Skip to content
You can now search across every topic, entity and event.What's new
European Tech Sovereignty
4AUG

ORG brands UK tech dependency a risk

4 min read
10:16UTC

The Open Rights Group published 'Tech Giants and Giant Slayers' on 15 April, branding Britain's decade of US-tech dependency a national security vulnerability. It cites a CMA estimate that the UK wastes £500m a year on cloud lock-in alone.

TechnologyDeveloping
Key takeaway

The CMA figure means the entire Sovereign AI Fund is being burned every year on cloud lock-in alone.

The Open Rights Group published "Tech Giants and Giant Slayers" on 15 April 2026, arguing Britain's decade of US-tech dependency is a national security vulnerability 1. The report cites a Competition and Markets Authority (CMA) estimate that the UK wastes £500m a year on cloud services due to lock-in, switching barriers and project overruns 1. It flags the US CLOUD Act, the US federal law requiring disclosure of overseas data held by US-headquartered companies, as a mechanism that can compel UK data disclosure without UK consent, and points to Microsoft's documented shutdown of email services for individuals hit by ICC-related sanctions as concrete precedent 1. Palantir contracts, the report adds, are expanding rather than shrinking 1.

The CMA figure sits awkwardly next to the Sovereign AI Fund . In budget terms, the annual cloud waste matches the entire fund spent every year on lock-in alone, yet DSIT has not matched it with a single cloud-layer instrument. The CMA cloud investigation closed in July 2025 without DMA-equivalent enforcement powers, leaving the exposure untouched. Britain is solving the model layer at the margin while the cloud layer still bleeds at scale.

The CLOUD Act flag shifts the framing from commercial efficiency to legal exposure. ICC-sanctioned individuals losing Microsoft email access is not a hypothetical: it is precedent that a US statute can reach UK users through the infrastructure they already use, regardless of where the data sits. The report treats this as an analogue of the EU-level Draghi Report's 11.2% implementation rate after one year : stated ambition without the matching legal instrument. Britain is building a national champion upstairs and leaving the front door open downstairs.

Deep Analysis

In plain English

The Open Rights Group is a British digital rights organisation. In April 2026 it published a report arguing that Britain's dependence on American technology companies carries national security consequences beyond commercial inefficiency. The core of the argument: a US law called the CLOUD Act means American companies can be ordered by US courts to hand over data they hold on behalf of British customers, including government data, without UK courts being involved. The ORG cites Microsoft shutting down email accounts for people sanctioned by the International Criminal Court as a real-world example where US law reached into British infrastructure and cut off services. The Competition and Markets Authority (the UK's competition regulator) estimates that Britain wastes £500m a year on cloud services purely because of the difficulty of switching providers. The report argues that building a domestic AI sector while leaving this dependency unaddressed is building on a compromised foundation.

First Reported In

Update #2 · Brussels buys, Britain backs, Google unlocks

The Register / Open Rights Group· 19 Apr 2026
Read original
Causes and effects
This Event
ORG brands UK tech dependency a risk
The report puts a number on the cloud-layer gap the UK's sovereign AI strategy leaves untouched, and flags the US CLOUD Act as a legal mechanism that can compel UK data disclosure without UK consent.
Different Perspectives
Germany (Bundeskartellamt)
Germany (Bundeskartellamt)
Germany's Bundeskartellamt declined to open antitrust proceedings against SAP, the company disclosed on 30 July, in the same fortnight the Commission's EUR 890m DMA fine against Google approached its 21 September compliance deadline. A German software champion cleared domestic scrutiny while an American platform faces enforcement, in the same regulatory season.
United States (USTR)
United States (USTR)
Washington's Section 301 investigation into EU digital enforcement, opened 24 July, had produced no Federal Register docket as of 4 August, even as Dell and 1,008 Nvidia GB200 NVL4 accelerators sit inside the EU's own sovereignty-branded MeluXina-AI build. The absent docket and the American hardware inside a European sovereignty project pull the same relationship in opposite directions.
UK government
UK government
The UK's Sovereign AI vehicle took a nine-figure equity stake in chip startup OLIX on 30 July, its fifth deal since April, while the Cabinet Office's 27 July fact sheet named no accounting officer for the GBP 1.1bn AI Hardware Plan. Whitehall is buying equity rather than capacity, inside a department mid-rename to Business, Innovation, Science and Trade.
Luxembourg government
Luxembourg government
Luxembourg is covering half of the newly disclosed EUR 80m contract value for MeluXina-AI, EuroHPC's Grand Duchy build, with Dell Technologies confirmed as supplying 1,008 Nvidia GB200 NVL4 accelerators, a hardware detail absent from the earlier project description. The disclosure means Luxembourg's national co-funding buys a facility built on American silicon under a European ownership badge.
European Commission
European Commission
The Commission activated its Article 101 fining power on 2 August while the Article 70 register it must keep current still showed a 26 September 2025 footer and blank rows for Denmark, Finland and Hungary. It issued no comment, though Article 70 puts the publication duty on Brussels, not member states.
China's Ministry of Commerce
China's Ministry of Commerce
Spokesperson He Yadong said on 16 July that Beijing and the Netherlands should let firms settle the Nexperia dispute through consultation, after a Dutch ministerial visit to Beijing. The conciliatory tone contrasts with the confrontational US trade response to the same fortnight's DMA enforcement.