sota.io
Join the waitlist
2026-07-31·11 min read·sota.io team

Airbus Just Moved 900 Apps Off AWS: The Sovereignty Framework Small Teams Can Steal

Airbus Just Moved 900 Apps Off AWS: The Sovereignty Framework Small Teams Can Steal

On July 16, 2026, Airbus confirmed it is moving hundreds of internal applications off Amazon Web Services and onto Scaleway, a French cloud provider, "amid a digital sovereignty push," as The Register reported. This isn't a symbolic pilot. It's 900 applications total, with 70 of the most critical ones moving first, spanning ERP, CRM, manufacturing execution systems, and product lifecycle management — the systems that keep a company with more than 165,000 employees actually building airplanes.

If you build or run software for a smaller team, the headline number ("900 apps!") isn't the useful part. The useful part is the decision logic Airbus used to get there, because it's a smaller, cleaner version of the same question every EU-based (or EU-serving) developer eventually has to answer: which parts of my stack can't afford to depend on a jurisdiction I don't control, and what do I actually do about it.

What Airbus announced, precisely

Catherine Jestin, Airbus's head of digital, launched a tender for the migration at the start of 2026. The stated goal, in her own words, was infrastructure that "keeps our critical data assets shielded from foreign extraterritorial laws" while still delivering "a very strong technical answer and a very strong commercial offer" competitive with hyperscaler pricing. Scaleway won that tender.

A few details matter more than the topline number:

That last set of facts is the real headline: Airbus didn't declare sovereignty as an absolute, all-or-nothing stance. It ran a criticality assessment and moved the subset that failed a specific test. That's the part worth stealing.

This is risk management, not virtue signaling

It's tempting to read one of Europe's largest aerospace manufacturers migrating off AWS as a political statement. The Register's own follow-up analysis pushes back on that reading directly, arguing the move demonstrates that "digital sovereignty is a real commercial driver and not something concocted by Europe as some sort of virtue signal." Airbus builds systems that European governments, defense ministries, and export-control regimes have opinions about. A US government compulsion order reaching Airbus's manufacturing execution data isn't a hypothetical risk on a slide — it's a plausible one for a company operating in that specific intersection of aerospace, defense adjacency, and multinational governance.

The mechanism Jestin referenced — "foreign extraterritorial laws" — has a name: the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act), codified in relevant part at 18 U.S.C. §2713. It compels any US-incorporated provider — and, per DOJ guidance, its foreign subsidiaries — to produce data in response to a US warrant or subpoena regardless of where that data is physically stored. A Delaware-incorporated cloud provider running servers in Frankfurt is still a Delaware corporation for the purposes of a US court order. Moving your data to an EU data center operated by a US company does not remove CLOUD Act exposure; only moving to a provider without US corporate jurisdiction does.

That's a legal fact, not a preference, and it's the actual thing Airbus's tender was solving for — not "cloud in Europe" as a geography, but "cloud outside US legal reach" as a jurisdiction.

Steal the test, not the budget

Airbus didn't move everything. It applied a criticality filter and only 900 applications passed it. You can run the same filter on a stack of ten services instead of ten thousand. Ask three questions per system or data flow:

  1. If a foreign government order made this system or its data inaccessible tomorrow, would your business stop functioning within a day? (Not "would it be annoying" — would you actually be unable to serve customers, ship product, or meet a contractual obligation.)
  2. Does this system process data where disclosure to a non-EU government would breach a contract, a regulator's expectation, or a customer's explicit trust condition? Health data, financial records, anything under an NDA with an EU public-sector client, source code you've promised a customer stays EU-only — this is where CLOUD Act exposure turns into an actual liability, not just an abstract discomfort.
  3. Does an EU-controlled alternative exist today that meets the same functional requirement without a multi-quarter migration project? If yes, the cost of acting is low and the excuse for not acting is thin.

A system that scores "yes" on questions 1 and 2, with a "yes" on question 3, is your Tier 0 — Airbus's 70-out-of-900. Everything else can wait, get monitored, or stay exactly where it is.

TierTest resultExampleRealistic action
Tier 0 — move nowFails Q1 or Q2, and Q3 is "yes"Core database, customer PII store, contractually-EU-only source codeMigrate to an EU-incorporated provider outside US jurisdiction within the current budget cycle
Tier 1 — plan itFails Q1 or Q2, Q3 is "not yet" (no drop-in alternative)A specialized SaaS tool with no EU-native competitorTrack the gap, revisit quarterly, budget for a future migration or a contractual data-processing addendum
Tier 2 — leave itPasses Q1 and Q2Internal analytics dashboard, marketing automationNo action — sovereignty effort here is wasted effort

This mirrors exactly what Airbus did with Salesforce, Coupa, and Workday: those stayed put because the criticality math didn't justify a migration, not because sovereignty stopped mattering. Applying sovereignty selectively, based on an honest test, is more defensible — and much cheaper — than either ignoring it entirely or trying to move everything at once.

Don't confuse "sovereign cloud" marketing with an actual certification

One detail in the Airbus story is easy to skip past: as of this writing, Scaleway has not yet completed France's SecNumCloud qualification — the ANSSI (French national cybersecurity agency) certification that formally attests both technical security controls and legal sovereignty against extraterritorial law. Scaleway announced it entered the qualification process in September 2025, and the official ANSSI registry still lists Scaleway under providers "in the process of qualification" (en cours de qualification), not among the qualified providers.

That's not a knock on Scaleway or on Airbus's decision — the qualification process itself involves rigorous, multi-year technical audits, and being in-process with a named target is a reasonable basis for a large enterprise's risk assessment. The lesson for developers evaluating any "EU sovereign cloud" claim is narrower: "sovereign" in a vendor's marketing copy and "certified sovereign" by a named national or EU authority are different claims, and only one of them is independently verifiable. Before you rely on a sovereignty claim for your own compliance documentation, ask the provider for the certificate number and check it against the issuing authority's public registry — not the vendor's own press page. The same applies to EUCS (the EU-wide Cybersecurity Certification Scheme for Cloud Services) once its assurance levels move from draft to enforceable: a provider "targeting" a level and a provider holding it are not interchangeable facts.

The honesty Airbus's own case study demands

The Register's analysis column raises a harder point that's worth sitting with: Airbus has roughly 18,000 global suppliers, and nearly all of them run on Microsoft. Even a fully EU-hosted ERP system generates purchase orders, contracts, and technical specs that flow to and from those suppliers' Microsoft 365 tenants, which sit under the exact extraterritorial exposure Airbus just spent a year-long tender trying to reduce.

That's not a reason to skip the exercise — it's a reason to be precise about what it accomplishes. Moving your database and application layer to an EU-controlled PaaS closes the exposure at that layer. It does not retroactively close it at every downstream vendor, contractor, or supplier who still emails you from an Outlook account. If you make a "we're sovereign" claim to a customer or in a compliance questionnaire, scope it to what you actually control: infrastructure, hosting, and the data you directly process. Overclaiming sovereignty is its own kind of risk — the moment a customer's security team asks about your email provider or your CRM, an overbroad claim collapses and takes your credibility with it.

You don't need a tender to run this test

Airbus ran a formal procurement process because it operates at a scale where informal decisions don't work. A five-person team doesn't need one. A practical version of the same exercise looks like this:

  1. Inventory once. List every third-party service in your stack — cloud hosting, database, email delivery, CI/CD, secrets management, analytics — and note the parent company's country of incorporation. Most of this is answerable from a pricing page or a package.json/requirements.txt scan of which SDKs you depend on; the rest is a five-minute search per vendor.
  2. Score each one with the three-question test above. Be honest about Tier 2 — most of your stack will land there, and that's fine. The goal is finding the handful of Tier 0 items, not re-architecting everything.
  3. For Tier 0 items without an EU-native option yet, don't wait for a perfect alternative — a contractual Standard Contractual Clauses (SCC) addendum plus documented data-minimization is a legitimate interim step while you evaluate migration.
  4. For Tier 0 items where an EU-native option exists, migrate on your own timeline, not a headline's. The Airbus story is a good prompt to run the audit; it is not a reason to panic-migrate a working system this week.

This is exactly the gap sota.io exists to close for step 3 and 4 on the hosting layer specifically: an EU-incorporated PaaS, hosted on Hetzner infrastructure in Germany, with no US parent entity and therefore no CLOUD Act exposure at the infrastructure layer, at a flat €9/month rather than a multi-quarter enterprise procurement process. You don't need Airbus's budget or Airbus's tender timeline to apply Airbus's logic — you need an honest three-question audit and a provider that's actually outside the jurisdiction you're trying to avoid, not just a marketing page that says "sovereign."

The bigger takeaway from July 16 isn't that everyone needs to migrate off AWS. It's that a company with essentially unlimited resources to build its own private infrastructure instead chose to buy sovereignty from a smaller, EU-native provider — because the criticality math, not the politics, said that was the right call for a specific 900-application subset of its stack. Run the same math on your own stack before you decide whether that conclusion applies to you too.

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.