top of page

UK Cloud Dependence Gives US Providers Leverage Over Public Services

3 days ago
12 min read

UK cloud dependence has become a political liability as lawmakers confront how much public infrastructure sits with American technology companies.

Amazon Web Services and Microsoft reportedly supply as much as 80% of the cloud services purchased by the UK government. Yet officials cannot state the exact level of dependence across departments, public bodies, and critical services.

That uncertainty matters because health records, tax systems, defense communications, and everyday government services are moving onto infrastructure controlled by US-based companies. Britain gains mature technology and rapid deployment, but loses some freedom to choose how essential systems operate.

A recent cloud dependence report sharpened the dispute. Members of Parliament described the concentration as a strategic and economic vulnerability, not merely a procurement problem.

The strongest warning concerns two different risks that are often blurred together. The US CLOUD Act can compel qualifying providers to disclose data under valid American legal process. Separate political or commercial decisions could also affect continued access to services.

The law does not create a simple button that instantly shuts down Britain’s infrastructure. However, concentrated dependence means a foreign decision can have consequences that UK authorities cannot fully control.

That is the central conflict. Britain wants the efficiency and scale of American clouds while retaining authority over its data, services, and political choices.

UK Cloud Dependence Is Now a Government Risk

The immediate change is that Parliament now treats cloud concentration as a question of national control.

The House of Commons Science, Innovation and Technology Committee reached that conclusion after examining Britain’s digital government plans. Its findings challenged the assumption that buying more cloud capacity automatically produces a more capable state.

The committee said dependence on a small number of US providers creates a “strategic and economic vulnerability.” It warned that foreign commercial or government decisions could derail Britain’s digital transformation program.

This conclusion extends beyond routine concerns about cybersecurity. Security teams usually ask whether a system can resist intrusion, detect abuse, and recover from technical failure.

Cloud sovereignty asks a wider question. It examines whether a country retains meaningful authority over essential technology, including its operation, data, contracts, and future availability.

The committee’s digital government findings identify AWS and Microsoft as central dependencies. They also highlight the government’s incomplete picture of its own exposure.

Official estimates suggest that the government spends heavily on cloud services each year. Chi Onwurah, the committee chair, said AWS and Microsoft may account for up to 80% of those purchases.

That figure should be treated carefully. It concerns government cloud purchasing, not a measured percentage of every public system running on those platforms.

Government officials do not maintain a complete centralized record covering all departments, public bodies, critical services, and infrastructure. The lack of measurement is itself part of the problem.

A department cannot build a credible exit plan without knowing which applications depend on a provider. It also needs to identify connected databases, identity systems, software licenses, security tools, and specialist skills.

Around 55% of surveyed central government organizations reported that more than 60% of their technology estate was hosted in the cloud. Every participant used one of the two leading providers.

That survey indicates widespread concentration, but it does not reveal how much of each organization’s estate belongs to AWS or Microsoft. It also does not measure every government organization.

The risks are no longer theoretical because public services are actively moving online. Tax administration, NHS records, government identity tools, and defense communications increasingly depend on remotely operated infrastructure.

The Cabinet Office’s own guidance illustrates the institutional momentum. It identifies AWS as a strategic hosting platform and tells teams to consider AWS first for many new services.

Microsoft Azure serves workloads built around Microsoft identity, collaboration, and server software. Once those surrounding tools become embedded, replacing the infrastructure becomes more complicated.

This UK cloud dependence therefore reflects years of rational project-level decisions. Each team selected mature services, available talent, established security controls, and familiar procurement routes.

The combined result is a national dependency that no individual department deliberately designed. Parliament is now asking whether convenience at the project level has reduced resilience across the state.

The CLOUD Act Raises a Data Control Conflict

Keeping information in a British data center does not necessarily keep it beyond American legal authority.

The Clarifying Lawful Overseas Use of Data Act applies to electronic information controlled by providers subject to US jurisdiction. Location alone does not determine whether a provider must respond.

The US Department of Justice says a covered company must disclose responsive information under valid legal process, regardless of where that information is stored. Its CLOUD Act guidance also explains that the provider must be subject to American jurisdiction.

This distinction challenges a common understanding of data residency. Data residency describes where information is physically stored, while legal control concerns which authorities can compel access.

A British region operated by an American company can satisfy contractual location requirements. It does not automatically remove every potential claim arising from the provider’s home jurisdiction.

The CLOUD Act also does not grant unrestricted access to every record held by an American cloud company. Authorities still require an applicable legal process, and providers can sometimes challenge conflicting demands.

The United Kingdom and United States also have a bilateral agreement covering lawful access to electronic evidence. That framework creates legal procedures rather than authorizing casual government browsing.

Even so, Parliament’s concern remains substantial. British agencies can choose local storage while still depending on a corporate group exposed to overseas obligations.

A June 2026 parliamentary answer acknowledged this issue. The government said departments must assess overseas legal obligations when acting as data controllers.

Officials identified encryption, access restrictions, contractual protections, and organizational controls as possible safeguards. These measures can reduce exposure, but their effectiveness depends on implementation and control of encryption keys.

Encryption offers stronger protection when the customer controls the keys and the provider cannot independently decrypt stored information. However, many cloud applications must process readable data during normal operation.

Administrative metadata, backups, logs, identity information, and managed services can also sit outside an application’s primary encryption model. A sovereignty assessment must cover the whole system.

Microsoft reportedly told Bloomberg that it had not provided UK government data in response to requests from American or other foreign authorities. That statement addresses past disclosures, not every possible future demand.

UK departments likewise say their contracts follow domestic security and data protection requirements. Those safeguards matter, but they do not eliminate the underlying jurisdictional conflict.

Political rhetoric has sometimes described the CLOUD Act as a foreign “kill switch.” That framing combines a documented data-access mechanism with a broader continuity concern.

The law itself focuses on preservation and disclosure of information. It does not directly authorize the US government to disable British tax, health, or defense services.

A service interruption would require a different legal, sanctions, export-control, contractual, or corporate mechanism. No public evidence shows that Washington has ordered a hyperscaler to disconnect UK public services.

Still, UK cloud sovereignty cannot ignore that possibility entirely. Governments already use sanctions and technology controls to restrict access by foreign organizations.

The credible concern is therefore structural, not imminent. Britain lacks complete control over systems whose continued operation depends on companies governed partly by another country’s laws.

That distinction strengthens the argument rather than weakening it. Policymakers can plan around a defined jurisdictional risk more effectively than an exaggerated claim of immediate shutdown authority.

AWS and Microsoft Lock-In Limits Britain’s Choices

The main opponent is not Britain against American technology, but government sovereignty against accumulated vendor lock-in.

Vendor lock-in occurs when technical, financial, or contractual dependencies make changing suppliers unusually difficult. It often grows gradually after an initial cloud migration.

Applications start using a provider’s databases, monitoring systems, identity tools, deployment services, and security controls. Employees then develop skills around the same platform.

Moving the original workload might appear manageable. Replacing every surrounding dependency becomes a costly engineering program with operational risks.

The UK Competition and Markets Authority found that AWS and Microsoft each held significant market power. Both reportedly controlled between 30% and 40% of relevant UK infrastructure services during 2024.

Google followed with a much smaller share. Smaller British and European providers faced substantial barriers to entering or expanding within the market.

The regulator’s cloud market decision identified technical and commercial barriers to switching and multicloud adoption. Multicloud means deliberately operating workloads across more than one provider.

Those barriers include data-transfer charges, incompatible interfaces, migration complexity, committed-spending agreements, and shortages of specialized staff. Microsoft’s software licensing practices created an additional concern.

The regulator concluded that certain Microsoft licenses weakened the ability of AWS and Google to compete for customers using Microsoft software. That reduced choice within an already concentrated market.

The CMA did not order a wholesale breakup of the cloud market. Instead, it recommended further consideration under Britain’s digital competition regime.

By March 2026, AWS and Microsoft had offered changes involving interoperability and data-transfer fees. The regulator said those measures could make multicloud use and switching easier.

It also opened a broader investigation into Microsoft’s business software environment. That investigation can address licensing practices connecting Windows, productivity software, databases, security products, and cloud services.

These competition measures address part of the sovereignty problem. Easier switching improves customer leverage and makes continuity plans more credible.

However, lower transfer charges do not create a domestic provider with the same service catalog, geographic reach, engineering workforce, or investment capacity. Market concentration cannot disappear through contract changes alone.

Public procurement reinforces the imbalance. Large suppliers can meet complex security standards, support global operations, and absorb lengthy government sales processes.

Smaller providers often struggle with certification, procurement overhead, and the demand for extensive service guarantees. They also lack the installed base that produces references for future contracts.

Government purchasing can therefore reward scale even when policy officially favors competition. A department under delivery pressure will usually choose a supplier it already knows.

The proposed central government cloud contract could deepen that pattern. Aggregating demand may secure better commercial terms, but it can also concentrate more workloads with winning suppliers.

Parliament wants the government to explain how its coordinated purchasing plan will prevent further lock-in. It also recommends publishing contract values, break clauses, licensing conditions, and value assessments.

That transparency would help reveal whether departments can genuinely leave a provider. An exit clause means little if applications cannot run elsewhere without extensive redesign.

The government must also distinguish backup from independence. Replicating data into another service does not ensure that an application can operate there during a failure.

True portability requires tested deployment processes, compatible data formats, independent identity controls, and staff who can run the alternative. These capabilities cost money before any emergency occurs.

Organizations face the same problem with internal information systems. Keeping important local technical documents usable outside one platform can preserve practical flexibility during migrations or outages.

For government, that principle must extend across code, data, contracts, operational knowledge, and service ownership. Sovereignty depends on usable alternatives, not procurement language alone.

Sovereign Clouds Cannot Erase Every Dependency

A sovereign label reduces selected risks, but it does not automatically give Britain independent control.

American providers have responded to European concerns with regional infrastructure, restricted administration, customer-managed encryption, and sovereign cloud offerings.

These designs can limit where information travels and who operates sensitive systems. They can also support compliance with British security and privacy requirements.

The difficult question is what happens when legal jurisdiction conflicts with the technical architecture. A regional subsidiary still depends on software, intellectual property, updates, and expertise from its wider corporate group.

Customers must examine which entity signs the contract, controls encryption keys, supplies administrators, and owns the underlying technology. They must also test what happens if those relationships change.

Government statements often emphasize that sensitive information stays in UK data centers. That is useful, but data location covers only one layer of sovereignty.

Operational sovereignty concerns whether Britain can keep a system functioning without continued action from a foreign supplier. Technical sovereignty concerns whether another provider can maintain or replace the system.

Legal sovereignty concerns which authorities can compel the provider. Supply-chain sovereignty includes software updates, chips, networking equipment, and specialist services.

No realistic national strategy will make every layer entirely domestic. Modern cloud systems depend on global hardware, open-source projects, international standards, and distributed engineering teams.

The practical objective is controlled dependence. Britain needs to identify where foreign reliance is acceptable and where an independent fallback is necessary.

Healthcare offers a clear example. A hospital can benefit from scalable cloud storage and managed security while retaining strict controls over patient information.

Yet its continuity plan must address more than backups. Clinicians need working applications, identity services, network access, and recent records during an outage.

Tax administration presents another challenge. A service might tolerate planned maintenance but cannot remain unavailable during important filing periods.

Defense systems require stricter controls still. Some workloads can use commercial infrastructure, while others need isolated environments and nationally controlled operations.

Britain has started imposing additional oversight in sectors where concentration could create systemic harm. In July 2026, it designated Microsoft, Google Cloud, AWS, and Oracle as critical third parties for financial services.

The resilience oversight regime allows financial regulators to assess and enforce continuity requirements for specified services. It does not cover every public-sector workload.

The regime demonstrates that government recognizes concentration as an operational risk. However, supervision cannot replace supplier diversity or tested exit options.

European governments are also experimenting with stronger alternatives. France has supported domestic cloud companies and moved selected health workloads toward European providers.

The German state of Schleswig-Holstein has been moving government systems from Microsoft products toward open-source alternatives. Open source provides code access and can reduce dependence on one licensing company.

Open source does not remove operational challenges. Governments still need maintainers, security teams, migration expertise, and organizations accountable for service quality.

European providers also remain much smaller than the largest American hyperscalers. They cannot immediately reproduce every managed database, AI service, analytics platform, or global network feature.

A rushed “buy national” policy could produce higher costs, weaker services, or a new form of lock-in. Ownership alone does not guarantee portability, security, or resilience.

The strongest approach combines several tools. Britain can use domestic providers for selected capabilities, open standards for portability, and hyperscalers where their scale offers clear benefits.

It can also require customer-controlled encryption, transparent subcontracting, tested recovery plans, and documented exit procedures. These requirements should reflect workload sensitivity.

The skeptical view is that genuine diversification will remain expensive. Departments face delivery deadlines and budget constraints, while alternative providers need predictable demand before expanding.

That circular problem explains why Parliament proposed advanced commitments and procurement targets. The government would promise future demand for strategically important capabilities, allowing suppliers to invest earlier.

Whether that approach succeeds depends on execution. Targets that reward nominal supplier diversity without testing independence would change reporting, not resilience.

What Comes Next for UK Cloud Sovereignty

Three coming decisions will show whether the political warning becomes an operational strategy.

The first signal is the government’s formal response to Parliament. Ministers must explain how they define technology sovereignty and which capabilities require stronger national control.

The committee also requested contingency plans for a CLOUD Act demand involving British citizens’ information. A detailed response would strengthen the case that the risk is being managed.

A vague response centered only on UK data centers would weaken it. Physical location does not fully answer questions about legal access, service continuity, or technical dependence.

The second signal is the national cloud strategy scheduled for February 2027. The government previously delayed that publication while its policy team conducted more research.

Its current cloud strategy roadmap promises guiding principles for secure, resilient, and sustainable public services. Those principles need measurable requirements.

The strategy should identify critical workloads, minimum portability standards, and acceptable recovery times. It should also require departments to maintain current dependency maps.

A credible strategy would distinguish routine productivity systems from essential health, tax, identity, and security services. Treating every workload identically would waste resources.

The document should also reconcile two competing government goals. Central purchasing can improve bargaining power, while supplier diversity can reduce concentration.

Success would mean government buyers receive better terms without committing more systems to one architecture. Failure would produce a larger contract with the same exit barriers.

The third signal is evidence that competition reforms produce actual switching and multicloud adoption. AWS and Microsoft have promised changes involving interoperability and transfer costs.

The CMA said it would review progress after six months. The important measures are customer outcomes, not the number of announced commitments.

Officials should track whether organizations move workloads, adopt independent interfaces, and test recovery on another platform. They should also measure the total cost and time required.

If switching remains rare, the reforms have not solved the underlying lock-in. Britain would still depend on contractual goodwill rather than practical alternatives.

The government also needs a reliable cloud consumption dashboard. Without consistent information, ministers cannot identify concentrations across suppliers, departments, and critical services.

That dashboard should include contract duration, renewal dates, break clauses, workload sensitivity, recovery arrangements, and dependency on proprietary services. Aggregate spending alone is insufficient.

For developers, this debate changes architecture decisions. Managed cloud services can shorten delivery time, but each proprietary component raises the future cost of moving.

Teams working on important services should separate portable application logic from provider-specific integrations where practical. They should document which features cannot be reproduced elsewhere.

Enterprise buyers should demand exit evidence before signing long commitments. A supplier should explain how data, logs, identities, encryption keys, and applications can be transferred.

Knowledge workers also have a stake in UK cloud dependence. Their records, communications, health information, and interactions with government increasingly pass through these systems.

The policy question is not whether American cloud companies are inherently unsafe. Britain uses them because they offer mature services, established security controls, and substantial engineering capacity.

The question is whether a state should operate essential services without knowing its exact dependence or possessing tested alternatives.

Britain does not need to abandon AWS, Microsoft, Google, or Oracle to regain leverage. It needs evidence that critical services can survive technical failure, legal conflict, and commercial change.

That requires mapping dependencies, testing exits, supporting credible alternatives, and matching safeguards to the sensitivity of each workload.

The next national cloud strategy will reveal whether UK cloud dependence remains a political warning or becomes a managed risk. Readers should watch its portability rules, published dependency data, and proof of real supplier switching.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page