UK Names 4 Cloud Giants Critical Third Parties [2026]

On July 13, 2025, Microsoft, Amazon, Google, and Oracle crossed a regulatory line no cloud provider had crossed in the UK before. HM Treasury formally designated all four as Critical Third Parties (CTPs) to the UK financial sector, a status that hands the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) direct oversight of how these companies run the infrastructure banks, insurers, and financial market infrastructures depend on every day.

The announcement, made public on July 10, 2026 and effective three days later, is the first real-world use of powers Parliament created in the Financial Services and Markets Act 2023. For three years those powers sat on the statute book, unused. Now they apply to four named companies: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL, and Oracle Corporation UK Limited.

The story matters well beyond London. It is the clearest sign yet that governments no longer treat hyperscale cloud providers as ordinary vendors. Regulators now treat them as financial infrastructure, and they are starting to police them like it.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What HM Treasury Actually Designated on July 13

The Critical Third Party designations became legally effective for four firms on 2025: Microsoft Ireland Operations Limited (the entity behind Azure), Google Cloud EMEA Limited, Amazon Web Services EMEA SARL, and Oracle Corporation UK Limited. Each now sits under joint supervision from the Bank of England, the PRA, and the FCA, specifically covering the systemic services those companies provide to UK banks, insurers, and financial market infrastructures.

The designation does not touch a company’s entire business. A retailer running its checkout on AWS, or a media company training models on Google Cloud, sits outside the regime entirely. Oversight is scoped to services UK financial firms rely on for functions regulators consider systemically important. Disruption to those specific services, in HM Treasury’s own test, could threaten the stability of, or confidence in, the UK financial system.

Officials framed the move as closing a gap that had existed since cloud computing became core banking infrastructure. Regulators could already examine the banks that buy cloud services. They had no direct authority over the cloud providers themselves. That gap is now closed, at least for four companies.

Inside the Legal Mechanics: How FSMA 2023 Created This Regime

The Critical Third Party framework did not appear overnight. It was written into law through the Financial Services and Markets Act 2023, which amended the original Financial Services and Markets Act 2000 to add a new set of powers. Section 312L(1) gives HM Treasury the authority to designate a third party as critical. Sections 312M and 312N give the Bank of England, PRA, and FCA the power to make binding rules for CTPs and to issue written directions telling a CTP to do, or stop doing, specific things.

Treasury can only use the designation power if it concludes that disruption to the third party’s services could threaten the stability of, or confidence in, the UK financial system. That test is deliberately narrow. It is not a general “is this company important” standard. It borrows the same logic that already governs how regulators treat systemically important banks.

The rules built on this legal foundation, detailed in a joint policy statement from the Bank of England, PRA, and FCA, took effect on 1 January 2025, after Treasury used them. That gap existed because the framework needed two separate steps. Rules had to be in force first, and then Treasury had to actually name a company under them. The wait gave regulators time to consult industry and build the supervisory machinery the framework assumes will already exist.

The Four Names on the List

The table below breaks down exactly which legal entities were named, the cloud brand each operates under, and the role each plays inside UK financial-sector infrastructure.

Designated Legal EntityParent / Cloud BrandPrimary Role in UK Financial SectorDesignation Effective
Amazon Web Services EMEA SARLAmazon / AWSCore infrastructure hosting for banks, insurers, and FMIsJuly 13, 2026
Microsoft Ireland Operations LimitedMicrosoft / AzureCloud and AI infrastructure for banks and FMIsJuly 13, 2026
Google Cloud EMEA LimitedAlphabet / Google CloudData analytics and AI infrastructure for financial firmsJuly 13, 2026
Oracle Corporation UK LimitedOracle / OCI and database systemsCore banking databases and enterprise back-office systemsJuly 13, 2026

No Statutory Cap on Future Designations

HM Treasury did not have to stop at four, and the government has said as much publicly. The law sets no statutory limit on how many providers can be designated as Critical Third Parties. The first four are also, unsurprisingly, the companies UK banks lean on most heavily for core infrastructure, data platforms, and increasingly, AI workloads. A fifth or sixth name is a matter of when, not if, according to the framework’s own design.

What Regulators Can, and Can’t, Do to a Designated CTP

The powers attached to CTP status are real, but they stop well short of the authority regulators hold over an actual bank. Designated providers must submit to resilience testing against “severe but plausible” scenarios, an approach that echoes the stress tests banks already sit through. They must deliver regular self-assessments of their own operational resilience, hand over information to regulators on request, and report major incidents that could affect the financial system rather than just their own operations. Regulators can also write binding rules specific to CTPs and issue direct written orders compelling a provider to act.

What the regime pointedly avoids is turning cloud providers into quasi-banks. There is no deposit-guarantee-style backstop if a cloud outage causes financial-sector losses. Being designated does not subject a company to bank-style capital or prudential fines simply for holding CTP status. Enforcement exists, and the policy statement is explicit that formal action is available where needed, but the government has drawn a clear line: this is oversight of operational resilience and information flow, not prudential regulation in the sense that term applies to a lender.

Why Now: The Concentration-Risk Problem Regulators Can’t Ignore

The timing traces back to a worry regulators have raised for years. A small number of companies now sit underneath a very large share of the UK’s financial infrastructure. The Bank of England’s 2024 report on artificial intelligence in UK financial services found that the top three third-party providers of cloud, AI model, and data services accounted for 73% of all providers named by the financial firms it surveyed. That figure covers more than cloud infrastructure alone, but it captures the same underlying concern: when a handful of vendors sit behind most of an industry’s technology stack, a bad day at any one of them stops being that company’s problem and becomes everyone’s problem.

Global cloud-market data reinforces the point. Synergy Research Group’s Q3 2025 figures put AWS at 29% of worldwide cloud infrastructure spending, Microsoft Azure at 20%, and Google Cloud at 13%, a combined 63% held by three companies in a market Synergy sized at $106.9 billion for the quarter alone, or roughly $390 billion on a trailing twelve-month basis. Regulators do not need a UK-only breakdown to see the shape of the risk. If three providers hold that much of the global market, they almost certainly hold a comparable or larger share of the UK financial sector specifically, given how concentrated enterprise cloud contracts tend to be. Recent incidents have not helped calm those nerves. Tech-Insider has tracked how AWS’s own us-west-2 region suffered its third incident in three months and how a fire at a Google Cloud facility in Delhi triggered the company’s sixth notable outage of the year, each a small preview of the kind of disruption regulators are now trying to get ahead of.

A Regulatory Timeline Three Years in the Making

The July 2026 designations were not a sudden move. They were the final step in a process regulators had been building since 2023, piece by piece.

DateMilestone
2023Financial Services and Markets Act 2023 creates the Critical Third Party legal framework
October 5, 2023Ofcom refers the UK cloud services market to the CMA for a full competition investigation
December 2023Bank of England and PRA publish their operational resilience approach for future Critical Third Parties
January 1, 2025UK Critical Third Party rules take legal effect, ahead of any actual designation
January 17, 2025EU’s Digital Operational Resilience Act (DORA) enters into application
July 31, 2025CMA publishes its final decision on the UK cloud market investigation
January 2026UK regulators and EU supervisory authorities sign a cross-border oversight MoU
July 10, 2026HM Treasury announces the first four UK Critical Third Party designations
July 13, 2026Designations take legal effect and active oversight begins

Each step added a piece of the machinery that made the July 2026 designations possible, from the underlying legal authority to the cross-border coordination needed once a provider serves both UK and EU financial firms from overlapping infrastructure.

How the UK Regime Compares to the EU’s DORA

The UK is not acting alone, and it is not moving as fast as its nearest neighbor. The EU’s Digital Operational Resilience Act entered into application on 17 January 2025, when DORA applied in practice. DORA’s oversight runs through the European Supervisory Authorities (EIOPA, ESMA, and the EBA) rather than through a central bank acting jointly with two other regulators. By July 2026, according to a client alert from law firm Morrison Foerster, the EU had already designated 19 critical ICT third-party providers under DORA, compared with the UK’s four.

DimensionUK Critical Third Party RegimeEU DORA CTPP Regime
Legal basisFinancial Services and Markets Act 2023Digital Operational Resilience Act (EU 2022/2554)
Lead oversight bodiesBank of England, PRA, FCAEuropean Supervisory Authorities (EBA, ESMA, EIOPA)
Providers designated as of July 2026419
Rules/regime effectiveJanuary 1, 2025 (rules) / July 13, 2026 (first designations)January 17, 2025
Cross-border coordinationMoU with EU supervisory authorities, signed January 2026MoU with UK regulators, signed January 2026
Statutory cap on designationsNoneNot capped, expands as ESAs identify new critical providers

The gap between four and nineteen partly reflects timing, since the EU designated its first cohort earlier, and partly reflects scope, since DORA’s definition of a critical ICT third-party provider is not limited to cloud infrastructure the way the UK’s early designations have been. The two regimes are close enough in structure that regulators moved to formally coordinate. The Bank of England and the European Supervisory Authorities signed a memorandum of understanding in January 2026 specifically to manage joint oversight of providers serving both markets, including how they communicate during a live outage or cyberattack that crosses borders.

A Second, Parallel Track: The CMA’s Competition Case

The CTP regime is not the only UK regulatory track bearing down on the same companies, and conflating the two would be a mistake. In a separate process, Ofcom referred the UK cloud services market to the Competition and Markets Authority for a full investigation on October 5, 2023. The CMA published its final decision on July 31, 2025, concluding that Microsoft and AWS are the two largest cloud providers in the UK and flagging competition concerns around egress fees, software licensing terms, and committed-spend agreements that make switching providers slow and expensive. Rather than impose remedies directly, the CMA recommended pursuing its newer digital-markets powers, weighing whether to open Strategic Market Status investigations into Microsoft’s and AWS’s cloud businesses, with a board decision on whether to proceed expected in the first quarter of 2026.

Put the two tracks together and the picture is a government leaning on the same companies from two directions at once. One track focuses on financial stability and operational resilience. The other focuses on market power and switching costs. Microsoft and AWS, named in both processes, face the most compounding regulatory exposure of the group.

Market and Industry Reaction

None of the four designated companies has publicly objected to the designations, and the muted response stands out given how aggressively some of the same companies have pushed back on other digital rules in the past. AWS addressed the shift directly on its own industries blog, acknowledging that the Financial Services and Markets Act 2023 gives HM Treasury the authority to name a third party as critical, and describing the framework as bringing designated companies into direct regulatory oversight aimed at managing systemic risk to UK financial stability. That framing, coming from AWS itself, suggests the major cloud providers see cooperation as the more practical position, particularly with the EU having already normalized a similar model under DORA.

Financial-sector commentary has largely treated the designations as overdue rather than surprising. Coverage in the days after July 10 framed the announcement as confirmation of a shift regulators had been signaling since the original Bank of England policy statement on operational resilience back in December 2023. That slow, telegraphed build-up may explain why the market reaction has been closer to a shrug than a shock.

Competitive Landscape: AWS, Azure, Google Cloud, and Oracle Under One Regulatory Roof

Grouping four competitors under a single regulatory framework does not mean they carry equal exposure. AWS and Microsoft Azure, the two largest providers to UK banks by most measures including the CMA’s own investigation, sit at the center of both the CTP regime and the parallel competition case. That gives them the largest compliance burden and the most to lose if enforcement turns adversarial. Google Cloud, smaller in UK financial-sector share but growing quickly on AI and data-analytics workloads, gains a form of validation from being named alongside the two market leaders. It is now officially systemic, not just aspirational.

Why Oracle Is the Surprise Name

Oracle’s inclusion is the least obvious to outside observers and the most revealing. Oracle is not a top-three hyperscaler by global cloud infrastructure share, sitting well behind AWS, Azure, and Google Cloud in Synergy’s Q3 2025 rankings. It remains deeply embedded in core banking systems, though, the databases and enterprise applications that predate the cloud era and still run much of the financial sector’s back office. Its designation signals that regulators are defining “critical” by dependency and disruption risk rather than by market-share ranking alone, a distinction that could matter a great deal if Treasury expands the list further.

What This Means for Banks, Fintechs, and IT Leaders

For the financial firms that rely on these four providers, the designations do not remove any existing obligations. They add a layer above them. UK banks and insurers already had to manage third-party and outsourcing risk under existing PRA and FCA rules, and that responsibility does not transfer to the cloud providers just because the providers are now directly supervised. What changes is the information available to regulators, and indirectly to the banks themselves, about how resilient their cloud infrastructure actually is. Resilience testing results, incident reports, and self-assessments that used to live entirely inside a cloud provider’s own risk function now flow to the Bank of England, the PRA, and the FCA as a matter of routine supervision.

For IT and compliance leaders at financial firms, the practical shift is less about new paperwork and more about leverage. A bank’s own third-party risk assessments of AWS or Microsoft can now reference an external regulatory relationship that did not exist a month earlier, giving procurement and risk teams a stronger basis for negotiating contractual resilience commitments. Fintechs and smaller financial firms that use these providers indirectly, through banking-as-a-service platforms or outsourced infrastructure, inherit some of that same benefit without negotiating it themselves. Teams still tracking cloud cost and FinOps discipline now have one more variable to fold into vendor reviews: resilience posture, not just price per compute hour.

Will the US Follow the UK and EU?

The US has no direct equivalent to the UK’s CTP regime or the EU’s DORA, and nothing currently moving through Congress would create one. US bank regulators, including the OCC and the Federal Reserve, already expect banks to manage third-party risk under existing interagency guidance, but that guidance obligates the banks, not the cloud providers, and stops well short of giving regulators direct examination authority over AWS, Microsoft, or Google the way the UK and EU frameworks now do.

That gap is unlikely to close quickly. US financial regulators have historically preferred to regulate through the banks they already supervise rather than reaching directly into vendor relationships, and the current deregulatory posture in Washington makes a new direct-oversight regime for hyperscale cloud providers a harder sell in the near term. The more realistic path for the US is pressure by example. If the UK and EU frameworks catch a resilience failure before it becomes a financial-sector incident, or fail to catch one, that outcome will shape the US debate more than any side-by-side comparison of statutes.

Five Predictions for the Next 12 Months

  1. More UK designations are coming. With no statutory cap and Treasury already on record about the possibility, expect additional providers, likely core-banking software vendors or payment-infrastructure firms rather than pure hyperscalers, to join the list within 12 to 18 months.
  2. Microsoft and AWS absorb the most scrutiny. As the only two companies caught in both the CTP regime and the CMA’s competition case, expect them to carry the bulk of new UK compliance costs and to push the CMA to resolve its Strategic Market Status question quickly rather than leave it open.
  3. Resilience reporting becomes a sales pitch. Expect AWS, Microsoft, and Google Cloud to start marketing their CTP compliance and resilience-testing track record to UK financial clients, the same way they already market ISO 27001 or SOC 2 certifications.
  4. Oracle and challenger clouds lean into diversification. Expect Oracle, along with smaller and neocloud providers, to use the concentration-risk narrative behind the CTP regime as a sales argument for UK banks to spread workloads across more than one provider.
  5. The US debate stays theoretical, until it isn’t. Expect continued discussion among US policymakers and financial-stability bodies about hyperscaler oversight, but no legislative action unless a cloud outage causes a demonstrable financial-sector disruption on US soil first.

Frequently Asked Questions

What is a UK Critical Third Party (CTP)?
A Critical Third Party is a non-financial company, typically a technology or cloud provider, that HM Treasury has formally designated under the Financial Services and Markets Act 2023 because a disruption to its services could threaten the stability of, or confidence in, the UK financial system. CTP status brings a company under direct oversight from the Bank of England, the PRA, and the FCA for the specific services it provides to financial firms.

Which companies are currently designated as UK Critical Third Parties?
As of July 13, 2026, four companies hold CTP status: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL, and Oracle Corporation UK Limited.

Does CTP designation mean these companies are regulated like banks?
No. CTP status gives regulators oversight of operational resilience, including mandatory testing, incident reporting, and information-sharing, but it does not create a deposit-guarantee backstop or subject the companies to bank-style capital and prudential fines simply for being designated.

How does the UK’s CTP regime differ from the EU’s DORA?
Both frameworks target systemically important technology providers to the financial sector, but DORA is overseen by the EU’s European Supervisory Authorities and had designated 19 critical ICT third-party providers by July 2026, compared with the UK’s four. UK and EU regulators signed a memorandum of understanding in January 2026 to coordinate oversight of providers that serve both markets.

Can more companies be added to the UK’s CTP list?
Yes. The Financial Services and Markets Act 2023 sets no statutory limit on the number of Critical Third Parties HM Treasury can designate, and officials have said publicly that the current list of four is not final.

Why was Oracle included alongside the three biggest cloud providers?
Oracle is not a top-three hyperscaler by global market share, but it remains deeply embedded in core banking databases and back-office systems across the UK financial sector. Its inclusion suggests regulators are designating providers based on how disruptive an outage would be, not purely on cloud market-share rankings.

Is this related to the UK competition investigation into Microsoft and AWS?
It is a separate process. The Competition and Markets Authority’s cloud market investigation, which concluded on July 31, 2025, focused on competition concerns like egress fees and switching costs, and continues independently of the financial-stability-focused CTP regime, even though Microsoft and AWS are named in both.

What should banks and fintechs using these providers do differently now?
Financial firms retain full responsibility for their own third-party risk management, and that obligation does not shift to the cloud providers. What changes is the amount of resilience information regulators, and by extension the firms themselves, can expect from designated providers going forward.

Related Coverage

For more cloud-computing coverage, see the full cloud computing archive on Tech Insider.

Marcus Chen

Marcus Chen

Gaming & Consumer Tech Editor

Marcus Chen is a senior editor at Tech Insider, where he leads coverage of the US online gaming market, including sweepstakes and social casinos, alongside consumer technology. He evaluates operators on their published terms, licensing and RNG certifications, stated redemption policies, and corroborating independent reporting, and writes plainly about what the evidence supports. Tech Insider does not run first-party money tests and does not gamble with reader funds. Marcus has reported on the technology and online-gaming industries for more than a decade.

View all articles