← Back to Home
Digital Sovereignty · Part 1 of 3

The Kill SwitchHow one email cancellation exposed Europe's digital dependency

On a January morning in 2026, ICC prosecutor Karim Khan opened his laptop to find that his Microsoft email had been cancelled. Not hacked. Not breached. Cancelled. The Trump administration had sanctioned him, and Microsoft complied within hours, cutting off the chief prosecutor of the International Criminal Court from his own work communications. A man investigating war crimes could no longer send email because a company in Redmond, Washington received a directive from a government in Washington, D.C. This single act exposed how deeply Europe depends on American tech for its most basic government operations.

01
The morning it happened
January 2026: Washington flips the switch
The ICC incident

The Trump administration sanctioned ICC prosecutor Karim Khan in January 2026. Microsoft cancelled his email access. There was no hack, no data breach, no security incident. It was a policy decision made in Washington that instantly cut off a foreign official's communications. The prosecutor investigating war crimes lost his work email because a US company was told to comply with US sanctions. The ICC, based in The Hague and serving 124 member states, had built its communications on Microsoft's infrastructure. That infrastructure turned out to have an off switch controlled from another continent.

Why this was different

Governments have always known about surveillance risks. Edward Snowden made that clear in 2013 when he revealed the scope of NSA monitoring. But the ICC incident was not surveillance. It was a kill switch. Microsoft did not read Khan's emails. They deleted his ability to send them. It proved something that had been theoretical until that morning: US companies can unilaterally cut off service to anyone, anywhere, based on US government directives, regardless of where that person is located or what international body they serve. Surveillance is passive. This was active denial of service, carried out not by hackers but by a vendor following orders.

02
The dependency nobody measured
How deep does it go?
French Data
70%

70% of French data sits on American cloud infrastructure. AWS, Azure, Google Cloud. Government pandemic loan applications for 530,000 companies ran through AWS. Health records for 67 million French citizens are stored on Microsoft Azure. EDF's nuclear facility maintenance records live on Amazon's servers. The most sensitive data a nation produces, from its citizens' medical histories to the maintenance logs of its nuclear reactors, is hosted by companies headquartered in Seattle and Mountain View.

European Infra
80%

80% of Europe's digital infrastructure relies on non-European providers. Operating systems, cloud platforms, identity providers, business software. Nearly all of it routes through Silicon Valley. When a French civil servant logs into their workstation, they boot Windows, authenticate through Azure Active Directory, open Outlook, join a Teams call, and save files to OneDrive. Every step in that workflow is controlled by a single American company.

German Businesses
95%

95% of German businesses say they could not survive two years without US digital services, according to a Bitkom industry survey. France's numbers are not public but are likely similar. German manufacturers run their supply chains on SAP but host it on AWS. Hospitals schedule surgeries through American SaaS platforms. Law firms store case files on Dropbox. The dependency is not just deep. It is existential, woven into every layer of how European economies actually function day to day.

The full stack of dependency

It is not just cloud storage. European governments depend on American companies for operating systems (Windows, macOS, iOS, Android), chips (Intel, AMD, Nvidia, Qualcomm), identity providers (GitHub, Google, Apple logins), business software (Office, Dropbox, Oracle), and communication platforms (Teams, Zoom, Slack). Each layer depends on the one below it. Replacing cloud storage does nothing if the operating system underneath still phones home to Redmond. Replacing the OS does nothing if the processor inside the machine was designed in Santa Clara. The dependency is a full stack problem, and pulling out one layer only exposes the next.

03
The legal weapon
The CLOUD Act and extraterritorial reach
What the CLOUD Act does

The US CLOUD Act of 2018 allows American authorities to compel US companies to hand over data regardless of where that data is physically stored. A French government ministry using Azure might have its data sitting in a data center in Frankfurt or Paris, but Microsoft is still a US company subject to US law. The physical location of the server is irrelevant. If the US government issues a warrant or a national security letter, Microsoft is legally obligated to comply, even if doing so violates EU data protection law. The CLOUD Act effectively means that any data stored with a US company is US-accessible data, no matter which country's soil the server sits on.

Microsoft's own admission

In a French Senate hearing, Microsoft France's president admitted the company could not guarantee that customer data would never be transferred to US authorities. This was not a leak. It was not a whistleblower. It was Microsoft's own executive, testifying under oath before a legislative body, stating plainly that the legal framework makes absolute data protection impossible. When pressed on whether French government data stored on Azure in Europe could be shielded from American law enforcement, the answer was no. The company that hosts health records for every French citizen publicly acknowledged it cannot promise those records stay out of Washington's reach.

04
The triggers kept coming
A cascade of wake-up calls
A timeline of escalation
Snowden
In 2013, NSA surveillance revelations triggered years of disputes between Washington and Brussels over transatlantic data transfers. The fallout led directly to the creation of GDPR and the invalidation of two successive US-EU data transfer agreements by the European Court of Justice. Europe learned its data was being read. It took a decade to respond with regulation.
Greenland
In 2025, the Trump administration's public posturing toward acquiring Greenland intensified fears across European capitals that Silicon Valley could be compelled to cut off European access to digital services as geopolitical leverage. If Washington was willing to pressure a NATO ally over territory, what would it do with the kill switches it already controlled?
Starlink
Ukraine's military communications depend on Elon Musk's Starlink satellite network. A single American billionaire controls critical wartime infrastructure for a European ally fighting a land war. Musk has publicly discussed limiting Starlink access in conflict zones based on his personal judgment. European defense officials watched a private citizen make battlefield decisions that affected their security interests.
Virkkunen
European Commissioner for Tech Sovereignty Henna Virkkunen publicly stated that Europe's reliance on US tech infrastructure can be weaponized. The fact that the EU created a commissioner portfolio specifically titled "Tech Sovereignty" tells you how far the conversation has moved from academic concern to institutional priority.
05
The numbers that changed everything
What's at stake
France's exposure

France controls only 2.4% of the global digital infrastructure market, valued at roughly $5 trillion. This is a country that builds its own fighter jets, designs its own nuclear submarines, launches its own satellites, and maintains an independent nuclear deterrent. France has spent decades and billions ensuring it never depends on another nation for its defense. Then it outsourced something arguably more critical than any single weapons system: the digital infrastructure that runs its government, its hospitals, its energy grid, and its economy. The disconnect between France's defense sovereignty and its digital dependency became impossible to ignore.

The political shift

This is no longer abstract policy debated in think tanks and academic conferences. After the ICC incident and the return of the Trump administration, the debate shifted from theoretical to existential across European capitals. European Commissioner Virkkunen created a new portfolio specifically for Tech Sovereignty. The word sovereignty moved from white papers to ministerial titles. France's digital minister began referencing the ICC email shutdown in press conferences. Germany's interior ministry opened a review of federal IT contracts with American vendors. The political class caught up to what technologists had been warning about for years: digital dependency is a national security problem.

Next in series
France decided to build its way out.

In Part 2, we look at La Suite Numérique — the open-source productivity stack that France built to replace Teams, Zoom, and Google. It is already live with 500,000 users across 15 ministries. And it is MIT-licensed.

Part 1: The Kill Switch (you are here) Part 2: La Suite Part 3: The Ghost of Cloudwatt