The Airbus sovereign cloud decision is a per-workload placement, and the public record evidences the placement, not the proof it depends on. On July 16, 2026, Scaleway announced that Airbus had selected it as its sovereign cloud provider, and The Register reported the same day that the first 70 applications would move, out of a program of 900. Between them, those two accounts say what was chosen and, in Scaleway's telling, how the bids were assessed. They do not say what evidence the choice rests on. For a sovereignty claim, that is the part an auditor ultimately needs to be able to inspect.
This post reads that record the way this site reads any sovereignty claim: as a chain that has to be evidenced link by link. It is a worked example of arguments this site has already made, not a new one. The question is narrower. A named buyer has made a real placement decision in public, so what can an outside reader actually verify about it? The answer is less than the headlines suggest, and the gap is instructive.
From Skepticism to Selection
The Register's December 19, 2025 exclusive reported that Airbus was preparing to tender the migration of mission-critical workloads to a digitally sovereign European cloud, and that Catherine Jestin, Airbus's executive vice president of digital, put the odds of finding a suitable provider at 80/20. Her stated reason was the sensitivity, from a national and European standpoint, of part of Airbus's information, and a wish to keep it under European control. The applications in scope were described as key on-premises systems: ERP, manufacturing execution, CRM and product lifecycle management. The Register named access to new software as the driver, since vendors such as SAP are developing innovations only for the cloud. On that reporting, sovereignty did not create the move. It constrained where the move could land, which makes this a cloud strategy architecture question before it is a procurement one.
The same article carried the concern that gives the later announcement its shape. Jestin was waiting for European regulators to clarify whether Airbus could be "immune to extraterritorial laws" and, in The Register's account, whether services could be interrupted. Those are two different questions. One is about jurisdiction. The other is about continuity. Both come back in the evidence-chain section below.
Five weeks later this site cited Airbus's skepticism in The European Sovereign Cloud is a Hard Fork — Not a Region. That post treated AWS's sovereign partition as a placement decision with two zones: workloads that must move into the partition because of their data class, and workloads that should stay in standard regions. It also used Airbus's doubt about whether any US-owned cloud can offer immunity from the CLOUD Act as evidence that sovereign cloud is a compliance tool, not a magic shield. That was a decision framework for one provider's partition, and it did not name a source for the skepticism. The public statement that matches it is the December one, which predates the partition's launch and concerned extraterritorial law and US providers in general, not that partition.
On July 16 the record changed. Scaleway's press release announced that Airbus had selected it as its sovereign cloud provider after a competitive tender, and The Register reported Jestin's account: the objective is to host the applications Airbus counts as required for its minimum viable company, which is 900 applications, starting with 70 that are hosted on AWS today. December's 80/20 has resolved, for the first tranche, toward a provider being found. Whether it resolves the same way for 900 is not something either account addresses.
What Actually Moved
Start with what the record establishes, because the headline numbers travel further than the evidence does. The claims about Airbus in this post rest on three documents: The Register's two articles and Scaleway's press release. No Airbus-published statement was reviewed, so wherever this post says Airbus said something, it is through one of those three. Everything below is scoped to them.
| Item | What the record says | Status |
|---|---|---|
| Program scope | Jestin told The Register the objective is to host the applications required for Airbus's minimum viable company: 900 applications | Established, as reported |
| First tranche | 70 applications, described as hosted on AWS today | Established, as reported |
| Application classes | ERP, manufacturing execution, CRM and product lifecycle management; Scaleway's release adds aircraft design, engineering, manufacturing and enterprise operations | Established, as reported |
| Staying on AWS | Skywise and Case Management Assistant | Established, as reported |
| Other US services retained | Salesforce, Coupa and Workday, plus Microsoft and Google productivity suites | Established, as reported |
| AWS exit | Airbus says it will continue to work with AWS; no source describes an exit | Not supported |
| Hosting of the other 830 applications | Not stated. December's reporting described on-premises systems; July's says the first 70 are on AWS | Not established |
| Completion date or deadline | Not in The Register or Scaleway's release | Not established |
| Contract value and term | No award figures in either source | Not established |
| Whether AWS's sovereign partition was evaluated | Not stated; AWS declined to comment | Not established |
Read the last four rows before the first six. The record establishes a scope and a first tranche. It does not establish where the rest of the program starts from, when it finishes, what it costs or whether AWS's own sovereign partition was ever on the table. December's coverage described on-premises applications moving to the cloud. July's says the first 70 are on AWS today. Both can be true of different applications, but the record does not say which of the 900 sit where, so AWS to Scaleway is established only for the first tranche.
The status column uses three grades on purpose. Established, as reported, means a named person said it to a named outlet, or a vendor published it, and this post is repeating the statement, not confirming the underlying fact. Not supported means the record points the other way. Not established means the record is silent, and silence is the only thing that grade asserts. It does not say the fact is false or that it is being withheld. It says nobody in these three documents states it.
The statement that carries the most weight is a short one. Jestin told The Register that Airbus does not intend to move away from all non-European solutions: "we balance our choices based on the criticality of the data." That is a per-workload principle, stated by the buyer, and it is the plainest description of the Airbus sovereign cloud decision that the record contains.
This site made the general form of that argument three days after the announcement. The New Cloud Repatriation Strategy Isn't About Cost argued that organizations are layering a control requirement onto their cloud estates workload by workload, and that national cloud providers and sovereign regions are legitimate control options alongside on-premises. It had no named buyer behind it. Airbus is a named buyer stating the same principle in its own words, as The Register reports them. What Airbus adds is not the principle. It is a real placement to test the principle against.
None of this is a claim about Airbus's cost model or how the program will be closed out, and the record says nothing about either. The mechanism this site calls dependency residue concerns what a program's cost model stops counting once something is declared eliminated. Nothing has been declared eliminated here, so this post makes no claim of that kind.
What the Tender Assessed
The criteria come from Scaleway's press release. That matters: the release is Scaleway's account of the tender, not Airbus's independent publication of the evaluation record. Treat what follows as the vendor's description of how the Airbus sovereign cloud tender was assessed.
According to the release, Airbus assessed several providers across three dimensions. The first was technical capability, meaning advanced cloud services, interoperability, scalability and AI capability. The second was operational excellence, meaning security, resilience, service continuity and integration with Airbus's existing multi-cloud ecosystem. The third was legal and governance safeguards, including European jurisdiction, data protection and protection against non-European extraterritorial legislation. In the release, Jestin describes the platform as keeping critical data assets "shielded from foreign extraterritorial laws."
Three observations follow, and all three are this post's reading, not Airbus's.
First, jurisdiction is one of three assessed dimensions. The release gives no weights, thresholds or indication that any one dimension functioned as a mandatory gate. The public record therefore establishes the criterion, but not how it affected the selection decision.
Second, integration with the existing multi-cloud ecosystem was assessed as part of operational excellence. An integration criterion is a dependency question: it asks what a placed workload has to stay connected to, and what happens if that connection is the thing that fails. That is the territory of Dependency Architecture, the stage where this site classifies what an architecture depends on before migration or exit pressure forces the question. The release tells us the integration was assessed. It does not say what it integrates with or under whose control.
Third, Jestin told The Register that Scaleway is committed to involving Airbus in defining its future product roadmap. That is a sourced statement about the relationship, not about jurisdiction. Our reading is that it is a form of influence over how the platform evolves, and that none of the three dimensions, as the release describes them, captures it. Whether the commitment is contractual is not established.
The release makes further claims about the platform itself: European infrastructure, open technologies, interoperability and preserved operational control. Those describe what Scaleway says it is providing. Like the assessed dimensions, they are assertions in a press release, not attestations, and they map onto the chain's custody and continuity links only by inference.
The release also frames the arrangement in per-workload terms: by complementing its existing multi-cloud approach, Airbus can place each workload in the environment best suited to its technical, operational and regulatory requirements. That is the vendor's language, and it lines up with the buyer's.
Running the Airbus Sovereign Cloud Decision Through the Evidence Chain
This site's Sovereignty Evidence Chain, Framework #134, treats a sovereignty claim as only as valid as the weakest link in the chain of evidence behind it. The chain has four links: the jurisdictional claim, custody evidence, continuity proof and standing re-validation. Any link that cannot be evidenced is treated as absent by an auditor, a regulator or an adversary.
Two limits apply to using it here. The chain is an audit instrument, and a press release is not an audit. Running the record through it tests what an outside reader can verify, not what sits in Airbus's own assurance file. And public silence is not evidence of absence: procurement files, contract terms and assessments exist that this post cannot see. Nothing below says Airbus's chain is weak. It says what the announcement lets anyone confirm.
| Link | What the public record shows | Status |
|---|---|---|
| Jurisdictional claim | Legal and governance safeguards, including protection against non-European extraterritorial legislation, were one of three assessed dimensions (Scaleway's release); the stated aim is shielding critical data from foreign extraterritorial laws | Criterion stated; evidence not public |
| Custody evidence | Nothing on who holds the encryption keys, or whether the provider could decrypt without Airbus | Not established |
| Continuity proof | Resilience and service continuity were assessed (Scaleway's release), and December's reporting relayed Airbus's concern about service interruption; nothing describes how continuity was proven | Criterion stated; proof not established |
| Standing re-validation | Nothing on how sovereignty is re-verified as the provider's ownership, subcontractors and technology stack change over the contract | Not established |
Neither source says whether the assessment used a published assurance scale, such as the Commission's SEAL levels that the Sovereignty Evidence Chain post covers. Without a scale, protection against non-European extraterritorial legislation is a stated property, not a comparable score.
For an outside reader, a row moves from not established to established only when a document does the work: a published assurance level, an independent attestation of key custody, a continuity test result, a re-validation clause. None of that is a claim about what exists here. It is a description of what would count, and of why a press release cannot be the document.
The public record also does not show whether Airbus evaluated these four links once at the provider level, per workload, or through some combination of both. That matters because the announcement establishes a per-workload placement decision without publishing the evidence structure behind it.
The record does establish a retained estate. The Register reports that Skywise and Case Management Assistant will continue to be hosted by AWS, and Jestin told it that Airbus will still use Salesforce, Coupa and Workday. Scaleway's release describes the new platform as fully integrated into Airbus's existing technology ecosystem. Because Scaleway, AWS and retained SaaS providers all remain in that estate, a multi-provider seam exists by construction, and it is not new for Airbus: December's article already described an estate with a consolidated datacenter footprint and Google Workspace, and July's adds Microsoft's productivity suite. The seam is where the chain's third link stops being abstract, since continuity asks whether a service keeps running under the same governance terms if an upstream party stops serving it. The record does not say what the first 70 applications depend on that stays behind, which of them cross the seam, or how continuity was proven across it, and this post will not guess. Who holds authority across that seam is not established in the public record either.
That is the practical takeaway for anyone using the Airbus sovereign cloud announcement as a precedent. The announcement is a decision. The chain is a separate body of work, and it does not appear in the press release.
Architect's Verdict
The Airbus sovereign cloud announcement is not an AWS exit. On the public record it is a per-workload placement: 70 applications first, 900 in scope, named platforms and SaaS staying where they are, and one stated principle, which is to balance choices by the criticality of the data.
The real problem is what is missing from the record. What has been published is a decision and, in the vendor's telling, a set of criteria. The proof is a separate artifact, and none of the sources reviewed describes it. For an outside reader, and for any architect copying the pattern, the decision is the cheap part. That is not a criticism of Airbus. Announcements announce decisions, and the error is reading one as evidence for the chain. Every placed workload therefore raises questions the announcement does not answer, about custody and continuity in particular, and every dependency it keeps raises a seam question nobody has published.
Borrow the decision structure: place by criticality, assess jurisdiction and integration together, keep what should stay. Do not borrow the assurance. The announcement does not say the chain holds. It says jurisdiction and continuity were among the criteria.
The decision is public. The proof is a different artifact, and it is the one that has to be inspectable.
Additional Resources
- Cloud Strategy Architecture — the pillar covering placement, governance and dependency decisions across cloud estates, including the jurisdictional constraints this post examines.
- Dependency Architecture — the Learning Path stage on classifying what an architecture depends on, the lens for the integration criterion in Scaleway's account of the tender.
- Sovereignty Without Evidence Is Just Marketing — Framework #134, the four-link Sovereignty Evidence Chain this post applies to the public record.
- The European Sovereign Cloud is a Hard Fork — Not a Region — the January placement framework for AWS's sovereign partition, and the Airbus reference this post follows up.
- The New Cloud Repatriation Strategy Isn't About Cost — the general argument that control is layered onto cloud estates workload by workload, published without a named buyer behind it.
- Multi-Cloud Coherence Is an Ownership Problem, Not a Technology Problem — the ownership question at the seam between clouds, the question the public record leaves open for Airbus.
- Dependency Residue: The Most Expensive Dependency Is the One You Think Is Gone — the cost-model mechanism this post explicitly does not claim, since nothing here has been declared eliminated.
- Airbus migrating 70 critical apps from AWS to France's Scaleway — The Register, Jul 16, 2026 — primary reporting on scope, retained platforms and Jestin's placement principle.
- Airbus to migrate critical apps to a sovereign Euro cloud — The Register, Dec 19, 2025 — the tender-stage exclusive: on-premises scope, the 80/20 odds and the continuity concern.
- Scaleway secures European "Trusted Cloud" services contract with Airbus — the vendor's announcement and the source for the three assessed dimensions; a vendor's account, not Airbus's own record.
Originally published at rack2cloud.com





Top comments (0)