You are a Dutch competition regulator. You correspond, by email, with the US platforms you supervise. You assume that correspondence is protected — by GDPR, by Dutch administrative law, by the fact that those platforms maintain European subsidiaries answerable to European courts. Last Friday afternoon you learned which of those assumptions was load-bearing.

The answer: none of them.

On Friday, 22 May 2026, the Dutch magazine Vrij Nederland published that Microsoft had handed your emails to a US Congressional subpoena. The recipient was the House Judiciary Select Subcommittee on the Weaponization of the Federal Government, chaired by Jim Jordan. The subpoenas had gone out the previous July — to ten tech companies, demanding internal communications with foreign governments about content moderation. Microsoft’s response, when Vrij Nederland verified it, included the unredacted names of civil servants at the Autoriteit Consument en Markt (ACM) and the Autoriteit Persoonsgegevens (AP) — the regulators enforcing the EU Digital Services Act in the Netherlands.

Then Microsoft offered an explanation that should worry you more than the disclosure. The CLOUD Act was not invoked. The compliance was voluntary.

That word — voluntary — is the part of this story that almost no public commentary has correctly placed. If the CLOUD Act had compelled the disclosure, the affected regulators would at least have a legal threshold to argue against in court. Voluntary compliance means there was no threshold. There was Microsoft’s commercial judgement that cooperating with a Congressional subcommittee was preferable to refusing. The judgement was rational. It was also, in the strict sense, completely unconstrained by European law.

The names are in Washington now. The committee that asked for them describes the work the affected civil servants do as “censorship of American speech”. The Dutch state secretary for digital sovereignty, Willemijn Aerdts, summoned the US ambassador on the same Friday. The data was already on its way.

This article is the audit of the architecture that produced the outcome, the reframe that makes the audit useful, and the procurement question every European regulator and ministry needs to answer before the next subpoena lands.

What Microsoft handed over

The contents were not summaries. They were the raw working material of regulators: emails between named ACM and AP staff and Microsoft’s corporate representatives, calendar entries for internal meetings, minutes from discussions of DSA implementation. The committee received the names in full. According to reporting in iBestuur, Meta shared similar data; the other eight subpoenaed companies have not publicly confirmed compliance.

The committee’s stated remit is to investigate whether European online-platform regulation constitutes censorship of US companies. The civil servants named in the documents are the people responsible, in the Dutch jurisdiction, for enforcing exactly the rules the committee is investigating. The Weaponization Subcommittee now has, in its files, the names of European officials enforcing rules it considers hostile.

Cybernews reports that some affected employees have family in the United States and now fear being denied entry. That fear is not theoretical: the Trump administration has sanctioned European civil-society leaders, including the management of the German NGO HateAid in December 2025, for what it considered hostile speech regulation. The pathway from a name on a Subcommittee list to an entry ban at the US border is shorter than European regulators have historically assumed.

By Friday afternoon, Staatssecretaris Willemijn Aerdts had told the US Ambassador, Joe Popolo, to his face: “Als ik problemen heb, vecht je die met ons uit of, indien nodig, in Europa, maar niet over de ruggen van ambtenaren heen.” (“If you have a problem, you fight it out with us, or if necessary in Europe, but not over the backs of civil servants.”) Aerdts had been appointed three months earlier as the Netherlands’ first Staatssecretaris for Digital Economy and Sovereignty, in the Cabinet-Jetten of 23 February. The ambassador she summoned had arrived in The Hague even more recently. The intervention was substantive. It was also, in the strict procurement sense, hollow: it summoned a diplomat, not a vendor.

The defence is the disclosure

Microsoft has not issued a detailed public statement on the Dutch matter. Reporting consistent across NL Times, Dutch IT Channel and Cybernews indicates the framing the company has used in private and in the trade press: the disclosure was not triggered by a CLOUD Act obligation. The released material, the framing goes, was correspondence between Microsoft and European authority representatives — and that correspondence fell outside the protections European regulators may have assumed they had.

The framing was offered as exoneration. Read carefully, it is the opposite. If the CLOUD Act had compelled the disclosure, European regulators would at least have a legal threshold to litigate against. The voluntary framing means there was no threshold at all — only Microsoft’s commercial judgement that cooperating with Jim Jordan’s Subcommittee was preferable to refusing it. The defence makes the situation worse than the accusation makes it.

The framing serves Microsoft in a second way: it allows the company to position the incident as a one-off matter of judgement rather than a structural exposure under US law. It also serves the Dutch cabinet, which can externalise the problem to a US vendor instead of explaining why ACM and AP communications were on a US-hosted platform at all. Aerdts’s intervention with Ambassador Popolo, while substantive, did not commit the cabinet to a procurement change. The Junior Minister for Economic Affairs, Eric van der Burg (VVD), called the disclosure “more than worrying” — strong language for a Dutch state secretary, weaker than a commitment.

What was on offer in the Microsoft framing was an absolution. What was actually said, once you parse it, was: we were under no obligation to hand this over. We chose to. That is not a defence in any sense the affected civil servants would recognise. It is an admission, dressed as a clarification.

The architecture this exposes

The Microsoft 365 estate of European regulators is large, deep, and almost entirely undocumented in public.

A rough estimate, working from procurement disclosures and trade-press reporting, puts the share of European national-level regulators with their primary internal communications running on Microsoft 365 above 70%. The Bundesnetzagentur in Germany, ARCEP in France, AGCOM in Italy, CNIL in France, the German Bundeskartellamt, the Spanish CNMC — most of these run on M365 or have substantial M365 surface in their day-to-day operations. Most of them also enforce, in some capacity, US-platform-relevant law: GDPR, DMA, DSA, Data Act, competition rules. The intersection — regulators of US platforms who use US platforms for their internal regulator communications — is essentially the European regulatory landscape as it stands today.

The architectural consequence is that every regulator in that intersection runs the same supply-chain exposure the ACM and AP just learned the operational definition of. The data lives on infrastructure operated by an entity that, when faced with a US Congressional subpoena, will respond commercially. That commercial response will reliably point in the direction of cooperation. The Microsoft framing in the Dutch case made the commercial logic explicit: the company was responding to a subpoena, not a CLOUD Act order; the cooperation was voluntary. Every other regulator in the same estate is in the same architectural position. The next subpoena will be answered by the same logic.

There is a second-order exposure that has not been widely discussed. The civil servants named in the Dutch documents were not the only ones in those email threads. Correspondence with Microsoft about DSA implementation routinely loops in adjacent staff at other European regulators — coordination across national authorities is part of how the DSA is enforced. The Subcommittee subpoena to Microsoft covered, by its own framing, internal communications with foreign governments about content moderation. That language is broad enough to reach the correspondence chains, not only the individual senders. The actual names list, on a careful read of the subpoena scope, plausibly extends beyond ACM and AP, into adjacent EU regulators that have not been publicly affected — yet.

The pattern beneath the case

This is not the first time a US vendor has exposed European officials to US authorities under political pressure. It is the third documented case in thirteen months.

In May 2025, Microsoft suspended the email account of Karim Khan, Chief Prosecutor of the International Criminal Court, after the Trump administration imposed sanctions on him personally under Executive Order 14203. In December 2025, the same administration sanctioned the management of HateAid, a German NGO that supports victims of online hate speech, with US entry bans. In May 2026, Microsoft handed over the Dutch regulators’ names.

The Khan case ran under a sanctions designation: legal compulsion. The HateAid case ran under entry-ban regulations: administrative action against named individuals. The Dutch case runs under a House subcommittee subpoena: legislative inquiry. The legal instruments differ. The pattern does not. In each case, a US-headquartered service provider was asked, formally or informally, to act against a European who had become politically inconvenient in Washington. In each case, the provider complied.

The Dutch case differs from the first two in a way that matters. The Khan case had a sanctions designation behind it; HateAid had administrative action. Both gave Microsoft a legal compulsion to point at when explaining itself to European regulators. The Dutch case has no such cover. Microsoft’s own framing concedes the absence: the disclosure was not legally required, it was commercially preferable. The pattern’s third case is the one where the commercial logic was named out loud.

That naming has a strategic consequence the trade press has missed. The first two cases produced general nervousness about US legal exposure under M365. The third case has produced specific evidence of US commercial exposure under M365: the same vendor, the same architecture, can produce the same outcome without any legal threshold at all. There is no court anywhere in Europe that can litigate against Microsoft’s commercial judgement. There is only the procurement contract, which is the level at which European institutions can change the architecture.

Why the protest does not change the architecture

The cabinet summoned the US ambassador. There has been a diplomatic exchange. Microsoft may yet issue a public clarification. None of this changes the structural conditions.

After the dust settles, three things remain exactly as they were. Microsoft can still receive requests from US legislative, executive and judicial bodies. Microsoft can still decide voluntarily to cooperate beyond what it is strictly required to do. ACM, AP and most other European regulators still run their offices on Microsoft systems, with their communications still subject to the same exposure. The incident has produced political heat. It has not produced architectural change.

The Dutch cabinet’s response is structurally what Microsoft’s framing predicted. The intervention treated the disclosure as a vendor-relations incident rather than as a procurement incident. The vendor was summoned via the diplomat; the procurement contract was not summoned at all. Aerdts is on record as an advocate for digital sovereignty. The structural problem is that her portfolio does not control the cabinet’s procurement decisions, and the procurement decisions are the lever the incident illuminated.

The Junior Minister’s “more than worrying” language is the index of how this story will end. Strong language signals concern. It does not signal commitment. A commitment would look like a date, a budget, a target, a named alternative. There is no date.

Sovereignty is not a diplomatic incident

This is the reframe the incident makes visible to anyone in a European regulator, ministry or public-sector body with operational responsibility.

The Dutch case is not the failure of a diplomatic relationship. The diplomatic relationship is doing exactly what diplomatic relationships do — it expresses concern, registers protest, summons ambassadors, drafts notes verbales. The Dutch case is the failure of a procurement decision made years earlier, when ACM and AP adopted Microsoft 365 on the same reasonable institutional grounds as every other European regulator. The cabinet’s diplomatic response operates at the wrong layer. The architecture lives at the procurement layer. The architectural answer also lives at the procurement layer.

This is the layer where the Dutch case applies to every reader who works in or with a European public-sector body. The question is not what will the cabinet do? The cabinet will do what cabinets do: summon, protest, register concern. The question is whether your organisation, on the next quarterly procurement review, treats the disclosure as a relevant fact about your own M365 contract.

The sovereignty question, properly framed, is not which vendor do we use for our email? It is: if Microsoft were asked, today, by a US Congressional subcommittee, for our internal communications, what would Microsoft’s commercial judgement be? The honest answer, on the Dutch precedent, is: the same as it was for the Netherlands. The architectural answer to that question is not a different vendor. It is a different architecture: regulatory communications routed through infrastructure that does not have a US commercial calculus in its chain of custody.

What this article is not

Anyone reading this analysis as a claim that Microsoft acted illegally has missed the point — by the company’s own framing the disclosure was neither legally compelled nor malicious, but a commercial calculation before a powerful US political actor. The analysis operates one layer deeper: at the structural condition that this commercial calculation can return to the table at any moment, as long as the underlying procurement architecture remains unchanged. Predictions about the behaviour of individual vendors in future cases are outside the scope of the investigation. For readers in regulated environments, this analysis does not substitute for legal or information-security advice.

The next name on the list

The civil servants whose names are in a House Judiciary subcommittee file are still at work. The Digital Services Act still needs to be enforced. The Weaponization Subcommittee has not closed its investigation. Microsoft has not retracted the documents — there is no procedure for retraction once a subcommittee has them.

The next request from a US authority to a US vendor about a European regulator will be answered by the same commercial logic that answered this one. Until the architecture changes, the names of the Dutch civil servants are not the last names that will end up in a House subcommittee file. They are the third.

The signal worth watching, twelve months from now, is procurement. If ACM or AP announce a migration of their internal communications off Microsoft, the incident has had structural consequences. If they do not, Aerdts’s intervention with Popolo will be the entire response — and the next name on the list is already on its way.

Sources


Topic overview: Digital Sovereignty in Europe Related articles: Sovereignty on Microsoft’s servers, Digital Sovereignty: Why Now