Skip to content
You can now search across every topic, entity and event.What's new
Iran Conflict 2026
3SEP

ORG brands UK tech dependency a risk

4 min read
16:40UTC

The Open Rights Group published 'Tech Giants and Giant Slayers' on 15 April, branding Britain's decade of US-tech dependency a national security vulnerability. It cites a CMA estimate that the UK wastes £500m a year on cloud lock-in alone.

ConflictDeveloping
Key takeaway

The CMA figure means the entire Sovereign AI Fund is being burned every year on cloud lock-in alone.

The Open Rights Group published "Tech Giants and Giant Slayers" on 15 April 2026, arguing Britain's decade of US-tech dependency is a national security vulnerability 1. The report cites a Competition and Markets Authority (CMA) estimate that the UK wastes £500m a year on cloud services due to lock-in, switching barriers and project overruns 1. It flags the US CLOUD Act, the US federal law requiring disclosure of overseas data held by US-headquartered companies, as a mechanism that can compel UK data disclosure without UK consent, and points to Microsoft's documented shutdown of email services for individuals hit by ICC-related sanctions as concrete precedent 1. Palantir contracts, the report adds, are expanding rather than shrinking 1.

The CMA figure sits awkwardly next to the Sovereign AI Fund . In budget terms, the annual cloud waste matches the entire fund spent every year on lock-in alone, yet DSIT has not matched it with a single cloud-layer instrument. The CMA cloud investigation closed in July 2025 without DMA-equivalent enforcement powers, leaving the exposure untouched. Britain is solving the model layer at the margin while the cloud layer still bleeds at scale.

The CLOUD Act flag shifts the framing from commercial efficiency to legal exposure. ICC-sanctioned individuals losing Microsoft email access is not a hypothetical: it is precedent that a US statute can reach UK users through the infrastructure they already use, regardless of where the data sits. The report treats this as an analogue of the EU-level Draghi Report's 11.2% implementation rate after one year : stated ambition without the matching legal instrument. Britain is building a national champion upstairs and leaving the front door open downstairs.

Deep Analysis

In plain English

The Open Rights Group is a British digital rights organisation. In April 2026 it published a report arguing that Britain's dependence on American technology companies carries national security consequences beyond commercial inefficiency. The core of the argument: a US law called the CLOUD Act means American companies can be ordered by US courts to hand over data they hold on behalf of British customers, including government data, without UK courts being involved. The ORG cites Microsoft shutting down email accounts for people sanctioned by the International Criminal Court as a real-world example where US law reached into British infrastructure and cut off services. The Competition and Markets Authority (the UK's competition regulator) estimates that Britain wastes £500m a year on cloud services purely because of the difficulty of switching providers. The report argues that building a domestic AI sector while leaving this dependency unaddressed is building on a compromised foundation.

First Reported In

Update #2 · Brussels buys, Britain backs, Google unlocks

The Register / Open Rights Group· 19 Apr 2026
Read original
Causes and effects
This Event
ORG brands UK tech dependency a risk
The report puts a number on the cloud-layer gap the UK's sovereign AI strategy leaves untouched, and flags the US CLOUD Act as a legal mechanism that can compel UK data disclosure without UK consent.
Different Perspectives
China's foreign ministry
China's foreign ministry
Spokesman Lin Jian rejected Treasury Secretary Scott Bessent's 25 August warning that Iranian oil buyers face an "economic D-Day", saying sanctions do not help and that Beijing would safeguard its own rights and interests. China's Iranian crude imports had already halved for unrelated reasons.
Iraq's government and Erbil authorities
Iraq's government and Erbil authorities
Erbil authorities said 10 explosive-laden drones were shot down over the city on 1-2 September with no casualties. Iraq's government condemned the attacks without naming Iran as their source, and neither Washington nor Baghdad confirmed the IRGC's claim to have hit US bases there.
Bahrain Defence Force
Bahrain Defence Force
The General Command said air defences intercepted several Iranian missiles and drones on 1-2 September and called the use of such weapons against civilians and private property a flagrant violation of international humanitarian law.
Kuwait's Fire Force and foreign ministry
Kuwait's Fire Force and foreign ministry
KUNA reported a hostile Iranian drone struck a residential complex in Kuwait City on 2 September; Fire Force spokesman Brigadier General Mohammad Al-Gharib said losses were confined to property. Kuwait's foreign ministry called the attack a clear breach of its sovereignty.
Jordan's Armed Forces
Jordan's Armed Forces
Petra carried a statement that air defences intercepted eight missiles violating Jordanian airspace early on 31 August and 10 of 13 fired on 1 September. The statement named no target and did not address the IRGC's claim to have struck Camp Titin and killed US personnel.
CENTCOM
CENTCOM
CENTCOM's 1 September target list named IRGC air defence, radar, maritime and mine-laying sites in Iran but no tanker, after Axios reported anonymous officials describing a Trump-approved "tanker for tanker" drone policy. A CENTCOM spokesman declined to confirm the policy and referred questions to policymakers.