A survey, and a very good headline
In early August 2026 Proton published research under a headline built to travel: three in four European businesses fear their US technology provider could cut them off. The survey covered 1,500 business leaders across the UK, Germany and France — 500 in each — fielded over ten days in late July.
74% said they were concerned a US provider could disable their access through what EU policymakers now call a "kill switch." That sat level with the same group's concern about ransomware. More than half said geopolitical risk factors into what technology they buy. Asked how long they could keep operating without their digital tools, 54% said less than a single business day.
Fear a US provider could disable their access — level with their fear of ransomware.
Proton business continuity survey, 2026Have a fallback for email, the system they rated most critical of all.
Proton business continuity survey, 2026Could not operate more than one business day without access to their digital tools.
Proton business continuity survey, 2026So — real shift, or a Swiss privacy company that sells European email discovering that Europeans are worried about American email?
Both. Less satisfying than picking a side, but accurate, and the two halves need separating before either is useful.
Yes, it is marketing. That doesn't make it wrong.
Proton conducted the survey itself rather than commissioning an independent polling firm, and it closes with a pitch for Proton's business continuity product. None of that is hidden — methodology and pitch are both stated plainly, which is more than many vendor surveys manage. But the research was designed by a party with an interest in a particular answer. Three things are worth knowing before you quote the number.
The question names the fear. Respondents were asked how concerned they were that a US provider could disable their access via a kill switch. Naming a risk and asking people to rate their concern reliably produces high scores. It measures how plausible a scenario sounds once described — not how much anyone was worrying beforehand.
The sample is three Western European countries. The UK, Germany and France are not Europe, and certainly not the world. The UK sample was a clear outlier on ransomware concern, which suggests national context matters more than the average admits.
The industry mix is unusual. Healthcare made up 26% of respondents and technology or software 22% — heavier on regulated and digitally-native sectors than a cross-section of European business would give. Both are sectors where sovereignty anxiety runs hot.
A vendor survey is a hypothesis, not evidence. The useful question is whether the world outside the survey agrees with it.
Now the part that survives scrutiny. The most interesting finding is not the 74% — it is the distance between what businesses say and what they have done. Concern ran at three in four. Coverage for the systems that would actually fail ran closer to one in four.
Concern, and coverage: the gap
That gap is hard to manufacture. Pure marketing would have found high concern and high intent to buy. What this found is a well-documented case of people naming a risk they have not acted on — a more honest result than the headline it was packaged in.
The events behind the survey are real
Two documented events do most of the work here.
In February 2025 a US executive order sanctioned Karim Khan, chief prosecutor of the International Criminal Court, over the court's investigations. In the months that followed Khan lost access to his ICC Microsoft email and moved to Proton Mail. Microsoft disputes the framing — president Brad Smith has said the company never ceased providing services to the ICC, and declined to elaborate on what disconnecting one account involved. Not in dispute: a sanctioned official at an international court stopped being able to use his work email, and by October 2025 the court was reported to be moving off Microsoft 365 to openDesk, a German government-backed open-source suite.
The second event was quieter and, for a business audience, more important. On 10 June 2025 Anton Carniaux, Microsoft France's director of public and legal affairs, appeared before a French Senate inquiry into procurement and digital sovereignty. Asked whether he could guarantee under oath that French citizens' data held under public contracts would never be passed to US authorities without French consent, he said he could not — noting it had never happened, and that Microsoft contests requests it considers unfounded.
Feb 2025
US executive order sanctions the ICC's chief prosecutor; his Microsoft email access ends.
Jun 2025
Microsoft France tells the Senate, under oath, it cannot guarantee EU data stays out of US hands.
Oct 2025
The ICC is reported to be replacing Microsoft 365 with the German-built openDesk suite.
That testimony is the most useful fact in the whole subject, and it is not really about Microsoft. Under the 2018 CLOUD Act a US-headquartered company can be compelled to produce data regardless of where it is stored. Any US provider would have to give the same answer. Most have simply never been asked under oath.
Data residency is not jurisdiction. A contract promising your data stays on Australian soil is a promise about geography. It says nothing about which legal system can compel the company holding it. Two separate questions — and most procurement paperwork only asks the first.
Who has genuinely changed direction
This is where the answer gets specific, because the gap between announcement and delivery is enormous and almost every article on this topic collapses the two.
Read the right-hand column and a pattern appears. The finished-work column belongs almost entirely to one German state and one French police force — both of which started years before the current political moment. Everything else is early, partial, or still at the planning stage.
That is not a criticism; large migrations take years. But "France is moving 2.5 million computers to Linux" and "France has told its ministries to write migration plans by autumn" are different sentences, and only one of them is true today.
The number that spoils the story
Announcements are cheap to make and easy to count. Market share is neither.
According to Synergy Research Group, European cloud providers held 29% of Europe's own cloud market in 2017. By 2022 that had fallen to 15%, and it has stayed at roughly 15% ever since. European providers did grow — more than tripling revenues over the period — but the market around them grew about sixfold, reaching roughly €61 billion by 2024. The beneficiaries were Amazon, Microsoft and Google, which together hold close to 70% of EU cloud spending.
European cloud providers' share of their own regional market. Down from 29% in 2017, flat since 2022 — across the entire period in which digital sovereignty became a headline political issue on the continent.
Synergy Research GroupFour years of speeches, resolutions and ministerial announcements have not moved that line. If a shift away from American tech were happening in the commercial market at any scale, this is where it would show first.
What has happened is easy to miss: the incumbents did not lose the argument, they bought into it and sold it back. On 15 January 2026 AWS launched its European Sovereign Cloud in Brandenburg — physically and logically separate from its other regions, operated by EU residents, backed by a stated €7.8 billion investment in Germany. Microsoft has made its own European commitments. Sovereign cloud is now among the fastest-growing categories in enterprise IT.
So the movement is real in that it changed what the market demands and what vendors must promise. It is not real in the sense of customers leaving. Mostly they bought a differently-packaged version of the same thing from the same companies — which is why the "sovereignty washing" complaint has teeth. Whether a separately-operated European subsidiary of a US parent sits genuinely beyond the CLOUD Act is a legal question no court has tested.
What "non-American software" actually means
"European" and "Australian" get used loosely enough to be meaningless, so be precise about what you would be buying. There are three separate questions, and a vendor can pass one while failing the others. Who owns it — which company, incorporated where. Which law binds it — the parent's jurisdiction, which determines whether a foreign government can compel it. Where does it run — the physical location of the servers, the question most procurement forms ask and the least decisive of the three.
Australia has a clean illustration of how far apart these drift. Atlassian is one of the great Australian software success stories — founded in Sydney, still substantially run from there. It is also, since October 2022, a Delaware corporation, having redomiciled its parent to the United States. On the jurisdiction question it answers as a US company. The flag on the marketing site and the flag on the incorporation certificate are not always the same flag, and only one of them is legally load-bearing.
With that established, a working map of credible non-US options by what they replace. Not exhaustive, not an endorsement — a starting point for a shortlist.
Office & collaboration
LibreOffice (Germany, non-profit) · Collabora Online (UK) · Nextcloud (Germany) · Open-Xchange (Germany) · Element / Matrix (UK) · OnlyOffice (Latvia) · openDesk (Germany, state-owned) · Zoho (India)
Email & secure comms
Proton, Infomaniak (Switzerland) · Tuta, mailbox.org (Germany). Note Switzerland sits outside the EU, so Swiss providers answer to Swiss law rather than EU enforcement — a different jurisdiction, not an absent one.
Cloud & hosting
OVHcloud, Scaleway (France) · Hetzner, IONOS, STACKIT (Germany) · Exoscale (Switzerland) · UpCloud (Finland) · Aruba (Italy). In Australia: NEXTDC, Macquarie Cloud Services, Vault Cloud.
Enterprise & industry
SAP (Germany) · Dassault Systèmes (France) · Hexagon (Sweden) · Temenos (Switzerland) · Amadeus (Spain) · Wolters Kluwer (Netherlands) · Sage (UK) · Odoo (Belgium) · Celonis, TeamViewer (Germany)
Australia & New Zealand
TechnologyOne (Brisbane, ASX-listed) · Canva (Sydney) · WiseTech Global · SafetyCulture · Xero (New Zealand). Check the incorporation, not the origin story: MYOB has been owned by US private equity firm KKR since 2019, and Atlassian is US-domiciled. Both still read as Australian.
AI & search
Mistral AI (France) · Aleph Alpha (Germany) · Qwant (France) · Ecosia (Germany). Much the thinnest category, and the one where the capability gap with US providers is largest and most openly acknowledged.
Could you actually run a business on Linux?
For servers the question is settled and has been for years. Unix-family systems — overwhelmingly Linux — run 91.9% of web-facing servers whose operating system can be identified, against 8.3% for Windows. Linux runs every one of the top 500 supercomputers, 91.6% of Google Cloud's virtual machines and 83.5% of Amazon's, and on Microsoft's own account more than 60% of customer cores in Azure. If you have a website, you already run a business on Linux.
The desktop is different, and the honest answer is yes for some businesses, and it will cost more than the licence savings suggest.
Start with measurement, because the published numbers are noisier than they look. StatCounter put Linux desktop share at 2.99% in April 2026 and 4.36% in June — a swing far too large to be real adoption. The cause is StatCounter's "Unknown" bucket, which has ballooned past 20% as more people use VPNs and hardened browsers. Treat any single monthly figure with suspicion. The defensible range is roughly 3–5% globally, rising, with the end of Windows 10 support in October 2025 a genuine accelerant.
91.9%
Unix-family share of web-facing servers with an identifiable OS. Linux is named on 61.7%; most of the remainder doesn't advertise its variant.
3–5%
Defensible range for global Linux desktop share in 2026. Monthly readings vary far more than reality does.
~80%
Windows' share of the Chinese desktop, after two decades of state-mandated domestic alternatives.
What works. Businesses whose work happens in a browser — email, documents, video calls, CRM, cloud accounting, anything SaaS. Development and technical work, where Linux has been the default for years. Reception, warehouse, kiosk and shared machines. Hardware compatibility is far better than its reputation, and Mint, Ubuntu and Zorin are genuinely approachable.
What breaks. Adobe Creative Cloud has no Linux version and no near-equivalent for professional work. Excel is the recurring killer — not the spreadsheet, but the macros, VBA and add-ins businesses have quietly built their operations on. Industry-specific desktop software — practice management, point of sale, CAD, dispatch, desktop accounting — often has no Linux build. Then the unglamorous layer: device management, directory integration, patch tooling, and a vendor with a support contract and a phone number.
Licence savings are the small number. Retraining, migration labour and the workflows that simply won't move are the large ones.
Schleswig-Holstein is the best available evidence on both counts. It is the most successful public-sector migration in Europe, and telling that after years of work it stands at about 80% — the remaining fifth held back not by user resistance but by specialist applications tied to Word and Excel. Its economics are genuinely favourable: over €15 million in annual licence savings against €9 million of one-off investment. Payback inside a year, on their numbers.
The counter-example is Munich, which began moving to Linux in 2003 and reversed in 2017. The most-cited difference is not technical: Schleswig-Holstein has sustained cross-party backing, Munich's project became a political football. Migrations like this fail on organisational commitment far more often than on software.
The pragmatic middle path, and the one most successful organisations actually take: move browser-first staff to Linux, keep a small managed Windows estate or virtual machines for what genuinely requires it, and stop pretending the last 15% will convert.
The other operating systems
Widen the question beyond Linux and the field is larger than most people assume — but the lesson it teaches is discouraging for anyone hoping to move quickly.
The mainstream alternatives. macOS and ChromeOS are both American, so neither solves the jurisdiction problem. ChromeOS is still worth naming: for a genuinely browser-only business it is the lowest-effort escape from Windows, and ChromeOS Flex runs on hardware you already own.
The BSD family. FreeBSD and OpenBSD are mature, independent Unix systems with strong security reputations; OpenBSD is developed from Canada. Excellent for servers and appliances, and essentially not desktop options for a general business.
The state-backed programs. China has the largest — Kylin and openKylin, UOS and Deepin, Huawei's openEuler on servers and HarmonyOS on devices. Russia has Astra Linux; India has run its own distributions in government. These are real, funded and in places technically impressive.
Which brings the reality check. China has pursued domestic operating systems since the early 2000s with state ownership, procurement mandates, a domestic chip program and every lever a government possesses. Windows still held around 80% of the Chinese desktop as recently as 2025.
The moat was never the kernel. It is the ecosystem on top — the applications, file formats, integrations, trained staff and muscle memory. Anyone can build an operating system; almost nobody can build the twenty years of software that runs on one. That is the honest ceiling on how fast any of this moves, for a government or for you.
Australia is answering a different question
It would be easy to assume Australia is on Europe's trajectory. It isn't, and the difference matters before you build a strategy on European headlines.
On 1 July 2026 the Digital Transformation Agency's Whole-of-Government Cloud Computing Policy came into effect. Its direction is not away from cloud but further into it: agencies must prioritise cloud when modernising, consider it for new digital initiatives and justify alternatives, with hybrid and multi-cloud encouraged where a pure cloud approach doesn't stack up.
Sovereignty is handled separately, and differently to Europe. The Hosting Certification Framework requires sensitive government data and PROTECTED-classified systems to sit in certified facilities, with supply chain and ownership conditions attached. But certification is something a provider earns, not something a nationality confers — Google Cloud, for one, holds Certified Strategic status under it.
That is a real philosophical difference. Europe increasingly treats the question as whose law binds this company. Australia treats it as can this arrangement be assured, audited and controlled. Neither is obviously wrong — but an Australian business copying European sovereignty logic will find its own government's policy pointing the other way.
For a private Australian business the obligations that actually bite are closer to home: Australian Privacy Principle 8, which keeps you accountable when personal information becomes accessible to an overseas recipient; the SOCI Act if you touch critical infrastructure; and APRA CPS 230 for regulated financial entities, which expects critical operations to continue through severe disruption and service provider risk to be managed. None require you to buy Australian. All require you to know what you have bought.
What a sensible business does on Monday
Nothing here argues for ripping out your stack. For most Australian businesses that would be an expensive answer to a risk they have never measured. But "do nothing" is only defensible once you have actually looked.
Map the concentration, not the nationality. List the tools you could not work without for a week. For each, write down four things: who owns it, which country's law binds the parent, where it physically runs, and how long you could operate without it. Most businesses have never written this down, and the exercise usually surprises them — not because of geopolitics, but because of how much sits with one supplier.
Diversify the single points, not everything. A second provider in the same jurisdiction protects you from an outage but not a legal order. A second provider in a different jurisdiction protects you from both, at the cost of running two things. Decide deliberately which risk you are buying down, and only for the systems that warrant it.
Then test it. This is where the survey's most damning number belongs: 94% of those businesses said they had a continuity plan. Only 44% said they test it. A fallback account nobody has logged into, on a system nobody has used, holding data nobody has checked, is not a fallback — it is a line item.
And the failure in a real continuity event is almost never the technology. It is a team doing this for the first time, under pressure, on unfamiliar tools, while somebody urgently asks them to reset a password or approve a payment or click a link that has arrived at exactly the right moment. Disruption is the best cover an attacker gets. The organisations that come through it are the ones where the right response was already a habit.
What this means for your organisation
Marketing and true, at once
The survey was vendor-run with a product pitch attached. Its headline still holds up against independently documented events.
Announcements outpace delivery
France has ordered plans, not migrations. Only Schleswig-Holstein and the French Gendarmerie have finished work at scale.
The money hasn't moved
European providers hold about 15% of Europe's cloud market, unchanged since 2022. The hyperscalers sold sovereignty back instead.
Residency is not jurisdiction
Where data sits and which law can compel it are separate questions. Most procurement paperwork only asks the first.
Linux is viable, not free
Fine for browser-first work. The cost is retraining and the workflows that won't move — not the licence saving.
Untested is untried
94% have a continuity plan. 44% test it. In a real disruption, the gap between those numbers is where losses happen.
The weakest point in a continuity plan is usually a person under pressure.
Disruption is when judgement gets tested and attackers get their best opening. Click or Flick trains the habit that holds up when systems don't — stop, check, then act — and measures whether it actually stuck.