Compliance Theatre: Why NIS2, DORA and the AI Act Are Quietly Incompatible With the Hyperscaler Stack

Article originally published on LinkedIn
View original article on LinkedInThree regulations, one uncomfortable conclusion: if you are an essential entity in Europe, the cloud architecture you bought between 2018 and 2024 is no longer the cloud architecture the law expects you to operate.
Three regulations, one architecture problem
Read NIS2, DORA, and the AI Act side by side and a pattern emerges that is not visible when you read them in isolation.
NIS2, Directive (EU) 2022/2555, transposition deadline October 2024, (already missed by most member states, now being aggressively enforced from 2025 onward) expands the scope of essential and important entities to roughly 160,000 organizations across the Union. These could be banks, insurers, energy, health service companies. It imposes personal liability on management bodies for cybersecurity failures, requires 24-hour incident notification, and — critically — demands supply chain security with explicit attention to ICT service providers. The text does not say "you must leave the hyperscalers". It says you must be able to demonstrate that your dependencies do not introduce systemic risk. Those are different sentences with the same operational consequence.
DORA. Regulation (EU) 2022/2554, in force since 17 January 2025, goes further for the financial sector. It introduces a formal oversight regime for "critical ICT third-party service providers", like AWS, Microsoft, Google, IBM and Oracle, under direct supervision by the European Supervisory Authorities. It mandates exit strategies, concentration risk management, and the right of competent authorities to inspect provider premises. The Commission and the ESAs have been explicit: a financial entity that cannot credibly exit a critical provider within a defined timeframe is not DORA-compliant, regardless of what its contracts say.
The AI Act Regulation (EU) 2024/1689, phased application 2025-2027, layers a third constraint. High-risk AI systems, which include most use cases in credit scoring, insurance underwriting, healthcare triage, employment, education, critical infrastructure, and law enforcement, must maintain detailed technical documentation, logging, human oversight, and post-market monitoring. The data governance requirements (Article 10) effectively require knowing where training and inference data lives, who processes it, and under which jurisdiction.
Each regulation, read alone, is survivable on a hyperscaler architecture. Read together, they describe an operating model that the dominant European cloud architecture of the last decade was simply not designed to deliver.
What Compliance actually requires now
Strip away the legal language and the practical requirements converge on five operational capabilities:
- Demonstrable data residency: the data, the keys, the logs, the backups, the metadata, and the operational access paths are all within EU jurisdiction and under EU-controlled entities.
- Verifiable exit: the ability to migrate critical workloads off a given provider within months, not years, with the migration tested rather than theorized.
- Concentration risk control: no single provider holding a position from which its failure or geopolitical unavailability would compromise the institution’s essential functions.
- Sovereign auditability: competent authorities able to inspect, in practice, the systems processing regulated data, including the personnel and physical sites involved.
- Documented data lineage for AI: for high-risk systems, a chain of custody from training data to deployed model to inference logs that survives a regulator’s third question.
Now ask honestly: how many European essential entities meet all five, today, on their current architecture?
The CLOUD Act problem nobody wants to litigate
Underneath all three regulations sits an unresolved jurisdictional conflict that the European Commission has documented but not solved: the U.S. CLOUD Act of 2018 grants U.S. authorities the right to compel U.S.-headquartered providers to produce data regardless of where that data is stored. The EU Sovereign Cloud offerings from the major hyperscalers are contractual and operational mitigations of this conflict. They are not a resolution of it.
The European Data Protection Board has said this explicitly. The CJEU said it in Schrems II. National data protection authorities — the CNIL in France, the BfDI in Germany, the Garante in Italy — have said it in successive opinions. The compliance industry has responded by producing ever more elaborate Transfer Impact Assessments, Standard Contractual Clauses, and Binding Corporate Rules.
These instruments are useful. They are not a substitute for infrastructure that is, in fact, outside the reach of the conflict.
What the architecture actually has to look like
The conclusion that European essential entities are reaching slowly, reluctantly, under pressure from regulators and boards rather than from CIOs, is that compliance with NIS2 + DORA + AI Act in 2026 and beyond requires a hybrid architecture in which:
- Regulated workloads run on EU-operated, EU-owned infrastructure under EU law, with keys, logs, and operational control held by EU entities.
- Non-regulated workloads can continue to use hyperscaler capacity, optimized for cost and elasticity.
- The boundary between the two is documented, technically enforced, and auditable.
This is not anti-cloud. It is anti-monoculture. It is the same architectural principle every other regulated industry has eventually adopted: critical functions on infrastructure you control, commodity functions on infrastructure you rent.
What has been missing in Europe is the supply side. You cannot tell a Spanish bank to move its core risk-modelling workloads to sovereign infrastructure if no such infrastructure exists with the capacity, latency, and AI-readiness the workload requires.
That gap is what BtMData is building against. The Edge Pod 100 program for distributed sovereign capacity, and the partnerships we are convening at the Data Defense Summit in Barcelona are all responses to the same underlying observation: the regulations have already decided what European AI infrastructure needs to look like. The market is now catching up.
The next eighteen months
Enforcement of NIS2 is accelerating. DORA’s first full supervisory cycle is underway. The AI Act’s high-risk obligations land in August 2026. By mid-2027, every essential entity in Europe will have had at least one substantive conversation with a regulator about its ICT supply chain.
The institutions that prepare now, by mapping which workloads are regulated, which are not, and what a credible sovereign architecture for the regulated portion looks like, will treat that conversation as a routine review.
Related Articles

The Trillion-Dollar Illusion: Why Data Centers Aren't the Next Renewables
The AI revolution has inverted the asset class. We are no longer building real estate; we are building rapidly depreciating industrial machinery inside a concrete box.

Oracle's $300B Bet — Why AI Infrastructure Revenues May Be More Solid Than Critics Think
Oracle's $300B deal with OpenAI and the rise of multi-billion-dollar inference contracts are anchoring AI infrastructure revenue models, countering the bubble narrative.

Are We Building the Next Bubble in Data Infrastructure?
AI capex is reshaping economies, but is construction running ahead of sustainable revenue? An analysis of the $800B gap between infrastructure investment and revenue generation.
