Two numbers define enterprise cloud strategy in 2026, and they are pulling in opposite directions. On one side, hyperscalers are on track to spend roughly $700 billion on data center infrastructure this year. On the other, global sovereign cloud spending is growing 35.6% to $80 billion, a rate that outpaces the hyperscalers’ own growth. For engineering and IT leadership teams evaluating cloud vendors, this is not a side debate about compliance paperwork. Cloud sovereignty is now a first-order architecture decision, and it is reshaping how enterprises think about data residency, encryption key ownership, and vendor lock-in.
The $700 billion bet behind hyperscaler capex
The scale of hyperscaler investment in 2026 is hard to overstate. TMT Finance’s August 2026 analysis puts combined capex for Alphabet, Amazon, Meta, and Microsoft at $720–745 billion for the year, climbing toward roughly $835 billion once Oracle’s fiscal 2027 guidance is included. Alphabet alone has guided to $195–205 billion, Amazon to around $220 billion, and Meta to $130–145 billion. Independent estimates converge on a similar order of magnitude: J.P. Morgan projects hyperscaler capex will reach $697 billion in 2026, driven almost entirely by AI infrastructure build-out. For enterprises, that scale translates into more regions, more availability zones, and more compute capacity than ever. It does not automatically translate into more control over where and how a specific enterprise’s data is processed.
Sovereign cloud spend is growing faster than the hyperscalers themselves
While the hyperscaler capex story gets the headlines, the more consequential trend for enterprise architecture teams is happening at the edges. Gartner forecasts that enterprises will shift roughly 20% of existing workloads off global public cloud platforms onto local or sovereign alternatives in the coming cycle, with EMEA and mature Asia-Pacific markets posting the fastest sovereign-cloud growth rates. A parallel survey from BARC, covering 320 companies, found that 51% now rate data sovereignty as “very important,” up from 42% a year earlier, and 76% expect that importance to keep rising. The same study identifies running AI on business-critical data as the leading internal driver, cited by 62% of respondents, which means sovereignty requirements are increasingly showing up not in the compliance backlog, but directly inside AI and data platform roadmaps.
Two regulatory playbooks: the EU’s CADA and Brazil’s EU adequacy deal
Enterprises operating across multiple regions are not facing one converging sovereignty standard. They are facing several, moving at different speeds. In the EU, the proposed Cloud and Data Sovereignty Act, published June 3, 2026, introduces four assurance levels for cloud and software providers, ranging from Level 1 (data processing and storage confined to EU infrastructure) to Level 4 (full software supply-chain transparency with no third-country interference). The strictest tiers effectively reserve the most sensitive public-sector workloads for EU-owned, EU-controlled providers, with final adoption targeted for late 2027. Brazil is taking a different route: on January 27, 2026, the European Commission and Brazil’s ANPD adopted a mutual data-protection adequacy decision, letting personal data flow between the two jurisdictions without extra transfer mechanisms such as standard contractual clauses. It is Brazil’s first-ever adequacy decision and the EU’s most comprehensive one to date, covering both public and private sectors. For a multinational, that means a compliance posture built for one region rarely transfers cleanly to the next.
What sovereignty actually changes in a cloud architecture
Three US hyperscalers still control roughly 70% of Europe’s cloud infrastructure market, against about 15% for European providers, yet 60% of Western European CIOs and IT leaders say they want to increase their use of local cloud providers. That gap between current vendor concentration and stated intent is exactly where sovereignty requirements bite into architecture decisions. According to a 2026 SiliconANGLE analysis of the sovereign cloud market, vendors like ServiceNow are already building for “a segment of customers who have higher degrees of sovereign requirements,” meeting them with hybrid and on-premises-adjacent stacks rather than pure multi-tenant SaaS. In practice, sovereignty requirements tend to surface in four concrete places:
- Data residency guarantees — contractual and technical confirmation of which regions store and process data, not just where the nearest region happens to be.
- Encryption key ownership — bring-your-own-key (BYOK) or hold-your-own-key (HYOK) arrangements that keep decryption capability out of the cloud provider’s default reach.
- Workload portability — containerized, cloud-agnostic architectures that can move a workload to a local or sovereign provider without a rebuild.
- Supply-chain transparency — visibility into subprocessors and support-access paths, the same concern driving the EU’s tiered CADA framework.
None of this requires abandoning the hyperscalers whose $700 billion build-out is generating the compute enterprises actually need. It does require designing for exit and for regional variation from the start, rather than retrofitting compliance after a migration is already locked in.
The takeaway for enterprise IT leadership
Hyperscaler capex and sovereign cloud spend are not competing narratives. They are two growth curves that every enterprise architecture team now has to plan against simultaneously. The practical response is not to pick a side, but to build cloud strategies that are portable by design: multi-cloud or hybrid where the regulatory picture demands it, with data residency, key management, and vendor exit paths defined before a migration begins rather than after a regulator asks. Teams that treat sovereignty as an architectural requirement now will spend less re-platforming later, as frameworks like the EU’s CADA move from proposal to enforcement. If your organization is mapping a cloud migration or modernization roadmap against these shifting sovereignty requirements, that assessment is worth doing before the next vendor contract is signed, not after.
