Technology
Hyperscale cloud infrastructure
Hyperscale cloud infrastructure provides compute, storage, databases, identity, networking and managed software across large provider estates. Concentration, proprietary services and switching costs can create strategic dependencies. States act through law, sanctions, export controls, procurement and supervision, while providers retain technical and contractual authority. Provider nationality does not give a state automatic customer-data access or unlimited termination power.
Function and control points
The National Institute of Standards and Technology defines cloud computing through on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service. Infrastructure, platform and software service models differ in legal scope, provider visibility and migration difficulty.
Control is distributed across accounts, identity, encryption keys, regions, networks, managed services, licences, data and contract rights. A customer can control an encryption key while depending on provider identity, storage or networking. A provider can suspend an account without holding application credentials. A software vendor can withdraw a subscription even when the infrastructure provider does nothing.
Cloud services can improve resilience through geographic redundancy, managed security and rapid recovery. They can also create correlated exposure. The US Treasury's 2023 financial-sector report found concentration around a limited number of providers, unequal contract negotiation, visibility gaps and practical migration constraints. It also stressed that data limitations prevented a full assessment of sector-wide concentration. The Bank for International Settlements similarly warns that disruption at a provider supporting many critical services could have systemic effects.
Statecraft pathways
There are 3 separate statecraft pathways. First, a state can compel a provider subject to its jurisdiction to produce specified data through lawful process. Second, sanctions or export controls can prohibit a defined service to a named person, sector or jurisdiction. Third, a provider can act under its own contract or policy. A single event can involve more than 1 pathway, but none should be inferred from another.
The US CLOUD Act clarifies that a provider subject to US jurisdiction can be required through valid process to produce data within its possession, custody or control regardless of storage location. It also provides for bilateral agreements governing qualifying orders. The Act did not create automatic government visibility, remove the need for legal authority or establish that a provider controls every stored item.
The US Treasury's June 2024 determination under Executive Order 14071 provides a bounded sanctions example. It prohibits the export, re-export, sale or supply by US persons of IT consultancy and design services, and of IT support or cloud-based services for specified enterprise-management and design-and-manufacturing software, to persons located in Russia, subject to stated exceptions. Office of Foreign Assets Control FAQ 1186 identifies covered categories such as enterprise resource planning, customer relationship management, business intelligence and computer-aided design software. The determination does not terminate every cloud service in Russia.
The provider remains a regulated intermediary. A sanctions authority defines legal scope; the provider interprets and implements the rule across products and accounts; software vendors and resellers can form additional layers; the customer holds data and workloads; supervisors oversee critical outsourcing and operational risk. A commercial suspension must not be described as a government order without evidence of the authority that required it.
Concentration, autonomy and resilience
Concentration can create leverage without producing automatic state control. Farrell and Newman's chokepoint and panopticon concepts explain how network centrality can support denial or information advantages. Applying that framework to cloud requires evidence of the actual topology, jurisdiction and control rights. A market-share figure must define the service layer, geography, period and metric.
European policy addresses the same dependency through resilience and switching rules. The Digital Operational Resilience Act creates a framework for financial-sector operational risk, incident management and oversight of critical third-party providers. The EU Data Act, which applied from 12 September 2025, includes cloud-switching and interoperability provisions. A legal right to switch does not prove that a complex workload can migrate within an operationally useful period.
Multi-cloud and sovereign-cloud strategies can reduce some dependencies while adding others. Workloads built around proprietary databases, identity systems, networking, data gravity or scarce skills can remain difficult to move. Localisation can change jurisdictional exposure without eliminating foreign software, hardware or corporate control. Resilience claims therefore require tested recovery times, data transfer, identity rebuild, substitute capacity and operating cost.
Effects and limits
Cloud denial can disrupt operations, but its effect depends on the service layer, customer architecture, backups, substitute providers and migration time. Lawful access can produce specified evidence, but it does not establish continuous surveillance. An outage can reveal vulnerability without constituting statecraft. Concentration is strategically relevant because it creates common dependencies and bargaining asymmetry, not because every provider decision is a government weapon.
This record belongs in the main sequence because lawful process, sanctions restrictions and critical-provider regulation create documented state transmission mechanisms. The intensity and intent of a particular episode remain contested. Every case must identify the authority, covered service, provider, customer location, exemption, effective date and actual action.
See also
Data as strategic resource and cross-border data flows · Panopticon effect · Chokepoint effect · Weaponised interdependence · Compute clusters and AI datacentres (sovereign AI compute) · Data-localisation and cross-border-data restriction · Sanctions-compliance and RegTech automation · Operational resilience
Sources
- Peter Mell and Timothy Grance, National Institute of Standards and Technology, The NIST Definition of Cloud Computing, Special Publication 800-145, September 2011. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf
- US Department of the Treasury, The Financial Services Sector's Adoption of Cloud Services, February 2023. https://home.treasury.gov/system/files/136/Treasury-Cloud-Report.pdf
- Ting Yang Koh and Jermy Prenio, Managing cloud risk: some considerations for the oversight of critical cloud service providers in the financial sector, FSI Insights No. 53, Bank for International Settlements, 16 November 2023. https://www.bis.org/fsi/publ/insights53.htm
- Basel Committee on Banking Supervision, Principles for the sound management of third-party risk, 10 December 2025. https://www.bis.org/bcbs/publ/d605.htm
- European Union, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32022R2554
- European Commission, 'Data Act explained', current following application from 12 September 2025. https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained
- US Department of the Treasury, Office of Foreign Assets Control, Prohibition on Certain Information Technology and Software Services, determination under Executive Order 14071, 12 June 2024. https://ofac.treasury.gov/media/932951/download?inline=
- US Department of the Treasury, Office of Foreign Assets Control, 'FAQ 1186', current guidance on covered IT support and cloud-based services. https://ofac.treasury.gov/faqs/1186
- US Department of Justice, Promoting Public Safety, Privacy, and the Rule of Law Around the World: The Purpose and Impact of the CLOUD Act (2019). https://www.justice.gov/d9/press-releases/attachments/2019/04/10/department_of_justice_cloud_act_white_paper_2019_04_10_final_0.pdf
- Henry Farrell and Abraham L. Newman, 'Weaponized Interdependence: How Global Economic Networks Shape State Coercion', International Security 44, no. 1 (2019): 42-79. https://doi.org/10.1162/isec_a_00351
- European Banking Authority, Risk Assessment Report, June 2026. https://www.eba.europa.eu/publications-and-media/publications/risk-assessment-report-june-2026
Recommended citation
Cite this entry
Tennant, James J., ed. 'Hyperscale cloud infrastructure.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/cloud-computing-infrastructure-hyperscale-providers/.
Suggest an edit