How sovereign is the cloud really, AWS and Microsoft?
What trends do you think will shape cloud infrastructure over the next five years? And what role will digital sovereignty play in this?
Marc Holitscher, Microsoft: Cloud infrastructures are currently evolving in line with several key trends. These include the increasing use of artificial intelligence, growing cybersecurity requirements, and a greater need for transparency and control over data and digital dependencies. Digital sovereignty is developing into a key design principle in modern IT architecture. Organizations want to leverage the innovative power of global cloud ecosystems while ensuring that sensitive data is protected and regulatory requirements are met. The focus here is not on isolating data, but on being able to make well-informed technological decisions and manage dependencies in a targeted way. So we believe it is a matter of striking the right balance between a global cloud and national infrastructure, rather than choosing between them. With today’s technical architecture – such as hybrid models, various encryption options, or locally operated data centers – it is possible to combine innovation, efficiency, and control.
Christoph Schnidrig, AWS: AI is becoming the norm in cloud infrastructure and enterprise applications, but customers still want full control over their data. We believe this includes control over data storage locations and access to data, the ability to encrypt data, and the resilience of the cloud. Digital sovereignty is no longer a niche topic; it is becoming a basic requirement. We are seeing this in Switzerland and throughout Europe. Customers want to know where their data is stored and who has access to it. That is exactly what our infrastructure is designed for.
In Switzerland and across Europe there is a growing need for digital sovereignty, meaning greater control over data, infrastructure, and dependencies. What role do you think global cloud providers play in this debate? And how exactly are you responding to that?
Christoph Schnidrig, AWS: At AWS, we have a “sovereign-by-design” approach. Data protection features and controls are built directly into the AWS Cloud, so customers can retain full control over their data at all times: where it is stored, how it is protected, and who has access to it. The important thing is that customers don’t have to make compromises when it comes to features, security, availability, or flexibility, meaning full control without compromise. For customers with the most stringent requirements, we have created the AWS European Sovereign Cloud. This is a separate, independent cloud within the EU, operated by EU-based staff, with additional sovereignty controls.
“The AWS Nitro System is designed so that AWS employees cannot access customer data on virtual machines.”– Christoph Schnidrig, AWS
Marc Holitscher, Microsoft: Microsoft takes a comprehensive approach that combines local infrastructure, robust security measures, and contractual guarantees. In Switzerland, Microsoft operates its own data centers, so customers can keep their data within the country and reliably meet regulatory requirements. Customers also benefit from a global security architecture that continuously analyzes threat intelligence and further develops protective mechanisms. Strict requirements regarding control, data se- curity, and data protection are core elements of our business. Customers and regulatory authorities have been imposing these requirements for years, especially in highly regulated sectors such as finance. As a result, we now have a solid technological foundation, reliable contractual frameworks, and established processes, as well as years of experience in implementing such requirements effectively. Microsoft is also developing flexible architectural options, including some based on sovereign cloud approaches. With these solutions, organizations can clearly isolate particularly sensitive data or workloads, or run them in their own environments if needed.
In theory, US laws such as the Cloud Act can enforce access to data even if it is stored outside the United States. Are there any specific scenarios where you would not be able to legally prevent the disclosure of data or metadata? Where do you draw the legal line regarding your promise to customers to protect data?
Marc Holitscher, Microsoft: It is important to point out that the Cloud Act is based on clearly defined legal grounds and does not permit automatic or unrestricted access to customer data. Every request is subject to explicit legal requirements and must be based on a specific, legally valid reason. Microsoft will also rigorously challenge any request that we believe is legally unfounded, excessive, or inconsistent with international law. In addition, we use technical and organizational safeguards, such as various encryption models and access architectures, to further restrict access to customer data. It is important to consider what is happening in practice too: To date, there have been no documented cases where Microsoft has disclosed public sector customer data in Switzerland under the Cloud Act.
Christoph Schnidrig, AWS: The Cloud Act does not grant governments or public authorities automatic or unrestricted access to data in the cloud. It simply allows US authorities to apply to an independent court for a search warrant, to combat serious crimes such as terrorism or cybercrime. Many European countries have similar laws. AWS takes action against any unreasonable or excessive requests. Since we first published statistics on this in 2020, we have never shared any corporate or government content from outside the United States with the US government. Technically, the crucial factor is that the AWS Nitro System is designed so that AWS employees cannot access customer data on virtual machines. An independent audit by the NCC Group confirmed this. AWS Key Management Service (AWS KMS) is based on the same “zero operator access” principle, so no one can access customer keys.
Many sovereign cloud services claim to offer local data storage and control. However, key platform functions such as updates, incident response, or privileged administrator access are often still managed on a global level. Which of these functions are actually located outside Switzerland or Europe, and why?
Christoph Schnidrig, AWS: At AWS, global innovation and local data storage are not mutually exclusive. Our infrastructure is designed so that engineers cannot log into customer systems. Operations, updates, and incident response are handled through automated, authenticated, and audited processes. It is also important to note that the AWS European Sovereign Cloud is developed and operated exclusively within the EU. Everything needed to run it is right here in the EU – the talent, the technology, the management, and even a copy of the source code. This guarantees operational readiness at all times. We also recommend that all customers systematically use encryption: AWS supports encryption at rest and in transit across all services, with the option to manage your own keys using our Key Management Service. Encrypted data is worthless without the right key, no matter who is trying to access it.
Marc Holitscher, Microsoft: Azure Local and Microsoft 365 Local can be operated in complete isolation from the global internet if needed. In this case, there is no external connection, and even updates are installed manually. This maximum level isolation naturally comes with certain limitations: These environments do not offer the scalability of a networked cloud, or the same range of functions. There are also different considerations involved in terms of security and operation. Incidentally, digital sovereignty does not mean isolating every function at the national level. It means making a conscious decision about which components should be operated locally and where global collaboration can enhance security, stability, and innovation. In principle, customer data and production workloads can be operated and stored locally in Switzerland or within Europe. However, some cross-platform functions are deliberately set up on a global scale. These include software updates, securityrelated incident response processes, and certain administrative control functions at the platform level. This is mainly due to the security and resilience of global cloud infrastructures. With a globally networked security architecture, we can detect attacks early, analyze patterns on a global scale, and roll out protective measures quickly and consistently. When it comes to updates and stability features, centralized management ensures that security vulnerabilities can be dealt with quickly and platforms operated reliably.
Sovereignty also means that customers can easily switch providers if needed, without having to develop new data, workloads, and governance models. To what extent do your platforms support open standards, inter-operability, or the concept of a sovereign-multi-cloud? And what specific obstacles do you think there are to making a genuine, sovereign exit from your cloud?
Marc Holitscher, Microsoft: Sovereignty also means having freedom of choice. Customers must be able to migrate their data, workloads, and governance models transparently, without having to rebuild their entire digital architecture. To ensure this, Microsoft relies on open standards, broad interoperability, and hybrid architectures. Many organizations use hybrid or multi-cloud approaches, where certain data or applications are run locally or in other environments, while other services are accessed from the public cloud. Technologies such as hybrid architectures or various encryption models support scenarios like this. We feel it is crucial for customers to be able to consciously design their digital architecture based on risk, regulatory requirements, and innovation needs. Switzerland has a well-functioning market with a broad ecosystem. This includes local startups, system integrators, software developers, data center operators, and international cloud providers. Customers have the final say on which service they use for what purpose.
“To date, there have been no documented cases where Microsoft has disclosed public sector customer data in Switzerland under the Cloud Act.”– Marc Holitscher, Microsoft
Christoph Schnidrig, AWS: We give customers the freedom to choose the technology that best suits their needs. Customers retain ownership of their data and can take it with them at any time. Our pay-per-use model does not involve any long-term lock-in contracts. We support open standards and open-source technologies. A good example is Swiss Post, which runs its parcel sorting system on AWS. It has deliberately designed the architecture to take full advantage of the cloud, but could also switch to another provider within one to two weeks. Open APIs and standards are used to ensure portability. And that is exactly what we are investing in.
Many Swiss organizations now face the question of how they can leverage innovation in the cloud without losing control over their data and dependencies. What advice would you give to customers in Switzerland who want to use the cloud but also want to maintain digital sovereignty?
Christoph Schnidrig, AWS: My advice would be to check the actual security mechanisms available, and not just the provider’s origin. First of all, the technical mechanisms: AWS offers full control over data location, encryption using the customer’s own keys, and the Nitro System – which technically prevents unauthorized access – in all regions, including Zurich. Secondly, the legal aspect: Our contract has been reviewed by Swiss banks, insurance companies, and public authorities, and it complies with local laws. Thirdly, compliance: Independent certifications such as SOC 2 and C5 assure customers that our technology and processes are implemented exactly as we say they are. Sovereignty and innovation are not mutually exclusive.
Marc Holitscher, Microsoft: We believe that digital sovereignty begins with a clear, riskbased classification of the customer’s data and applications. Not all information requires the same level of control or protection. Organizations should therefore carefully define which data is particularly sensitive, which regulatory requirements apply, and where additional controls are needed. For these sensitive areas, local data storage, customer-managed encryption models, or hybrid architectures may be appropriate. At the same time, there are many applications that benefit from the innovative capabilities and scalability of global cloud services, such as AI-powered services or data-driven business models. Many Swiss organizations have successfully adopted a pragmatic approach that strengthens control where it is needed, while also fostering innovation. This combines control and compliance with technological advancement, and lays the foundation for sustainable digital resilience.
ti&m Special “Digital Sovereignty”