Skip to content
You can now search across every topic, entity and event.What's new
Iran Conflict 2026
17JUN

ORG brands UK tech dependency a risk

4 min read
09:37UTC

The Open Rights Group published 'Tech Giants and Giant Slayers' on 15 April, branding Britain's decade of US-tech dependency a national security vulnerability. It cites a CMA estimate that the UK wastes £500m a year on cloud lock-in alone.

ConflictDeveloping
Key takeaway

The CMA figure means the entire Sovereign AI Fund is being burned every year on cloud lock-in alone.

The Open Rights Group published "Tech Giants and Giant Slayers" on 15 April 2026, arguing Britain's decade of US-tech dependency is a national security vulnerability 1. The report cites a Competition and Markets Authority (CMA) estimate that the UK wastes £500m a year on cloud services due to lock-in, switching barriers and project overruns 1. It flags the US CLOUD Act, the US federal law requiring disclosure of overseas data held by US-headquartered companies, as a mechanism that can compel UK data disclosure without UK consent, and points to Microsoft's documented shutdown of email services for individuals hit by ICC-related sanctions as concrete precedent 1. Palantir contracts, the report adds, are expanding rather than shrinking 1.

The CMA figure sits awkwardly next to the Sovereign AI Fund . In budget terms, the annual cloud waste matches the entire fund spent every year on lock-in alone, yet DSIT has not matched it with a single cloud-layer instrument. The CMA cloud investigation closed in July 2025 without DMA-equivalent enforcement powers, leaving the exposure untouched. Britain is solving the model layer at the margin while the cloud layer still bleeds at scale.

The CLOUD Act flag shifts the framing from commercial efficiency to legal exposure. ICC-sanctioned individuals losing Microsoft email access is not a hypothetical: it is precedent that a US statute can reach UK users through the infrastructure they already use, regardless of where the data sits. The report treats this as an analogue of the EU-level Draghi Report's 11.2% implementation rate after one year : stated ambition without the matching legal instrument. Britain is building a national champion upstairs and leaving the front door open downstairs.

Deep Analysis

In plain English

The Open Rights Group is a British digital rights organisation. In April 2026 it published a report arguing that Britain's dependence on American technology companies carries national security consequences beyond commercial inefficiency. The core of the argument: a US law called the CLOUD Act means American companies can be ordered by US courts to hand over data they hold on behalf of British customers, including government data, without UK courts being involved. The ORG cites Microsoft shutting down email accounts for people sanctioned by the International Criminal Court as a real-world example where US law reached into British infrastructure and cut off services. The Competition and Markets Authority (the UK's competition regulator) estimates that Britain wastes £500m a year on cloud services purely because of the difficulty of switching providers. The report argues that building a domestic AI sector while leaving this dependency unaddressed is building on a compromised foundation.

First Reported In

Update #2 · Brussels buys, Britain backs, Google unlocks

The Register / Open Rights Group· 19 Apr 2026
Read original
Causes and effects
This Event
ORG brands UK tech dependency a risk
The report puts a number on the cloud-layer gap the UK's sovereign AI strategy leaves untouched, and flags the US CLOUD Act as a legal mechanism that can compel UK data disclosure without UK consent.
Different Perspectives
Lloyd's Market Association
Lloyd's Market Association
War-risk underwriters price the Houthis' Red Sea attacks because the group announces its targets in advance, but the unclaimed Damietta drone gives insurers a hit with no author to price against. An attack nobody claims costs shipping more than one that is claimed, since premiums are set against a known pattern, not raw damage.
US Central Command
US Central Command
CENTCOM has announced no strike on Iran since resuming bombing on 30 July within hours of an IRGC salvo on Jordan, and centcom.mil did not respond to requests to confirm any pause. The command has gone quiet before while a larger operation was being weighed, so silence alone proves nothing about what it has or has not done.
Hengaw
Hengaw
Hengaw recorded at least 67 executions in Iran during July, of which the state acknowledged only eight, and reported the 1 August execution of protest detainee Arvin Kheirkhahan at Shahrud with no advance notice to his family. A family's first notice of a death sentence is now usually the instruction to collect a body.
Egypt
Egypt
Egypt's government asked media on 2 August to report the Damietta attack accurately, named no author, and said no findings will be published before its own investigation concludes. Cairo holds the debris and jurisdiction over an attack on its own soil, and naming a culprit now would pull it into a dispute it has avoided for five months.
Iran's Foreign Ministry
Iran's Foreign Ministry
Araghchi called the Hormuz talks with Oman final-stage on 2 August, four days after his own deputy rejected Oman's lane proposal, and denied the Damietta drone strike as an Israeli false flag while two Iranian officials privately claimed it for Tehran. Iran's public position now contradicts itself on both files at once.
Bahrain and Kuwait
Bahrain and Kuwait
Bahraini and Kuwaiti aircraft flew their own strikes on Iranian depots in July with Emirati air cover behind them, and Ynetnews reports some Gulf capitals wanted the 2 August strike to proceed rather than stop. States that have already taken fire see a closing window on Iranian weakness, not a reason to pause.