Sovereign cloud is the most misused phrase in European technology. It is invoked to mean data residency, then jurisdictional immunity, then supply-chain independence, then simply "not American" — four different claims with four different price tags. OVHcloud and Scaleway are where the phrase gets tested against physical infrastructure, real margins and real hiring. This is what the sector actually is, and what it takes to build a career in it.
The four definitions, and why the distinction decides everything
Before any career or procurement decision, the term has to be disaggregated. Each layer is strictly harder than the one below it.
| Layer | The claim | What it actually requires |
|---|---|---|
| 1. Data residency | Data sits in an EU region | A datacentre location setting. Every hyperscaler offers it. |
| 2. Operational sovereignty | Only EU staff can access systems | Personnel vetting, access-control engineering, audited support workflows |
| 3. Jurisdictional immunity | No non-EU legal order can compel disclosure | EU-owned, EU-controlled corporate structure — not achievable by a subsidiary of a non-EU parent |
| 4. Technological autonomy | Stack can be maintained without non-EU vendors | Open-source control plane, own hardware design, credible silicon and networking supply |
OVHcloud and Scaleway compete on layers 3 and 4, because layers 1 and 2 are commoditised. That positioning explains almost every engineering decision they make — and it explains what they hire for.
OVHcloud: the vertically integrated bet
OVHcloud is not a reseller of someone else's hardware. The company designs its own servers, assembles them in its own facilities at Croix in northern France, and cools them with a direct water-cooling design it has iterated for well over a decade rather than relying on room-level air conditioning. It operates its own fibre backbone and its own points of presence. Listed on Euronext Paris since 2021 and still founder-anchored, it is one of the very few European infrastructure companies that controls its stack from the water block to the API.
This vertical integration is the entire strategic argument. It produces a cost structure that is difficult for a rebadging competitor to match, it makes the layer-4 autonomy claim credible rather than rhetorical, and it converts efficiency engineering into a durable moat: when power is the binding constraint on the industry, a company that owns its thermal design owns its unit economics.
It also produces a distinctive risk. Vertical integration means owning failure end to end. The March 2021 fire that destroyed the SBG2 datacentre in Strasbourg remains the reference case study in European cloud resilience — and the honest lesson from it is not simply "OVHcloud had a fire." It is that a material number of customers discovered they had no functioning backup outside the affected site, because they had assumed redundancy they had never purchased or tested. The engineering culture that followed — on fire compartmentalisation, on region isolation, on making backup defaults explicit — is now part of what the company sells. Candidates should read that history as a hiring signal: resilience engineering here is not a slide, it is institutional memory.
Scaleway: the developer-experience bet
Scaleway, part of the Iliad group, attacks the same market from the opposite end. Where OVHcloud's centre of gravity is physical infrastructure at scale, Scaleway's is the surface a developer touches: clean APIs, managed Kubernetes, serverless functions, object storage with S3 compatibility, and an early, deliberate push into GPU capacity for AI workloads. Its datacentre work — notably adiabatic cooling at its Paris-region facilities — is real, but the product argument is that European sovereignty should not cost you the developer ergonomics you get from a hyperscaler.
The two companies together describe the sector's actual dilemma. Sovereignty is won at layers 3 and 4, but purchasing decisions are made by engineers who compare documentation quality, provisioning latency and managed-service breadth. A sovereign cloud that is unpleasant to build on loses to a non-sovereign one that is delightful, regardless of what the policy paper says.
The demand side is changing in their favour — but not automatically
Three forces are moving procurement. First, regulation: the EU's data-protection framework, sector rules such as DORA for financial entities and NIS2 for critical sectors, and national schemes such as France's SecNumCloud qualification have made "where does this run, and who can compel access to it" a board-level question rather than an IT preference. Second, the AI build-out: sovereign AI ambitions require sovereign compute, and GPU capacity located in Europe under European control is now a scarce, strategically-priced asset. Third, cost discipline: after a decade of default hyperscaler adoption, egress fees and committed-spend agreements are being audited seriously for the first time.
None of this converts automatically. European providers remain an order of magnitude smaller than the top three hyperscalers in revenue and in managed-service catalogue depth. Sovereignty is a tiebreaker, not usually the primary purchase driver, and it becomes decisive mainly where a regulator or a public buyer makes it decisive. That is the honest commercial frame around every job in this sector.
What these companies actually hire — and what the work is
Cloud-infrastructure hiring is misread by candidates who imagine it resembles working at a software startup. It does not. The product is availability, and availability is produced by people who understand power, heat, packets and failure modes.
- Datacentre and facilities engineering. Power distribution, redundancy topology, thermal design, water-cooling loops, fire compartmentalisation, capacity planning against grid connection queues. This is the least visible and most structurally scarce skill set in the industry.
- Network engineering. BGP, peering strategy, anti-DDoS at the edge, backbone capacity planning, and increasingly the traffic engineering required by AI training clusters, whose east-west patterns look nothing like classic web workloads.
- Systems and kernel-adjacent engineering. Hypervisors, storage engines, Linux internals, performance under contention. Vertical integration means these teams write software that runs on hardware their colleagues designed.
- SRE and platform engineering. Control-plane reliability, multi-region failover, observability, incident command. In a provider, an SRE's blast radius is other people's businesses — the discipline is correspondingly harsher.
- Security and compliance engineering. Mapping SecNumCloud, ISO 27001, NIS2 and DORA obligations into concrete technical controls and evidence. This is the role where regulation becomes code, and it is the fastest-growing function of the four.
- Hardware and supply-chain engineering. Server design, component qualification, sourcing under geopolitical constraint, lifecycle and refurbishment — an area where European providers' repair-and-reuse practices are genuinely ahead.
Two career observations follow. First, the highest-leverage skill in this sector is the ability to reason about failure across layers — to know that a cooling-loop decision, a BGP policy and a storage replication setting are all the same conversation about availability. Almost nobody arrives with that; it is built by being on call in an environment that has real physical consequences. Second, compliance engineering is badly underrated by ambitious engineers. It is where sovereign providers differentiate, it is where public and financial-sector contracts are won or lost, and the supply of people who can speak both regulation and infrastructure is very thin.
What could go wrong
Scale asymmetry persists. Hyperscalers can outspend European providers on managed services indefinitely and are actively marketing their own "sovereign" offerings built on layers 1 and 2. If buyers accept that definition, the European differentiator erodes without a single technical defeat.
Capital intensity. Datacentres and GPUs consume cash before they generate it. A listed, comparatively small provider financing an AI build-out is exposed to both interest rates and demand timing.
Power and grid access. Connection queues, land, and the environmental permitting of high-density compute are now the binding constraints on datacentre expansion across Europe — a physical ceiling that no amount of software excellence removes.
Talent competition. The same network, kernel and SRE profiles are hunted by hyperscalers, financial infrastructure and AI labs, often at compensation levels a European infrastructure margin cannot casually match. Providers compete on mission, technical depth and autonomy — which works, but only with candidates who value those things.
The unit economics behind every job here
Cloud infrastructure is a leasing business dressed as software. A provider buys servers, power, space and network, then rents them by the hour at a margin. Three levers determine whether that works: utilisation, power efficiency, and the mix between raw compute and higher-margin managed services. European providers are structurally strong on the first two — owned hardware, owned cooling, owned network keep cost per served unit low — and structurally behind on the third, because managed-service breadth is a function of engineering headcount accumulated over fifteen years.
That asymmetry is the strategic problem of the sector stated numerically, and it determines hiring. Every euro spent on building a new managed database, queue or AI inference service is a bet on moving revenue mix upward. Every euro spent on datacentre and hardware engineering defends the cost advantage that funds the bet. A candidate can read a provider's roadmap as a statement about which side of that trade-off it is currently prioritising — and choose accordingly.
Sovereign GPUs are the sharpest version of the bet
AI training and inference concentrate the sector's entire thesis into one product line. GPUs are expensive, supply-constrained, power-dense and depreciate fast, so committing to them is the riskiest capital decision an infrastructure provider can make. But it is also the only place where the sovereignty argument currently commands a genuine premium: European institutions, hospitals, defence-adjacent suppliers and regulated financial entities increasingly cannot place sensitive training data on infrastructure exposed to non-EU jurisdiction. That creates demand that is not price-driven and therefore not commoditised.
Technically, this work is distinct from classical cloud engineering. High-density racks change the thermal problem, collective communication patterns change the network problem, and scheduling multi-node training jobs changes the control-plane problem. Engineers who can operate that stack — interconnect, cluster scheduling, storage throughput for training data — are among the scarcest profiles in Europe today, and the skill is transferable to every AI-adjacent employer.
How to enter, concretely
The entry path here rewards demonstrable systems literacy over credentials. Run your own infrastructure and understand it to the metal: Linux, networking beyond the tutorial layer, and at least one incident you have genuinely debugged. Learn BGP properly if you want networking. Read post-mortems — the public ones from every major provider — and be able to discuss failure domains without hand-waving. If you want the compliance track, read the actual texts of NIS2 and DORA and the SecNumCloud requirements; almost no candidate has, and the ones who have are immediately distinguishable in interview.
The larger point is that Europe's digital sovereignty debate will not be settled by declarations. It will be settled by whether a small number of providers can staff, cool, secure and price infrastructure well enough that choosing them is a good engineering decision and not only a good political one. That is an unusually clear mission for a career — and an unusually measurable one.
Five signals to watch over the next 24 months
- SecNumCloud-qualified service scope. Which services carry the qualification, not merely which provider holds one, is what public buyers can actually consume.
- Revenue mix shift. Growth in managed and platform services relative to bare compute is the single clearest measure of strategic progress.
- GPU capacity announcements with named customers. Committed capacity is a demand signal; uncommitted capacity is inventory risk.
- Hyperscaler "sovereign" packaging. If layer-1 and layer-2 offerings win regulated deals, the European differentiator is being redefined by competitors.
- Grid connection and datacentre permitting in France and the Netherlands. Power access, not demand, is the current constraint on expansion.
