Cloud & Data Sovereignty
The CLOUD Act, FISA 702, EUCS, and the fight over where data lives versus who can legally reach it.
Every major incident looks like its own story - AI governance one week, an enterprise authentication bypass the next, then a banking malware campaign, a cloud migration, a nation-state compromise, a national blackout. Read enough of them and the same thing keeps surfacing underneath. The breach is rarely the beginning of the story; the beginning is almost always an assumption that had never been tested. Storm-0558 exposed the assumption that a consumer signing key could never authenticate an enterprise account. ServiceNow, that the platform holding the map of every system deserved less scrutiny than the systems. Kimi K3, that self-hosting a model resolves the trust question. The Iberian blackout, that transparency and operational security are the same objective. FASTCash, that banks on shared payment rails carry risk independently. The subject of the analysis is not the technology - it is the widening distance between what organisations believe about their systems and how those systems actually behave under pressure, which may be one of the most important attack surfaces in modern security.
American force fails against the decisive chokepoint at every scale — and so would Iranian force against the Gulf. Why the war keeps returning to limbo instead of ending, who prefers it that way, and who is handed the bill. Part II of a two-part, deliberately neutral assessment.
The Iran war has resumed. Washington sells salvation; Tehran sells resistance. Neither story explains why a war both sides keep pausing keeps coming back. The structure does — and the bill radiates to the Global South. Part I of a two-part, deliberately neutral assessment.
Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.
I saw The Lives of Others in 2011, and it shook me to my core — not the cruelty of the Stasi, but the ordinariness of it: a life catalogued by professionals simply doing their jobs. I have spent the years since watching a version of that filing system being rebuilt, not by a police state but by democracies, for reasons that are mostly good, using tools most people carry willingly in their pockets. This DSI assessment maps the six-layer identity-and-surveillance stack now in deployment across the EU, UK, Australia and beyond — identity wallets, age verification, message scanning, biometric driver monitoring, ambient audio, and behavioural data — each introduced with a genuine justification, and ungoverned in combination. It corrects the viral misreading of what Von der Leyen actually said, sets the 1984 Stasi against the 2026 stack, and closes with five dated, falsifiable forecasts and the risks I would put on any register I was responsible for. The Stasi needed forty years, 91,000 staff and 175,000 informants. The equivalent capability now needs an app, a camera, and a terms-of-service agreement — and there is no wall to tear down.
The EU's 'Chat Control' is back for the sixth time - and the way it is coming back matters more than whether it passes. Chat Control 1.0, the interim derogation letting US platforms voluntarily scan unencrypted messages for CSAM, expired on 3 April 2026 after Parliament rejected an extension 311-228 (not, as claimed, by a single vote). The Council is reviving it through a formally 'new' law with identical content: an urgent-procedure vote cleared the way 331-304 on 7 July, with the substantive vote on Thursday 10 July - the last sitting day before recess, when 361 members (an absolute majority) would be needed to stop it. Whose interest does this serve? Several at once: a genuine child-protection case; institutional pressure (four Commissioners lobbied MEPs); the EPP closing a 'legal gap' while dodging the Chat Control 2.0 vote its members are blocking; and - the interest nobody names - legal-cover restoration for Meta, Google, Microsoft and Snap, who have scanned without authorisation since April. My assessment: this is not the EU overriding democracy but circumventing it through procedure while keeping formal cover - harder to name, and harder to stop. And the surveillance architecture (EUDI Wallet, age verification, ADDW cameras) keeps building regardless of Thursday's vote. Every box is governed; the intersection is no one's job.
Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.
Flying back from Ayatollah Khamenei's state funeral in Tehran, Russia's Dmitry Medvedev said the Strait of Hormuz has become a weapon 'no weaker than a nuclear weapon' for Iran - and that Iran holds 'a thermonuclear weapon in reserve, the Bab el-Mandeb Strait.' Medvedev does not speak carelessly. This piece puts his claim under scrutiny: Hormuz carries a fifth of world oil and works as a deterrent whose power derives from the threat, not the use; Bab el-Mandeb carries roughly a tenth of global trade by volume and, as the Houthi campaign proved, can be disrupted by a non-state actor without physical control. The nuclear analogy names the energy market; the thermonuclear analogy names the entire container-shipping architecture. Delivered at a funeral no Western government attended, as France and the UK signal naval deployment to Hormuz and Iran answers with a sovereignty claim, the statement reframes the series' four-month chokepoint map: what this series read as vulnerabilities, Moscow is naming as weapons. The thermonuclear weapon has not been used - which is the most important fact in the statement, and the reason he said it out loud.
From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.
Breaking update. Between 2 and 3am on 28 June 2026, Iran's IRGC launched ballistic missiles and drones at two US military facilities at once - the Ali Al Salem Air Base in Kuwait and the Fifth Fleet headquarters at Salman Port in Bahrain - claiming eight installations destroyed, after a second wave of US strikes on Iran. It is the end of a 48-hour collapse: the drone strike on the container ship Ever Lovely and the IMO's paused evacuation of 11,000 sailors on 25 June, a US strike on the 27th, Iran's drone hit on the tanker Kiku carrying 2 million barrels of crude, a second US strike, and Israel's approval of continued operations in southern Lebanon two days after a ceasefire. The Versailles MOU of 17 June is functionally dead. A week ago, in 'The War That Cannot End,' my assessment was that the MOU was as valid as its weakest enforcement node, and that the node was in Jerusalem. Four written judgments - the Lebanon tripwire, Netanyahu's electoral calendar, Iran's temporal asymmetry, and the resumption of tanker attacks - have now been confirmed in 48 hours. This is a fight over a shipping lane, and Iran is enforcing a claimed sovereignty over Hormuz with ballistic missiles. The MOU was the pause, not the settlement.
In March 2026, FulcrumSec found an Azure Container Registry token in a public JavaScript bundle on a Novo Nordisk subdomain. Two months later it had walked out with 1.3 terabytes: 41,000 drug compounds, 30 trained AI models, and a marketed drug's manufacturing recipe. The pharmaceutical industry's credential problem, mapped globally.
Since the 2026 Iran war opened on 28 February, Iran has pushed at least 11.7 million barrels of crude through the Strait of Hormuz it declared closed — every barrel to China, and on 4 March it made the arrangement explicit: only Chinese vessels may pass. The strait was never closed. It was reserved. Western coverage of the 20 June closure reads the map upside down. Hormuz carries ~20 million barrels a day, close to a third of seaborne crude, and almost 90% sails east — China 5.4 mb/d, India, Japan, and South Korea another slice each. The hostage is not the empire; it is the Global South that buys from the Gulf, led by Iran's own creditor. The weapon points home: ~90% of Iranian crude leaves via Kharg and must transit Hormuz, so a blockade of the strait is mechanically a blockade of Iran — which is why Tehran is quietly loading at Jask, beyond the chokepoint. And the leverage belongs to the buyer: China pre-stocked its reserves, kept Brent near $80 when analysts forecast $200, and now sets the price of any closure. Iran holds the geography. Beijing holds the economy of the geography. This is conditional sovereignty in the energy age — the inherited chokepoint exercisable only on terms set elsewhere. Part II of two; Part I is 'The Architecture Beneath the Signature.'
After the October 2023 Okta compromise, Cloudflare rotated more than five thousand credentials. On Thanksgiving Day a nation-state actor walked into its Atlassian environment anyway — through the four machine identities the rotation missed: a Moveworks service token, a Smartsheet account with admin rights to Jira, a Bitbucket account reaching source code, an AWS credential. Every one a non-human identity nobody believed was theirs. This is Part II of the cross-cutting threat analysis: a vulnerability is a property of a component, a threat is a property of the system, and the actors crossing your organisation are now overwhelmingly not human. Machine identities outnumber people by as much as eighty to one, nearly half hold privileged access, and OWASP now publishes a separate Top Ten for them. A service account is a seam with permissions — connective tissue that spans the boundaries human silos are built around, held by an account no team owns. And the seam has begun to act: AI agents are non-human identities that reason, hold credentials across every silo at once, and can be redirected by a planted instruction at machine speed. The fix is the same operating model from Part I, extended to actors that are not people: every machine identity and every agent needs a named owner, a defined scope, an expiry, and a decommissioning trigger. Run the removal test this afternoon — pick any service account or agent and ask who owns it, what it can do, and when it expires.
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
In the early 1990s, exporting strong cryptography from the United States was, legally, exporting a weapon. A T-shirt with RSA source code was a controlled export. Phil Zimmermann spent three years under US Customs investigation for publishing PGP. It took most of a decade — and Executive Order 13026 in November 1996 — to dismantle the regime. The signal, WhatsApp, Telegram, TLS, and every banking app on every phone exist in their current globally-available form because that restriction was eventually lifted. On Friday 12 June 2026, at 5:21pm ET, the same structural argument returned in a sharper form. A letter from the US government to Anthropic. Fable 5 and Mythos 5 suspended for any foreign national worldwide. The artefact has changed — from published math to hosted frontier model. The mechanism has changed — from court enforcement to a configuration flag at a single provider. The argument has not. The market consequence will not either. Whoever fills the gap during the restricted years keeps the customers after liberalisation. The companion historical-precedent piece to “The Export Control That Reached Inside the Model.”
The operational lesson of the Fable 5 and Mythos 5 suspension is not about whether the directive was justified. It is about what it demonstrated: every non-US enterprise running production AI workloads on a US-headquartered frontier model is, structurally, one letter away from an outage that no contract, no regional setting, and no sovereign cloud reseller can prevent. Anthropic had to “abruptly disable” both models for all customers globally to comply — within hours of receiving the 5:21pm ET letter. Three categories of exposure: hard-coded production dependencies, research collaborations with non-US personnel, and government / regulated-industry partnerships (TCS-50K-users-across-56-countries, DXC-banking, all in scope). The full threat surface framework now treats provider home jurisdiction as a primary variable. Single-provider risk is single-sovereign risk. The failover architecture that survives the next 5:21pm letter, with five cross-cutting controls (contract, cache, drill, audit, board), the sovereignty risk matrix across seven provider categories, and the action list for the next four working days under DORA, NIS2, the EU AI Act, and the Tech Sovereignty Package.
At 5:21pm ET on Friday 12 June 2026, a US government letter directed Anthropic to suspend Fable 5 and Mythos 5 for any foreign national, anywhere in the world, including its own non-US employees. Anthropic complied within hours, in full, worldwide — while publicly dissenting from the action and stating that the underlying capability is freely available from competing models without restriction. Sixteen days earlier, the European Commission had published the Tech Sovereignty Package built for exactly this scenario. The letter is the first operational use of Export Control Classification Number 4E091, finalised in the BIS Framework for AI Diffusion on 15 January 2025 to cover frontier model weights trained on more than 10^26 computational operations. The pattern it completes — CLOUD Act 2018, Schrems II 2020, the chip rules 2022, the AI weight rule 2025, the ICC sanctions, the Solvinity block, the EU package, now this — is the ladder of US extraterritorial reach this series has been mapping. The new layer is cognition itself. With the eight-rung extraterritoriality timeline, the seven-region cognitive-dependency map, and the strategic read for EU, UK, India, China, Japan, Korea, Middle East, and Africa.
Regeringskansliets molnpolicy Fi2026/01233 publicerades 28 maj 2026. Den mandaterar i strikt mening en sak: att varje offentlig aktör ska göra en självständig, riskbaserad bedömning och bära ansvaret för den. Allt övrigt ligger nedströms den bedömningen. Delegationen är policyn. Här är de elva frågor varje myndighet, region och kommun behöver kunna besvara innan bedömningen lämnar e-posten — från mall-DPIA och Schrems III-beredskap till säkerhetsskydd, OSL 10 kap. 2 a §, portabilitet i mätbara termer, jurisdiktionsmatrisen för icke-USA-leverantörer, och frågan om vem som någonsin sammanställer den systemiska bilden av 290 oberoende bedömningar.
Two Doctrines, One Coastline named the coalition chokepoint. This piece names what the United Arab Emirates is actually doing inside that coalition. The federation flew Israeli targeting packages out of Al Dhafra against Iranian targets it has held a constitutional grievance with since 1971. The Abu Dhabi capital base has been welded into the American artificial intelligence stack at the chip, model, and platform level — through MGX, OpenAI, Anthropic, the Stargate project, BlackRock, and Microsoft — in commitments that cannot be unwound without vaporising approximately eighty billion dollars of Emirati positioning. The federation will survive the war structurally. The brand promise the survival depended on will not.
The AI cost crisis, the permission problem, and the workforce destruction that is already being reversed. The AI replacement doctrine rested on three assumptions that 2026 has tested to destruction simultaneously: that costs would stay at pilot-phase pricing as deployment scaled, that AI could replicate the human contribution adequately enough to make replacement economically rational, and that AI agents could be granted full access without creating governance obligations the security architecture needed to be built to address. All three assumptions are failing at once, the data confirming each is now unambiguous, and the organisations that built genuine AI governance have a structural advantage over the ones that bought a subscription, fired their people, and are now rehiring them six months later at higher cost.
Trellix's source code repository was breached on May 2. Three weeks earlier, Medtronic confirmed a ShinyHunters attack on 9 million patient records. They join Microsoft, Okta, and LastPass on a list that should never exist — the security vendors whose entire commercial proposition is preventing the attacks they cannot prevent on themselves. This briefing maps the structural failure and the four predicted outcomes.
France’s national identity agency — the system managing every passport, ID card, and driver’s licence in the country — was breached by a 15-year-old exploiting an IDOR vulnerability so basic the attacker called it “really stupid.” 11.7 million records confirmed exposed. France was one of six EU member states rated “high preparedness” for the EUDI Wallet. The wallet that 450 million Europeans will use from December 2026 depends on these same government identity APIs for its initial provisioning. The certification standard does not yet exist. Part 4 of the EU Regulatory Landscape series.
China spent $400 billion on robotics in 2026. The CHIPS Act allocated $50 billion total. China built 30,000 smart factories over eleven years. Only 8.3% of US manufacturers have incorporated robots. The diagnosis is settled — four requirements remain unbuilt: institutional authority, investment parity, allied supply chain coordination, and deployment at federal scale. Part 3 of the Chokepoint Doctrine series maps what a credible American industrial robotics and AI response actually requires.
While America races to build AGI, China shipped 87–90% of the world’s humanoid robots in 2025. Unitree’s $13,560 factory robot outsold Tesla’s entire Optimus production target. 140 Chinese manufacturers, 330 humanoid models, 15 automakers pivoting into robotics. The frontier model race gets the headlines. The deployment race gets the factory floor. Part 2 of the Chokepoint Doctrine series examines the AI layer of America’s industrial sovereignty gap.
The country that invented the industrial robot no longer makes one at meaningful scale. FANUC and Yaskawa are Japanese. KUKA is Chinese-owned. ABB Robotics was just sold to SoftBank. The top four vendors control 75% of global shipments. The United States controls none. Every CHIPS Act fab, every EV gigafactory, every reshoring announcement depends on robotic arms that answer to Tokyo or Beijing. This is the chokepoint inside the factory.
The United States is demanding access to European biometric data under threat of revoking visa-free travel for 450 million EU citizens. HIPAA protects American health data from any foreign government. The GDPR was supposed to do the same for Europeans. The asymmetry of this arrangement is the question nobody in Brussels is answering.
ENISA has confirmed in writing that no security standard for the EU Digital Identity Wallet is available or foreseen to be available by the deployment deadline. The first generation of wallets will be certified against national schemes of varying robustness, not a unified European standard. The weakest wallet in the EU becomes the entry point for every service provider required to accept it.
Peter Diamandis says humanity is about to fork into five branches. He describes the opportunities. He does not describe the attack surfaces. Every fork he names -- AI creators, longevity, brain-computer interfaces, space, digital consciousness -- creates vulnerabilities that no defensive architecture yet exists to contain. And the fork he did not name is the most dangerous of all.
China blocks Meta's $2B acquisition of Manus AI and exit-bans its founders, establishing that technological nationality follows people, not incorporation documents. The AI control stack now extends from rare earths through chips and models to the human layer -- the one you cannot replicate.
Within twenty days in March and April 2026, the EU rejected mass surveillance of private messages by a single vote and launched a government age verification app built on the same infrastructure as the EU Digital Identity Wallet. The two decisions are not contradictory in intent. They are contradictory in architecture. This is Part 1 of the DSI EU Regulatory Landscape series.
OpenAI products are used by 72 percent of enterprises working with AI globally. The AI layer is structurally more dangerous than software dependency because AI processes the most sensitive information in the organisation, creates cognitive lock-in that is harder to reverse than software migration, and embeds invisible dependencies across business processes. ARIA maps three scenarios for European AI sovereignty.
Two legal systems govern Europe's digital infrastructure. The CLOUD Act follows provider control, not data location. GDPR Article 48 prohibits foreign data demands without international agreement. Every time a US agency serves a CLOUD Act warrant on data stored in Europe, the provider faces a binary choice: comply with US law and violate EU law, or vice versa. There is no middle ground.
In February 2025, the Trump administration sanctioned the ICC's Chief Prosecutor. Microsoft blocked his email. Nine hundred staff were banned from the US. By October, the ICC had replaced Microsoft with a German open-source alternative. The question European governments are now asking is not whether this could happen to them. The ICC proved it can.
The US Navy has zero frigates. Iran's desalination plants are being destroyed under laws that don't bind the states doing the destroying. The frigate gap and the water gap are the same gap — the arithmetic of a system that has priced itself out of the strait.
Iranian drones struck three AWS data centres in the UAE and Bahrain on March 1, 2026 — the first known physical attacks on data centres in history. The demonstrated 3,800km strike on Diego Garcia has placed every European data centre within a threat envelope that no risk model had previously contemplated. Europe built the sovereign cloud without building the sovereign defence around it.
Europe did not break its energy dependency. It rotated it. US LNG now supplies 60% of EU imports. Norway is maxed out. Qatar got bombed. Russia is still earning $501 million a day. And 85% of Europe's cloud runs on American servers. The leash changed hands. The collar did not come off.
A cyberattack on Intoxalock stranded thousands of drivers across 46 US states. Smart beds overheat during AWS outages. Solar panels in Africa go dark when payment servers fail. 20 billion IoT devices, 75% without update mechanisms, attacked 820,000 times per day. The EU's Cyber Resilience Act is Europe's answer — but the deadline is December 2027.
Mapping the strategic implications of telecommunications infrastructure investments across Central Asia and Eastern Europe, and the data sovereignty risks they create for organizations operating in affected regions.
January 3, 2026 established a new doctrine: existing indictments plus presidential authority equals legal permission to bomb capitals and extract heads of state. No congressional debate. No UN authorization. Just Article II and Delta Force.
The continent that wrote the handbook on colonial control now finds itself subject to those very mechanisms under different management. Europe's imperial playbook has come full circle.