Cybersecurity
Cloud, local or hybrid in 2026: five sovereignty decisions for an SME
· Updated on · 10 min read · Paul-Antoine Tual
Useful digital sovereignty means deciding where each workload should run from explicit risks, because European hosting, SecNumCloud qualification and a local server answer different needs and none alone guarantees security, compliance or availability.
- Jurisdiction: who can lawfully compel access, and who holds the keys or technical control?
- Data: which content, logs, secrets and metadata leave the organisation?
- Resilience: which dependencies can interrupt service, and which recovery plan has been tested?
- Economics: what is the full cost per accepted task over the contract period?
- Crypto-agility: which data must remain confidential after 2030?
1. Map jurisdiction, control and continuity
The CLOUD Act creates a real but conditional legal risk: 18 U.S.C. § 2713 requires a covered provider to respond to valid US legal process for data within its “possession, custody, or control”, including when the data is stored outside the United States.
- A French data centre does not automatically neutralise the jurisdiction of the provider or its parent company.
- The Act does not authorise free or systematic government access: the legal request, jurisdiction and effective control must each be established.
- The GDPR continues to govern personal data; a foreign demand does not by itself make a disclosure lawful in the European Union.
An SME can turn this legal question into testable architecture and contract requirements, then choose a level of control proportionate to each processing activity’s sensitivity.
- Location: active data, backups, logs, administration and support.
- Control: entities able to access data, key management and conditions for compelled disclosure.
- Continuity: network dependencies, RTO/RPO, data export, exit procedure and restoration tests.
- Assurance: relevant audit evidence and qualifications; SecNumCloud adds requirements concerning non-European laws without relieving the customer of its own controls.
2. Govern the data sent to coding assistants
GitHub’s policy effective from 24 April 2026 clearly distinguishes individual from business plans, so the plan, repository owner and privacy setting must be checked before deciding whether an interaction may be used for training.
- Individual: Free, Pro and Pro+ participate by default with an opt-out.
- Business: Business, Enterprise and enterprise-owned repositories are excluded from the announced change.
- Evidence: retain the applicable account setting and contract.
| Copilot plan or context | Announced treatment of interactions for training | Control action |
|---|---|---|
| Individual Free, Pro, Pro+ | Inputs, outputs, code snippets and context used by default | Opt out in Settings → Privacy if this use is unsuitable |
| Business, Enterprise | Excluded from the March 2026 change | Check the enterprise agreement and account policies |
| Enterprise-owned repository | Interactions excluded from the announced programme | Confirm repository ownership and organisation rules |
The intellectual-property risk extends beyond model training because the service processes context to answer, while the development environment can expose secrets, dependencies or malicious instructions.
- Minimisation: exclude secrets, keys, customer data and sensitive repositories from transmitted context.
- Retention: document retention periods, locations, subprocessors and telemetry.
- Software supply chain: verify the existence, publisher, signature and reputation of a suggested package before installation to limit slopsquatting.
- Agency: treat files, tickets and dependencies as untrusted input, restrict permissions and require approval for consequential actions.
- Local control: block unnecessary network egress, since an on-site model may still send telemetry or call an external service.
3. Adapt defence to AI-assisted attack speed
GTIG’s report of 11 May 2026 documents an actor using a zero-day that Google believes was developed with AI, wording that supports an attributed observation without proving that an autonomous system created the entire exploit alone.
- GTIG observes AI accelerating vulnerability research, tool development and obfuscation.
- The report also describes CANFAIL and LONGSTREAM, whose decoy code appears to have been LLM-generated.
- The main operational effect is a possible reduction in the time between discovery, exploitation and remediation.
Shortening the defensive response requires controls over code and access as well as hosting decisions, because an exposed, unpatched private server remains vulnerable.
- Inventory reachable assets, dependencies and operational owners.
- Reduce public exposure, standing privileges and secrets available to agents.
- Detect abnormal behaviour with central logs, alerts and tested rules.
- Remediate according to exploitability, exposure and business impact.
- Rehearse restoration and compromised-credential revocation.
4. Compare architectures with a dated full-cost model
Microsoft’s 1 July 2026 update illustrates subscription price risk, but a sound comparison preserves the official scope: monthly US-dollar commercial list prices for suites with Teams, possible local variation and application to existing customers on renewal.
- Date: 1 July 2026 for new purchases, then renewal for existing contracts.
- Scope: commercial suites with Teams shown below.
- Currency: US dollars before country, currency and contract adjustments.
| Plan | Price before 1 July 2026 | Announced list price | Announced change |
|---|---|---|---|
| Microsoft 365 Business Basic | $6 | $7 | 16% |
| Microsoft 365 Business Standard | $12.50 | $14 | 12% |
| Microsoft 365 Business Premium | $22 | $22 | 0% |
| Microsoft 365 E3 | $36 | $39 | 8% |
| Microsoft 365 E5 | $57 | $60 | 5% |
The end of support for Exchange Server 2016 and 2019 on 14 October 2025 requires a migration decision, but Microsoft identifies two broad routes that deserve comparison: Microsoft 365 and Exchange Server Subscription Edition.
- Cost licences, migration, administration, backups, anti-spam, high availability and internal skills.
- Compare the functions actually required, including security, mobility, archiving and collaboration.
- Test reversibility and restoration before assigning financial value to continuity.
4.1 Calculate the cost of a local, cloud or hybrid LLM
A local LLM carries no variable token invoice, but its full cost includes hardware, electricity, idle capacity, operations, security, redundancy and refreshes, while an API also charges for tokens, tools, storage and egress.
- Measure the workload: input and output tokens, peaks, latency, availability and accepted-task volume.
- Measure quality: success rate on a business test set, human review cost and any need for a stronger model.
- Use a defined period: compare annualised local cost with avoidable cloud spend at equivalent quality and service.
- Value constraints separately: confidentiality, offline operation or latency may justify local deployment without direct savings.
In a scenario with five million tokens per month at a hypothetical price of $0.72 per million, the API bill reaches $3.60 per month, so a local investment of €50,000 to €250,000 requires a justification beyond reducing that consumption cost.
- A credible break-even case identifies the cloud model, input-output mix and hardware utilisation.
- A hybrid architecture can route simple tasks to a compact model and reserve an API for complex cases, but savings must be measured on accepted work.
- There is therefore no universal 90% saving or generic 18-to-30-month payback.
4.2 Assess agents and email as complete services
For an agent or email service, hosting location alone does not establish sovereignty, eIDAS compliance, availability or lower cost, because those outcomes depend on the contract, architecture, operations and use case.
- For an agent, include the orchestrator, model, connectors, logging, human control, secret management and error recovery.
- For email, include deliverability, archiving, anti-spam, backup, administration, support and continuity.
- For legal review, check GDPR roles, transfers, subprocessors and evidence applicable to the exact service.
- For the decision, pilot a representative workload, then compare cost, quality, risk and reversibility over the same period.
5. Plan post-quantum migration around data lifetimes
The “store now, decrypt later” scenario makes long-lived confidential data the first priority, while 2035 is a migration horizon in the European roadmap rather than a certain date for the arrival of a cryptographically relevant quantum computer.
- Inventory uses of RSA and elliptic curves, certificates, VPNs, PKI, HSMs, signatures and embedded protocols.
- Assign each data set its required confidentiality or authenticity period, flagging requirements beyond 2030.
- Identify supplier dependencies, update paths and unavoidable replacement cycles.
- Prioritise critical systems and flows that could be captured now and decrypted later.
Available standards and the hybrid transition
The three NIST standards finalised in August 2024 provide reference building blocks for key encapsulation and signatures, while Falcon-based FN-DSA remains under development as FIPS 206 as at 6 September 2026.
- Key establishment: ML-KEM is the finalised building block.
- Signatures: ML-DSA and SLH-DSA are finalised with different properties.
- Compact alternative: FN-DSA is not yet a final standard.
| Standardised algorithm | Use | NIST status |
|---|---|---|
| ML-KEM, derived from CRYSTALS-Kyber | Key establishment | Final FIPS 203 |
| ML-DSA, derived from CRYSTALS-Dilithium | Digital signature | Final FIPS 204 |
| SLH-DSA, derived from SPHINCS+ | Hash-based signature | Final FIPS 205 |
| FN-DSA, derived from Falcon | Compact signature | FIPS 206 in development |
Separate the ANSSI and European milestones
The published dates structure a gradual, risk-based migration programme with a defined regulatory scope rather than imposing the same duty on every SME.
- From 2027: ANSSI aims to introduce PQC requirements for products entering qualification, rather than withdrawing every product already qualified.
- After 2030: ANSSI considers buying products without PQC unreasonable and asks organisations to anticipate data requiring protection beyond that date.
- By 2030, then 2035: the European roadmap prioritises high-risk use cases, followed by medium-risk cases.
- During transition: ANSSI strongly recommends combining classical and post-quantum cryptography where quantum protection is needed.
Crypto-agility is the ability to replace an algorithm or protocol without rebuilding the system, so it depends more on inventories, interfaces and contracts than on cloud or local hosting alone.
- Design algorithm versions, key rotation and certificate renewal without hard-coded dependencies.
- Test key and signature sizes, network fragmentation, performance, HSMs and device compatibility.
- Require a dated supplier PQC roadmap and an update or exit clause.
Conclusion: five decisions, one architecture for each risk
A robust decision assigns each processing activity to the environment that meets its documented constraints, then revisits that choice at contract renewal, after a material threat change or when regulation evolves.
- Establish constraints before selecting a provider or hardware.
- Retain the technical, legal and financial evidence behind the decision.
- Schedule a review whenever one of those sources of evidence changes.
| Decision | Evidence question | Possible option |
|---|---|---|
| Jurisdiction | Who controls the data and under which laws? | Public cloud, qualified service, private or local |
| Source-code data | What is sent, retained or reused? | Settings, enterprise contract, local isolation |
| Cybersecurity | Which assets are exposed and how quickly can they be patched? | Hardening, segmentation, detection, recovery |
| Cost | What is the full cost per accepted task? | SaaS, API, local or hybrid routing |
| Post-quantum | How long must the data remain protected? | Inventory, hybrid cryptography and planned refresh |
The Junyr Method™ therefore treats sovereignty as an architecture decision governed by data, risk and economics, using SecNumCloud where qualification meets the need, local deployment where it provides useful control and hybrid deployment where workloads have different constraints.
- Classify before migrating.
- Ask for contractual and technical evidence before accepting a commercial claim.
- Measure a representative workload before calculating return on investment.
- Keep a tested exit route for data, models and operations.
Position your next decision in 30 minutes
Book the Junyr AI maturity audit: a free, no-commitment 30-minute video call to identify your next project.
Paul-Antoine TUAL · AI Transformation Leader · Founder of Croissance & Transitions and the Junyr Method™
Sources
- 18 U.S.C. § 2713 — data in a provider’s possession, custody or control
- ANSSI — SecNumCloud FAQ
- CNIL — cloud security
- GitHub — 2026 update to Copilot interaction-data use
- Google Threat Intelligence Group — AI threat tracker, 11 May 2026
- Microsoft — Microsoft 365 pricing and scope from 1 July 2026
- Microsoft — end of support for Exchange Server 2016 and 2019
- ANSSI — post-quantum cryptography FAQ
- European Commission — post-quantum transition roadmap
- NIST — FIPS 203, 204 and 205 standards
Frequently asked questions
- Does the CLOUD Act give automatic access to all data hosted in Europe by a US company?
-
No: it requires certain providers subject to US jurisdiction to respond to valid legal process for data within their possession, custody or control, regardless of where that data is stored.
- The provider's jurisdiction and effective control over the data matter.
- European server location alone is therefore insufficient to remove the risk.
- Any disclosure of personal data must also be assessed under European law, including the GDPR.
- Does GitHub Copilot use code from every plan to train models?
-
No: from 24 April 2026, training use applies by default to interactions on individual Free, Pro and Pro+ plans, with an opt-out, while Business and Enterprise are excluded from this change.
- Interactions may include inputs, outputs, code snippets and associated context.
- Individual users should check their Privacy setting.
- A business should still examine retention, subprocessors, telemetry and contractual terms.
- Does a local LLM cost nothing?
-
No: removing a per-token bill does not remove hardware, electricity, operations or security costs, and the economics depend on actual volume and service requirements.
- Compare full local cost with full API cost over a defined period.
- Include redundancy, upgrades, monitoring, staff and unused capacity.
- Test model quality on business tasks before projecting savings.
- Does ANSSI require every SME to adopt post-quantum cryptography in 2027?
-
No: the 2027 objective concerns products entering qualification, while regulatory duties depend on scope and ANSSI advises every organisation to begin an inventory now.
- Classified and Restricted Distribution data and certain vital systems are subject to particular rules.
- For other organisations, 2030 is a procurement planning milestone rather than a universal compliance date.
- Priority depends on the required confidentiality period and the replacement cycle.
- Which hosting model should an SME choose?
-
The sound choice assigns each workload to public cloud, a qualified service, a private environment or a hybrid architecture according to its constraints rather than one universal doctrine.
- Classify data, secrets and retention periods.
- Define availability, reversibility, jurisdiction and sector duties.
- Measure quality, latency and full cost with a representative workload.
Paul-Antoine Tual
AI Transformation Leader · Junyr Method™ · Transition manager specialising in AI for French SMEs and mid-caps. Engineer from the École des Mines de Nantes, lawyer, developer since 1993.