A 'kill switch' is a US provider's or the US government's ability to remotely cut a customer off from software, data, or cloud, and only 44% of European businesses have a tested continuity plan.
Almost three in four European businesses fear a US "kill switch": a US provider's or the US government's ability to remotely cut a customer off from software, data, or cloud services. Only 44% of them have a business-continuity plan they actually test, according to a survey of 1,500 firms across the UK, France, and Germany published Wednesday by Proton.
67.8% of respondents said they would switch providers if a US government action cut off their access, but only 44% have a documented continuity plan they rehearse. Stated willingness to move is roughly two-and-a-half times as common as tested preparation. The distance, not the fear, is the news.
A tested business-continuity plan for software dependencies is not a memo. It typically includes a vendor audit that maps which US-incorporated providers sit between the firm and its daily operations, an egress clause in each contract that defines how data leaves when access is cut, a multi-cloud or sovereign-fallback architecture for critical workloads, and a tabletop exercise that simulates a 24-hour outage. Proton asked whether respondents had tested such a plan; fewer than half said yes.
54.5% of respondents said they could continue operating for no more than a single business day before shutting down if they lost access to cloud and digital services, per The Register's reporting on the survey. Among large businesses, 28.7% estimated a day offline would cost more than €100,000 (about $115,000), and 45% put the damage above €50,000 (about $57,000). Every one of the 1,500 respondents reported at least one disruption in the prior 12 months: outages, cyberattacks, or service-access loss.
US hyperscalers control roughly 70% of the European cloud infrastructure market, and local European providers hold about 15%, per Synergy Research. Identity and Access Management (the authentication and authorization layer that gates every employee into every internal system) is, in The Register's framing, entirely dominated by US-incorporated vendors operating under American law. Over 74% of publicly listed European companies depend on US-based tech services for core operations, according to Proton's prior research.
A US export-control directive in June prevented non-US citizens from accessing some Anthropic AI models, per The Register. Two weeks later, the European Commission published technological-sovereignty proposals targeting risky dependencies in cloud, AI, and semiconductors, including member-state risk assessments for sensitive cloud in defence, criminal justice, and border management. Commission vice-president for tech sovereignty Henna Virkkunen said the EU must be sure no one has the "kill switch possibility." The proposals still require agreement by member states and the European Parliament.
The survey is not a neutral measurement. Proton sells a business-continuity platform covering email, conferencing, and productivity, and its report frames the gap as a market opportunity. The geography is also narrow: 1,500 firms across three countries does not represent the full EU. Proton's separate 83% consumer-concern figure, cited in TechRadar's coverage, is from a different 3,000-person poll and is not the right denominator for a business piece.
Proton COO Raphaël Auphan called the kill switch "no longer an abstract geopolitical concern but a business continuity crisis." Stated risk-aversion is cheap because a tested egress plus an audit of every US-incorporated vendor is expensive. The fear-to-preparation gap is structural, not a campaign failure. Closing it requires a contract-by-contract audit, a tabletop drill, and a budget line for multi-cloud redundancy, work that 56% of survey respondents have not done.
The next test date is the EU's legislative calendar: the Commission's proposals need member-state and Parliament sign-off before they bind.