Prakash Nanda
Does Japan’s Ministry of Defence’s recent decision to shift the hosting of classified information from its own environment to a private cloud environment provided by United States-based technology providers from the fiscal year 2027 pose a arisk or enhance the country’s security? Is it not losing its sovereignty in the process?
These are the questions many strategic experts are debating, because many Euro-pean countries and Australia have already attempted Japan's plan. Even India’s de-fense mandarins are debating the issue.
Despite all talk of self-dependence, the stark global strategic reality is that in the sphere of Clouds-technology, there are only two countries that matter - China and the United States. So avoiding one means embracing the other.
Every country that banned Huawei and ZTE from 5G, and kept out Chinese AI models and EV batteries, citing security, seems to have opted for the American al-ternative. And here, when one talks of Americans, it means three companies — Amazon Web Services (AWS), Microsoft Azure, and Google Cloud — who together control nearly 70% of the global cloud market. More significantly, they have en-tered the defense sector, the heart of state power.
A recent study showed that the global cloud market is worth hundreds of billions of dollars, with the military and defense sector accounting for a growing multi-billion-dollar slice driven by secure cloud and tactical edge computing.
The cloud market is heavily dominated by the "Big Three" hyperscalers, who control over 60% of total spending. Amazon Web Services (AWS) leads the global market with roughly 28% to 32% share. Microsoft Azure holds the second position with roughly 20% to 22% share, growing fast in enterprise and AI integration. Google Cloud Platform (GCP) holds around 11% to 14% global share, driven by data analyt-ics and AI tools.
The Big Three’s challengers happen to be regional and enterprise players like Aliba-ba Cloud, Oracle Cloud, and IBM Cloud.
Reportedly, the military cloud market is said to be valued at roughly $13.8 billion and is expanding rapidly as defense agen-cies modernize command, control, and in-telligence systems. The Big Three domi-nate here too.
Cloud environments are believed to offer three main advantages to the military over on-premises infrastructures ( physical hardware and servers in offices and data centers): Scalability and interoperability; Enhanced Cybersecurity; and Reduced Costs.
In terms of scalability, the cloud enables the scaling of processing power when needed. For example, during active mili-tary operations, it facilitates collecting massive data from satellites and drones and sharing joint operation data seamless-ly between allied forces.
Cloud also enables cybersecurity, instant threat detection, and automated patching, often within minutes. Such ‘zero trust’ en-vironments matter as cyber attacks con-tinue to grow, increasingly powered by AI.
Cloud is also said to be a significant up-front investment since it reduces costs. It optimises hardware and data storage and generally cuts enterprise and defence IT spending by 20-40%. This is a real bene-fit, as many countries increasingly face budgetary constraints in the defence sec-tor.
Commercial clouds offer what defence ministries cannot build - AI chips, zero-day patching, and global interoperability for coalition warfare. As NATO fights in Ukraine with Starlink, Palantir and AWS, sharing targeting data over a classified commercial cloud is faster than over be-spoke military datalinks.
All this is said to have been behind the decision of the Pentagon in 2019 to re-place the single-source JEDI (Joint En-terprise Defense Infrastructure) contract of $ 10 billion with the multi-cloud JWCC (Joint Warfighting Cloud Capability), in-volving AWS, Microsoft, Google, and Ora-cle.
It represented a monumental paradigm shift in national security. It radicalized the idea that the most sensitive military data can live on commercial infrastructure.
Once the US initiated the trend, its part-ners and allies followed. A recent study by the International Institute for Strategic Studies (IISS), supported and cited by AWS, shows that maintaining sovereign control and using non-national public cloud providers are not conflicting goals for governments managing national secu-rity and defense.

According to the study, Thailand is using AWS for policing, the UK MoD workloads on Microsoft Azure, and the German Federal Police depend on AWS and Mi-crosoft 365.
The study found 23 of 28 EU countries plus Britain "seem to rely on US tech" for national security functions, with 16 — in-cluding Germany, Poland and Britain — at "high risk to a potential US “kill switch" ( a safety mechanism used to immediately shut down a device, machine, software system, or vehicle in an emergency when normal shutdown procedures are too slow or unsafe).
This raises the question of whether coun-tries depending on American companies are not losing sovereignty in the pro-cess. In a way, the answer is “Yes”, given two particularly noteworthy points:
One, the US CLOUD Act of 2018 gives the US government authority to obtain da-ta held by US corporations irrespective of where it is stored. The law applies to any communication or remote computing ser-vice provider that has a legal presence or operates in the U.S., meaning jurisdiction follows corporate control rather than the physical location of the servers.
So even if a foreign Army log sits in an AWS data centre in its own territory, Am-azon, as “ a US person”, must comply with a US warrant. For instance, Mi-crosoft admitted in 2024 that it cannot guarantee UK data will stay in the UK.
In other words, physical data localization (keeping servers inside a country's physi-cal borders) does not guarantee immunity from foreign laws if the operating compa-ny is subject to US jurisdiction. Relying on foreign commercial infrastructure for vital defense functions thus exposes nations to potential operational disruptions and es-pionage.
Over-reliance on foreign-owned or exter-nally hosted Cloud computing infrastruc-ture could even significantly compromise a country's operational resilience. When a nation migrates its government, military, or critical infrastructure (like power grids and banking) to the Cloud, it effectively hands over control of its digital backbone to private corporations that are often sub-ject to the laws of foreign governments. For instance, the foreign government can compel those companies to cut off service during a geopolitical conflict.
A foreign power could pull a digital "kill switch," instantly blinding a nation's mili-tary logistics, shutting down government communications, or freezing its financial systems without firing a single missile. For instance, Ukraine relies heavily on West-ern-supplied advanced weapons (such as HIMARS, Patriot missile systems, and F-16 fighter jets). However, much of this high-tech U.S. military hardware contains built-in software restrictions or remote control mechanisms that allow Washing-ton to dictate how and where they are used. The US has effectively used these mechanisms as a "soft kill switch" by geofencing weapons to prevent Ukraine from launching deep strikes inside Rus-sian territory, heavily limiting Ukraine's operational independence.
Similarly, many in India remember how, in July 2025, Microsoft blocked services to Nayara Energy, India’s oil refiner with Russian shareholding, due to US sanc-tions. The block was temporary but devas-tating. It cut the company’s core digital in-frastructure and brought its r operations to a grinding halt.
Secondly, there is also the issue of what is called “Cognitive Sovereignty”, the capaci-ty and right to maintain independent ownership, authorship, and governance over one's own thoughts, attention, and decision-making processes in environ-ments shaped by artificial intelligence and persuasive technology.
After all, modern defense is AI — drone swarm recognition, predictive mainte-nance, and deepfake detection, etc. Those AI models run on US GPUs, trained on US stacks. As Qatari digital sovereignty archi-tect Jasim Rahman noted recently, "The risk is not just data residency. It's data plus the models. Nobody can see what's inside the model. It's like a black box."
One may own the data, but if the model that interprets it is closed, foreign-controlled, and updated from Redmond or Mountain View, the interpretive sover-eignty gets lost.
The point is that for years, nations focused heavily on "data residency", ensuring in-formation stayed physically within nation-al borders. But as artificial intelligence be-comes the core layer for decision-making, governance, and infrastructure, data resi-dency alone is no longer enough.
If a nation relies on a "black box" model hosted or updated remotely by foreign tech giants, it faces significant risks to its sovereignty in interpreting developments.
Similarly worrisome is the feature of “ vendor lock-in” in military cloud compu-ting. Once an air force builds its logistics on, say, Azure, moving to another cloud is like changing a fighter jet engine mid-flight. The United Nations Institute for Disarmament Research (UNIDIR) high-lights this because, unlike a commercial enterprise experiencing downtime, a mili-tary cloud failure or sudden contract dis-pute directly compromises combat readi-ness.
Viewed thus, it can be said that countries storing defense data on US commercial clouds are trading short-term capability for long-term control. In the process, some of the features of their sovereignty are vulnerable to compromise.
Hence, one sees recent attempts by many to have their respective “Sovereign Clouds” and till then, to have bilateral agreements with the US and local data-protection laws with American compa-nies.
Incidentally, the US allows trusted part-ner nations to sign executive agreements under the CLOUD Act. This lets foreign users request data directly from US com-panies without waiting for slow Mutual Legal Assistance Treaties (MLATs).
The U.S.-U.K. Data Access Agreement was the first of its kind, allowing British law enforcement to query US providers di-rectly while meeting specific privacy and human rights thresholds.
In January 2026, AWS launched in Ger-many’s Brandenburg the European Sover-eign Cloud, which is completely separate from the standard global AWS commercial partition. It is physically and logically iso-lated, and operated by EU citizens. Here, no data moves to the US.
Microsoft created Microsoft Cloud for Sovereignty and Bleu in France with Tha-les, and Delos Cloud in Germany — local companies using Microsoft tech but owned locally.
Google has S3NS with Thales and T-Systems with Deutsche Telekom — where Google provides AI, but the French/German partner holds encryption keys.
Organizations across the EU now leverage the Gaia-X Trust Framework, which es-tablishes rigid security labels and federat-ed identity protocols to guarantee local operational control.
Besides, rather than utilizing US regions, the European Commission and EU de-fense entities are working increasingly towards routing sensitive workloads through highly qualified local European alternatives like OVHcloud and Scaleway (France), or IONOS and Open Telekom Cloud (Germany), which meet stringent local certifications like France's SecNumCloud.
Australia, another military ally of the US, has, with Washington’s approval, decided to partner with “trusted providers”, diver-sifying between domestic and foreign op-tions, and establishing legal and technical control mechanisms.
Australia has selected AWS for its top se-cret cloud; domestic provider Vault Cloud for secret and top secret workloads, and Google, Oracle, and Macquarie Govern-ment for lower classification levels. All these have legal and technical safeguards, as per its bilateral CLOUD Act Agreement with the US.
What about India? According to Bharat Digital Infrastructure Association (B-DIA), 66% of government cloud data is al-ready hosted with foreign CSPs, mostly on Virtual Private Cloud. India does not have good enough domestic cloud systems that can rival those from the US. Indian clouds are said to be lacking GPU density, global regions, and AI tooling.
Therefore, IwThe above suggestion seems closer to models practised in Europe, particularly in Germany and France. As experts say, rejecting US clouds could be technologi-cally suicidal.
Pragmatism lies in using global clouds while retaining full visibility and lawful control through data classification, Indi-an-held encryption keys, and strong ac-cess controls, though highly sensitive top secrets are not to be hosted on the cloud and should be kept on air-gapped
premis-es.
(prakash.nanda@hotmail.com)
Leave Your Comment