Last Updated on August 8, 2026 by Karl Thompson
The previous chapter argued that modern Britain runs on a clock it does not own. This one makes a larger version of the same argument. Over roughly two decades, British organisations — including the British state — have stopped owning the computers they depend on and started renting them from a handful of American corporations. This article is about how that happened, what the rent buys, what it costs, and why the arrangement has proved so difficult to reverse even when the government’s own competition regulator concluded it was not working.
This is part of How Modern Society Works, a series on the hidden systems that shape everyday life. Each article takes something ordinary and works outwards to the system that produced it.
Three Tenants, One Building
A district council processes planning applications. A hospital trust manages patient records. A university runs its virtual learning environment, and a challenger bank clears payments.
Each of these organisations has its own IT department, its own budget line, its own systems, its own logo on the login screen. Each appears, from the outside and often from the inside, to run its own computing.
In a great many cases they are tenants in the same building, renting space from the same landlord, and they would all go dark together.
That is not a metaphor about interconnection. It is a description of a commercial relationship. The council’s planning portal, the trust’s records system and the bank’s clearing engine may be running on physical machines owned by a single company, in a facility that company operates, under contractual terms that company writes. What the organisations own is a lease.
This is the transformation the word “cloud” conceals. The metaphor invites us to imagine dispersal — data floating free, everywhere and nowhere. The reality is the opposite. Cloud computing has been one of the most thorough concentrations of productive infrastructure in modern economic history, and the vocabulary we use to discuss it makes the concentration nearly impossible to see.
How Does Cloud Computing Actually Work?
The technical arrangement is straightforward enough, and worth understanding before the economics.
In 2005, an organisation that needed computing bought computers. It purchased servers, found a room for them, cooled the room, employed people to maintain them, and — because it had to size for its busiest day of the year — accepted that most of that capacity sat idle most of the time. Computing was a capital asset. You owned it, you depreciated it, and you replaced it every few years.
The technology that changed this was virtualisation: software that divides one powerful physical machine into many independent virtual ones, isolated from each other, each behaving as though it were a separate computer. A single server could now serve dozens of unrelated customers at once. Idle capacity in one organisation could be sold to another.
Amazon, whose retail business had built enormous computing capacity that was underused for eleven months a year, recognised the commercial implication before anyone else. In 2006 it launched Elastic Compute Cloud, letting customers rent virtual machines by the hour. Microsoft and Google followed. Within fifteen years the model had become the default.
What customers rent comes in three broad layers. Infrastructure as a Service is closest to the old arrangement: you lease virtual machines and storage and install whatever you like on them. Platform as a Service rents you a ready-made environment to build applications in. Software as a Service is the layer most people touch daily — Microsoft 365, Gmail, Salesforce — where you rent the finished application and never think about what it runs on.
The higher up those layers an organisation goes, the more convenience it gains and the less of the stack it controls. This matters enormously later.
The genuine advantages are worth stating plainly, because the rest of this article is critical and the advantages are real. A small charity can now access computing that only a multinational could once afford. A start-up can go from nothing to serving millions without buying a single machine. Capacity that used to take months to procure arrives in minutes. Organisations that could never have justified employing a security team now inherit one. None of this is illusory, and none of it should be sentimentalised away.
But convenience and ownership are different things, and the question this article asks is what happened to the second while everybody was enjoying the first.
Who Owns Cloud Computing?
There is an old sociological question hiding in all of this, and it is worth naming directly.
Marx’s central analytical move was to ask who owns the means of production — not who works, not who consumes, but who holds the tools, the machines and the premises without which production cannot happen. His argument was that this ownership determines a great deal else: how the surplus is divided, who bears risk, and who has to accept whatever terms are offered.
Computation is now a means of production for a very large share of the economy. Retail, banking, logistics, media, healthcare administration, public services and increasingly artificial intelligence all require it in the way that nineteenth-century textiles required a mill. The question of who owns it is not a technical footnote.
The answer, in the United Kingdom, is unusually well documented, because a public body spent three years establishing it. In its market investigation into public cloud infrastructure services, the Competition and Markets Authority found that Amazon Web Services and Microsoft Azure were each estimated to hold a UK market share by value of up to 40%, that both enjoyed substantial and entrenched market power, and that they were protected by high and persistent barriers to entry. The market in question was worth roughly £9 billion a year.
Two firms, both headquartered in the United States, holding up to four-fifths of the infrastructure between them.
Nick Srnicek’s argument in Platform Capitalism is useful here precisely because it explains why this shape recurs. Platforms, he argues, are firms whose power comes not from making things but from owning the infrastructure through which others make things — and platform markets tend towards monopoly because scale itself is the advantage. Every additional customer lowers the average cost of the enormous fixed investment, funds further investment, and makes the platform more attractive still. The dynamic does not need anybody to behave badly. It simply runs. Srnicek himself is more careful than this summary suggests — he gives reasons for thinking the platform moment may prove less all-conquering than it currently appears. The tendency is his argument; the inevitability is not.
Brett Christophers has given the resulting economic form a sharper name: rentier capitalism, an economy organised increasingly around the ownership of scarce assets and the charging of fees for access to them, rather than around producing goods in competition. On this account, the crucial question about a firm is not what it makes but what it controls and what it can charge for entry.
Which brings us to the mechanism that converts a competitive service into a rent.
What Is Cloud Vendor Lock-In?
A market where customers can leave easily disciplines its suppliers. A market where they cannot does not. Everything about cloud competition turns on this, and the CMA’s findings amount to a detailed account of why leaving is hard.
The investigation identified three adverse effects on competition, and the second and third are the ones that matter here.
Technical barriers. Cloud services from different providers are differentiated enough in features and interfaces that customers struggle to compare them, let alone move between them. An application built over five years against one provider’s particular set of services is not portable in any meaningful sense; it has been shaped by the environment it grew in. Migrating means re-architecting the application, rebuilding operational tooling and retraining staff.
Commercial barriers. Chief among these are egress fees — charges levied when a customer moves their own data out of a provider’s environment. Data goes in free. It comes out priced. The larger the accumulated dataset, the more expensive departure becomes, which is to say that the cost of leaving rises with every year of loyalty.
Licensing. The CMA’s most pointed finding was about Microsoft specifically: that it charged AWS and Google materially higher wholesale prices for its own business software than it charged customers running that same software on Azure. Organisations that use Windows Server or SQL Server — which is to say, an enormous proportion of British institutions — therefore face a penalty for hosting them anywhere but Microsoft’s own cloud. Dominance in one layer becomes leverage in the layer below.
Alongside these sit committed spend agreements, in which a customer promises a certain volume of spending over a certain period in return for discounts. The structure rewards concentrating everything with one provider, because the best discount goes to the largest commitment. Notably, the CMA did not find that these agreements, or free cloud credits, were harming competition — a finding worth reporting honestly even though it cuts against the general thrust.
The cumulative effect is that switching costs are high, rising, and largely invisible at the moment of the original decision. An organisation choosing a cloud provider in 2015 was making a procurement decision. By 2026 it had made a structural one.
How Much Does the UK Government Spend on Cloud?
The most consequential customer in Britain is the British state, and its position is now extraordinary.
Research by Computer Weekly, analysing spending across more than 1,100 public bodies, found that 95% of central and local public sector organisations spent on hyperscale cloud in 2023/24 — rising to 99% once software running on those platforms is counted. Of twenty-two government departments in the data, twenty-one spent on hyperscale cloud, and thirteen spent half or more of their entire technology budget on it, whether directly or through resellers. Of sixty-four police forces and agencies, fifty-five did.
The largest spenders form a roll-call of the state’s core functions: the Ministry of Defence at £1.09bn, HM Revenue & Customs at £1.01bn, the Home Office at £775m, the Department for Work and Pensions at £622m and NHS England at £442m.
Two individual arrangements illustrate the direction of travel. Under the Strategic Partnership Arrangement agreed with Microsoft, the UK public sector expects to spend in the region of £9 billion over five years, with approximately £1.9 billion spent on Microsoft licences through resellers in 2024/25 alone, according to a parliamentary answer. And the AWS “One Government Value Agreement”, signed in 2020, was followed by a roughly tenfold increase in government spending with AWS, from around £0.1 billion to over £1 billion, on the Crown Commercial Service’s own figures.
The consequences are not only financial. In one instance that ought to be better known, Scottish police forces using Microsoft 365 were found to be unable to establish which country their data was held in — and were not told. A police force is the institution with the strongest conceivable claim to know where its records physically reside. It could not find out.
This is what distinguishes tenancy from ownership at the level of the state. It is not merely that the government pays rent. It is that important properties of its own operations — where data sits, which legal jurisdiction governs it, what the terms will be at renewal — are determined by a counterparty. Weber’s account of modern bureaucracy assumed that the official is separated from the means of administration, which belong instead to the organisation. It did not anticipate that the organisation would in turn be separated from them.
In January 2026, forty-five MPs signed an Early Day Motion on UK digital sovereignty, pointing to the dependence of government services, democratic functions and critical infrastructure on a small number of providers. Whether that produces anything is another matter. The point is that the question has finally arrived in Parliament, roughly fifteen years after the decisions that made it urgent.
What Caused the October 2025 AWS Outage?
On the night of 19 October 2025, a latent defect in the automated system that manages DNS records for Amazon’s DynamoDB database in the Northern Virginia region caused those records to be erased. Applications trying to reach the database could no longer find it.
DynamoDB is not a consumer product and almost nobody outside the industry has heard of it. It is, however, the store that a great many other AWS services use to keep track of their own internal state. When it became unreachable, the failure propagated: the system that manages leases on physical servers for EC2 lost its own records and began marking machines unavailable; new virtual machines could not be launched; load balancers failed health checks. By Amazon’s own account, disruption ran from 11:48pm on 19 October to 2:20pm on 20 October — roughly fifteen hours.
The visible consequences were global and almost comically miscellaneous. Snapchat, Fortnite, Roblox, Signal, Duolingo, Ring doorbells, McDonald’s mobile ordering, airline booking systems — and HMRC’s website, which meant British taxpayers could not reach a British government service because of a software defect in a data centre in Virginia.
That last detail is the whole argument in one line.
Three things about this incident matter sociologically rather than technically.
First, the failure was not of a service but of a shared dependency. In the old arrangement, a server crash affected one organisation. Here, thousands of organisations with no commercial relationship to one another, in dozens of countries, failed simultaneously, because underneath their apparent independence they shared a single point of failure that none of them had chosen or could see.
Second, the concentration is geographic as well as corporate. Northern Virginia is the largest concentration of cloud infrastructure on Earth, for reasons of history, electricity and fibre rather than anything about the internet’s supposed placelessness. A great deal of the world’s computing depends on the weather, politics and power supply of one American county.
Third, the resilience engineering worked as designed and did not help. Cloud providers build in redundancy: multiple availability zones, multiple regions, automatic failover. But this was a control-plane failure — the coordinating machinery, not the machines — and the redundancy that protects against a data centre burning down does not protect against the system that manages redundancy losing track of itself. Complexity introduces failure modes that redundancy cannot address, because redundancy is itself part of the complexity.
Ulrich Beck argued that advanced societies increasingly generate risks that are the products of their own technological successes rather than external threats. Cloud outages are a precise instance. Nobody attacked anything. The system’s own automation, built to make it more reliable, made it fail.
Who Regulates the Landlord
The final part of this story is about what happened when a state regulator tried to do something about all this, and it is more instructive than any of the technical detail.
The chain of events ran roughly as follows. Ofcom examined the cloud market and raised concerns. The matter was referred to the Competition and Markets Authority in October 2023. After nearly two years of investigation, the CMA published its final decision on 31 July 2025, concluding that competition was not working well and identifying the adverse effects described above.
Its independent inquiry group then recommended that the CMA use its new powers under the Digital Markets, Competition and Consumers Act to open investigations into designating Microsoft and AWS as having Strategic Market Status — a classification that would allow the regulator to impose legally binding conduct requirements.
On 31 March 2026, the CMA Board declined to do so.
Instead it accepted voluntary commitments from both companies on egress fees and interoperability: Microsoft extending its free-switching window from 60 to 180 days, offering at-cost egress across its own network for multicloud use, and establishing a mechanism for interoperability requests from competitors; AWS publishing a UK addendum covering data portability and switching. The CMA said it would review progress in six months. Simultaneously, it opened a Strategic Market Status investigation into Microsoft’s business software ecosystem — Windows, Office, Teams, Copilot, server operating systems and the licensing practices flagged the previous July — with a designation decision due by February 2027.
Reactions divided predictably. The regulator argued it had secured real change faster than litigation would have. Critics observed that the CMA’s own investigators had recommended binding designation and been overruled, and that the licensing practice identified as the single clearest harm was not addressed by the commitments at all. Microsoft and AWS both maintained that the findings understated how competitive the market actually is.
You do not have to take a view on who was right to notice what the episode demonstrates. A well-resourced regulator, with new statutory powers written specifically for digital markets, spent three years establishing that a market was not working, and then settled for undertakings from the firms concerned. This is not necessarily a failure of nerve; it may be a realistic assessment of what enforcement against infrastructure of this scale would actually cost and achieve. But it tells us something about the balance of capacity between national regulators and global infrastructure owners.
There is also an uncomfortable circularity. The CMA is itself among the government bodies that spend on hyperscale cloud. So is every department that would have to implement any remedy. The state regulating this market is a customer in it.
Access Without Ownership
Cloud computing has produced a genuine paradox, and the chapter should end on it rather than on the outages.
By almost any measure, access to computing has been democratised. A charity, a school, a two-person start-up or an individual researcher can today deploy computing power that in 2005 was available only to governments and large corporations, at a price scaled to what they actually use. This is a real and substantial gain, and it has enabled an enormous amount of activity that would otherwise never have happened.
At the same time, ownership of that computing has concentrated to a degree without much precedent. The same period that widened access narrowed control. Millions of organisations gained the use of infrastructure; a handful of firms gained the infrastructure.
These are not contradictory findings. They are the same finding described from two positions, and the relationship between them is precisely what “rent” means. The tenant gains use of something they could never have built. The landlord gains a stream of payments and the power to set terms. Both are better off than under the alternative in which the building does not exist. That does not make them equals.
What the sociological imagination adds here is the recognition that this was not a series of individual procurement decisions that happened to aggregate. Each organisation made a reasonable choice given its options. The structure that resulted — a national health service, tax authority, defence ministry and police forces operating on rented American infrastructure under terms none of them wrote — was chosen by nobody and is now extremely difficult for anybody to change. That is what a social structure is: the pattern that emerges from many rational individual decisions and then constrains all subsequent ones.
Three systems, three allocation mechanisms. Grid capacity in west London was rationed by a connection queue. Fibre was rationed by expected return. Computing has been rationed by a lease, and the lease was written by the landlord.
None of these is a conspiracy and none was hidden. Each was a reasonable arrangement adopted for local reasons by people who were not asking a national question. What they have in common is that the aggregate outcome — where the power went, which streets got cable, who owns the machines the state runs on — was determined by mechanisms that nobody designed to determine it.
We have moved, in about twenty years, from a society whose institutions owned their own means of computation to one in which they lease it. The terms of that lease are now among the more consequential facts about how Britain is governed.
Most people have never seen it. Nobody was asked to sign it.
References
| Claim | Source | URL | Why it supports the claim |
|---|---|---|---|
| AWS and Microsoft each hold UK market share by value of up to 40%; entrenched market power; high barriers to entry | CMA, Cloud services market investigation, final decision, 31 July 2025 | https://www.gov.uk/cma-cases/cloud-services-market-investigation | Case page hosting the final report and its findings on market structure |
| Three adverse effects on competition: concentration, technical and commercial switching barriers, Microsoft licensing | as above | as above | Final decision summary of AECs |
| Microsoft charged AWS and Google materially higher wholesale prices for its own software than Azure customers pay | as above | as above | Licensing AEC in the final report |
| Committed spend agreements and cloud credits were not found to be harming competition | Datacenter Dynamics report on the CMA final decision | https://www.datacenterdynamics.com/en/news/competition-is-not-working-well-says-uk-cma-concluding-cloud-market-investigation/ | Reports this specific negative finding alongside the AECs |
| CMA Board declined SMS investigations on 31 March 2026, accepting voluntary commitments instead | Tech Policy Press | https://www.techpolicy.press/uk-cloud-regulator-opts-for-voluntary-commitments-launches-microsoft-investigation/ | Sets out both limbs of the 31 March 2026 decision |
| Microsoft commitments: free egress window extended 60→180 days; at-cost egress; interoperability request mechanism | Datacenter Dynamics | https://www.datacenterdynamics.com/en/news/uks-competition-watchdog-launches-sms-investigation-into-microsoft-aws-avoids-further-scrutiny/ | Lists the specific commitments given |
| SMS investigation into Microsoft business software opens May 2026; designation decision due February 2027 | Computer Weekly | https://www.computerweekly.com/news/366640828/CMA-to-launch-strategic-market-status-investigation-into-Microsoft-Amazon-Web-Services-off-the-hook | Reports scope, timetable and nine-month statutory period |
| 95% of UK public bodies spent on hyperscale cloud in 2023/24, 99% including software; 13 of 22 departments spent 50%+ of tech budget; 55 of 64 police forces | Computer Weekly, data analysis of public sector hyperscale dependence | https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses | Reports the underlying dataset and percentages |
| Top five public sector spenders: MoD £1.09bn, HMRC £1.01bn, Home Office £775m, DWP £622m, NHS England £442m | as above | as above | Named figures in the same analysis |
| Scottish police using Microsoft 365 could not establish which country their data was held in | as above | as above | Reported in the same feature |
| Public sector expects ~£9bn over five years under the Microsoft SPA24 arrangement; £1.9bn spent in 2024/25 via resellers | The Register, reporting a parliamentary answer | https://www.theregister.com/2025/08/07/uk_microsoft_spending/ | Quotes the parliamentary answer and CCS position |
| AWS “One Government Value Agreement” preceded a roughly tenfold rise in AWS spending, £0.1bn to over £1bn since 2020 | National Preparedness Commission | https://nationalpreparednesscommission.uk/publications/the-concentration-crisis-why-cloud-dominance-in-the-uk-demands-immediate-cma-action/ | Cites Crown Commercial Service figures for the agreement |
| 45 MPs signed an Early Day Motion on UK digital sovereignty, January 2026 | Computer Weekly | https://www.computerweekly.com/feature/Breaking-the-stranglehold-Responses-to-data-sovereignty-risk | Reports the motion and its subject |
| October 2025 outage: DNS defect in DynamoDB; impact 11:48pm 19 Oct to 2:20pm 20 Oct; cascade into EC2 and Network Load Balancer | AWS, Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region | https://aws.amazon.com/message/101925 | Amazon’s own post-incident report, with timings and causal chain |
| Services affected included Snapchat, Fortnite, Roblox, Signal, Ring, McDonald’s ordering, airline bookings and HMRC | Tech Upkeep incident analysis | https://www.techupkeep.dev/blog/aws-outage-october-2025-analysis | Lists affected services including HMRC |
Note on sourcing. Several claims above rest on trade-press reporting rather than primary documents, because the underlying analysis (the Computer Weekly spending dataset) is original journalism rather than a published statistical release. Where a primary source exists — the CMA case file, Amazon’s own incident report, the parliamentary answer — it is cited in preference.
Reading
- Nick Srnicek, Platform Capitalism (Polity, 2017)
- Brett Christophers, Rentier Capitalism: Who Owns the Economy, and Who Pays for It? (Verso, 2020)
- Ulrich Beck, Risk Society: Towards a New Modernity (1992)
- Max Weber, Economy and Society — on bureaucracy and the separation of the official from the means of administration
How Modern Society Works
← Previous: Britain’s Hidden Fibre Network · Series hub · Next: What Are Payment Networks? →




