UK Lawmakers Call Reliance on AWS and Microsoft a Strategic Vulnerability
Cloud

UK Lawmakers Call Reliance on AWS and Microsoft a Strategic Vulnerability

A parliamentary committee says Britain cannot build a domestic rival to AWS or Microsoft, and that leaves government data exposed to a US law most departments barely understand.

PublishedOctober 8, 2026
Read time5 min read
Share

A committee says the dependency is already too deep to measure

Britain's Parliament has a new line in its risk register, and it reads like something a CIO should have flagged years ago. Chi Onwurah, who chairs the House of Commons science, innovation and technology committee, told colleagues that UK government reliance on American cloud providers has become a strategic and economic vulnerability. The trigger is not performance or price. It is the US CLOUD Act, which can compel a US-headquartered provider to disclose data stored on its servers, or in certain circumstances withdraw service, regardless of where that data physically sits.

What makes the finding uncomfortable is the admission buried inside it: nobody in government actually knows how exposed they are. Estimates put AWS and Microsoft at up to 80 percent of UK government cloud purchases, out of roughly 1 billion pounds a year in departmental cloud spend. That is a concentration ratio most procurement teams in the private sector would flag immediately. In government, it accumulated contract by contract, department by department, without anyone owning the aggregate picture.

The contracts naming names make this concrete

This is not an abstract worry about hypothetical overreach. HM Revenue and Customs has a 473 million pound, 10-year contract with AWS to manage UK tax data. The Ministry of Defence signed a 400 million pound agreement with Google Cloud. NHS trusts are actively moving patient records onto US cloud infrastructure. Each of those contracts was presumably justified on its own technical and cost merits. Stacked together, they describe a government that has outsourced custody of its most sensitive data categories, tax, defense, and health, to a small number of foreign-headquartered firms.

Departments have pushed back by pointing to UK-based data centers and standard security clauses. That defense misses the point the committee is making. Data residency inside UK borders does not change who a US court can compel, or what a US parent company is legally obligated to do with data its subsidiary holds. The legal jurisdiction follows the corporate entity, not the server rack, and that distinction is exactly what the CLOUD Act exploits.

Europe is already hedging, and the UK has fewer options

The committee's own read on remedies is blunt: Onwurah said Britain is unlikely to ever build a domestic cloud competitor that can match AWS, Microsoft, or Google at scale. That rules out the easiest answer, a national champion, and pushes toward cooperation with France and Germany instead. Both have already started moving. France replaced Azure with domestic provider Scaleway for its national health data hub in April. Germany's Schleswig-Holstein has been shifting state systems from Microsoft products toward open-source alternatives.

Those moves were not cheap or fast, and neither will be anything the UK attempts at similar scale. But they establish a working precedent that regulated European customers can and will walk away from a hyperscaler once sovereignty concerns outweigh switching costs, even for systems as entrenched as a national health data hub or a state government's productivity stack. The European Commission is separately developing a framework explicitly aimed at increasing Europe's cloud and AI sovereignty, which suggests this is hardening into policy rather than staying isolated political sentiment in a handful of regions.

Why this matters beyond government IT

If you sell software or run infrastructure for public-sector or regulated private-sector customers in the UK or EU, this committee finding is a preview of your next procurement cycle. Buyers who previously treated data residency as a simple checkbox are now asking a harder question on top of it: which government can compel disclosure of this data regardless of where the server physically sits. That distinction will start showing up in RFPs, security questionnaires, and renewal negotiations well before any legislation actually changes, because procurement teams move faster than parliaments do once a risk has been named this publicly.

The practical move is to get ahead of it now, while it is still a committee finding and not yet a binding requirement. If your product depends on a single US hyperscaler for data storage or processing, map which of your customers or prospects sell into UK or EU public-sector and regulated markets, and build an honest answer for how their data is reachable under US law. A credible multi-region or sovereign-cloud option, even a partial one covering your most sensitive data categories, functions as a genuine sales qualifier in these markets today, and vendors who have one ready will close deals that vendors without one will lose on this question alone.

What to watch next

Expect UK departments to be asked, formally, to quantify their single-vendor dependence, something the committee says they currently cannot do. That exercise alone will take months and will likely surface uncomfortable numbers in sectors beyond tax and defense. Any resulting policy is unlikely to mandate wholesale migration away from AWS or Microsoft in the near term, given the committee's own skepticism about domestic alternatives, but procurement rules requiring documented dependency risk and exit plans are a realistic near-term outcome.

The more interesting signal is cross-border cooperation. If the UK formalizes cloud and data cooperation with France and Germany, as Onwurah suggested, that effectively creates a third pole of sovereignty requirements alongside the US CLOUD Act and China's data laws. Any enterprise selling into all three markets will need a cloud architecture that can satisfy sovereignty requirements in each without three separate codebases. That is the real roadmap item hiding inside a parliamentary committee's risk warning.

Tagged#news#cloud#infrastructure#datacenter#aws#azure#gcp#hyperscalers#uk-parliament#cloud-act#data-sovereignty#government-procurement#eu-cloud-policy#chi-onwurah