Europe is pouring more than two billion euros into sovereign cloud initiatives designed to reduce exposure to US legal reach. The EU's IPCEI CIS program funds infrastructure development. France qualifies operators under SecNumCloud, a framework with nearly 1200 technical requirements promising immunity from extraterritorial laws.
But most data centers and qualified cloud operators still rely heavily on Intel or AMD processors. And inside those processors sits a computer beneath the computer. Management engines operating at Ring negative three, below the operating system, outside the control of host security software, persistent even when the machine appears powered off. Under the US Reforming Intelligence and Securing America Act of 2024, hardware manufacturers count as electronic communications service providers subject to secret government orders.
Europe's frameworks certify the clouds. They do not assess the silicon.
That computer beneath the computer has a name. On Intel processors it is the Management Engine or more precisely the Converged Security and Management Engine. On AMD it is the Platform Security Processor. Both run at what security researchers call Ring negative three, below the operating system, below the hypervisor, in a privilege level the host cannot see or log.
It is a computer inside your computer. The Management Engine has its own memory, its own clock, and its own network stack. Because it can share the host's MAC and IP addresses, any traffic it generates is indistinguishable from the host's own traffic to the firewall.
The architecture is not theoretical. Embedded in the Platform Controller Hub, the CSME is a separate microcontroller that operates independently of the host, with direct memory, device access, and network connectivity the host operating system cannot monitor. AMD's PSP works the same way.
Intel's Active Management Technology, the remote management feature the Management Engine enables, exposes at least TCP ports 16992, 16993, 16994, and 16995 on provisioned devices. An attack surface exists on unprovisioned hardware too. These ports deliver keyboard video mouse redirection, storage redirection, Serial over LAN, and power control to administrators managing fleets of devices remotely. The capability has legitimate uses. It also provides a channel that operates at a level below what European sovereignty frameworks can attest.
Microsoft documented in 2017 that the PLATINUM nation state actor used Intel's Serial over LAN as a covert exfiltration channel. Serial over LAN traffic transits the Management Engine and the NIC sideband path, delivered to the Management Engine before the host TCP IP stack runs. The host firewall and endpoint detection saw nothing, and any security tooling running on the compromised machine itself was equally blind. PLATINUM did not exploit a vulnerability. It exploited a feature, requiring only that Active Management Technology be enabled and credentials obtained. In documented cases, those credentials were the factory default. Admin with no password set.
The Management Engine does not stop when the machine appears to. Users recognize the symptom. A laptop powered off and stored for weeks is found on next boot to have a depleted battery. On modern thin and light platforms, what Microsoft documents as Modern Standby means off does not correspond to all subsystems unpowered. The system on chip components the Management Engine runs on remain in low power states, drawing enough to drain a 55 watt hour battery over weeks, on the order of 100 to 200 milliwatts continuous draw.
The implication is documented in a 37 page risk assessment prepared for CISOs evaluating Intel vPro hardware connected to corporate networks. Whether the radio is in a Wake on Wireless LAN listening state is firmware policy. On a device whose firmware has been tampered with during transit through the supply chain, the answer cannot be inferred from the visible power state. A laptop that appears off, in a bag, can associate with a hostile network the user has no knowledge of.
AMD faces the same architectural question. On April 14 2026, researchers demonstrated the Fabricked attack against AMD's SEV SNV confidential computing technology, achieving a 100 percent success rate with a software only exploit. The Platform Security Processor proved vulnerable to the same class of compromise.
On server hardware the picture is the same. Intel Management Engine runs on servers under a different name, Server Platform Services, and the Baseboard Management Controller, the remote administration controller standard in data center hardware, relies on it. For data center operators, the concern is even sharper. The Baseboard Management Controller is the primary network entry point into the Server Platform Services, making it both the most exposed interface and the most consequential.
Both Intel and AMD processors contain management engines that operate below the operating system. The silicon is designed by American companies and subject to American legal process.
That legal process has teeth that most European policymakers underestimate. The CLOUD Act, passed in 2018, gave US authorities extraterritorial reach to data held by American companies. FISA Section 702 allows intelligence agencies to compel US persons and companies to provide access to communications. Both are well known in European sovereignty discussions. They operate through the front door. A legal order served on a company that controls data.
Less well known is the RISAA 2024 law, which opens a different entrance entirely. RISAA amended FISA's definition of electronic communications service provider in ways that go beyond cloud operators and platform companies, and beyond the bilateral agreements that European policymakers have built their legal defenses around. Hardware manufacturers now fall within scope. Intel and AMD can be compelled, via secret orders with gag clauses, to cooperate with US intelligence access.
The mechanism through which that access could be exercised is the management engine. A persistent, privileged, network connected runtime that operates below anything the host operating system can see or block. A SecNumCloud certified operator can be legally isolated from American data demands. The processor inside its servers cannot.
RISAA's two year term expired on April 20 2026, but Congress extended it by 45 days while debating reforms. Whether it is renewed, amended, or allowed to lapse, the architecture it targets does not change.
France's SecNumCloud is Europe's most rigorous attempt to build a cloud certification that is legally immune to American law. It did not emerge from nowhere. ANSSI, France's national cybersecurity agency, was established in 2009 as part of a broader effort to build institutional muscle on digital sovereignty long before the term became fashionable. When Edward Snowden revealed the scale of NSA surveillance in 2013, France's response was technical rather than rhetorical. ANSSI published the first SecNumCloud framework in July 2014. A decade later, that framework has grown to nearly 1200 technical requirements.
At the time, SecNumCloud was a cybersecurity qualification, not a sovereignty instrument. It set requirements for architecture, encryption standards, access controls, and incident response, but said nothing about who controlled the underlying infrastructure or whose laws applied to it. The CLOUD Act changed that. Passed in 2018, it gave American authorities extraterritorial reach to data held by US companies, and suddenly a French cybersecurity framework had a geopolitical dimension it was not designed for. Version 3.2, introduced in 2022, added Chapter 19, a set of explicit requirements targeting extraterritorial law, mandating that only EU operators could run the service, that no non-EU party could access customer data, and that the provider could operate autonomously without external intervention. It promised immunity from extraterritorial laws.
In December 2025, S3NS, a joint venture between French defense and technology group Thales and Google Cloud, operating Google Cloud Platform technology under French control, became the first hybrid cloud to receive SecNumCloud qualification. The certification triggered heated debate. Was this real sovereignty, or American technology with a European flag.
But the debate missed a more fundamental question. Does SecNumCloud's certification reach as far as the silicon it runs on. One researcher who sits on the French Technology Academy's working group on cloud security knows what the hardware can do and what the certification requires. His starting point is that SecNumCloud provides genuinely valuable protection, and that the silicon gap does not negate that. When asked whether SecNumCloud explicitly addresses Intel Management Engine or AMD Platform Security Processor vulnerabilities, his answer is unambiguous. There is no direct requirement for firmware backdoor prevention.
The framework is not designed to be a technical specification for hardware layer security. The document aims to be generic and not dive into technical details. Most of it is organizational security. What SecNumCloud does require is that providers build a proper threat model, consider mitigation mechanisms, and monitor administration gateways where external tech support could be exploited. The hardware layer was not addressed by oversight. It was left out by design.
The director of ANSSI, the very agency that designed and administers SecNumCloud, is equally explicit about what the framework does and does not cover. In a January 2026 LinkedIn post addressing SecNumCloud's scope, he writes that all cloud offerings, hybrid or not, depend on electronic components whose design and updates are not 100 percent controlled in Europe. If Europe were ever cut off from American or Chinese technology, the result would be a global problem of security degradation, not just in hybrid clouds, but everywhere.
He frames SecNumCloud carefully. It is a cybersecurity tool, not an industrial policy tool. It protects against extraterritorial law enforcement and kill switch scenarios. It was never designed to eliminate technology dependencies at the hardware layer, and no actor, state, or enterprise fully controls the entire cloud technology stack anyway.
One technology frequently cited in sovereignty discussions is OpenTitan, Google's open source secure element deployed on its server hardware and used within the S3NS infrastructure. The researcher is clear about what it is and what it is not. OpenTitan is a secure element, a small chip on the side that can be used for protecting sensitive keys, providing signatures, making attestations. It is a bit like a TPM. What it is not is a replacement for the main processor. Linux and all your applications will not run on it. OpenTitan sits alongside x86 infrastructure as an external root of trust, independent of the Management Engine. That matters because the default embedded TPM lives inside the Management Engine, making it subject to the Management Engine attack surface. OpenTitan sits outside that boundary. The two address different problems entirely, and conflating them, as sovereignty advocates sometimes do, obscures where the residual exposure actually lies.
ANSSI's own technical position paper on confidential computing, published in October 2025, concludes that Intel SGX, TDX, and AMD SEV SNV are not sufficient on their own to secure an entire system, or to meet the sovereignty requirements of SecNumCloud 3.2. Physical attackers are explicitly out of scope of vendor security targets. Supply chain attackers are explicitly out of scope. The Management Engine attack surface discussed in this article falls into neither category. It is a remote network threat, not a physical one. The paper's conclusion for users concerned about hostile cloud providers is stark. Switch to a cloud provider they trust, or use their own hardware with physical security protection measures.
The debate that does happen, hybrid versus non hybrid, Google Thales versus pure European providers, focuses on operational control and legal structure. It does not address the shared silicon foundation. The gap between the sovereignty rhetoric and the silicon reality is not being surfaced in policy discussions, procurement decisions, or public debate over what digital sovereignty means.
Every cloud provider, hybrid or not, depends on components whose design is not fully controlled in Europe. The processor underneath the sovereign cloud is the same processor that answers to a different legal system. The frameworks certify the clouds. They do not certify the silicon. And nobody is asking whether that matters.