The most alarming figure from the survey is about operational fragility. 54.5% of respondents said they could not operate for more than one business day if a US kill switch were activated . Many businesses have built their core operations — email, file storage, CRM, infrastructure — around a small number of US-based platforms, including AWS, Azure, Google Cloud, and Microsoft 365, creating a single point of catastrophic failure
.
Among large enterprises, 28.7% estimated losses exceeding €100,000 per day in such a scenario . The financial exposure is not uniform, but it is severe for those most deeply integrated with US hyperscalers.
Here is the central paradox: fewer than half of surveyed businesses have a tested and documented continuity plan that accounts for a potential US kill switch . The Register summed it up bluntly: "European firms afraid of US tech kill switch but haven't made an escape plan"
.
The gap between concern and concrete action is wide. While 67.8% of respondents said they have started looking for alternatives or are considering doing so, the lack of prepared fallback plans means many companies would be caught flat-footed .
Experts warn that standard US cloud provider contracts typically do not protect customers against government-ordered service termination. The fine print often allows suspension of service to comply with US law — which is precisely the legal mechanism a kill switch would use .
IT Pro and The Register both note that many businesses mistakenly assume their service-level agreements (SLAs) offer protection, but a government directive would likely override contractual commitments . This makes the lack of tested fallback plans especially dangerous.
The legal tension is rooted in the US CLOUD Act of 2018, which allows American authorities to compel US-based technology companies to hand over data regardless of where it is stored globally — directly clashing with European privacy regulations like GDPR .
A companion Proton survey of 3,000 citizens across the same three countries found that 73% of Europeans think the continent is too dependent on US tech . A notable share said they would avoid doing business with a European company that relies on US technology, suggesting that pressure for digital sovereignty is coming from both the boardroom and the marketplace
.
The European Commission has proposed new rules to prevent any foreign government or corporation from possessing a kill switch that could disrupt essential tech services across Europe. The Guardian reported in June 2026 that the EU executive aims to codify this protection into law . Under these proposals, EU member states would be required to perform risk evaluations of their cloud computing providers in sensitive sectors such as defense, critical infrastructure, and public administration
.
Similarly, the Future of Technology Institute (FOTI) found that most European countries rely on US cloud providers for military operations, exposing them to kill-switch risk in national defense .
Despite the urgency, weaning Europe off US hyperscalers is extremely difficult. Google, Microsoft, and Amazon alone account for an estimated 70% of Europe's cloud computing infrastructure, and European alternatives remain fragmented and under-scaled . Analysts at Reuters and the BBC have noted that the continent's dependence is structural and will take years to unwind
.
Some progress is visible. A consortium of European tech firms — Cubbit, SUSE, Elemento Cloud, and StorPool Storage — launched what they describe as Europe's first fully sovereign disaster recovery pack in April 2026 . Meanwhile, 61% of European CIOs and tech leaders say they want to increase their use of local cloud providers, and more than half say geopolitics will prevent them from leaning further on US-based hyperscalers
.
Bottom line: European businesses are highly worried about a US cloud kill switch — on par with ransomware fears — and over half say they would be crippled within a single day. Yet few have actually prepared. The gap between concern and readiness is wide, and while the EU is pushing new sovereign cloud rules, the structural dependence on US hyperscalers remains deep, leaving most businesses exposed.