Cloud Computing Watch: Cloud Becomes Critical Infrastructure; Multicloud as a Continuity Strategy
The Cloud Is Becoming Critical Infrastructure: Resilience, Sovereignty and the New Cloud Risk
The Cloud Is Becoming Critical Infrastructure
Amazon Web Services has told customers it cannot restore access to its cloud facility in Bahrain and one availability zone in the United Arab Emirates after infrastructure was damaged during the Iran war earlier this year. AWS has been helping customers move operations to other regions and recover from remote backups.
The incident is not evidence that cloud computing is inherently unreliable. It is evidence that the cloud is physical infrastructure—and that the risks facing physical infrastructure increasingly determine the reliability of digital services. Beneath every cloud abstraction are data centers, servers, accelerators, storage systems, cooling equipment, electrical substations, backup systems and fiber connections.
As enterprises move databases, AI systems and critical applications into hyperscale infrastructure, cloud resilience is becoming a strategic issue involving physical security, geopolitics, sovereignty, business continuity and concentration risk. The phrase “it is in the cloud” no longer answers the disaster-recovery question.
The Cloud’s Hidden Physical Layer
Cloud computing is an abstraction built on a large and highly concentrated physical system. Beneath an application programming interface are data centers, servers, accelerators, storage systems, cooling equipment, electrical substations, backup generators, and fiber connections.
That physical layer has become more consequential as workloads grow more demanding. AI systems require high-density accelerators, fast interconnects, large storage pools and substantial power. A database or enterprise application may tolerate a carefully managed performance reduction during a crisis. A large AI cluster may depend on a particular combination of GPUs, networking and data access that is difficult to reproduce elsewhere.
Microsoft’s latest disclosures show how physical constraints are already influencing cloud economics. The company said Azure demand continued to exceed available capacity and that it expected to remain constrained through 2026. Microsoft added another gigawatt of capacity during its fiscal third quarter and said it remained on track to double its overall data-center footprint in two years.
Cloud abstraction reduces operational complexity, but it does not eliminate physical risk.
AWS Bahrain and UAE: A New Resilience Case Study
AWS’s Middle East disruption is an important case study because it affected the layer of infrastructure that customers often treat as a resilience boundary.
Availability zones are designed as separate facilities within a cloud region. They generally have independent power and cooling systems and are separated by enough distance to reduce the risk that a single incident affects all of them. Customers can distribute applications across multiple zones to protect against the loss of one facility.
That model is powerful, but it has a defined scope. AWS said the Bahrain damage spanned multiple availability zones and exceeded what its regional and multi-zone services were designed to withstand. In the UAE, AWS said it was unable to restore resources and data hosted exclusively in one availability zone, while recovery continued elsewhere in the region.
The problem was therefore not simply that one server failed. It was that an event crossed the boundary between an isolated facility incident and a regional infrastructure crisis.
AWS has supported Bahrain customers in re-establishing operations in other regions. Reports based on AWS updates indicate that customers have had to restore from remote backups, copy accessible data, or implement alternative arrangements. Some resources that were not moved before the disruption could not be restored.
A multi-availability-zone deployment is not automatically a multi-region disaster-recovery plan. Nor is a backup policy useful if the backup is stored in the same geographic and physical risk area as the production system.
“It’s in the Cloud” Is Not a Recovery Strategy
Cloud resilience is a shared responsibility. Providers are responsible for infrastructure, core services, and the design of their availability architecture. Customers remain responsible for selecting regions, configuring replication, testing recovery procedures, and determining how much data loss is acceptable.
The practical lesson is straightforward: resilience must be designed against the failure scenario that matters, not merely against the failure scenario a provider’s default architecture is intended to handle.
Multicloud as a Continuity Strategy
Multicloud has often been justified by price negotiations, regulatory flexibility, or access to different services. Those motivations remain valid, but a new rationale is becoming more important: business continuity.
A single-hyperscaler strategy can be efficient. It simplifies identity, networking, observability, security, and procurement. Applications can use tightly integrated services, while internal teams avoid learning several control planes. For many workloads, the operational simplicity may outweigh the theoretical benefits of provider redundancy.
The trade-off is concentration. A company that uses one provider, one region, and several proprietary services may be highly efficient under normal conditions but difficult to move during a crisis.
| Architecture | Main Benefit | Main Risk |
|---|---|---|
| Single hyperscaler | Lower complexity and deeper integration | Greater provider and geographic concentration |
| Multicloud | Provider and regional redundancy | More complex identity, networking, and operations |
| Hybrid cloud | Local control for selected workloads | Higher infrastructure and management burden |
| Sovereign cloud | Jurisdictional and operational control | Smaller scale and potentially higher cost |
The appropriate choice depends on workload criticality. A low-risk internal application may not justify the cost of operating across two providers. A payments platform, emergency service, industrial control system, or national-government database may require independent recovery infrastructure even if that creates additional expense.
Sovereignty Becomes Operational
Cloud sovereignty is often reduced to data residency: the requirement that information remain inside a particular country or region. That is only one part of the issue.
Enterprises and governments increasingly want to know:
- Where data is stored and processed.
- Who operates the infrastructure.
- Which jurisdiction governs the provider.
- Who can access administrative systems.
- Whether foreign authorities can compel disclosure.
- Whether the service can remain operational during a geopolitical crisis.
- Whether the organization can recover without relying on a foreign region.
The European Commission’s Cloud Sovereignty Framework reflects this broader definition. It evaluates providers across sovereignty and resilience objectives, including strategic, legal, operational, environmental, supply-chain, technological and security considerations.
The market is therefore moving beyond a simple public-cloud versus private-cloud distinction. The emerging architecture includes public cloud, private infrastructure, sovereign cloud, edge systems and multiple providers connected through common identity, data and security controls.
AI Increases Concentration Risk
AI makes cloud resilience more important because it increases the physical and financial concentration of computing.
AI workloads depend on accelerators, high-speed networking, large-scale storage and dense power and cooling systems. Those components are expensive and difficult to replicate quickly. A company may be able to move a conventional web application between regions relatively easily, but relocating a large training cluster or a latency-sensitive inference service may require compatible hardware, software and network capacity.
Oracle is a useful example. The company booked more than $30 billion in new AI cloud contracts during its latest fiscal quarter, lifting its remaining performance obligations to $664 billion. Oracle said roughly half of its backlog is expected to convert into sales during the next 36 months.
The same infrastructure that creates economies of scale can create correlated failure. If a single region contains the necessary accelerators, data, model-serving software and network paths, moving the workload elsewhere may be technically possible but commercially impractical.
A Concentrated Cloud Market
The cloud market is not a fragmented utility market. A small number of providers control a substantial share of global compute, storage, networking and enterprise workloads.
Microsoft has now disclosed Azure revenue separately, reporting $29.4 billion in quarterly sales and $101.9 billion for the fiscal year ended June 30, 2026. AWS reported approximately $42.2 billion in quarterly cloud sales, while Google Cloud reported about $24.8 billion.
According to figures attributed to Synergy Research Group, AWS, Azure and Google Cloud together represented approximately 63% of global cloud infrastructure spending in the second quarter of 2026.
What Enterprises Should Watch
Cloud resilience
- Multi-region deployment for critical workloads.
- Clearly defined recovery time objectives and recovery point objectives.
- Tested restoration from independent backups.
- Recovery procedures that do not depend entirely on the affected provider region.
Geographic risk
- Data-center location and physical separation.
- Exposure to conflict, natural disasters, water stress, and power shortages.
- Diversity of fiber routes and network providers.
- Availability of compatible capacity in a second region.
Sovereignty and concentration
- Data residency, processing location, and administrative access.
- Applicable jurisdiction and legal-compulsion risk.
- Dependence on one hyperscaler or proprietary platform services.
- Cost and time required to migrate.
- Availability of portable data and application layers.
What to Watch Next
- Hyperscaler geographic diversification: Are AWS, Azure and Google Cloud distributing critical capacity more broadly?
- Sovereign-cloud investment: Does regional infrastructure become a larger part of enterprise cloud strategy?
- Multicloud interoperability: Do providers make cross-cloud workloads easier to operate?
- Disaster-recovery requirements: Will enterprises increase spending on independent backup and recovery?
- AI workload concentration: Does AI increase dependence on a small number of cloud regions and providers?
The CODEW Stat
63%: The approximate combined share of global cloud infrastructure spending held by AWS, Azure, and Google Cloud in the second quarter of 2026. The figure illustrates both the scale advantages and the systemic-risk implications of hyperscaler concentration.
The cloud is becoming critical infrastructure because the economy has begun to depend on it as if it were a utility, while its underlying risks remain closer to those of a concentrated industrial system.
Hyperscalers still provide stronger infrastructure and recovery capabilities than most enterprises could build alone. But that advantage does not absolve customers from designing for regional, provider, and jurisdictional failure.
The next phase of cloud strategy will therefore be less about choosing between cloud and on-premises infrastructure. It will be about assigning each workload an appropriate level of geographic diversity, operational control and provider independence.
Cloud is no longer merely where computing happens. It is part of the infrastructure that modern economies must learn to protect.
Sources
- Reuters — AWS unable to restore access to Bahrain and one UAE cloud zone after war damage
- AGBI — AWS war damage puts some cloud data beyond recovery
- Microsoft Investor Relations — Fiscal Year 2026 Third Quarter Earnings
- Reuters — Oracle tops estimates as AI demand drives cloud demand
- Reuters — Microsoft reveals Azure cloud sales in reporting shift
- European Commission — Sovereign Cloud Framework
- European Commission — Strategic procurement and cloud sovereignty
- Synergy Research figures — Cloud infrastructure market concentration
- The CODEW — AI Turns Cloud Infrastructure Into a Capacity Race
Reviewed by Erwin Castro
on
Wednesday, September 16, 2026
Rating:
