Tuesday, September 1, 2026
Home Asia Pacific

US ‘Kill Switch’ Fear Returns as Japan To Move Classified Military Data to American Clouds in 2027

Does Japan’s Ministry of Defense’s recent decision to shift the hosting of classified information from its own environment to a private cloud environment provided by United States-based technology providers from fiscal year 2027 pose a risk or enhance the country’s security? Is it not losing its sovereignty in the process?  

These are the questions many strategic experts are debating, because many European countries and Australia have already attempted Japan’s plan.

Even India’s defense mandarins are debating the issue.

Despite all talk of self-dependence, the stark global strategic reality is that in the sphere of cloud technology, there are only two countries that matter  – China and the United States. So avoiding one means embracing the other.

Every country that banned Huawei and ZTE from 5G, and kept out Chinese AI models and EV batteries, citing security, seems to have opted for the American alternative. And here, when one talks of Americans, it means three companies — Amazon Web Services (AWS), Microsoft Azure, and Google Cloud — who together control nearly 70% of the global cloud market. More significantly, they have entered the defense sector, the heart of state power.

A recent study showed that the global cloud market is worth hundreds of billions of dollars, with the military and defense sector accounting for a growing multi-billion-dollar slice driven by secure cloud and tactical edge computing.

The cloud market is heavily dominated by the “Big Three” hyperscalers, who control over 60% of total spending.

Amazon Web Services (AWS) leads the global market with roughly 28% to 32% share. Microsoft Azure holds the second position with roughly 20% to 22% share, growing fast in enterprise and AI integration. Google Cloud Platform (GCP) holds around 11% to 14% global share, driven by data analytics and AI tools.

The Big Three’s challengers happen to be regional and enterprise players like Alibaba Cloud, Oracle Cloud, and IBM Cloud.

Reportedly, the military cloud market is said to be valued at roughly $13.8 billion and is expanding rapidly as defense agencies modernize command, control, and intelligence systems. The Big Three dominate here too.

Cloud environments are believed to offer three main advantages to the military over on-premises infrastructure (physical hardware and servers in offices and data centers): scalability and interoperability; Enhanced Cybersecurity; and Reduced Costs.

In terms of scalability, the cloud enables you to scale processing power as needed. For example, during active military operations, it facilitates collecting massive data from satellites and drones and sharing joint operation data seamlessly between allied forces.

Cloud also enables cybersecurity, instant threat detection, and automated patching, often within minutes. Such ‘zero trust’ environments matter as cyber attacks continue to grow,  increasingly powered by AI.

Cloud is also said to be a significant upfront investment, even though it reduces costs. It optimizes hardware and data storage and generally cuts enterprise and defense IT spending by 20-40%. This is a real benefit, as many countries increasingly face budgetary constraints in the defense sector.

Commercial clouds offer what defense ministries cannot build – AI chips, zero-day patching, and global interoperability for coalition warfare. As NATO fights in Ukraine with Starlink, Palantir and AWS, sharing targeting data over a classified commercial cloud is faster than over bespoke military datalinks.

All this is said to have driven the Pentagon’s 2019 decision to replace the single-source JEDI (Joint Enterprise Defense Infrastructure) contract of $10 billion with the multi-cloud JWCC (Joint Warfighting Cloud Capability), involving AWS, Microsoft, Google, and Oracle.

It represented a monumental paradigm shift in national security. It radicalized the idea that the most sensitive military data can live on commercial infrastructure.

The Japanese national flag is seen at the Bank of Japan (BoJ) headquarters in Tokyo on September 1, 2026. (Photo by Yuichi YAMAZAKI / AFP)

Once the US initiated the trend, its partners and allies followed. A recent study by the International Institute for Strategic Studies (IISS), supported and cited by AWS, shows that maintaining sovereign control and using non-national public cloud providers are not conflicting goals for governments managing national security and defense.

According to the study, Thailand uses AWS for policing, the UK MoD runs workloads on Microsoft Azure, and the German Federal Police depend on AWS and Microsoft 365.

The study found 23 of 28 EU countries plus Britain “seem to rely on US tech” for national security functions, with 16 — including Germany, Poland and Britain — at “high risk to a potential US “kill switch” (a safety mechanism used to immediately shut down a device, machine, software system, or vehicle in an emergency when normal shutdown procedures are too slow or unsafe).

This raises the question of whether countries that depend on American companies are losing sovereignty in the process. In a way, the answer is “Yes”, given two particularly noteworthy points:

First, the US CLOUD Act of 2018 gives the US government authority to obtain data held by US corporations regardless of where it is stored. The law applies to any communication or remote computing service provider that has a legal presence or operates in the U.S., meaning jurisdiction follows corporate control rather than the physical location of the servers.

So even if a foreign Army log sits in an AWS data center in its own territory, Amazon must comply with a US warrant. For instance, Microsoft admitted in 2024  that it cannot guarantee UK data will stay in the UK.

In other words, physical data localization (keeping servers inside a country’s physical borders) does not guarantee immunity from foreign laws if the operating company is subject to US jurisdiction. Relying on foreign commercial infrastructure for vital defense functions thus exposes nations to potential operational disruptions and espionage.

Over-reliance on foreign-owned or externally hosted Cloud computing infrastructure could even significantly compromise a country’s operational resilience. When a nation migrates its government, military, or critical infrastructure (like power grids and banking) to the Cloud, it effectively hands over control of its digital backbone to private corporations that are often subject to the laws of foreign governments. For instance, the foreign government can compel those companies to cut off service during a geopolitical conflict.

A foreign power could pull a digital “kill switch,” instantly blinding a nation’s military logistics, shutting down government communications, or freezing its financial systems without firing a single missile. For instance, Ukraine relies heavily on Western-supplied advanced weapons (such as HIMARS, Patriot missile systems, and F-16 fighter jets).

However, much of this high-tech U.S. military hardware contains built-in software restrictions or remote-control mechanisms that allow Washington to dictate how and where it is used. The US has effectively used these mechanisms as a “soft kill switch” by geofencing weapons to prevent Ukraine from launching deep strikes inside Russian territory, heavily limiting Ukraine’s operational independence.

Similarly, many in India remember how, in July 2025, Microsoft blocked services to Nayara Energy, India’s oil refiner with Russian shareholding, due to  US sanctions. The block was temporary but devastating. It cut the company’s core digital infrastructure and brought its operations to a grinding halt.

Second, there is the issue of what is called “Cognitive Sovereignty”: the capacity and right to maintain independent ownership, authorship, and governance over one’s own thoughts, attention, and decision-making processes in environments shaped by artificial intelligence and persuasive technology.

After all, modern defense is AI — drone swarm recognition, predictive maintenance, and deepfake detection, etc. Those AI models run on US GPUs, trained on US stacks. As Qatari digital sovereignty architect Jasim Rahman noted recently, “The risk is not just data residency. It’s data plus the models. Nobody can see what’s inside the model. It’s like a black box.”

One may own the data, but if the model that interprets it is closed, foreign-controlled, and updated from Redmond or Mountain View, the interpretive sovereignty gets lost.

The point is that for years, nations focused heavily on “data residency,” ensuring information stayed physically within national borders. But as artificial intelligence becomes the core layer for decision-making, governance, and infrastructure, data residency alone is no longer enough.

If a nation relies on a “black box” model hosted or updated remotely by foreign tech giants, it faces significant risks to its sovereignty in interpreting developments.

Similarly worrisome is the feature of “ vendor lock-in” in military cloud computing. Once an air force builds its logistics on, say, Azure, moving to another cloud is like changing a fighter jet engine mid-flight. The United Nations Institute for Disarmament Research (UNIDIR) highlights this because, unlike a commercial enterprise experiencing downtime, a military cloud failure or sudden contract dispute directly compromises combat readiness.

Viewed thus,  it can be said that countries storing defense data on US commercial clouds are trading short-term capability for long-term control. In the process, some of the features of their sovereignty are vulnerable to compromise.

Hence, one sees recent attempts by many to build their own “Sovereign Clouds” and, until then, to enter into bilateral agreements with the US and local data-protection laws with American companies.

Incidentally, the US allows trusted partner nations to sign executive agreements under the CLOUD Act. This lets foreign users request data directly from US companies without waiting for slow Mutual Legal Assistance Treaties (MLATs).

The U.S.-U.K. Data Access Agreement was the first of its kind, allowing British law enforcement to query US providers directly while meeting specific privacy and human rights thresholds.

In January 2026, AWS launched the European Sovereign Cloud in Germany’s Brandenburg, completely separate from the standard global AWS commercial partition. It is physically and logically isolated, and operated by EU citizens. Here, no data moves to the US.

Microsoft created Microsoft Cloud for Sovereignty and Bleu in France with Thales, and Delos Cloud in Germany — local companies using Microsoft tech but owned locally.

Google has S3NS with Thales and T-Systems with Deutsche Telekom — where Google provides AI, but the French/German partner holds encryption keys.

Organizations across the EU now leverage the Gaia-X Trust Framework, which establishes rigid security labels and federated identity protocols to guarantee local operational control.

Besides, rather than using US regions, the European Commission and EU defense entities are increasingly working to route sensitive workloads through highly qualified local European alternatives like OVHcloud and Scaleway (France), or IONOS and Open Telekom Cloud (Germany), which meet stringent local certifications like France’s SecNumCloud.

Australia, another military ally of the US, has, with Washington’s approval, decided to partner with “trusted providers”, diversifying between domestic and foreign options, and establishing legal and technical control mechanisms.

Australia has selected AWS for its top-secret cloud; domestic provider Vault Cloud for secret and top-secret workloads; and Google, Oracle, and Macquarie Government for lower classification levels. All of these have legal and technical safeguards under its bilateral CLOUD Act Agreement with the US.

What about India? According to Bharat Digital Infrastructure Association (B-DIA), 66% of government cloud data is already hosted with foreign CSPs, mostly on Virtual Private Cloud. India does not have good enough domestic cloud systems that can rival those from the US. Indian clouds are said to lack GPU density, global regions, and AI tooling.

Therefore, India is adopting what ETTelecom calls a risk-based framework: Critical sectors—government, defense, power, healthcare—mandate sovereign cloud; education, manufacturing—hybrid; and Commercial non-sensitive—interoperability.

The above suggestion seems closer to models practiced in Europe, particularly in Germany and France. As experts say, rejecting US clouds could be technologically suicidal.

Pragmatism lies in using global clouds while retaining full visibility and lawful control through data classification, Indian-held encryption keys, and strong access controls; however, highly sensitive top secrets should not be hosted in the cloud and should be kept on air-gapped premises.

  • Author and veteran journalist Prakash Nanda is Chairman of the Editorial Board of the EurAsian Times and has been commenting on politics, foreign policy, and strategic affairs for nearly three decades. He is a former National Fellow of the Indian Council for Historical Research and a recipient of the Seoul Peace Prize Scholarship.
  • CONTACT: prakash.nanda (at) hotmail.com
Previous articleTurkey’s Two Biggest Adversaries, Israel & Greece, OK Historic $3.6B Deal For Multilayered AD System
Prakash Nanda
Author and veteran journalist Prakash Nanda has been commenting on Indian politics, foreign policy on strategic affairs for nearly three decades. A former National Fellow of the Indian Council for Historical Research and recipient of the Seoul Peace Prize Scholarship, he is also a Distinguished Fellow at the Institute of Peace and Conflict Studies. He has been a Visiting Professor at Yonsei University (Seoul) and FMSH (Paris). He has also been the Chairman of the Governing Body of leading colleges of the Delhi University. Educated at the Jawaharlal Nehru University, New Delhi, he has undergone professional courses at Fletcher School of Law and Diplomacy (Boston) and Seoul National University (Seoul). Apart from writing many monographs and chapters for various books, he has authored books: Prime Minister Modi: Challenges Ahead; Rediscovering Asia: Evolution of India’s Look-East Policy; Rising India: Friends and Foes; Nuclearization of Divided Nations: Pakistan, Koreas and India; Vajpayee’s Foreign Policy: Daring the Irreversible. He has written over 3000 articles and columns in India’s national media and several international dailies and magazines. CONTACT: [email protected]