Airbus Moves Sensitive AI Workloads to a Sovereign Cloud. What Businesses Can Learn

July 16, 2026

Airbus has selected European cloud provider Scaleway to host sensitive industrial, defence and AI workloads. The decision was not based only on computing power or price. Airbus also examined data protection, legal exposure and control over critical information. For businesses, the lesson is clear: choosing a cloud provider is no longer just an IT decision.…

Table of contents
Key Takeaways
  • Airbus has entered a multi-year cloud infrastructure agreement with European provider Scaleway.
  • The platform will host sensitive industrial, defence and AI-powered applications.
  • Airbus assessed more than 150 technical and legal requirements before making the decision.
  • The company plans to migrate around 70 critical applications by 2028, with the potential to move up to 900 applications over the following five to six years.
  • Businesses should review data location, legal control, backup separation, access management and provider dependency before placing critical workloads in the cloud.

Most companies choose cloud services by looking at a few familiar things.

Price.

Storage.

Processing power.

Support.

Uptime.

These are important.

But they are no longer enough.

As businesses place more sensitive information and AI workloads in the cloud, another question is becoming harder to ignore:

Who really controls the data?

Airbus has now made that question part of a major cloud decision.

On 16 July 2026, Airbus announced a multi-year agreement with Scaleway, a European cloud provider owned by French telecommunications group Iliad. The cloud environment will support sensitive industrial and defence applications, including AI tools used across aircraft design, engineering, production and corporate functions.

Airbus did not simply compare server specifications.

It reportedly assessed more than 150 technical and legal requirements, including data protection standards and safeguards against foreign laws that could create access or control concerns.

That makes this more than a cloud hosting story.

It is a useful example of how companies should evaluate cloud risk when important data and business operations are involved.

What Airbus Is Moving to the Cloud

Airbus plans to use Scaleway’s infrastructure for critical applications and AI workloads.

These applications will support areas such as:

  • Aircraft design
  • Engineering
  • Manufacturing and production
  • Corporate operations
  • Industrial AI
  • Defence-related work
  • Applications developed using Mistral AI technology

Airbus is expected to move approximately 70 critical applications to the new environment by 2028. The wider arrangement could eventually cover as many as 900 applications over the next five to six years.

This is a significant migration.

Airbus is not moving only test systems or public information.

It is placing sensitive workloads into an environment selected partly because of its legal, security and sovereignty characteristics.

That is the important lesson.

The cloud provider is becoming part of the company’s risk environment.

What Is a Sovereign Cloud?

The term “sovereign cloud” is often used in marketing.

But the idea behind it is practical.

A sovereign cloud is designed to give an organisation stronger control over where its data is stored, which laws apply, who can access the environment and how dependent the organisation is on foreign technology or legal systems.

Scaleway describes itself as a European sovereign cloud and AI provider focused on giving organisations control over their data and infrastructure.

The European Commission is also developing a common sovereignty framework under its proposed Cloud and AI Development Act. The proposal includes different assurance levels for cloud and AI sovereignty, allowing public-sector organisations to select requirements based on their risk level.

In simple terms, sovereign cloud planning looks beyond the physical location of a server.

It also looks at:

  • Who owns the provider
  • Which country’s laws apply
  • Whether foreign authorities could request access
  • Where administrators and support teams are located
  • Whether encryption keys are controlled by the customer
  • Whether the organisation can move its data elsewhere
  • Whether the provider depends heavily on foreign technology
  • Whether sensitive workloads remain under approved control

These questions matter most when the data is commercially sensitive, regulated or connected to critical operations.

Data Residency and Data Sovereignty Are Not the Same

These two terms are often confused.

Data residency normally refers to where the data is physically stored.

For example, a company may require its customer records to remain in Malaysia.

Data sovereignty is broader.

It considers the laws, ownership, access rights and control structures surrounding that data.

A server may be physically located in one country but operated by a company subject to another country’s laws.

This does not automatically mean the service is unsafe.

But it may affect compliance, legal exposure and customer requirements.

Businesses therefore need to ask more than:

“Where is the data centre?”

They should also ask:

“Who controls the platform, and under which legal system?”

Why Airbus Did Not Choose Based Only on Technology

Most established cloud providers can offer strong computing, storage and networking capabilities.

The difference is often in the details.

Airbus reportedly evaluated more than 150 legal and technical requirements before selecting Scaleway. The assessment included data protection and legal safeguards against extraterritorial laws.

This shows that cloud procurement for sensitive workloads is no longer based only on performance.

A proper review should also cover:

  • Security architecture
  • Data protection
  • Identity and access control
  • Legal jurisdiction
  • Contractual protection
  • Encryption
  • Backup and recovery
  • Service portability
  • Incident reporting
  • Audit rights
  • Provider ownership
  • Supply-chain dependency

Many businesses do not need a review as detailed as Airbus.

But the same principles still apply.

The more important the system, the more carefully the provider should be assessed.

Why This Matters Beyond Aerospace and Defence

It is easy to assume that sovereign cloud only matters to governments, banks or defence companies.

That is not true.

Many ordinary businesses handle information that would cause serious problems if it were exposed or lost.

Examples include:

  • Customer databases
  • Financial records
  • Employee information
  • Contracts and quotations
  • Product designs
  • Source code
  • Supplier pricing
  • Technical documentation
  • Business plans
  • Medical or personal information
  • Internal emails
  • Backup copies
  • Intellectual property

A company does not need to manufacture aircraft for data control to matter.

A property company may hold identity documents and tenancy information.

A professional services firm may hold client contracts and financial records.

A manufacturer may hold confidential product drawings.

A software company may hold source code and customer credentials.

A retailer may hold customer contact and transaction information.

The risk level is different, but the question is the same:

Does the company understand where its data is going and who can access it?

AI Makes Cloud Control More Important

AI systems depend heavily on data.

A company may use AI to analyse documents, support customers, review code, search internal records or automate business processes.

This often requires the AI platform to interact with existing files, databases, emails or applications.

That creates new questions.

  • Is the data stored after it is processed?
  • Can the AI provider use the data to improve its models?
  • Does the information leave the selected region?
  • Can administrators inspect prompts or output?
  • Is confidential information separated from public AI services?
  • Can the business delete the data later?
  • Are logs retained?
  • Who controls the encryption keys?
  • Can the AI system take actions inside other applications?

Airbus plans to use the Scaleway environment to support AI tools developed in collaboration with French AI company Mistral, including applications used in design, engineering and production.

This reflects a wider change.

AI is no longer separate from cloud strategy.

The AI model, data, infrastructure, access control and legal environment must now be reviewed together.

Europe Is Treating Cloud Dependency as a Strategic Risk

Airbus’s decision is happening while Europe is trying to strengthen its own cloud and AI capabilities.

The European Commission proposed the Cloud and AI Development Act in June 2026. One goal is to expand European cloud and data-centre capacity while reducing strategic dependence on non-EU providers for critical digital infrastructure.

The Commission has said it wants to at least triple the European Union’s data-centre capacity over the next five to seven years and fully meet the cloud and computing needs of European businesses and public administrations by 2035.

This does not mean businesses must reject global cloud platforms.

Major international cloud providers remain important and may be the right choice for many workloads.

The lesson is about dependency.

Companies should understand what they depend on, what happens if that dependency fails and whether they have practical alternatives.

Five Cloud Questions Every Business Should Ask

You do not need Airbus’s procurement team to make a better cloud decision.

Start with five practical questions.

1. Where Is Our Data Stored and Processed?

Ask for the actual region or data-centre location.

Do not assume the company’s local sales office means the data is stored locally.

Also check whether backup, logs, analytics and technical support data are stored in the same location.

The main system may be hosted in Malaysia while backup or monitoring information is processed elsewhere.

A proper review should cover the full data flow.

2. Which Laws and Contracts Apply?

The data-centre location is only one part of the answer.

Review:

  • The provider’s country of incorporation
  • The entity named in the contract
  • The governing law
  • Data-processing terms
  • Subcontractors
  • Government access policies
  • Breach notification obligations
  • Customer audit rights
  • Data deletion procedures

For sensitive workloads, legal review should be part of cloud procurement.

3. Who Controls Administrative Access?

Cloud environments often fail because access control is weak.

A company should know:

  • Who has administrator rights
  • Whether the provider can access customer data
  • Whether support access is logged
  • Whether multi-factor authentication is mandatory
  • Whether privileged access is time-limited
  • Whether vendor accounts are reviewed
  • Whether former employees have been removed
  • Who controls the encryption keys

Administrative access should be limited to the people who genuinely need it.

4. Can We Recover Without Depending on the Same Environment?

A backup stored inside the same cloud account may not provide enough separation.

If the main account is compromised, the attacker may also be able to delete or encrypt the backup.

Businesses should consider:

  • Separate backup credentials
  • Offsite copies
  • Immutable storage
  • Different administrative access
  • Recovery testing
  • Documented restoration steps
  • Backup outside the primary production environment

The important question is not whether a backup job completed.

The question is whether the business can restore clean data after a serious incident.

5. Can We Move to Another Provider?

A cloud service may work well today.

But circumstances can change.

Prices may increase.

Service quality may decline.

Compliance requirements may change.

The provider may discontinue a product.

The company may need to enter a new country or industry.

Businesses should understand:

  • How data can be exported
  • Which file formats are available
  • Whether applications use proprietary technology
  • How long migration would take
  • What data-transfer charges apply
  • Whether documentation is complete
  • Whether another provider can support the workload

An exit plan does not mean the company is planning to leave.

It means the company is not trapped.

Is Local Cloud Always Better?

Not automatically.

A local cloud provider may offer advantages such as:

  • Local support
  • Lower network latency
  • Clearer data location
  • Familiar legal jurisdiction
  • Easier communication
  • Local invoicing
  • Better understanding of customer requirements

However, location alone does not guarantee quality.

A local provider should still be evaluated for:

  • Security
  • Infrastructure reliability
  • Backup
  • Service-level commitments
  • Monitoring
  • Technical support
  • Financial stability
  • Certifications
  • Incident response
  • Recovery capability

The same applies to global providers.

A well-designed global cloud environment may be more suitable than a poorly managed local environment.

The decision should be based on the workload, risk and business requirement.

Does Every System Need Sovereign Cloud?

No.

Different workloads carry different levels of risk.

A public marketing website does not necessarily require the same controls as a defence application, financial database or healthcare platform.

Businesses can classify workloads into groups.

Low-Sensitivity Workloads

Examples may include public websites, product catalogues and public marketing content.

These systems still need security and backup, but sovereignty may not be the main concern.

Business-Operational Workloads

Examples include email, CRM, accounting systems, file storage and internal applications.

These require stronger access control, backup, monitoring and continuity planning.

High-Sensitivity Workloads

Examples include regulated data, intellectual property, critical infrastructure, defence information, medical records and highly confidential business data.

These may require stricter control over jurisdiction, administrators, encryption, audit rights and provider dependency.

The goal is not to apply the most expensive environment to every system.

The goal is to match the cloud design to the risk.

Multi-Cloud Is Not Automatically the Answer

When businesses hear about cloud dependency, they often assume they need several providers.

That may help in some situations.

It can also create more complexity.

A poorly managed multi-cloud environment may lead to:

  • Inconsistent security controls
  • More admin accounts
  • More complicated billing
  • Different backup methods
  • Harder monitoring
  • Skills gaps
  • Configuration mistakes
  • Higher support costs

Before adopting multi-cloud, a company should first improve the basics:

  • Asset inventory
  • Access control
  • Backup
  • Monitoring
  • Recovery testing
  • Provider assessment
  • Incident response
  • Documentation

After that, the business can decide whether multi-cloud, multi-region or hybrid cloud provides enough value to justify the complexity.

What Management Should Ask the IT Team

Management does not need to understand every cloud product.

But it should ask clear questions.

  • Which systems are hosted in the cloud?
  • Which provider supports each system?
  • Where is the data located?
  • Who has administrator access?
  • Are backups stored separately?
  • When was recovery last tested?
  • What happens if the provider is unavailable for one day?
  • Can we export our data?
  • Which systems contain sensitive information?
  • Are AI tools processing confidential data?
  • Who reviews provider contracts and security requirements?
  • What is our exit plan?

If the answers are unclear, the company has a visibility problem.

That should be fixed before more critical systems are moved to the cloud.

What Businesses Can Learn From Airbus

Airbus’s cloud decision offers three useful lessons.

Cloud Procurement Is Risk Management

Cloud selection should not be handled only as a price comparison.

Security, law, access, recovery and portability are part of the decision.

Sensitive AI Needs a Controlled Environment

AI tools can interact with valuable business information.

The infrastructure, model and data controls must be assessed together.

Provider Dependency Should Be Deliberate

Using one provider is not automatically wrong.

Depending on one provider without understanding the risk is the problem.

The business should know what it depends on and what it will do if circumstances change.

Closing Thoughts

Airbus’s decision to place sensitive AI, industrial and defence workloads with a European sovereign cloud provider shows how cloud strategy is changing.

Computing power still matters.

Price still matters.

Performance still matters.

But control now matters too.

Businesses need to know where their data is stored, which laws apply, who can access it and whether the company can recover or move the system when necessary.

These questions should not be asked only after a contract is signed.

They should be part of the buying decision.

Airbus reportedly examined more than 150 legal and technical requirements before choosing its provider. Most businesses will not need a review of that scale, but every company should at least understand its critical systems, data location, administrative access, backup arrangement and provider dependency.

Cloud does not remove responsibility.

It changes how responsibility is shared.

At Net Onboard, we help businesses design and manage secure cloud environments through cloud hosting, managed support, cybersecurity, backup and business continuity services.

If your company is reviewing cloud hosting, data location, provider dependency or recovery readiness, Net Onboard can help assess the current environment and design a practical cloud strategy based on your operational and security requirements.

Frequently Asked Questions About Sovereign Cloud and Data Control

  1. What did Airbus announce today?

    Airbus entered a multi-year agreement with European cloud provider Scaleway to support sensitive industrial, defence and AI-powered applications. Airbus plans to migrate around 70 critical applications by 2028, with the potential to move up to 900 over the following five to six years.

  2. What is sovereign cloud?

    Sovereign cloud refers to cloud infrastructure designed to provide stronger control over data location, legal jurisdiction, ownership, access and dependency. The exact requirements vary depending on the organisation and the sensitivity of the workload.

  3. Is data residency the same as data sovereignty?

    No. Data residency mainly concerns where data is physically stored. Data sovereignty also considers which laws apply, who controls the provider, who can access the environment and whether the organisation remains dependent on foreign technology or legal systems.

  4. Does every business need sovereign cloud?

    Not necessarily. The decision depends on the sensitivity of the data, regulatory obligations, customer requirements and business impact. Public websites may not require the same controls as financial, healthcare, defence or highly confidential workloads.

  5. Is local cloud always safer than global cloud?

    No. Local hosting can provide useful advantages, but security still depends on infrastructure quality, access control, backup, monitoring, support and recovery capability. Businesses should assess the complete service rather than choosing based only on location.

  6. What should a company check before selecting a cloud provider?

    Review data location, legal jurisdiction, provider ownership, administrator access, security controls, backup separation, recovery capability, service-level commitments, portability and exit procedures.

  7. Should backup be kept outside the primary cloud environment?

    For critical workloads, maintaining a separately controlled or offsite backup can reduce the risk that one account compromise, technical failure or provider incident affects both production data and recovery copies.

  8. What is cloud vendor lock-in?

    Vendor lock-in happens when moving a system or data to another provider becomes difficult, expensive or disruptive because of proprietary technology, data formats, integrations or contractual limitations.