Britain has placed Microsoft, Google, Amazon Web Services and Oracle under direct financial regulation, formally naming all four as 'critical third parties' to the UK financial sector. The designation, announced on Friday 10 July and reported by Reuters, takes effect on 13 July and marks the first time any government has applied financial-sector supervisory powers directly to US cloud companies.

The three regulators sharing responsibility are the Bank of England, which oversees financial stability; the Prudential Regulation Authority (PRA), which supervises banks and insurers; and the Financial Conduct Authority (FCA), which polices market conduct. Together, they will now have the authority to scrutinise the cloud infrastructure that underpins everything from digital payments to fraud detection at British banks.

Why 'concentration risk' alarmed regulators

The core concern is one regulators have been tracking for years. Amazon, Google and Microsoft alone supply around 73% of UK financial firms' cloud services, according to Traders Union. That means a single serious outage at any one of them could ripple simultaneously across dozens of banks, insurers and market infrastructure providers, with consequences for millions of customers.

"As banks, insurers and financial market infrastructures become increasingly reliant on cloud services, disruption at a major supplier could affect multiple firms at the same time, potentially impacting services customers depend on." — UK government statement, 10 July 2026

The Bank of England first flagged the problem publicly in 2021, warning that deeper dependence on a concentrated group of providers could increase financial stability risks without stronger direct oversight. The legislative foundation for the new regime was laid by the Financial Services and Markets Act 2023, which gave HM Treasury the power to designate critical third parties where disruption could threaten financial stability or market integrity.

What the rules actually require

Under the new framework, the four companies must conduct annual self-assessments of their own resilience and run scenario-testing exercises that simulate major disruptions, from cyber-attacks to power failures and natural disasters. Any significant incident must be reported directly to the Bank of England and the FCA. Regulators can gather information, assess operational resilience and, if necessary, introduce rules specific to individual critical third parties.

Crucially, the oversight is ring-fenced: it applies only to the services these firms provide to the financial sector, not to their broader cloud businesses or consumer products. The specific legal entities named are Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL and Oracle Corporation UK Ltd, reflecting the European and UK corporate structures through which these services are delivered.

A model others may follow

The UK's move comes as regulators in multiple jurisdictions wrestle with the same tension between the efficiency gains of cloud adoption and the systemic risks of market concentration. The EU's Digital Operational Resilience Act (DORA), which came into force in January 2025, imposes similar third-party oversight requirements across the eurozone. Britain's designation is nonetheless significant: it is among the first to name specific global cloud firms by entity and place them under a standing supervisory regime tied to financial stability law.

"The increasing reliance on a small number of cloud service providers... could increase financial stability risks without greater direct regulatory oversight." — Bank of England Financial Policy Committee, 2021

Shares in all four companies showed little immediate reaction to the announcement, which had been widely anticipated following years of regulatory consultation. For London's financial sector, the practical impact will become clearer once the supervisory bodies begin their first formal assessments under the new powers.

This article is free to read. It always will be — no paywall, no account, no tracking.