty Gap: Why Governments Don't Actually Control Their Cloud
- A sovereign cloud for government promises legal control, but recent survey data shows many public agencies cannot say who actually holds their encryption keys or whose laws reach their data.
- Cisco's 2026 benchmark found that 42 percent of organizations let their cloud provider control most or all of the encryption keys, and 31 percent lack full visibility into which jurisdiction governs their data.
- Data residency (where the bytes sit) is not data sovereignty (whose courts can compel them); an EU-hosted region run by a US company still answers to the US CLOUD Act.
- Closing the gap is an engineering and procurement problem: customer-held keys, confidential computing, and contract language that names extraterritorial law, not a slogan.
- The fastest way for an agency to find its own gap is to ask its vendor five blunt questions and watch which ones get a straight answer.
Every agency I talk to believes it controls its cloud. Most of them are describing data residency and calling it sovereignty, and the difference is the whole ballgame. A sovereign cloud in government is supposed to mean that your data, your keys, and your legal exposure all sit under a jurisdiction you answer to. What a lot of public-sector IT organizations actually bought is a data center with a local flag on the door and a key ring that still hangs in another country. That is the sovereignty gap, and until 2026 almost nobody was measuring it.

The Sovereign Cloud Gap Nobody Measured Until Now
The sovereignty gap is the distance between the control an agency thinks it has over its cloud and the control it can actually prove, and the new data says that distance is wide. For years "sovereign cloud" was a marketing category, not a measured one. That changed when the big trust surveys finally started asking the uncomfortable question: who holds the keys?
The answer is unflattering. Cisco's 2026 Data Privacy Benchmark Study, drawn from thousands of security and privacy professionals, found that 42 percent of organizations say their cloud provider controls most or all of the encryption keys protecting their data, according to Cisco's benchmark research. A further 31 percent admit they do not have full visibility into where their cloud data is processed or which country's laws apply to it. PwC's 2026 Global Digital Trust Insights told the same story from the executive suite: only about one-third of organizations had high confidence that they control all the encryption keys guarding their most critical data across their cloud estate.
For a private company that is a risk. For a government agency holding tax records, student data, health files, or law-enforcement material, it is a sovereignty failure hiding inside a compliance checkbox. This is the same pattern I described when digital sovereignty stopped being a talking point and became an infrastructure bill: the promise is easy, the plumbing is where control is won or lost.

Who Actually Holds The Keys
Whoever can decrypt the data controls the data, and in most government cloud deployments that is still the vendor, not the agency. Encryption is not the hard part. Every serious provider encrypts data at rest and in transit. The hard part is key custody: who generates the keys, who can use them, and who can be legally compelled to hand over what they unlock.
There is a spectrum here, and agencies rarely know where they sit on it. At one end, the provider generates and holds the keys, which is convenient and gives you almost no sovereignty. In the middle sits bring your own key, or BYOK, where you generate keys in your own hardware security module and import them, keeping lifecycle control and the ability to revoke. Further along is hold your own key, or HYOK, where the key never leaves your custody and the provider must call back to your key service to decrypt anything, which means a foreign court order served on the provider gets them ciphertext and nothing else. Confidential computing goes one step further by keeping data encrypted even while it is being processed in memory, shrinking the window where anyone, including the provider, can see it in the clear.
The distinction that undoes most "sovereign" claims is the one between data residency and data sovereignty. Residency is about where the data physically lives, as NetApp lays out plainly: storing EU data in Frankfurt. Sovereignty is about whose laws and authorities can reach it. You can have perfect residency in a Frankfurt data center and still be fully exposed to a foreign subpoena if the operator of that data center answers to another government. Residency is a location. Sovereignty is a jurisdiction. Buying the first and believing you got the second is exactly how vendor lock-in works, a trick I unpacked in why vendor lock-in is just outsourcing with better branding.

The Extraterritorial Exposure
The reason key custody matters so much is a US law called the CLOUD Act, which lets American authorities compel US-headquartered providers to produce data regardless of where in the world that data is stored. Passed in 2018, the Clarifying Lawful Overseas Use of Data Act settled a simple and inconvenient question in favor of reach: a US company can be ordered to hand over data it controls even if the servers sit in another country. Local data residency does not cancel that obligation. If your "sovereign" region is operated by a company incorporated in the United States, the law travels with the corporate parent.
This is not a fringe concern anymore, it is reshaping procurement. KuppingerCole's 2026 analysis of Microsoft's sovereign cloud offering concluded that even EU-bounded clouds run by US firms remain within reach of US extraterritorial frameworks, and it reframed the whole problem in a line worth quoting: as KuppingerCole put it, "sovereignty is no longer about where data resides, it is about what risks matter." Governments are responding by writing legal exposure directly into their buying rules. In Canada, Alberta's Sovereign Compute Environment procurement went beyond federal requirements to include explicit prohibitions on providers subject to the US CLOUD Act or equivalent foreign laws, according to reporting by law professor Michael Geist on the 2026 global fight over data control. Geist also notes that more than 30 countries now restrict cross-border data access, with cloud and localization measures rising by roughly 50 percent in a single year, many of them a direct reaction to the reach of laws like the CLOUD Act.

What Closing The Government Cloud Gap Costs
Closing the sovereignty gap costs real money and real architectural effort, which is why the market for sovereign cloud in government is growing on the back of mandates rather than enthusiasm. Nobody re-platforms for fun. They do it because a regulator, an auditor, or a public scandal made the exposure impossible to ignore.
The spending reflects that pressure. MarkNtel Advisors valued the global sovereign cloud market at roughly 156 billion dollars in 2026 and projects it climbing toward 572 billion dollars by 2032, with data sovereignty requirements making up about 55 percent of demand and public-sector rules doing most of the pushing. Precedence Research, using a slightly different model, puts North America at 34 percent of that market, driven by government data-localization and cybersecurity mandates. Public buyers are already writing the checks: the European Commission ran a sovereign cloud procurement worth around 209 million dollars in 2025 for EU institutions, tied explicitly to sovereignty requirements.
The cost is not only the invoice. Real sovereignty usually means customer-controlled keys with your own hardware security modules, confidential computing for sensitive workloads, local operational staff who can pass a background check, and contracts that name the extraterritorial laws you are trying to escape. It can mean accepting fewer bleeding-edge managed services, because the newest features often ship first on the hyperscaler's terms, not the sovereign region's. That trade-off is the honest math, and it is the same discipline I recommend before handing any sensitive data to an outside platform in three questions to ask before you feed data to an AI vendor.

Questions Every Agency Should Ask Its Vendor
The fastest way to find your sovereignty gap is to ask your provider five direct questions and notice which answers arrive as a clause and which arrive as a shrug. Sovereignty is provable or it is marketing, and these questions separate the two.
First, who generates and holds the encryption keys, and can you produce data in the clear without our involvement? If the honest answer is yes, you have residency, not sovereignty. Second, is any entity in your corporate chain subject to the US CLOUD Act or another country's extraterritorial law? A local subsidiary with a foreign parent is still exposed. Third, where are the people who operate and support this environment, and what citizenship or clearance do they hold, because human access is access. Fourth, if we terminate, do we get our data and our keys back in a portable format, or is exit its own hostage situation? Fifth, will you put every one of these answers in the contract with penalties, not just in a sales deck? A vendor who means it will write it down. The public sector, and especially schools sitting on mountains of minor children's data, cannot afford to guess here, which is why I made the same argument for sovereign AI protecting student data. Control you cannot prove is not control. It is a story you are telling yourself until the day a court, a breach, or an audit tells you a different one.

Frequently Asked Questions
What Is A Sovereign Cloud?
A sovereign cloud is cloud infrastructure designed so that a specific country's laws, and only that country's authorities, govern the data, the encryption keys, and the people who operate it. The goal is legal control, not just a local data center, so that no foreign government can compel access to the data.
What Is The CLOUD Act?
The CLOUD Act is a 2018 US law that lets American authorities compel US-based cloud providers to hand over data they control even when that data is stored on servers in other countries. It means a US company's overseas "sovereign" region can still be reached by a US legal order, which is why extraterritorial exposure has become central to government cloud procurement.
What Is The Difference Between Data Residency And Data Sovereignty?
Data residency is about where data is physically stored, such as keeping EU data in an EU data center. Data sovereignty is about which nation's laws and courts can access or compel that data, regardless of where it sits. You can have residency without sovereignty, and that gap is where most agencies lose control.
Who Controls The Encryption Keys In A Government Cloud?
In most deployments the provider still controls the keys, which is why Cisco's 2026 research found 42 percent of organizations letting their vendor hold most or all of them. Agencies can reclaim control through bring your own key or hold your own key models, where the keys stay in the customer's own hardware and the provider cannot decrypt data without calling back to the agency.
How Can A Government Actually Regain Control Of Its Cloud?
It combines technology and contracts: customer-held encryption keys, confidential computing for data in use, locally cleared operational staff, portable exit terms, and written guarantees that name any extraterritorial law the provider is subject to. The five vendor questions in this article are the quickest diagnostic for whether a provider can deliver that or is selling residency dressed as sovereignty.
References
- Cisco 2026 Data Privacy Benchmark Study
- PwC Global Digital Trust Insights
- NetApp: What Is Data Sovereignty?
- KuppingerCole: Microsoft's Sovereign Cloud in 2026
- Michael Geist: The Global Battle for Data Control
- MarkNtel Advisors: Global Sovereign Cloud Market Report
- Precedence Research: Sovereign Cloud Market
