UK Lawmakers Flag Strategic Risks in Reliance on U.S. Cloud Providers

UK lawmakers warn that heavy reliance on U.S. cloud companies could expose critical services to strategic risks, as public spending on cloud reaches about £1 billion annually.
Server racks in a UK government data centre with an official reviewing cloud infrastructure. Server racks in a UK government data centre with an official reviewing cloud infrastructure.

Updated:

British lawmakers have warned that the government’s growing reliance on U.S.-owned cloud companies for critical public services creates a strategic and economic vulnerability. The concern, reported by Bloomberg and carried by Investing.com on October 4, is that dependence on a small number of overseas suppliers could expose essential services and data to risks beyond the UK’s control.

Government departments spend about £1 billion a year on cloud services, according to estimates cited in the report. Amazon Web Services (AWS) and Microsoft may account for as much as 80% of government cloud purchases, although officials do not have a precise measure of the government’s overall dependence.

The warning comes as public bodies move more sensitive functions onto cloud platforms, including health, tax and defence services. Lawmakers’ concerns encompass not only where data is stored, but also the legal jurisdiction and supplier concentration affecting access to services and information.

Advertisement

Committee chair raises questions over legal jurisdiction

Chi Onwurah, chair of Parliament’s Science, Innovation and Technology Committee, drew attention to the U.S. CLOUD Act, according to the report. Experts who gave evidence to the committee said U.S.-headquartered providers could, in certain circumstances, be compelled to disclose data held on their servers or withdraw services.

The issue is distinct from the physical location of a data centre: storing information in Britain does not, by itself, resolve questions about the legal obligations of a company headquartered elsewhere. The reported concerns relate to potential legal demands and service continuity; they do not establish that U.S. authorities have accessed specific UK government records or that providers have threatened to discontinue UK services.

In a March 2026 parliamentary answer, the government said it takes a balanced approach to cloud services, aiming to keep public-sector systems secure and resilient while benefiting from global technology. Parliament’s written question had specifically asked about the CLOUD Act, the Patriot Act and entity-list controls in relation to data sovereignty and access to cloud services.

Major public services are moving to cloud contracts

The report points to several large public-sector arrangements as examples of the shift. HM Revenue & Customs awarded AWS a 10-year contract worth £473 million to manage UK tax data, while the Ministry of Defence secured a £400 million Google Cloud agreement intended to support secure communications and classified information sharing.

The Ministry of Defence announcement described the Google partnership as strengthening secure links between the UK and the United States. Separately, NHS trusts are moving patient records from local servers to cloud providers, the Bloomberg-sourced report said. These examples span different public functions and contracts; the available reporting does not set out a single government-wide cloud migration schedule.

Domestic capacity and supplier concentration

Onwurah said the UK was unlikely to build a domestic provider able to match the scale of the largest U.S. cloud companies, and suggested that Britain could cooperate more closely with France and Germany. That points to a policy challenge beyond procurement: reducing reliance would require credible alternatives and a plan for how public services could keep operating if a supplier or its services became unavailable.

Earlier parliamentary work has also examined the broader question of digital sovereignty. A House of Commons committee report on digital government called on the government to explain what contingencies it has to protect citizens’ data if the United States invokes data-access provisions under the CLOUD Act. That recommendation demonstrates parliamentary scrutiny of the issue, but is not itself evidence of a new government policy or a timetable for changing suppliers.

European alternatives are under development

European governments are exploring other approaches, according to the report. France replaced Microsoft Azure with French provider Scaleway for its national health data hub in April, while Germany’s Schleswig-Holstein has been moving away from Microsoft products toward open-source alternatives.

The European Commission is also developing a framework intended to strengthen European cloud and artificial-intelligence sovereignty. The report does not specify a completion date for that framework or detail its final requirements, so its eventual impact on UK procurement remains unclear.

The UK government said it was working to improve resilience and public-sector cloud procurement, and that departments must consider the risks of excessive dependence on individual suppliers. The available reporting does not identify a new procurement deadline, a target for lowering the U.S. providers’ share, or a decision to replace the contracts cited. The immediate issue for lawmakers is whether existing protections and contingency plans are sufficient as more essential services rely on cloud infrastructure.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement