NATO’s thumbs-up for AWS shows Europe still needs America
Amazon Web Services has become the first cloud provider cleared to handle sensitive information for all NATO members, underscoring that an increasingly independent Europe still relies on capabilities made in America, and suggesting that it's not as hard for U.S. firms to compete there as the White House insists.
The company announced on Tuesday that it has received alliance approval to handle information at the NATO RESTRICTED level, which is not classified but requires safeguarding.
As European militaries fuse radar, satellite, and even acoustic information to more easily detect Russian drones and other threats, NATO-approved rapid data and information sharing is critical.
AWS, which already handles sensitive military and intelligence data for many NATO members, beat its competitors—primarily from other U.S. cloud providers such as Microsoft—to win the alliance’s first blanket approval. That’s the result of “a sustained, multi-year effort,” David Appel, acting vice president of Worldwide Public Sector at AWS, said in the company’s Tuesday statement, AWS worked with Spain’s National Cryptographic Centre, or CCN, to test its services against NATO security directives; CCN then shared its findings to all member states.
The announcement also reflects a broad, evolving NATO digital transformation strategy. The alliance is eager to incorporate more commercial information technology into its coordination and planning. And AWS remains the biggest commercial cloud operator in Europe, with nine data-center clusters, or regions, across Europe, including the U.K.
“Strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance,” according to Dylan Browne, general manager of the NATO Communications and Information Agency, or NCIA, as quoted in Amazon’s statement.
While NATO members and AWS cloud users across Europe will be able to share their data more easily, they will also be able to retain control over it. The 2024 European Union Data Act requires cloud providers to protect EU data from other governments, including the United States. Practically speaking, that means housing data on European soil beyond the reach of U.S. court orders, although that’s not an explicit requirement of the Act. AWS, like Microsoft and other enterprise cloud providers, has been investing in European versions of its cloud stacks to meet those Data Act requirements.
Tuesday’s announcement shows both that U.S. technology is still a core feature of NATO military capability and that it is central to NATO’s future plans. But it also shows that European Union regulations on data storage aren’t a challenge to the success of U.S. cloud companies across Europe, even though White House rhetoric and executive orders suggest otherwise.
Amazon Web Services received NATO approval to handle sensitive information at the NATO RESTRICTED level, enhancing data sharing among NATO members. This approval underscores the reliance of European militaries on U.S. technology and reflects NATO's evolving digital transformation strategy. AWS's collaboration with Spain’s National Cryptographic Centre was crucial in meeting NATO security directives, while the 2024 EU Data Act mandates protection of EU data from external governments.
- AWS is the first cloud provider cleared to handle NATO RESTRICTED information.
- The approval reflects NATO's digital transformation strategy.
- AWS has been working with Spain’s National Cryptographic Centre to meet NATO security directives.
- The 2024 EU Data Act requires cloud providers to protect EU data from other governments.
- AWS remains the largest commercial cloud operator in Europe.