EU Proposal Takes Aim at Major Cloud Providers
Jo writes that the EU’s new digital package could find large cloud providers operating in the bloc subject to potentially invasive oversight, as the EU strives for “data sovereignty”.
After years of worrying about the operational risk that cloud concentration poses to the financial system, European Union authorities have proposed a digital finance package—a set of proposals that, among many other measures, would single out cloud providers and subject them to a unified oversight regime.
The package, which was published last week, sets out a comprehensive framework for the regulation of tech in hot-button areas, including regulatory approaches to crypto assets and blockchain, increased power for firms to dictate the terms of contracts and service level agreements, better and more standardized resilience testing, and a single EU hub for reporting cyber security breaches.
But it’s the provisions that are clearly aimed at gaining some kind of oversight of cloud providers that I found to be most interesting. Chapter V of the proposal, which is concerned with third-party resilience, would make cloud service providers like Amazon Web Services, Microsoft Azure, Google Cloud Platform, and IBM Cloud answerable to one of the three European Supervisory Authorities (ESAs): the European Securities and Markets Authority, European Banking Authority, and European Insurance and Occupational Pensions Authority.
If the proposal became law, the ESAs would have the power to designate a cloud provider as “critical” based on a set of criteria: Is the vendor providing infrastructure and other cloud services to a massive, systemically important financial entity, such as a too-big-to-fail bank? Or, to state the problem slightly differently (as the proposal does): If the services offered were to fail—let’s say a major cloud provider suffered an outage that rendered critical data inaccessible during a critical time—would that have a devastating, knock-on impact on the entire financial system, because the bank is so interconnected with other financial institutions? At the point of disaster, would another service provider be able to step into the breach, and could customers be ported over easily and quickly, minimizing systemic disruption?
Once these vendors are designated as critical, one of the ESAs becomes its “lead overseer.” The proposal states that critical service providers “shall cooperate in good faith with the lead overseer,” which will be able to impose fines and have the right to examine data and records, request phone logs and data traffic, and conduct on-site inspections, if necessary.
Now, the proposal doesn’t explicitly say that it’s referring to the giant cloud service providers; it calls them only “critical ICT third-party service providers.” But it’s clear which companies are being targeted here, as regulatory bodies in Europe have expressed their concerns over concentration risk and that service level agreements lock in clients to particular vendors.
Firms in the EU already have the right to conduct audits of cloud providers, and they have to keep a close eye on their relationships with third parties—and their third parties’ third parties—under various rules, regulations, and guidelines. What this proposal would do is bring that all together in a much more comprehensive framework for operational resilience.
But it seems to me that this level of oversight of such firms is unprecedented in the EU.
While the major public cloud providers invest massive resources into their infrastructure, human resources, and resilience planning, you can’t plan for every scenario. Authorities are afraid of earthquakes, cyber attacks, climate events—any black swan that might swim along out of nowhere, taking down the grid and subjecting the financial system to a systemic shock or crisis.
These fears are compounded by the fact that not only do the vast majority of financial services firms have outsourcing relationships with the major cloud providers, but these companies are also all US-based entities, with their ultimate oversight conducted on another continent.
And then, of course, with this proposal the EU is trying to protect its markets. While the bloc has set the template for regulating data—with groundbreaking approaches such as the General Data Protection Regulation, which has inspired similar efforts worldwide—its leaders fear that it has fallen behind on emerging tech and innovation and is losing out to the US and China. As new EC president Ursula von der Leyen said in her first speech to the European Parliament, “We must have mastery and ownership of key technologies in Europe. These include quantum computing, artificial intelligence, blockchain, and critical chip technologies.”
The EC is collaborating with France, Germany, and about 100 companies and organizations—including Deutsche Bank and SAP—on a project to challenge the dominance of US big tech. The initiative, Project Gaia-X, aims to launch next year, and will consist of a network of cloud and data services operating across industries under the protection of European data laws. According to Wired, Gaia-X is fundamentally about “data sovereignty”—the idea that the EU will shape how data is managed and governed within its own borders.
So, perhaps what is important about this latest proposal is not just that EU supervisors are looking for ways to make the bloc safer from cloud outages; it’s also that it is part of a wider strategy to nurture tech and finance industries that can compete with the rest of the world.
Further reading
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: https://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Regulation
Federal court moves to certify class in Cusip antitrust suit
The SDNY judge has handed a procedural win to plaintiffs, allowing swaths of end-user firms and third-party data vendors to join the class action.
Report once: will Esma’s €1bn reforms deliver the full picture?
Critics say plan to merge three reporting regimes will see scant returns, and won’t mesh with single-sided reporting.
Reasoning agents enter the onboarding process for banks
The next phase for banks in the KYC/AML space will be using agentic AI to replace sequential, siloed checks with orchestrator agents, IBM technologists say.
SEC gunning to take over CAT in 2027
Chairman Atkins has plans for the SEC to run the Consolidated Audit Trail directly. Industry participants are split on the idea.
Managing regulatory transformation through a Dual-Flow Operating Model
Darshan Shah presents an operating model that enables project teams to implement complex regulatory programs, preserve business continuity, reduce risk, and prepare enterprise platforms for regulatory change.
The complexity of using AI to tackle compliance
The Waters Wrap: Law firms are introducing new tools to help with regulatory compliance, potentially encroaching on regtech vendors’ territory, Wei-Shen writes.
SEC denies 24X’s requested SIP exemption, for now
Start-up exchange cannot begin its overnight market session before the equity data plans’ hours are scheduled to be extended on December 6. But that’s only half of it.
Cyber audit leaves Eiopa with a credibility problem
The Dora supervisor charged with overseeing critical tech vendors has been critiqued for IT security failings.