Corruption Files
UK financial regulators announce new oversight for Amazon Web Services, Google Cloud, Microsoft, and Oracle.
Big Tech & Surveillance

UK Tightens Oversight of Big Tech Cloud Giants Over Data Security Risks

By

The UK government has formally classified Amazon Web Services, Microsoft, Google Cloud, and Oracle as 'critical third parties' to the country's financial services sector, bringing the four major cloud providers under direct regulatory oversight for the first time. The designation, announced by HM Treasury on 10 July 2026, took effect on 13 July, with joint supervision by the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA).

The move reflects growing concern over how deeply a small group of technology companies has become embedded in banking, payments, and insurance. The top three IT services groups — Amazon, Microsoft and Google — accounted for 73 per cent of cloud computing services provided to UK financial companies, according to a survey by the Bank of England and FCA. A major outage or cyberattack at one widely used cloud provider could disrupt several financial institutions at once, creating risks that spread well beyond a single company.

What the 'Critical Third Party' Designation Means

Under the new regime, designated cloud providers must meet operational resilience, cyber-security, and incident-reporting standards for the systemic services they supply to the financial sector. Regulators now have the authority to set resilience standards, require scenario testing, review self-assessments, and receive reports about serious incidents. The providers must identify threats to their critical services and communicate promptly with regulators and customers when significant problems arise.

The rules are limited to the specific 'systemic' services a provider supplies to the financial sector rather than regulating their entire global businesses. However, designated firms must comply with six fundamental rules requiring them to conduct their business with integrity, due skill and care, act prudently, have effective risk management systems, organize their affairs responsibly, and deal with regulators openly and cooperatively.

FCA Chief Executive Nikhil Rathi said: 'Critical third parties provide essential services which support innovation and growth. At the same time, when the same providers serve thousands of firms, a single failure can reverberate across the financial system. Operationalising this regime strengthens our ability to tackle those risks and improve overall resilience'.

Regulatory Response and Industry Implications

The critical third party regime was created by the Financial Services and Markets Act 2023 and took effect on 1 January 2025, but the July 2026 designations bring the framework into live operation. The Treasury has taken a 'targeted and proportionate approach, with these first designations focused on the most critical providers,' according to a government statement. More companies could be designated over time 'where this is necessary to protect UK resilience'.

The new oversight adds a layer of regulatory visibility on top of existing obligations. Banks and financial firms have long been responsible for assessing vendors and managing outsourcing risks — those obligations remain in place. The practical effects may appear in technology contracts, audit rights, and incident-notification procedures, potentially raising compliance costs, particularly for fintechs that build quickly by relying heavily on a single provider.

Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, said: 'As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability'.

Future Outlook and AI Considerations

Dame Meg Hillier, chair of the Treasury committee of MPs, called the move 'a huge step forward' and noted that as the use of AI in financial services expands, there may come a time when the government needs to consider designating specific AI firms under the critical third parties regime. The Mills Review, published by the FCA in July, warned that concentration in AI models, computing capacity, and cloud infrastructure could leave financial companies facing higher prices, restricted access and weaker bargaining power.

The UK's approach is narrower than the EU's, which last year designated a much longer list of 19 IT services providers for direct oversight by the bloc's regulators. City minister Rachel Blake said: 'These designations will help ensure the critical services financial firms rely on remain resilient, protecting consumers and businesses while supporting growth across the economy'.

Corruption Files — Investigative Journalism
Simone Varlette — author photo
About Author

Simone worked in network security for six years before she realized the bigger threat wasn't coming from outside corporate firewalls. She now writes about the companies that have built entire business models on the quiet collection of personal data — who they sell it to, which regulators look the other way, and how the legal language in terms-of-service agreements is specifically designed to be unreadable. She is not particularly interested in being reassured that everything is fine.

SubstackMedium

Related posts