Wero : payment sovereignty, Bezos’s servers, the costly oxymoron

Third installment in a series on payment sovereignty in Europe. Wero: victory of the nations or the ECB’s antechamber? CB + Wero: natural alliance or programmed absorption?

The triumph and the reality on the same day

On April 21, 2026, the BPCE Group announced with great fanfare the first Wero e-commerce transactions in France. The École du Ski Français as the testing ground, Banque Populaire and Caisse d’Epargne as standard-bearers. Martina Weimert, EPI’s CEO, trotted out her usual superlatives: “a key step”, “a major step toward European payment sovereignty”, 53 million users, 130 million by 2027. The press release reeks of incense.

The same day, the German site Netzpolitik.org (the equivalent of a Mediapart specializing in digital liberties, with added rigor) published the conclusions of an unsettling investigation: Wero, the self-proclaimed champion of European digital independence, runs its critical infrastructure on the servers of Amazon Web Services.

Two announcements for a single Tuesday. One out front, the other in the wings. Which one tells the truth about the real state of Wero’s “sovereignty”? The answer, unfortunately, leaves no doubt.

The admission pried out of EPI

Netzpolitik didn’t have it easy. EPI first refused to detail which infrastructure providers Wero used, invoking “security reasons”. It was only when cornered by the journalists’ direct request that the initiative finally conceded: Wero relies on “a combination of European and international technology providers, including managed infrastructure and software services from AWS”.

Note the wording. “A combination of European and international providers”. The order of the adjectives is there to flatter. The reality is that we don’t know what share of the infrastructure is really European, nor what AWS manages exactly. EPI doesn’t say. It adds that it “retains full control of the architecture, the security model and operations” and applies “multi-layered security measures, including encryption in transit and at rest”.

These are admissible technical arguments. They aren’t worth a cent against American law.

In my first two articles on Wero, I had praised the ambition of European interoperability while staying cautious about the foundations. That caution was justified. What I didn’t know (what none of us knew) is that the foundations in question are called Amazon.

The CLOUD Act: the American law that couldn’t care less about servers on the Rhine

The Clarifying Lawful Overseas Use of Data Act, adopted in the United States in 2018, is of a brutal simplicity: it compels American technology companies to hand over to American federal authorities the data they host, wherever it is physically located in the world. It doesn’t matter whether the servers are in Paris, Frankfurt or Seoul. If the company is American, American jurisdiction applies.

This isn’t a debatable interpretation. It’s the conclusion of a legal opinion commissioned by the German Federal Ministry of the Interior itself from the University of Cologne, delivered in March 2025 and made public via the German freedom-of-information law. The ministry’s spokesperson confirmed bluntly that the use of American cloud services represents a “considerable risk of data leakage”.

It’s the German government, whose banks are among EPI’s founding members, that commissions this opinion. And EPI’s member banks still chose AWS.

Faced with this argument, Amazon puts forward its “AWS European Sovereign Cloud”, launched in January 2026 in Brandenburg. The legal entity is German, the managing director is a European citizen, the supervisory board is composed exclusively of Europeans. All of that is real. And all of that is sovereignty washing, the expression is the IT security experts’, not mine. Because the parent company remains Amazon.com, a company under American law. The legal obligations travel up the ownership chain. A European operator within a German subsidiary of Amazon can’t prevent an American federal judge from issuing an injunction to the parent company. The Rhenish facade doesn’t change the title of ownership.

AWS knows this very well, by the way. The group claims it has never disclosed data stored outside the United States in response to a request linked to the CLOUD Act, “at least since 2020, the date from which we began tracking them statistically”. The temporal qualification in that sentence should alarm any serious legal director. And the precision “linked to the CLOUD Act” leaves entirely open the question of the other legal grounds available in the arsenal of the American DOJ.

The hypocrisy toward the digital euro

This is where the case becomes frankly unbearable.

In November 2025, EPI had sent European decision-makers a scathing letter against the digital-euro project led by the European Central Bank. Central argument: the project was supposedly “designed without a clear strategic framework” and would entail “a duplication of structures and unnecessary inefficiencies”, since Europe already has a functional instant-payment infrastructure. Undiplomatic translation: move along, we’re here, no need for the ECB.

This letter had been hailed by some as an act of entrepreneurial lucidity against the technocracy of Frankfurt. I myself had granted this argument a certain legitimacy in my previous articles.

But let’s look at what EPI omitted to specify in that letter. The digital euro, by construction, would have been carried by the infrastructure of the Eurosystem: national central banks, the ECB, European public institutions. That is, a natively sovereign infrastructure, with no exposure to the CLOUD Act, no dependence on an American hyperscaler, no Jeff Bezos in the loop.

EPI therefore torpedoed a European public solution (imperfect, slow, technocratic, granted) in the name of competition and operational efficiency, in order to prefer a private solution that turns out today to be hosted at Amazon. The contrast is genuinely striking: the ECB is denied the right to build a sovereign infrastructure, it’s forbidden to “duplicate existing structures”, and one builds for oneself an alternative dependent on a company whose founder is now in Donald Trump’s political orbit.

It’s lecturing on sovereignty while living in a glass house.

The double paradox that finishes off the argument

EPI’s communication rests on a premise hammered home at every press conference: Wero frees us from Visa and Mastercard, two American companies that capture billions in commissions on European transactions and over which we have no serious regulatory hold.

The argument is correct. The conclusion (choosing AWS) is not.

Because the reasoning substitutes one American dependence for another. Worse: it degrades it. Visa and Mastercard are processing networks. They see transaction metadata pass through. AWS, for its part, hosts. It stores. It has access not only to the rails, but to the warehouse: potentially to the transactional data themselves, to usage profiles, to histories, to account aliases.

There’s a technical nuance we have to add to be honest: Visa and Mastercard, after decades of regulatory tug-of-war with Europe, ended up accepting strict constraints on data flows, audit mechanisms, binding contractual commitments. That dependence was endured, then framed over the long term. Wero, by choosing AWS from the very genesis, didn’t endure a dependence: it built it into its DNA. It’s no longer a historical constraint one is trying to extract oneself from, but a founding architectural choice.

And EPI knows it. In its responses to Netzpolitik, the initiative itself acknowledges “potential extraterritorial access requests” as a “relevant legal and geopolitical risk” and says it has “contingency and exit plans for critical technology services”. Plans whose content, stages, or activation date it refuses to reveal.

The time-to-market argument and its antidote

One has to be intellectually honest: EPI probably has an argument. It’s easy to imagine, it wasn’t formulated publicly, but it’s structural. Launching a payment infrastructure on a European scale, with 53 million users, 99.99% availability requirements, transactions in under ten seconds, unpredictable load spikes, is a colossal technical challenge. AWS offers elasticity, redundancy, certifications, support. No European cloud player in 2023-2024 had a level of operational maturity comparable at this scale. They had to move fast to exist against PayPal and Apple Pay. You take AWS now, you migrate to OVHcloud or Scaleway later.

It’s an admissible argument. It has an expiration date.

OVHcloud is SecNumCloud-qualified, the ANSSI standard that guarantees immunity to extraterritorial laws and data localization in France. Scaleway is pursuing its qualification. These players exist, they’re ramping up, they’re viable. The question isn’t, then, “can we migrate?” but “when do we migrate, and to whom?”

EPI doesn’t answer this question. It names no target European provider. It gives no date. It speaks of “exit plans” without showing them. A migration plan with no public roadmap, no milestones, no visible contractual commitment isn’t a roadmap: it’s an empty promise, whose main function is to cut short awkward questions.

Without a date for migration to a SecNumCloud infrastructure, the time-to-market argument is no longer a provisional justification. It’s the permanent excuse for a status quo that suits everyone, except the 53 million users whose data transit through it.

Conclusion: the foundations matter more than the flag

The metaphor imposes itself. Building Wero on AWS is like building a European Defense Ministry on land leased from a foreign power. You can put European guards at the door, a starred flag on the roof, appoint a managing director who is a citizen of the Union. The owner always has a spare set of keys. He can cut off the water whenever he decides, or whenever a federal judge asks him to.

And in 2026, the risk is no longer merely theoretical. Digital sovereignty has become a concrete lever of geopolitical pressure. When Washington decides to sanction a European policy (on tariffs, on Ukraine, on Big Tech regulation), having a hand on the infrastructure of the continent’s most promising payment system represents a formidable kill switch. This is no longer paranoia: it’s elementary geopolitics at a time when Jeff Bezos dines at Mar-a-Lago.

The DGFIP is considering integrating Wero for the payment of taxes, municipal levies, hospitals. Let’s allow ourselves to appreciate the irony in its fullness: the French State could find itself paying indirect commissions to Amazon to collect its own taxes, all while knowing (via the University of Cologne opinion, commissioned by its German neighbor) that this fiscal data is potentially accessible to American authorities on a simple injunction. The Republic’s fiscal sovereignty hosted at the very party it’s precisely seeking to gain financial autonomy from.

Wero has achieved something real: aggregating European banks, offering a credible alternative to the Visa/Mastercard duopoly, reaching 53 million users. That’s no small thing. In my two previous articles, I defended this project against its detractors and against those who preferred the convoluted contraption of the digital euro.

But credibility on substance demands rigor on form. And on form, Wero doesn’t yet hold to its own argument. The project’s real maturity test won’t be the move to 100 million users. It will be the day you can open the app, make a transfer, and know with certainty that the transaction never touched a server subject to American law.

That day, the “strong and independent solution” will fully deserve its slogan. Not before.


Écrivez quelques éclats d'âme...

Dans l'ombre vacillante d'une chandelle, où les murmures du vent se mêlent aux secrets d'un vieux parchemin, je vous invite à tisser une toile de mots. Écrivez quelques éclats d'âme – rêve, étoile, abîme, étreinte, brume – et laissez-les danser sur la page, comme des lucioles dans une nuit d'encre. Que diriez-vous de les entrelacer dans une phrase, un souffle, une histoire ?

Subscribe
Notify of
guest
0 Commentaires
Oldest
Newest Most Voted