The company has become the first cloud provider to win approval to handle sensitive data for all alliance members.
Amazon Web Services has become the first cloud provider cleared to handle sensitive information for all NATO members, underscoring that an increasingly independent Europe still relies on capabilities made in America, and suggesting that it's not as hard for U.S. firms to compete there as the White House insists.
The company announced on Tuesday that it has received alliance approval to handle information at the NATO RESTRICTED level, which is not classified but requires safeguarding.
As European militaries fuse radar, satellite, and even acoustic information to more easily detect Russian drones and other threats, NATO-approved rapid data and information sharing is critical.
AWS, which already handles sensitive military and intelligence data for many NATO members, beat its competitors—primarily from other U.S. cloud providers such as Microsoft—to win the alliance’s first blanket approval. That’s the result of “a sustained, multi-year effort,” David Appel, acting vice president of Worldwide Public Sector at AWS, said in the company’s Tuesday statement, AWS worked with Spain’s National Cryptographic Centre, or CCN, to test its services against NATO security directives; CCN then shared its findings to all member states.
The announcement also reflects a broad, evolving NATO digital transformation strategy. The alliance is eager to incorporate more commercial information technology into its coordination and planning. And AWS remains the biggest commercial cloud operator in Europe, with nine data-center clusters, or regions, across Europe, including the U.K.
“Strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance,” according to Dylan Browne, general manager of the NATO Communications and Information Agency, or NCIA, as quoted in Amazon’s statement.
While NATO members and AWS cloud users across Europe will be able to share their data more easily, they will also be able to retain control over it. The 2024 European Union Data Act requires cloud providers to protect EU data from other governments, including the United States. Practically speaking, that means housing data on European soil beyond the reach of U.S. court orders, although that’s not an explicit requirement of the Act. AWS, like Microsoft and other enterprise cloud providers, has been investing in European versions of its cloud stacks to meet those Data Act requirements.
Tuesday’s announcement shows both that U.S. technology is still a core feature of NATO military capability and that it is central to NATO’s future plans. But it also shows that European Union regulations on data storage aren’t a challenge to the success of U.S. cloud companies across Europe, even though White House rhetoric and executive orders suggest otherwise.
Facts Only
* Amazon Web Services received alliance approval to handle information at the NATO RESTRICTED level.
* The approval concerns information that requires safeguarding but is not classified.
* AWS worked with Spain’s National Cryptographic Centre (CCN) to test services against NATO security directives.
* CCN shared its findings with all member states.
* AWS handles sensitive military and intelligence data for many NATO members.
* AWS operates nine data-center clusters across Europe.
* The European Union Data Act requires cloud providers to protect EU data from other governments.
* AWS has invested in European versions of its cloud stacks to meet Data Act requirements.
Executive Summary
Full Take
The dynamic presented suggests a convergence where geopolitical necessity intersects with technological infrastructure, creating a dependency that is simultaneously being managed by regulatory frameworks. The assertion that European independence still relies on American capabilities, formalized through an AWS endorsement, speaks to a structural reality of technological scaffolding within defense alliances. The successful navigation of the approval process, involving direct testing with a national cryptographic center, highlights a practical mechanism for achieving trust outside purely diplomatic channels—a reliance built on demonstrable technical security protocols rather than pure political agreement.
The tension arises between the operational realities established by U.S. technology dominance in the alliance and the emerging regulatory environment seeking to enforce data sovereignty (like the EU Data Act). The fact that U.S. cloud providers can successfully integrate these stringent European data residency demands, even while maintaining a core role in military systems, suggests that technological capability is proving more adaptable than political insistence on absolute separation. This pattern indicates that cognitive sovereignty is not solely about decoupling infrastructure but about mastering the interface between sovereign legal requirements and globally integrated technical systems. The ongoing reliance reveals a central assumption: that access to advanced commercial technology necessitates an acknowledgment of underlying geopolitical realities.
What assumptions underpin the narrative that U.S. firms can successfully manage European regulatory conflicts while simultaneously remaining central to military capability? Does this ease in adaptation mask a deeper, unstated structural advantage embedded within the existing relationship? How does this balance between necessary reliance and emerging legal control affect the long-term trajectory of digital autonomy for independent European states?
Sentinel — Human
The text effectively synthesizes technological agreements, corporate strategy, and regulatory contexts to explore the complex interplay between U.S. technology dominance and evolving European autonomy in NATO data sharing.
