Hamburg Calls Microsoft Dependency a Strategic Risk. The Same Logic Hits AI APIs.

On 6 May 2026, Hamburg's parliament passed a motion to assess replacing Microsoft 365 with the open-source suite openDesk across the city's public administration. The vote was near-unanimous. Only the AfD opposed it. The stated concern was not cost or features but strategic dependency on an American company subject to the US CLOUD Act.
From "Market Standard" to Sovereignty Risk in Four Months
In January 2026, the same parliament defended Microsoft as the de facto market standard, arguing that the software was too deeply integrated into inter-agency workflows to replace. By May, the SPD, Greens, CDU, and the Left had reversed course. Tim Stoberock, the SPD digitalization spokesperson and co-author of the motion, framed the shift in political rather than technical terms: the issue is strategic dependency, not whether the software works.
The Green Party went further, comparing Germany's reliance on Microsoft to its former reliance on Russian gas. The analogy is pointed. The gas dependency was also defended as pragmatic and too entrenched to unwind, right up until it became an acute vulnerability.
The CLOUD Act Problem
The legal mechanism underlying the concern is the Clarifying Lawful Overseas Use of Data (CLOUD) Act, signed into US law in March 2018. It compels American companies to provide data to US law enforcement agencies regardless of where the data is physically stored. Microsoft, incorporated in Washington State, is subject to these orders. Hamburg's data stored in a European data center is still accessible to US authorities under this statute.
This is not speculative. The Schrems II ruling (C-311/18) invalidated the EU-US Privacy Shield precisely because US surveillance law provides inadequate protection for EU personal data. The European Data Protection Board's supplementary measures guidance makes clear that data processed by US-incorporated providers carries inherent jurisdictional risk, regardless of the server location.
For Hamburg's administration, the calculus is straightforward: Microsoft's shift to cloud-default storage and subscription licensing means more data flows through US-jurisdiction infrastructure, not less.
Schleswig-Holstein: The Working Precedent
Hamburg set a deadline of 1 December 2026 to complete an analysis of Schleswig-Holstein's migration. The northernmost German state has already migrated nearly all administrative workstations from Microsoft to LibreOffice, saving an estimated EUR 15 million per year in licensing costs.
About 20% of Schleswig-Holstein's workstations still require individual Microsoft Word and Excel installations for specialized applications. The state's existing Microsoft contracts expire in 2029 and will not be renewed. Dirk Schroedter, the state's digitalization minister, has been explicit about the trajectory.
Hamburg is not starting from zero. In the Dataport data center that serves Hamburg and neighboring states, 40% of servers and 70% of middleware already run on open source.
The AI Layer Carries the Same Risk
The argument Hamburg is making about Microsoft 365 applies with equal force to AI inference APIs. When a German company sends prompts to an OpenAI or Anthropic endpoint, the data traverses infrastructure governed by the same CLOUD Act provisions. The GDPR requires that personal data processed outside the EU receives an adequate level of protection, and Schrems II established that US surveillance law does not meet that bar for data accessible to US authorities.
The risk profile is actually worse for AI APIs. Productivity suite data sits in storage, where encryption and access controls can be documented. AI inference prompts and completions are processed in transit, and most US AI providers do not offer enforceable zero data retention guarantees. The data exists, however briefly, on US-jurisdiction infrastructure, and the provider's terms of service are subordinate to the CLOUD Act.
For financial institutions subject to DORA, the concentration risk is acute. DORA Article 29 requires ICT third-party service providers to be assessed for concentration risk. Routing all AI inference through a single US provider creates exactly the kind of concentration that DORA's oversight framework is designed to prevent.
OpenDesk's Gaps Are Not the Point
A recent study found that openDesk cannot yet fully replace Microsoft 365. It has limited functionality for notifications, data exchange, sensor access, and some security features. The study's authors note that openDesk is under continuous development and that some gaps can be filled by other open-source tools like LibreOffice and Thunderbird.
The functionality gap matters for procurement decisions, but it is separate from the sovereignty argument. Hamburg's motion does not assert that openDesk is ready today. It asserts that the dependency on Microsoft is a strategic risk that must be assessed and reduced. The timeline reflects this: the motion calls for analysis by December 2026, not immediate migration.
The same framing applies to AI infrastructure. EU-native inference providers may not yet match every capability of the largest US models, but the strategic case for reducing dependency does not require feature parity. It requires a viable alternative and the political will to use it.
What This Means for EU Companies Using AI APIs
Hamburg's motion is one data point in a consistent pattern. The German Federal Ministry for Digital Transformation introduced a framework in March 2026 requiring official documents in open formats only. Munich's ruling coalition committed to open-source as the procurement default. Schleswig-Holstein is two years into a working migration. The regulatory direction is clear.
Companies building AI-powered products for EU public sector clients will face the same procurement requirements. A product that routes inference through US-jurisdiction infrastructure will not satisfy a procurement standard built on sovereignty and CLOUD Act risk avoidance.
For teams evaluating AI API providers, the assessment criteria from Hamburg's motion translate directly:
| Criterion | Microsoft 365 Assessment | AI API Assessment |
|---|---|---|
| Provider jurisdiction | US-incorporated, CLOUD Act subject | US-incorporated, CLOUD Act subject |
| Data storage location | EU data center, US-accessible | EU endpoint, US-accessible |
| Data retention | Provider stores data by default | Provider may log prompts and completions |
| Concentration risk | Single vendor for productivity | Single vendor for AI inference |
| Subprocessor transparency | Limited | Varies by provider |
EU-only inference with zero data retention and published subprocessor lists addresses these criteria directly. The infrastructure question is the same whether the workload is a spreadsheet or a chat completion.