What an Aircraft Maker in France Taught Every Australian Business About Its Data

A few days ago, one of the largest aerospace companies in the world quietly started moving house.
Airbus is taking 70 of its most critical applications off Amazon Web Services and handing them to a French provider called Scaleway. These are not the customer-facing apps or the analytics platforms it uses to sell services, but the systems at the heart of the business: enterprise resource planning (ERP), manufacturing execution, customer records, and the product lifecycle systems that hold the design DNA of its aircraft. The company has told the press this is only the first tranche of roughly 900 applications it eventually wants kept, in its own words, under European control.
The reason it gave is worth sitting with for a moment, because it has nothing to do with price or performance. Airbus decided that data touching its most sensitive operations should not sit anywhere a foreign government could reach into it, and it concluded that on AWS, however well run, that guarantee simply did not exist.
The sentence that changed the conversation
To understand why a company would take on the cost and disruption of moving 900 applications, it helps to go back to a hearing room in Paris last year.
A Microsoft executive was giving sworn testimony to a French Senate inquiry into digital sovereignty when a senator asked him a direct question: could he guarantee that French citizens’ data held by Microsoft would never be handed to the United States government without French consent? His answer, under oath, was “No, I can’t guarantee it,” though he added that such a scenario had never happened before.
The honesty is almost disarming, because he was not describing a flaw in Microsoft’s engineering or a gap in its security. He was describing the law. Under the US CLOUD Act, passed in 2018, American authorities can compel a US-headquartered company to produce data it controls regardless of which country that data physically sits in. Where a provider is headquartered decides which government’s laws can compel it, which means a company with an American parent can be required, through US legal process, to produce data its Australian arm holds even when that data never leaves Sydney. The United States and Australia have since signed a CLOUD Act agreement that adds independent judicial review and bars either government from deliberately targeting the other’s citizens and companies, so this is a framework with real limits rather than an open door. What it does not remove is the underlying point that the jurisdiction governing your provider is a design choice, and most cloud conversations never get to it.
Where your data lives is not the same as who can reach it
For years, “we store your data in Australia” has been treated as the end of the sovereignty question, when it is closer to the beginning. If jurisdiction is the thing that decides who can compel your provider, then where the data sits matters far less than who is allowed to reach for it.
Data residency is a statement about geography, telling you little more than the postcode of the disk, whereas data sovereignty is a statement about control, telling you whose laws govern the data, who can be compelled to hand it over, and whether a foreign court order can travel through a parent company to reach information sitting on Australian soil. A hyperscaler can run a pristine data centre in Sydney and still, if its head office is in Seattle, be legally obliged to respond to a US warrant. The data never moved, but the reach did.
This gap has quietly become a CIO-level problem in Australia, and the research bears it out. ADAPT’s 2025 CIO Edge Survey found that 78% of Australian CIOs now rank regulatory compliance and data sovereignty among their top three board concerns. This stat marks the point at which sovereignty became a strategic risk that directors ask about by name.

The news reflects the growing need for sovereign cloud solutions globally
Why this landed in Australia at the same time it landed in Europe
It would be comfortable to file the Airbus decision under European politics and move on, except the timing makes that difficult.
On 1 July 2026, the Australian Government’s Whole-of-Government Cloud Computing Policy came into effect, setting cloud as the default posture for agencies modernising their infrastructure and tightening expectations around how sensitive information is hosted. Sitting underneath it, the Hosting Certification Framework already requires sensitive government data and systems classified PROTECTED to run in certified, sovereign-controlled facilities, which means the bar for public sector data is now explicit and written down.
The private sector rarely stays on the other side of that line for long. When the Privacy Act penalty regime was strengthened, the maximum exposure for a serious breach climbed to A$50 million, and procurement teams in banking, health and critical infrastructure began mirroring government hosting expectations in their own contracts whether or not the law strictly required it. A financial services firm running core banking cannot dismiss the possibility of a foreign authority accessing customer records, and a health provider holding patient histories cannot accept that a support engineer offshore might route metadata across a border during a routine ticket. The question stops being theory the moment an auditor asks it.
What the Airbus move signals
The instinct, reading a story like this, is to assume it is about distrust of American companies, and it is not. Airbus was careful to say so, keeping Salesforce, Workday and Coupa, and continuing to run Microsoft and Google productivity tools. Its head of digital framed the decision around a single idea, which was to match the criticality of the data to the sovereignty of where it sits.
That is a far more useful lesson than “move everything home,” because most organisations do not need to. A marketing website, a public knowledge base, or a general workload with no sensitive payload can happily live on a hyperscaler and benefit from the scale. The discipline lies in knowing which of your systems hold the data that would cause real harm if it were reached, and treating those differently. Airbus drew a line between the applications its business could not survive without and everything else, then moved the first group somewhere the reach of a foreign law could not follow. Every Australian organisation holding regulated, sensitive or nationally significant data has the same line to draw, and most have simply never been asked to draw it.
How RackCorp is different
RackCorp was built sovereign by design. We are an Australian company operating Australian infrastructure, which means your data is governed by Australian law and answerable to Australian legal process, rather than a foreign parent’s jurisdiction. Our platform is ISO 27001 certified for information security management. When we describe our cloud as sovereign, we mean the control layer as much as the postcode, covering who administers the platform, whose laws apply, and which government’s legal process a request would have to travel through to reach you.
For organisations weighing the same question Airbus just answered, the practical starting point is not a migration but a conversation about classification. Working out which of your workloads genuinely need to sit beyond foreign reach, and which are perfectly fine where they are, is the honest first move, and we would rather help you draw that line than sell you a wholesale migration you do not need. If the events of the past week have you wondering who could reach your most sensitive workloads, then start a conversation with us. It costs you nothing but the hour it takes to find out.
No Comments
No comments yet.
RSS feed for comments on this post. TrackBack URI
Leave a comment
You must be logged in to post a comment.