In December 2025, Gartner published its annual list of trends impacting infrastructure and operations. Among agentic AI and hybrid computing, one entry stood out: geopatriation — the deliberate relocation of workloads and applications away from global cloud hyperscalers toward regional or national alternatives, driven by geopolitical uncertainty.
Gartner's forecast was stark. As of 2025, fewer than 5% of enterprises in Europe and the Middle East had geopatriated any workloads. By 2030, they expect that figure to reach 75%. That is not a niche trend. That is a structural shift in where enterprise workloads live — and it has direct consequences for how IT operations teams instrument, monitor, and respond to incidents.
This post explains what is driving that shift, which regulatory events made it inevitable, and what it actually means for your operations stack when the data sovereignty conversation moves from legal to operational.
The moment that changed the conversation
In June 2025, Microsoft's French subsidiary appeared before a French Senate hearing on digital sovereignty. Under questioning, Microsoft's own representatives confirmed that they could not guarantee that data stored in France — even under Microsoft's "sovereign cloud" offering, operated by a French entity, marketed specifically for French public sector compliance — would be protected from access by US authorities under the CLOUD Act.
That moment ended a years-long debate. European enterprises, regulators, and governments had spent years asking whether the EU-US Data Privacy Framework resolved the CLOUD Act problem. The answer from Microsoft's own legal team: it does not. The framework does not override the CLOUD Act's extraterritorial reach. A US court order directed at Amazon.com, Inc. reaches into AWS Paris, regardless of which legal entity operates it locally.
The practical implication is significant. If your workloads run on AWS, Azure, or Google Cloud — regardless of which region, regardless of which local subsidiary — a US legal demand can compel the US parent company to hand over data. For regulated industries, this is not a hypothetical risk. It is a documented compliance exposure, confirmed by the affected vendor under oath.
What is driving geopatriation
The regulatory cascade landing in 2026
DORA became enforceable in January 2025. It requires financial services firms to document ICT risk across every provider — including hyperscalers — and to maintain a credible exit strategy. "We rely on AWS and here is our migration plan" is no longer a hypothetical exercise; it is a compliance artifact that regulators audit. Financial institutions that cannot produce it face supervisory action.
NIS2, which dramatically expanded the scope of critical infrastructure cybersecurity obligations across the EU, includes supply chain security provisions that create de facto sovereignty requirements. Under Article 21, risk assessments may require selecting EU-based providers — particularly where a provider's exposure to foreign government data access represents a supply chain security concern. For energy, transport, and healthcare operators, the analysis points toward European alternatives.
The EU AI Act reaches full application on August 2, 2026, with penalties of up to 7% of global annual turnover for non-compliant high-risk AI systems. The Act requires operators of high-risk AI systems to implement data governance frameworks with documented data sources, quality controls, and complete audit trails. SaaS AI platforms running on shared managed infrastructure typically cannot provide the infrastructure-level provenance the regulation demands. This creates a specific problem for organizations using cloud-based AIOps — the AI processing your incident and infrastructure data is running on someone else's shared compute, with provenance you cannot document.
The convergence of DORA, NIS2, and the AI Act is not a coincidence. The EU is explicitly pursuing digital sovereignty as industrial policy. What looks like three separate compliance regimes is one coordinated strategy to reduce European digital dependence on US technology companies — and the 2026 enforcement timelines make it actionable now, not later.
The money following the signal
Sovereign cloud spending is not a policy discussion anymore — it is a capital allocation decision. Worldwide sovereign cloud spending is projected to reach $80 billion in 2026. European sovereign cloud spending alone is growing at 83% year-over-year, from a base of $6.9 billion in 2025. That is the fastest-growing segment of the cloud market by a significant margin.
The alternatives to US hyperscalers are maturing rapidly. OVHcloud (France) carries SecNumCloud certification — the credible option for French public sector and regulated workloads requiring EU-only operational staff. T-Systems (Germany) operates Microsoft Cloud for Sovereignty under a German legal entity. Hetzner, Exoscale, Scaleway, and Deutsche Telekom's Open Telekom Cloud are gaining enterprise deployments across regulated industries. In Canada, the federal government's cloud-first policy is driving evaluation of regional alternatives for sensitive workloads.
These are not niche providers. OVHcloud is the fourth-largest cloud provider in the world by data center count. The market infrastructure for geopatriation exists, and it is scaling.
What this means for IT operations teams
Legal and compliance teams understand geopatriation as a data residency and regulatory problem. What is less discussed is the operational consequence for the teams who actually run infrastructure day to day. Geopatriation is not just a decision about where workloads live — it reshapes every layer of the IT operations stack.
Monitoring and observability data crosses borders too
Most enterprise monitoring tools — Datadog, Dynatrace, Splunk Cloud, New Relic — route telemetry to US-based SaaS infrastructure by default. Logs, metrics, traces, and events from your regulated workloads are being processed in AWS us-east-1 even if the workloads themselves run on OVHcloud Paris. The monitoring layer is frequently overlooked in data sovereignty assessments, and it is often the most sensitive layer: infrastructure failure signatures and configuration telemetry are exactly the data a foreign authority would want.
AIOps tools send your incident data externally by design
AIOps platforms correlate your infrastructure events using AI models that run in the vendor's cloud. Your failure signatures, error patterns, configuration data, and infrastructure topology are all processed externally. Under the EU AI Act, this creates audit trail and data provenance obligations that SaaS vendors cannot satisfy — you cannot document the data lineage of an AI inference running on a shared managed platform you don't control.
Runbook execution and ITSM integrations
Automated remediation workflows often call external APIs, log to external systems, and push ticket updates to cloud-hosted ITSM platforms. In a sovereign operations context, every external call is a potential compliance event. The full incident lifecycle — signal detection, qualification, remediation, and ticket closure — needs to be assessed against the same sovereignty criteria as the workload itself.
The hybrid complexity tax
Most enterprises will not move everything. The practical outcome of geopatriation is a two-tier architecture: regulated and sensitive workloads on regional or sovereign infrastructure, less sensitive workloads remaining on US hyperscalers. Running unified incident detection, correlation, and response across two fundamentally different environments — without tooling designed for it — adds operational overhead that is difficult to quantify in a planning spreadsheet but immediately visible to the team absorbing it.
The sovereign operations gap
The market for sovereign compute is maturing fast — OVHcloud, T-Systems, Hetzner. The market for sovereign operations tooling is behind. Most IT operations platforms were designed for a world where your monitoring vendor, your AIOps vendor, and your ITSM vendor all sit in US data centers and your data flows freely to them. That world assumption is now a compliance liability.
For organizations navigating geopatriation, the operations layer needs the same treatment as the workload layer: audit which tools process sensitive telemetry externally, understand the CLOUD Act exposure of each vendor's legal entity, and identify where self-hosted alternatives exist.
IBM Cloud Pak for AIOps is the established enterprise option — deployed on OpenShift on-premises, with genuine data sovereignty. The operational overhead is significant: it requires an OpenShift cluster, IBM Professional Services or a certified partner, and six-to-seven figure annual licensing. BMC Helix AIOps offers an on-premises deployment path for organizations running the BMC ecosystem. Both are credible; neither is accessible for most mid-market teams.
Self-hosted AIOps with local LLM support — where the entire operations loop from signal detection to ticket closure runs inside your perimeter — is the category emerging to fill the gap. The AI inference runs on your hardware. Your infrastructure telemetry stays in your network. Your incident data is yours, and its provenance is documentable.
Practical starting point for IT ops teams
Geopatriation is a five-year structural trend with a 2026 regulatory catalyst. The enterprises that treat it as a legal problem to be handled by the compliance team will find themselves rebuilding their operations stack under pressure, at audit time, with a regulator watching. The ones that treat it as an architecture decision now will have time to do it deliberately.
The compute sovereignty decision is visible and planned. The monitoring sovereignty decision is invisible — until it isn't.
References
- Gartner — Top Trends Impacting Infrastructure and Operations for 2026 (December 2025)
- TrueFoundry — Geopatriation Explained: AI Data Sovereignty Guide
- Editorialge — Geopatriation Shift: Why 2026 is the Year of Sovereign Cloud
- DanubeData — The US CLOUD Act: Why European Businesses Need Non-US Cloud Alternatives (2026)
- Wire.com — What the CLOUD Act Really Means for EU Data Sovereignty
- Nutanix / The Forecast — IT Teams Design for Geopatriation and Data Sovereignty
- ASEE — EU Cloud Sovereignty: Why Businesses Are Moving Away from US Providers
- SoftwareSeni — DORA, NIS2, and the EU AI Act Are Making Sovereign Cloud Mandatory for Some Workloads
- Msafe — Demonstrable Compliance in 2026: NIS2, DORA & AI Act
- The Cloud Standard — Sovereign Cloud & Geopatriation
Axiometica AIR runs entirely self-hosted with local LLM support. Infrastructure telemetry never leaves your network — by design, not by configuration. No US parent company, no CLOUD Act exposure, no shared managed infrastructure.