Slight correction of tense
"could quickly become a national security headache"
The only way it could become a headache if to start thinking about it which obviously HMG so far hasn't. For anyone who has thought about it it already is a headache.
Britain has spent years wiring its public sector into US Big Tech, and a new report says that dependence could quickly become a national security headache. The warning comes from Open Rights Group, whose latest report, "Tech Giants and Giant Slayers," argues that the UK has let a small group of American megacorps entrench …
Indeed!
I echo your thoughts Doctor Syntax.
We have been riding the coat tails of everyone else for far too long in the UK.
The UK, and others, should start to look at the next decade's worth of investment and think where it truly needs to be.
No "Sovereign" Cloud will cut it I'm afraid.
We need to support the minnows and help them, where applicable, get a fair market share.
Also, we need to wean ourselves off all this US centric software that we don't truly need.
Just my opinion of course, or do we need to get a manumission to be free?
If by this you mean you wouldn't consider amazon's internal use of AWS to be "cloud" computing then yes.
It *sort* of still is, in that it uses exactly what anyone would use to operate, but at the same time it isn't that simplistic definition "someone else's computer"
There is a debate in Westmister tomorrow about the Palantir NHS contract. Write to your MP, correction: the MP in your constituency.
M$ and gmail send my email to spam: I wrote on Mathstodon about this and have just passed 1000 boosts and 1000 favorities, so join the club!
I work with the UK branch of a US multinational supporting a system that fall into the remit of GDPR-UK and the Official Secrets Act..
I really have issues with things like the US Cloud Act, and how it relates to GDPR-UK and the Official Secrets act.
If an instruction comes from the US holding company to leak data, it is not just the UK subsidiary that would be breaking UK law, it is everybody involved in the extraction in the UK who support the systems who would also be breaking the law at a personal level.
I have actually asked my management chain about this, and I've been told that the situation would never arise, but I've made it clear that if I was asked to break UK law in order to knowingly provide information to the US parent in breach of data protection, I would walk, but I don't think that everyone around me would take the same decision.
In this case, there is a bit of a get-out, as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for, and we are just the maintainers and administrators. There is an approval process involving the client that should/would stop large scale export of data, which would make it clear if something is being asked for under the covers, as it would have to avoid the change process.
, as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for,
This is just a coping mechanism. If request comes they need to make it available. You cannot evade a control-based legal regime by playing dress-up with ownership. A UK badge on the bonnet does not help if the steering wheel is still in California.
And that is why I would walk.
It's an interesting conflict though. No matter what the US laws say, the data is domiciled in the UK, run on systems owned by the UK client, by a UK limited company (albeit owned by a US one), and run by people who have been vetted and also signed the acknowledgement that they understand that they are covered by the Official Secrets Act (as is everyone in the UK, whether they've signed it or not).
UK law should be the prevailing law, no matter what the US thinks.
Nobody from outside specific UK sites is allowed any access, especially remote access from abroad, and nobody gets access to these sites without either being escorted, or signing the aforementioned acknowledgement. This makes it a personal offence, punishable by prison in the UK, to export the data to the US.
So the US government can fine or otherwise penalise the US company, but they should have no way short of cyber warfare to get access to the data without someone in the UK risking arrest. This is not a US run Cloud operation where data can be duplicated or moved within the Cloud infrastructure out of the UK at the click of a button.
The CLOUD Act works by compelling the US parent, not by sneaking into a UK data centre.
If the US parent controls the company, it doesn’t need ‘access from abroad’. It can instruct the UK operation to produce the data. That instruction doesn’t have to look like ‘export secrets to the US’. It can look like routine work: generate reports, enable logging, run queries, adjust backups. No one on the ground needs to think they’re committing an offence.
And if the parent refuses, the US can enforce compliance where it actually has power: against the parent company and its executives. At that point, the internal pressure to comply is overwhelming.
It can attempt to compel the people with access. That does not absolve the the prople in th UK from the effects of UK law. In order to comply with the compulsiom, the authorized people in the UK would be breaking UK law, and would be subject to arrest and trial, and it is very probable that the UK subsidiary would also be breasking GDPR-UK and other security laws.
And as I tried to point out, people outside of the reach of UK law have no acces to the data so are not in the process.
You are correct that it could be disguised as regular work, but such work is overseen by a process including the client. I was involved in officially exporting data out of one pf the data centres, and the hoops to jump through to do it were significant. And at any point, if it was thought that the data was being done inappropriatly, I would have stopped.
You’re imagining a whistleblowing moment. In reality, it looks like a Jira ticket.
If you push back, it doesn’t trigger a dramatic legal standoff. It becomes a performance issue, or the work is reassigned, or the requirement is reframed until it fits within existing process. Large organisations don’t rely on one person agreeing to do something obviously improper, they route around friction.
And crucially, the obligation isn’t being enforced on you in the UK, it’s being enforced on the US parent. That’s where the real pressure sits. Once the parent decides it must comply, the question internally stops being ‘should we do this?’ and becomes ‘how do we do this in a way that fits our processes?’
At that point, the perimeter controls and sign-offs you’re describing don’t stop it, they just shape how it’s done.
I respectfully disagree. I suppose I'm fortunate enough that the environment I'm supporting makes it very difficult, both by design and architectural differences, to export data in volume. Any attempt involving physical media has to get client approval. I'm lucky that way and I'm late enough in my career that the consequences would make little difference to me, either work wise, or personally.
The point at which the UK subsidiary decides "How should we do this?" is the point where they have to make up their mind as to whether they will break UK law, and as such, is a decision about whether they still want to be a company operating in the UK, and whether the people in control of the UK subsidiary want to become criminals. If the Government finds out, and decides that at a corporate level, the UK subsiduary has breached the law is the point at which they can fine and ultimately shut down the UK company, These are not toothless regulations.
There is an absolute obligation under UK law and enforceable in the UK by the UK authorities. Even if you are subtly compelled, you can still be personally liable. Such is the nature of the Official Secrets Act. "Only doing it under orders" is not a defence if you have any idea whatsoever what is going on. If you are bound by it, I strongly suggest that you re-read the UK Official Secrets Act, and possibly the GDPR-UK regulations.
In this case, there is a bit of a get-out, as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for
But that's not the case for an awful lot of stuff. I'm pretty sure that if the orange buffoon make the right noises to Microsoft, they could effectively shut down UK defence (along with the rest of UK government). Such is the degree to which we're now entwined with Microsoft's clouds. Doesn't matter that some of it is hosted on-prem, I'm fairly certain that we now use MS's AD and authentication etc. - so they can stop us logging in.
I'm afraid that you're correct, especially now Windows is effectively becoming an OS-as-a-service, having to check in with the mothership on a regular basis for authorisation to allow it to keep running,
And anything relying on Azure, AWS or the Google Cloud is equally vulnerable to this type of service denial.
In my case, being a non-Windows environment several arms distant from MS services, we could keep my part running without MS's approval, but the infrastructure around it is not so fortunate.
I was reminded recently of the financial crisis of 2008 onwards. One of the features then was the intertwined nature of investment banking with retail banking. Everybody was happy with this in rising markets when the investment gains were cross-subsidising retail. Not so much when the investments went bad on such a scale that Govts had to step in to prop the banks up.
I can see a scenario now where some (all?) of the US tech giants get burnt on AI investments and need to cover their losses by squeezing their "retail" customers - in this case those rather badly advised public bodies over here that are locked in. So the UK (local or national) taxpayer will end up paying that bill for them.
There's a further point of comparison.
Back then there was an assumption that an economy could exist which was able to ignore the inflationary effects of rising house prices to maintain low interest rates.
Nor there's an assumption that an economy can exist which is able to ignore the amount of money already burnt on AI data centres to provide a return on investment.
Tech independence and data sovereignty would have been much easier to achieve if the UK could have joined the EU in developing solutions which each European nation could deploy domestically. Scale matters.
But someone just loved their ring a little too much, and one of the ironically-named results is Palantir, which just happens to report back to an aggressively interventionist dark lord in a foreign land.
There's a lesson about unity in there, brought to us by one of the greatest British writers of all time.
Just because the UK isn't part of the EU doesn't mean they couldn't partner with the EU for solutions to de-USify themselves. They would just have to accept that any EU wide solution that was developed would have to be operated under EU law which would mean it couldn't be located in the UK or operated by UK based companies.
But that involves a lot more friction than pushing fellow EU members to fund a common code base which each nation can deploy on their own, sovereign hardware.
Only some of it is from scratch. Particularly, the national security related stuff which competes with Palantir.
Many existing use cases for everyday software are already being addressed, they just need funding. Take, for example, Nextcloud or desktop Linux. The cost to turbocharge development under the helm of longtime open source leaders and European universities is a drop in the bucket compared to what Brussels spends on a regular basis.
As they say in politics: if you're not at the table, you're on it.
The UK is not at the table.
I guess as long as Gordon Brown, Thatch or Tony Benn still get blamed for things.
Closing down most UK Nuclear and abandonment of technical known how/research (remember Dounreay) and a ‘Dash for Gas’ now also seems ridiculous for Electricity Generation from 1990’s and 2010’s Tories…. Esp. This week where Rolls-Royce got a £1/2bn bung for SMR’s.
Much that’s shit in the US can be tracked back to Regan Era who was Thatch’s Buddy.
This is already a national security issue, and should be treated as one. But it won't be, because 'our' politicians see themselves as petty princes in the American kingdom. Britain is a rump state.
The USA has built profiles on every British politician. This is aided by the self-inflicted security hole of granting the USA unfettered access to all of parliament's email, files, data, address books. In times gone past, this would have been seen as a security issue.
Link: https://www.theregister.com/2026/04/13/digital_sovereignty/
Quote: "....you need to partner with reliable open source providers to run an IT stack that you, not Trump, control...."
Once upon a time, CIOs were wedded to having their own data centres!
Once upon a time, CIOs were wedded to having their own back up data centre!
Of course, the software running in those data centres might come from SAP, or ORACLE, or IBM........
.....but the CIO could look in the mirror and smile and say "At least I control the IT stack which operates my company".
That was then......and now we get Steven J. Vaughan-Nichols telling us that this retrospective picture MIGHT HAVE BEEN CORRECT ALL ALONG!!!
Back to the future!
Sigh!!
It wasn't long ago when every government entity and each company owned it's own hardware, handled its own networking, hosted its own web server, ran its own mail host, hosted its own databases, and had some expertise somewhere in the organization over what it took to make it all work and likely employed a few IT "professionals" who while not getting rich, made enough to put a roof over their heads, a car in the garage, food on the table and clothes on the kids. We were all sovereign at the time. Many of the vultures here recall.
But as with the most common ills of the past 30 years, the hype-machine started extolling the virtues of cloud storage, governments, companies and individual were lured to keep their documents and photos on somebody else's hardware. The same play was made for e-mail and web hosting and finally complete IT solutions all with the promises of huge savings in IT spending. Each time promising expertise in all areas of tech where the cloud could do it better, faster and more secure relying on economies of scale to create magic savings and improved security. Soon governments and companies fired or laid-off their IT staff, removed their hardware and over time lost all "corporate knowledge" of how to make it all work.
The articles in The Register provide a daily chronicle reminding us all of there being no more truth to the promises of IT savings or data security by Big Tech than there was in the orange lunatic portrayed as Jesus claiming he thought the depiction was of him as a doctor. We've done it to ourselves.
I'm not sure data sovereignty necessarily means our Big Tech Bros here against your Big Tech Bros. The problem seems to have been the Big Tech Bros all along, regardless of where they reside.
Learning is expensive, and the best lessons -- are very expensive, but if we've learned nothing over the past 30 years in this area, that turning your hardware, software and data over to companies that over promise and under perform, then there is still some expensive learning to take place. Instead of rushing to turn every part of your IT over to someone else closer to home, perhaps the better and more sovereign path is to buy only those services you can't provide for yourself, and keep the rest in-house -- just as we all used to do it.
> Open Rights Group says years of reliance on US giants have left Britain exposed
"Reliance on US giants" is purely the natural result of Britain being, de facto, a US colony, along with the rest of Western Europe.
Lend-lease did the trick for the UK, as the Marshall plan did for the continentals.
For their part, the US were hedging both ways, with Germany's side of the war being financed and enabled, to a large extent, by US capital (hello Mr Prescott Bush) and companies (the likes of Ford, the owner being a fervent fascist and raging antisemite, or IBM, who supplied the computers that processed the numbers tattooed onto the arms of my grandfather's family and many others).
So, isn't it a bit late to start acting all surprised?