News
Cloud Sovereignty Should Include Architecture | Aleph Cloud
Europe's CADA debate is right to focus on cloud dependency. Sovereignty assessments should ask who can stop a workload, who can inspect it, and how those answers can be verified.
Jonathan Schemoul
4 min. read -
Europe’s cloud sovereignty debate has accelerated since the Cloud and AI Development Act, and it is aimed at the right target. But for the workloads that actually matter, the assessment still skips a layer — the one that asks who can pull the plug on a system, who can read what is inside it, and whether anyone outside the provider can check either answer.
The European Commission’s June technology package puts cloud dependency back on the policy agenda, framed as part of a broader push for technological sovereignty. The Guardian read CADA as a central piece of the plan for cloud providers handling public-sector data, and Le Monde made the same dependency point about AI infrastructure after the latest American export-control shock around advanced models.
It is the right debate. It just needs a technical layer to sit alongside the legal one.
Most sovereignty frameworks start in the same place: geography, ownership, who holds the admin keys, where the data physically sits. Those things matter — they tell a public buyer a great deal about legal exposure, procurement risk, and how dependent it is on a foreign government. What they don’t capture is control.
When compute, storage, coordination, billing, and day-to-day operations all run through a single operator, that operator is a pressure point. A European flag on the company doesn’t make the pressure point disappear, and for a critical workload it is exactly where things break.
So a serious assessment should map that control surface directly:
Answering these doesn’t replace the jurisdictional analysis. It grounds it in something you can actually point at.
Decentralized infrastructure won’t make geopolitics disappear. What it changes is where the single points of failure are, and how many of them there are.
Run a workload across independent operators, open protocols, and portable infrastructure, and no single provider holds practical control over the whole system. That is fewer control points for procurement rules to wrestle with later, and weaker ones.
Confidential computing attacks a different part of the problem. With trusted execution environments and remote attestation, you can design a workload so the operator runs it without ordinary access to its secrets. The question stops being “who has an admin badge” and becomes “can the execution environment itself be verified.”
Then there is the coordination layer. Depend on opaque control-plane software and buyers are stuck trusting the vendor’s description of it. Make that layer public and the assessment can rest on code, topology, and operational evidence instead.
The CADA debate should treat architecture as part of the assessment, especially for sensitive public-sector and AI workloads. In practice that means funding and stress-testing the systems that make control points visible:
Some of this is rougher than hyperscaler infrastructure today — we know that better than most. That is an argument for testing it honestly, publishing the gaps, and funding the parts that reduce real dependency, not for leaving it out of the conversation.
Full disclosure: this is our field. Aleph Cloud has spent eight years building decentralized cloud infrastructure from France — compute, storage, hosting, indexing, and confidential execution across a distributed network.
We also know what we still owe: better onboarding, better documentation, stronger proof assets, more product polish. We are not arguing that every workload should move to decentralized infrastructure tomorrow, or that architecture on its own settles every sovereignty question.
The narrower claim is the one worth making. When Europe weighs cloud sovereignty, architecture belongs in the evidence — not as a footnote, but as something you measure.
Because for any workload that matters, the assessment has to land somewhere concrete: who can stop it, who can see inside it, and who outside the room can check the answers. Architecture is how you get those answers in writing.
News
Europe's CADA debate is right to focus on cloud dependency. Sovereignty assessments should ask who can stop a workload, who can inspect it, and how those answers can be verified.
Payments
Deploy a decentralized VM in 10 minutes with Aleph Cloud's Rust CLI. Install, fund with USDC/ALEPH, launch Ubuntu instances for ~$10/month, and SSH in. No Python, no centralized cloud.
Computing
Aleph tokenomics introduces a dual-stream rewards model for decentralized cloud operators: a transitional reward floor plus a usage-based revenue share.
Payments
Pay As You Go and Holder Tier payments are officially deprecated. Aleph Cloud now runs on a single credit system. Top up with USDC, fiat, or ALEPH and pay for what you use.