Skip to main content

Brussels picks a French portal to open its €180 million cloud to 5,000 developers

Ilustrační obrázek
For years, a public-sector developer in Europe who needed somewhere to run their code had one obvious answer, and it was usually American. That answer now has a European front door. The European Commission has confirmed the French platform vendor Cycloid as the developer-facing portal for its sovereign multi-cloud framework — a six-year, €180 million arrangement designed to give up to 5,000 Commission developers a single place to build, deploy and manage workloads across four pre-selected European cloud groups. It is not a new cloud. It is the doorway to several.

A €180 million door, not a €180 million cloud

Start with the number people quote, and then with the number that actually matters. The framework is worth roughly €180 million over six years — about €30 million a year spread across every supplier involved. For scale, the largest US cloud providers measure their infrastructure spending in tens of billions of dollars annually. Brussels is not trying to out-build Amazon, Microsoft or Google. It is trying to buy something those companies cannot sell: a documented, checkable guarantee about where European public-sector data sits, and who can be compelled to hand it over.

That distinction is the whole story. As IT Europa reported, and the EU procurement records confirm, Cycloid's portal acts as a central access layer rather than a hosting product. The work still happens in other people's data centres — they are just European data centres, chosen in advance, under contract, with audits attached.

Four clouds, one interface

The framework selected four provider groups. In plain language:

  • POST Luxembourg, together with the French providers Clever Cloud and OVHcloud;
  • STACKIT, the cloud arm of Germany's Schwarz Group — the retail giant behind Lidl and Kaufland;
  • Scaleway, the French cloud owned by the Iliad group;
  • Proximus, the Belgian incumbent, in a consortium with S3NS, Clarence and the French AI company Mistral.

That list is more interesting than it looks. It mixes a telecom operator, a supermarket group, a hosting company and an AI lab. The Commission is not treating the four groups as interchangeable: the award also records assurance results for the sovereignty dimensions that matter to the framework.

Sovereignty now comes with a grade

The Commission did not simply ask suppliers to promise they were sovereign. It required SEAL levels — Sovereignty Effectiveness Assurance Levels. The available Commission result identifies a SEAL-3 level for the Digital Resilience dimension, not a provider-by-provider Data Sovereignty grade. That distinction matters: the published award record does not explicitly confirm separate Data Sovereignty results for the four selected groups, and the SEAL dimension named in the award is what gives the comparison its meaning.

For anyone outside procurement, this sounds like bureaucracy. It is the opposite. "European cloud" has never been a binary state. A European company can run European data centres while depending on non-European software, non-European support staff with privileged access, or a non-European parent company that could be ordered to disclose data. A graded scale lets a buyer compare those claims instead of taking them on faith — and, crucially, it lets a buyer say no.

The rulebook that made this urgent

This purchase did not happen in a vacuum. The AI Act's rules for general-purpose AI models began applying on 2 August 2025, with the Commission's AI Office responsible for enforcement of those provider obligations from that date. The Act as a whole, including the Article 50 transparency obligations for providers and deployers of certain AI systems, applies from 2 August 2026, subject to the Act's specific transitional rules. The AI Act framework therefore does not support one blanket 3% to 7% fine range: penalties depend on the infringement. Prohibited practices can attract up to €35 million or 7% of worldwide annual turnover, whichever is higher; breaches of other obligations can reach €15 million or 3%; and supplying incorrect, incomplete or misleading information can reach €7.5 million or 1%, with the applicable ceiling depending on the category and the organisation involved.

The old assumption that open-weight models escape all of this is also gone. Open-source developers keep certain exemptions, but they must still supply technical documentation and summaries of training content under copyright provisions — and if a model is classified as posing systemic risk, the exemptions largely evaporate. Those GPAI obligations are distinct from the later application date for Article 50 transparency rules.

Add GDPR to the same paragraph and you get the practical reason a public administration cares where its servers stand. The GDPR can apply to providers outside Europe when its territorial rules are met, and transfers of personal data to countries outside the EEA require an adequacy decision or appropriate safeguards such as standard contractual clauses, together with any necessary supplementary measures. European hosting can help with governance and access controls, but it does not by itself remove the legal risk or make an international transfer disappear. Brussels is not buying patriotism. It is trying to reduce the number of jurisdictions, suppliers and access routes that have to be assessed.

Why it matters outside the Berlaymont

Very few readers of this magazine work for the Commission. But public procurement has a habit of becoming a template. When a buyer as large and as legally cautious as the Commission signs a six-year framework, ministries, regional governments, hospitals, universities and banks read it as a signal about what a defensible cloud decision looks like in 2026. Most of the four provider groups sell to private customers as well, so the same names will appear in far smaller tenders over the next few years.

There is also a genuinely human detail in the numbers. Cycloid is the company handed the developer-facing role: the award documents identify it as the portal provider, rather than as one of the four underlying cloud groups. That is a small company being asked to make a large institution's multi-cloud life tolerable. It is the kind of asymmetry worth watching: a portal is only useful if it survives contact with real developers, real deadlines and real support tickets.

And a portal, it should be said plainly, does not move a single workload. The migration work, the retraining, the rewriting of deployment scripts and the slow negotiation with a service catalogue that is younger than the one you left — none of that is included in the €180 million. Neither is the risk that lock-in simply changes shape, from one hyperscaler to a consortium of four providers you now depend on collectively. If you want context on how we judge infrastructure and models in practice, our AI Arena benchmark rig exists for exactly that reason: claims are cheap, measurements are not.

The honest caveats

Three things are worth holding in mind. First, sovereignty is graded for a reason — the available award record identifies a SEAL-3 result for Digital Resilience, but it does not explicitly confirm a provider-by-provider grade for Data Sovereignty. The SEAL framework is the Commission's way of drawing that line in the open rather than pretending it does not exist. Second, "European" does not automatically mean faster, cheaper or better documented; latency, service maturity and the size of the engineering community still decide whether a team stays. Third, this is a framework, not a finished migration — announced capability and working capability are two different stages, and only the second one shows up in a developer's week.

What has changed, though, is real. A European developer working for a European public institution now has a European procurement route that did not exist in this form. That does not guarantee that every legal or operational risk disappears — data protection, sub-processor access and migration risk still have to be assessed. But as of now, there is a door, and it is European.

Can my company use the same European clouds, even though the framework is for the Commission?

In most cases, yes. The four provider groups sell commercially, and this contract does not lock them to public-sector customers. What you will not get automatically is the framework's negotiated terms or its SEAL requirements — if sovereignty matters to you, ask the provider directly which SEAL result applies to the specific service you want, not to the company as a whole.

Does hosting in a European cloud mean my data never leaves the EU?

Not by itself. Location of the data centre is only one of several factors: support staff access, sub-processors, the parent company's jurisdiction, international-transfer safeguards and the software stack all matter. That is exactly why graded assurance levels exist. A useful first question to any vendor is which SEAL result applies to the specific service you are buying — including any digital-resilience or data-sovereignty assurance the vendor can document — and what safeguards apply to transfers and remote access. Ask for it in writing.

Is Cycloid's portal something ordinary paying customers can use?

The portal role described here is specific to this Commission framework, so private users should not expect the same single sign-on across all four provider groups. Cycloid sells its internal developer platform as a commercial product, which means the practical answer for a small European team is to evaluate the platform and the cloud provider separately rather than assuming they come as a bundle.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.