Cloud Concentration Risk: What UK CIOs Must Manage in 2026
UK CIOs must treat hyperscaler dependency as a governance risk, not a procurement footnote: the Competition and Markets Authority (CMA) opened a Strategic Market Status investigation into Microsoft’s cloud licensing in May 2026.
The probe, launched under the Digital Markets, Competition and Consumers Act 2024 (DMCCA), targets licensing terms that critics say make it harder and more expensive to run Windows Server and SQL Server workloads on rival clouds. For CIOs who have spent a decade consolidating infrastructure onto one or two hyperscalers, the investigation is a signal: concentration that once looked efficient now looks like exposure — commercial, operational and regulatory.
Why Is the CMA Investigating Microsoft’s Cloud Licensing Now?
The CMA’s concern is straightforward: Microsoft’s dominant position in enterprise software gives it leverage to shape cloud competition through licensing terms, egress charges and interoperability restrictions. The Strategic Market Status investigation, expected to run around nine months, follows an earlier cloud services market investigation that concluded in July 2025 without SMS designations, after Microsoft and AWS agreed voluntary commitments on egress fees and interoperability. Regulators judged those commitments insufficient to address licensing-driven lock-in, hence the fresh, narrower probe.
Executive Action:
- Ask procurement and legal to flag every Microsoft licensing clause that restricts running Windows Server or SQL Server on non-Microsoft infrastructure.
- Track the SMS investigation timeline and build contract renewal decisions around its expected conclusion.
- Brief the audit or risk committee on how licensing terms currently affect multi-cloud optionality.
How Concentrated Is the UK’s Cloud Market?
According to CMA market data reported by Computer Weekly and Data Center Dynamics, Microsoft and AWS each hold around 40% of the UK cloud infrastructure market, with Google Cloud a distant third at roughly 10%. That leaves the overwhelming majority of UK enterprise workloads sitting on two providers. For CIOs, this is the structural fact behind every resilience conversation: a single regional outage, contractual dispute or licensing change at either provider has systemic reach across the UK economy, not just within one organisation.
Executive Action:
- Map what percentage of critical workloads sit with a single hyperscaler and quantify the cost of a 30-day migration to an alternative.
- Include cloud concentration explicitly in the enterprise risk register, not folded into generic “IT risk”.
What Does Strategic Market Status Mean for Enterprise Contracts?
If Microsoft is ultimately designated with Strategic Market Status, the CMA gains powers to impose conduct requirements — potentially forcing changes to licensing terms, pricing structures and interoperability commitments within existing contracts. CIOs currently negotiating or renewing enterprise agreements should build in flexibility rather than locking into multi-year terms that assume today’s licensing model persists unchanged. This is not a reason to pause cloud strategy; it is a reason to negotiate exit and renegotiation clauses more carefully than in the last cycle.
Executive Action:
- Insert re-opener clauses tied to CMA findings into any enterprise agreement signed before the investigation concludes.
- Require vendor account teams to disclose how proposed licensing terms would be affected by potential conduct requirements.
How Should CIOs Reduce Concentration Risk Without Disrupting Delivery?
Full multi-cloud parity is expensive and, for most organisations, unnecessary. The pragmatic path is tiering: identify the workloads where concentration is a genuine resilience or regulatory issue (payments, customer data, safety-critical systems) and build portability only there, while accepting single-vendor efficiency elsewhere. This mirrors how regulated financial services firms are already approaching third-party concentration risk under supervisory expectations for operational resilience.
Executive Action:
- Classify workloads by criticality and apply portability requirements only to the top tier.
- Pilot one workload migration to a second provider annually to keep exit capability real, not theoretical.
- Use INFORMD’s technology risk assessment tools to benchmark current concentration against peers.
What Should CIOs Brief the Board on Now?
Boards do not need a lecture on cloud architecture; they need a clear statement of exposure and a credible mitigation timeline. Present concentration risk in the same terms as any other third-party dependency: likelihood, impact, mitigation cost and mitigation timeline. Tie the briefing to the CMA investigation’s milestones so the board sees this as a tracked, time-bound issue rather than an open-ended technical concern.
Executive Action:
- Present cloud concentration risk to the board using the same likelihood/impact framework as other principal risks.
- Set a review checkpoint aligned to the CMA’s expected conclusion date.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
Launched in May 2026 under the Digital Markets, Competition and Consumers Act 2024, it examines whether Microsoft’s cloud licensing terms restrict competition by making it costlier to run Windows Server and SQL Server on rival cloud platforms. It is expected to run around nine months.
Microsoft and AWS each hold around 40% of the UK cloud infrastructure market, with Google Cloud at roughly 10%, according to CMA market data. Most UK enterprise workloads sit with just two providers.
Not pause, but negotiate carefully. Build re-opener or renegotiation clauses tied to CMA findings into any enterprise agreement signed before the investigation concludes, rather than locking into multi-year fixed terms.
No. Most organisations should tier workloads by criticality and build portability only for payments, customer data and safety-critical systems, accepting single-vendor efficiency elsewhere to control cost.
