WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Policy

Every insurer in Europe is quietly re-reading its cloud contract this month. Here is why.

DORA's first supervisory letters landed in August. They ask one question the hyperscalers can't answer cleanly: how do we leave you?

Illustration slot. The seven bleeds off the frame on lead stories only.

Placeholder article. The frontmatter is the real schema; the words are scaffolding for the template and are not editorial copy.

Placeholder copy. The frontmatter above is the real schema; the words below exist to make the template honest about line length, rhythm and where a pull quote sits.

The letters went out in the third week of August, which is either a coincidence or the most Brussels thing that has happened all year. They are short. They are polite. They ask a regulated entity to describe, in operational terms, how it would move a critical function off its current cloud provider inside a defined window, and what it would cost.

Nobody has answered yet in a way that survives a follow-up question.

The exit clause nobody costed

The exit clause has been in these contracts for years. It is usually two paragraphs long and it usually says that the provider will offer reasonable assistance during a transition period. Reasonable assistance is not a runbook. It is not a tested failover into a second provider, and it is certainly not a number.

We can tell you what our recovery time objective is. We cannot tell you what our exit time objective is, because nobody has ever asked us to have one.

A group risk officer at a mid-sized Belgian insurer, on condition that we did not name the insurer, the province, or the province next to it.

That gap is the story. DORA did not invent the requirement so much as it removed the place where the requirement used to hide.The register of information under Article 28 is the part that turned a policy question into a spreadsheet question, and spreadsheets are harder to be vague in.

What the supervisors are actually reading

Three things, in this order. First, whether the register of information matches the contracts. Second, whether the critical-or-important determination was made by someone who understands the business process rather than someone who understands the procurement portal. Third, whether the exit plan has ever been tested against anything.

The third one is where it falls apart. Testing an exit is expensive, disruptive, and produces a document that a supervisor can then read. Three excellent reasons not to do it, and none of them will survive a letter.

The part the hyperscalers get wrong

The provider response so far has been to point at portability tooling. Object storage can be replicated. Containers are containers. This is true and beside the point. The thing that does not port is the operational dependency: the identity model, the managed database's specific failure behaviour, the four engineers who know which alert is real.

A regulator asking how you would leave is not asking about data formats. It is asking whether the answer to "what if this stops" is a plan or a hope.

What happens next

Nothing dramatic, which is the usual shape of these things. The letters get answered. The answers get graded. Somewhere around the second quarter of next year, one firm gets asked to demonstrate rather than describe, and the demonstration goes badly enough to become a case study that everyone reads and nobody is named in.

Then the exit clause gets four more paragraphs, and a number.

Elias Dahnin

Editor

Placeholder bio. Elias founded Hosaka Seven and writes on procurement, devices and the gap between a policy and the invoice that follows it.