In February 2026, at the International Criminal Court (ICC) in The Hague, a prosecutor found one morning that she could no longer open her work email. Chief Prosecutor Karim Khan had become a target of sanctions under the Trump administration, and Microsoft, complying with an executive order, suspended his account. For the first time, this became a concrete demonstration that even officials of allied nations' public institutions could be locked out overnight from services run by American companies.
A year and a half has passed since that incident. European business leaders are beginning to think, "This could happen to us too." But fearing something and preparing for it are two different matters.
Cloud Adoption Created a "Central Switch"
The structure by which European companies depend on American technology was built gradually over the past two decades. Everyday business software—email, document creation—came to be handled by Microsoft and Google, and data storage shifted to the cloud. According to research by Synergy Research Group, the share held by local providers in Europe's cloud infrastructure market has fallen from 29% in 2017 to just 15%, with Amazon, Microsoft, and Google together accounting for roughly 70%. Even SAP and Deutsche Telekom, among the largest local players in Europe, each hold only about 2%.
This shift was driven by economic rationality. Renting only what you need is cheaper, faster, and more scalable than procuring your own servers and maintaining staff to run them. Each individual company's decision was rational on its own, and the cumulative effect of these decisions produced a single overarching structure. The three major US companies continue to pour roughly €10 billion each quarter into European capital investment, and the gap in capital strength keeps widening.
In the on-premises era, servers sat inside a company's own building, and it wasn't easy for an outsider to physically pull the plug. The shift to the cloud changed this structure. Whether access is granted or denied now comes down to a single switch on the provider's administrative dashboard. Moreover, even when a service is run by a US company out of a European data center, the parent company remains under the jurisdiction of US law. Whether the data physically resides in Frankfurt or Paris, legal control crosses the Atlantic. A separate survey conducted by Proton found that more than 74% of publicly listed European companies depend on US-based technology services.
As dependency deepens, US politics has begun showing signs of using this dependency as a diplomatic tool. In June 2026, the US government issued an export control directive restricting access to some of Anthropic's AI models for non-US nationals. The fact that AI models were treated as subject to export controls suggests that the scope of potential cutoffs could extend beyond email and cloud services. What was once a hypothetical "kill switch" is gradually becoming an actual policy instrument.
The Gap Between Fear and Preparedness, in Numbers
Proton's survey was conducted between July 15 and 24, 2026, targeting executives and IT decision-makers at 500 companies each in the UK, France, and Germany—1,500 companies in total. Respondents were limited to individuals involved in decisions about their company's technology and business continuity. In other words, this survey measures the perceptions of those holding budgets and responsibility, not the anxieties of frontline staff.
The core findings are as follows. 73.9% said they were concerned about the possibility that the US government might cut off access to US technology providers. Only about one in twenty companies (roughly 5%) said they had no concern at all. If they were to completely lose cloud and digital services, 54.5% said they would be forced to halt operations within one business day. Among large enterprises, 28.7% estimated losses from a single day's shutdown would exceed €100,000 (about $115,000), and 45% estimated losses would exceed €50,000.
There is a wide gap between fear and preparedness. Only 44% of companies have a documented business continuity plan that is regularly tested. 36% have a plan but haven't tested it, and 13% have only something informal. Even if a plan exists, without rehearsal there's no way to know whether it will actually function during a real cutoff. An evacuation route on paper and an evacuation route that works on the night of an actual fire are two different things. Only 34% of companies had prepared a backup for email—arguably their most critical piece of infrastructure.
| Metric | Percentage/Amount |
|---|---|
| Companies concerned about a kill switch | 73.9% |
| Would shut down within one business day of total access loss | 54.5% |
| Large enterprises estimating over €100,000 in losses per day | 28.7% |
| Have a regularly tested continuity plan | 44% |
| Have prepared an email backup | 34% |
| Intend to switch providers after a government-imposed cutoff | 67.8% |
What stands out is that this concern is no longer hypothetical. Every single responding company had experienced at least one outage, cyberattack, or loss of service access within the past 12 months. In other words, respondents are answering based on the memory of actual disruptions they've experienced, not imagined disasters. Proton's Chief Operating Officer Raphaël Auphan states, "The kill switch is no longer an abstract geopolitical concern—it's a business continuity crisis." "Geopolitical risk related to digital dependency is no longer boardroom abstraction. It's joining the same ledger of threats as criminal attacks, with the same urgency and the same premonition that it could materialize without warning."
The implication of this statement is significant. Preparedness for cyberattacks has been budgeted for at many companies, and insurance has been established. For geopolitical cutoffs, there is neither an established insurance market nor established countermeasure standards. Behind these figures lies a situation in which awareness of the threat has outpaced the tools available to address it.
Searching for an Escape Route, Only to Find the Exit Itself Was American-Made
Even if a company tries to migrate from a US provider to a European or Swiss alternative, a structural barrier awaits. As an analysis reported by The Register in May 2026 shows, the IAM (Identity and Access Management) layer—which handles authentication and access control—is almost entirely dominated by US vendors. As the analysis cited in The Register's article puts it, "the infrastructure layer that authenticates every user and authorizes every access decision is, in most cases, operated by vendors incorporated in and subject to the laws of the United States." Even if a company replaces its email and storage with European products, as long as the layer holding the keys to the front door remains under US legal jurisdiction, the risk of cutoff cannot be eliminated.
The reason IAM goes unnoticed is that when it's functioning correctly, it doesn't register in anyone's mind. It's the layer that lets employees log in each morning and confirms they can access only the applications they need—normally, a mere behind-the-scenes presence. But when a cutoff occurs, this is the layer that stops first. No matter how many domestic applications a company adopts, if login itself becomes impossible, none of it can be used.
This problem has also been discussed in policy circles. At the Open Source Policy Summit held in Brussels in February 2026, the fact that European government agencies themselves run on Microsoft was raised, with open-source-based self-sufficiency proposed as a solution. Germany's Open-Source Business Alliance, responding to the ICC incident, has warned that "we cannot depend on companies not under our own jurisdiction." Given that governments themselves are dependent users, there is also a self-referential difficulty underlying the discussion: it's not easy to sever dependency through regulation or procurement rules when the regulator itself is dependent.
| Layer | Dominant Providers | State of European/Alternative Players |
|---|---|---|
| Cloud infrastructure | Amazon, Microsoft, Google: ~70% combined | Local players total 15% (down from 29% in 2017) |
| Productivity & email | Microsoft, Google | Proton and others offer business continuity products |
| Authentication & access management (IAM) | Almost entirely dominated by US vendors | Little substantive alternative exists |
It's worth noting that Proton itself sells a business continuity platform that provides email, meetings, and productivity tools on European infrastructure, and thus this survey carries a commercial motive. A survey conducted by a vendor to gauge the market for its own products may be designed in ways that emphasize anxiety. Even so, the survey's own design—an even split across three countries, with respondent attributes disclosed—offers a certain degree of reliability as material for discerning overall trends. This is a survey that should be read less for its absolute figures than for the structural gap it reveals between concern and preparedness.
Questions That Remain
What the survey illuminates is an asymmetry between the breadth of fear and the shallowness of preparedness, but several questions remain open. First, while 67.8% said they would switch providers if cut off, migrating data may become impossible after the cutoff has already occurred. Once an account is suspended, you can't even access the admin dashboard needed to export your data. This survey does not measure how much of this post-cutoff intent to switch translates into actual pre-emptive migration planning.
Second, the survey was limited to three countries—the UK, France, and Germany—and it remains unverified whether the same level of awareness holds among small and medium-sized businesses in southern or eastern Europe. Large enterprises have the staff and budget to consider migration options, but for many small and medium-sized businesses, simply maintaining their existing services already stretches their capacity to the limit. This gap in awareness could translate directly into a gap in preparedness, and in turn into a gap in damage suffered during an actual crisis.
Third, there is the question of how to rebuild, as a Europe-wide industrial policy rather than through individual company efforts, areas like the IAM layer where no market alternative currently exists. Against the three major US companies pouring roughly €10 billion each quarter into European capital investment, there is currently no visible path for local players to reclaim market share—as Synergy Research's own analysts acknowledge. Changing procurement standards, public investment in open source, jointly building shared authentication infrastructure: options can be listed, but all of them are matters measured in years. Given that most companies have only a single business day of grace, the speed of preparedness is what will be tested from here on.
