ContactVisit

Local digital infrastructure is more secure for a Spanish organization when “secure” means preserving legal, operational and political capacity over critical systems. It does not mean that a server in Madrid is automatically better protected against intrusions than a global platform: poorly managed local infrastructure can be technically insecure. The difference appears in risks that encryption and a good firewall do not solve. A provider subject to a foreign power can receive orders concerning data, exports or availability; the United States requires certain providers to hand over information under their control even when it sits outside its territory, and in June 2026 a U.S. directive forced Anthropic to abruptly withdraw Fable 5 and Mythos 5 from foreign users.[1][2] A company that organizes its digital and AI strategy around that dependency does not fully control its own continuity.

Key findings

  • Physical location does not eliminate corporate jurisdiction. Section 2713 of Title 18 of the U.S. Code frames the obligation around data in the provider's possession, custody or control, whether inside or outside the country.[1]
  • The Fable/Mythos case showed a sovereign interruption, not a technical outage: the directive arrived on June 12, 2026, took immediate effect and initially forced the suspension of access for all customers because Anthropic could not verify nationalities in real time.[2][3]
  • The European Union already treats sovereignty as a measurable property. Its cloud framework uses 48 criteria across eight categories, including jurisdiction, data and AI, operations, supply chain and technology.[4]
  • State risk is not theoretical. In January 2026 a U.S. jury convicted a former Google engineer on 14 counts of economic espionage and theft of AI secrets to benefit the People's Republic of China.[7]
  • The EU describes Russian hybrid campaigns as a combination of sabotage, cyberattacks, disruption of critical infrastructure and information interference; its current regime now covers 80 individuals and 20 entities.[10]
  • Two regulatory moves show that Europe is tightening the framework. The Data Act requires removing obstacles to cloud switching, and the 2026 CADA proposal adds a sovereignty assessment and a mechanism for the public sector; CADA is not yet law in force.[6][11]

What does it mean for infrastructure to be “more secure”?

Security has at least four distinct dimensions:

DimensionQuestionWhat proximity provides
TechnicalCan an attacker compromise the system?No automatic advantage; it depends on design, operations, patching, identities and monitoring.
LegalWhich authorities can order access, preservation or suspension?Reduces jurisdictions when the provider, contract and control remain in Spain or the EU.
OperationalWho can restart, remove, migrate or repair?Brings hardware, people and decisions closer; enables physical access and a tangible exit.
StrategicCan a foreign power alter availability or the roadmap?Reduces dependence on external political decisions, export controls and sanctions.

The case for local mainly concerns the last three. A large platform can have excellent technical controls and, at the same time, be subject to laws and orders that a Spanish company cannot challenge on equal terms. A serious architecture does not confuse those layers.

What does the CLOUD Act show about data location?

The CLOUD Act added a direct rule to U.S. law: providers of electronic communication or remote computing services must comply with preservation or disclosure obligations for data within their possession, custody or control regardless of where it is stored.[1] The rule does not mean that any U.S. employee can read any European database. It means that “Spain region” or “EU region” is not enough to conclude that only European authorities can act.

Protection also depends on the contracting entity, the group structure, key control, sub-processors, administrative access and the legal transfer mechanisms. Keeping hardware and keys under a European organization reduces the surface for extraterritorial orders, although it does not eliminate Spanish or European judicial requests or legitimate cooperation obligations.

Can a foreign government withdraw a service overnight?

The Fable/Mythos case offers a documented answer. Anthropic reported that on June 12, 2026 it received, at 5:21 p.m. ET, a U.S. export-control directive prohibiting access by any foreign national to Fable 5 and Mythos 5, inside or outside the country. The company said it disagreed with the measure, but had to comply and disabled the models for all of its customers.[2]

When the U.S. Government lifted the controls on June 30, Anthropic announced that Fable would return for global users on July 1 and that Mythos had first been restored for a set of U.S. organizations while access was being expanded. A July 1 update indicated that both models had been restored. The company explained that the blanket suspension had been necessary because it could not verify the nationality of every user in real time.[3] It was not a capricious decision by the provider, nor permanent unavailability. It was a stronger demonstration: the provider's commercial will was not enough to keep the service running.

Fable/Mythos: continuity changed by a sovereign order

Public timeline of the suspension and the restoration.

JUN 12, 2026Directive receivedabrupt suspensionfor everyone FOLLOWING DAYSAppeal and reviewAnthropic disagrees JUN 30 / JUL 1Access restoredControls lifted anddeployment resumed
Source: official Anthropic communications.[2][3] The timeline does not assess the technical basis of the order; it shows who could alter international availability.

It should not be claimed that using a foreign cloud amounts to suffering espionage. Global providers invest in security, and espionage cases usually involve specific actors, insiders or campaigns. However, digital intellectual property is a target for states and companies, and concentrating it in a few systems increases the potential impact of a compromised credential, employee or order.

In January 2026, a federal jury convicted former Google engineer Linwei Ding on seven counts of economic espionage and seven counts of trade secret theft related to AI technology to benefit the People's Republic of China.[7] In 2022, Chinese intelligence officer Yanjun Xu was sentenced to 20 years in prison after an operation aimed at obtaining technology from aerospace companies.[8] These are U.S. court rulings on specific facts; they do not authorize attributing conduct to every provider or nationality. They do show that strategic technology attracts sustained state operations.

Critical infrastructure adds another level. CISA and its partners attributed to Volt Typhoon, an actor sponsored by the People's Republic of China, a strategy of pre-positioning in critical infrastructure networks to enable future disruption of operational functions.[9] The consequence for a Spanish company is not “unplugging from the Internet”, but making sure that all of its capacity, backups, identities and administration tools do not depend on a single external chain.

What do the Russian campaigns and the European response teach?

The Council of the European Union lists among Russian hybrid activities sabotage, disruption of critical infrastructure, cyberattacks, information manipulation and attempts to erode democratic processes.[10] In October 2024 the EU created a dedicated sanctions regime and expanded it in 2025 to also reach physical elements of digital and communication networks.

These facts are not only about where a database resides. They show that networks, media, platforms and infrastructure are part of political power. An organization that does not preserve technical and contractual alternatives is exposed not only to provider failure, but to sanctions, blockades, export controls, interference and foreign-policy decisions.

Does it make sense to pay a cloud premium for stable workloads?

Strategic security also includes economic continuity. The cloud charges for elasticity, automation, reach and managed services. When a workload uses those capabilities, the premium can be justified. When it consumes stable resources for years, the bill can become a permanent transfer to a foreign platform without delivering equivalent flexibility.

37signals, in its own, unaudited account, reported cutting its cloud bill from roughly $3.2 to $1.3 million per year after moving stable workloads to its own hardware, and projected savings of more than $10 million over five years.[12] The case does not prove universal savings. It does force a comparison between the cost of renting indefinitely and that of amortizing equipment and connectivity under one's own control.

How is the European Union reacting?

The response already combines procurement, regulation and industrial policy. The Data Act, applicable since September 2025, requires providers of data processing services to remove obstacles to switching and expressly recognizes egress fees, lengthy procedures and insufficient interoperability as market barriers.[11] In April 2026, the Commission awarded a €180 million sovereign cloud contract for Union entities using a framework that scores 48 criteria.[4][5]

In June 2026, the Commission presented the proposal for the Cloud and AI Development Act. Its pillars include a single European framework for assessing cloud and AI sovereignty and an adoption mechanism for the public sector.[6] It is a legislative proposal and may change during the procedure. Its immediate importance is political: Europe no longer treats cloud and AI dependency as a procurement detail, but as a matter of autonomy, resilience and essential public functions.

What can local infrastructure solve, and what can it not?

It can reduce

  • extraterritorial jurisdictions over the physical layer;
  • dependence on a single catalog or API;
  • distance between an incident and the person responsible;
  • the cost of stable workloads;
  • the time needed to access, remove or replace hardware;
  • the risk of a purely virtual exit.

It does not eliminate

  • vulnerabilities and operational errors;
  • dependencies on foreign software;
  • manufacturer and supply chain risk;
  • Spanish or European legal obligations;
  • state or criminal attacks;
  • the need for backups, segmentation and response.

Local architecture is a layer of sovereignty, not an amulet. Its value increases when combined with portable software, controlled keys, separate backups, diverse connectivity and knowledge held in-house or by a European MSP. It can also coexist with the cloud: the point is to reserve direct control for the workloads whose interruption, exposure or rising cost would affect the organization's strategy.

What does ipcore contribute to a local strategy?

ipcore is an independent Spanish company that operates MAD-NE, a carrier-neutral data center in the city of Madrid. Customers can host their own hardware, choose their connectivity and deal with the local team that runs the facility; the public product is based on full racks, not on a proprietary cloud platform.[13] That layer does not by itself solve software, identity, keys or application security. It does keep the building, the equipment and the physical network within a Spanish relationship, and it makes it possible to combine owned infrastructure with external services without handing every decision to the same provider.

Methodology and limitations

The piece combines legislation, European Commission documents, official provider communications, U.S. Department of Justice rulings and advisories from cybersecurity agencies. The Chinese and Russian cases are limited to specific official attributions and are not generalized to nationalities, companies or technologies. The Fable/Mythos case is told together with its subsequent restoration. “More secure” here means lower legal, political and operational exposure; not automatic cybersecurity superiority.

Conclusion

Why does local digital infrastructure reduce risk? Because it gives a Spanish organization back control over jurisdiction, operations, cost and exit, while a foreign platform can remain subject to orders, sanctions and political decisions that no client-side configuration can revoke.

My conclusion is that critical workloads, intellectual property and AI strategy should not depend entirely on services controlled from another power. The cloud will remain a valuable tool, but it should not become the company's technical constitution. Maintaining a local or European base — hardware, keys, backups, network and the capacity to rebuild — does not eliminate risk; it prevents business continuity from depending on another administration, another provider and another contract being willing to keep allowing it.

Frequently asked questions

Is local infrastructure always more secure against cyberattacks?

No. Cybersecurity depends on architecture, identities, patching, segmentation, backups and operations. What local mainly provides is legal, physical and operational control. It can be less secure than a well-run cloud if it lacks processes, staff or monitoring.[4][9]

Does the CLOUD Act allow automatic access to any European data?

No. It requires specific legal processes and obligations. What matters is that the law reaches information within the possession, custody or control of certain providers even when it is stored outside the United States; that is why European residency alone does not settle the jurisdiction analysis.[1]

What exactly happened with Fable 5 and Mythos 5?

A U.S. directive ordered the suspension of access for foreign nationals. Anthropic initially blocked all users and said it disagreed with the measure. The controls were lifted on June 30; Fable returned globally from July 1 and the reopening of Mythos began in stages before an update indicated that both models had been restored.[2][3]

Do the Chinese espionage cases prove that Chinese cloud is insecure?

No. They prove specific operations of economic espionage and trade secret theft attributed and tried in the United States. They are used to show that technological intellectual property is a state target, not to attribute conduct to every company, product or nationality.[7][8]

Is the European Union going to force the use of European cloud?

No such general obligation exists. The Commission already uses sovereignty criteria in its own procurement and has proposed CADA to create a common framework and a public-sector adoption mechanism. The proposal must complete the legislative procedure before becoming law.[4][6]

Can a company keep using foreign cloud?

Yes. The thesis does not require eliminating it, but avoiding total dependency. Cloud can be reserved for elasticity and managed services, while keeping stable workloads, strategic data, keys, backups and a real path to rebuild under European control.[6][11]

Sources

  1. U.S. House, 18 U.S.C. §2713, obligation covering data inside or outside the United States.
  2. Anthropic, U.S. directive to suspend Fable 5 and Mythos 5, June 12, 2026.
  3. Anthropic, lifting of controls on June 30 and restoration of Fable 5 and Mythos 5 on July 1, 2026.
  4. European Commission, “Sovereign Cloud Framework explained”, June 1, 2026.
  5. European Commission, €180 million sovereign cloud award to four providers, April 17, 2026.
  6. European Commission, proposal for the Cloud and AI Development Act, June 3, 2026.
  7. U.S. Department of Justice, conviction for economic espionage and theft of AI technology, January 30, 2026.
  8. U.S. Department of Justice, sentencing of Yanjun Xu for espionage, November 16, 2022.
  9. CISA and international partners, advisory on Volt Typhoon and pre-positioning in critical infrastructure, February 7, 2024.
  10. Council of the European Union, Russian hybrid activities and sanctions regime, page current as of August 2026.
  11. European Commission, “Data Act explained”, provider switching and third-country access.
  12. 37signals / David Heinemeier Hansson, self-reported savings estimate after a partial cloud exit.
  13. ipcore, profile, positioning and canonical facts of MAD-NE, reviewed August 23, 2026.
EU label for content produced with the assistance of artificial intelligence

AI tools were used for light editing and corrections in the preparation of this article. Research, claims and editorial responsibility remain with the signing author.