UK designates cloud giants as critical third parties
Analysis based on 27 articles · First reported Apr 20, 2026 · Last updated Jul 14, 2026
The regulatory designation imposes new compliance costs on Microsoft, Alphabet Inc., Amazon — Amazon Web Services, and Oracle, but also provides regulatory clarity that may reduce long-term operational risk for financial sector clients. The move is unlikely to materially affect revenues given the essential nature of cloud services, but could set a precedent for other jurisdictions.
The UK government has designated Microsoft, Alphabet Inc., Amazon — Amazon Web Services, and Oracle as critical third parties (CTPs) to the financial system, effective July 13, 2026. This brings the four cloud giants under direct regulatory oversight by the United Kingdom — Bank of England, United Kingdom — Prudential Regulation Authority, and United Kingdom — Financial Conduct Authority for the first time under the Critical Third Parties regime established by the Financial Services and Markets Act 2023. The designation aims to protect the financial system from risks posed by increasing reliance on cloud services, where an outage at a major provider could affect multiple financial firms simultaneously. The companies will be required to undergo resilience testing, conduct regular self-assessments, and report major incidents. United Kingdom — HM Treasury noted that over 65% of UK organizations depend on these four providers for cloud infrastructure services. The UK's approach contrasts with the European Union, which designated 19 technology firms under a similar framework in November 2025. All four companies issued supportive statements, with Microsoft calling the designation 'a new chapter' in its relationship with UK agencies.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard