Skip to main content

The Market Has Started Pricing Cloud Risk. Enterprises Haven't.

Tyler

Tyler

Co-Founder & CEO

|
An exchange board above a trading floor quoting cloud uptime as a live market, with AWS, Azure, Google Cloud, Office 365 and GitHub all falling and a Cloud Uptime Index down 65%

For about fifteen years, "how reliable is our cloud provider" was a question for engineers. It lived in architecture reviews and postmortems, it produced diagrams with redundant boxes, and it almost never reached a board deck. The assumption underneath it was simple and, for a long time, roughly correct: the hyperscalers are more reliable than anything you would build yourself, so buy from them, sign the standard agreement, and spend your risk attention elsewhere.

Something changed in the last twelve months, and it did not change in engineering. It changed in finance.

Three separate markets that have no particular interest in cloud architecture have now put an explicit price on cloud dependency. Capital markets are repricing the companies building the infrastructure. Reinsurers are selling catastrophe bonds against its downtime. Regulators have designated the three largest providers as systemically critical and put them under direct supervision. Each of those groups did the work, ran the numbers, and concluded that this risk is large enough to require a mechanism.

The enterprises actually running on that infrastructure are, so far, the only participants who haven't repriced anything. Most are still working from a service agreement whose worst-case remedy is a percentage of one month's bill.

That gap is the story of 2026, and I think it is about to close, one way or another.

What the Capital Markets Are Saying

Start with the money going in, because the scale of it is what pulled everyone else's attention.

Amazon, Microsoft, Alphabet, and Meta are guiding to roughly $725 billion in capital expenditure for 2026, up about 77% from $410 billion in 2025. In the four quarters through March 2026 those four purchased $433.9 billion of property and equipment, with first-quarter capex alone reaching $129.8 billion, up 80% year over year. Analysts tracking the group put capital intensity, capex as a share of revenue, somewhere between 45% and 57%. That is not a software company's balance sheet. That is a utility's.

The interesting part isn't the size. It's what the market did next.

The divergence between AI capital expenditure and AI revenue growth is running near 46%, which already exceeds the roughly 32% divergence recorded during the 2001 telecom build-out. Analysts have flagged an annual gap on the order of $600 billion between infrastructure spend and what the AI ecosystem actually books in sales. Hyperscalers have quietly stretched depreciation schedules for AI hardware from the historical three-year norm toward five and six years, which by some estimates understates true depreciation by around $176 billion across 2026 to 2028 and flatters reported earnings today. The sector raised $108 billion of new debt in 2025, and Morgan Stanley and J.P. Morgan both estimate the technology sector will need to issue roughly $1.5 trillion more over the next three years to finance the build.

AI capex to revenue divergence running near 46% in 2026, above the roughly 32% divergence recorded during the 2001 telecom build-out, against $725 billion of planned hyperscaler capex and an estimated $1.5 trillion of new technology sector debt needed over three years

Investors noticed. Shares in Google, Amazon, and Microsoft all sold off following recent earnings calls, not because the results were bad but because the spending was large and the return timeline was vague.

I'm not making a bubble call here, and it isn't the point. The point for anyone buying cloud services is narrower and more practical: your providers are now leveraged, capital-intensive businesses under visible pressure to demonstrate returns on an enormous build. Companies in that position optimize. They stretch asset lives, they run hardware hotter and longer, they fill capacity they were holding as headroom, and they prioritize the workloads with the best margins. None of that is scandalous. All of it reduces the slack in the system that used to absorb your bad day quietly, and none of it shows up anywhere in your contract.

What the Insurance Market Is Saying

This is the signal I find most persuasive, because insurers are the one group in this story with money at stake on the downside and no incentive to be dramatic.

In March, Parametrix placed Cumulus Re Series 2026-1, a $35 million catastrophe bond providing Hannover Re with retrocessional protection against cloud outage losses through April 2027. It is the third in the series and by far the largest: $13.75 million in 2024, $20 million in 2025, $35 million in 2026, a 75% increase in a single renewal, upsized on investor demand and drawing more participants than either predecessor. The structure is parametric. It pays on a measured trigger, sustained downtime at AWS, Azure, or Google Cloud across specified US and EU regions, with no claims adjustment and no requirement to prove a loss. Parametrix acts as calculation agent, monitoring the covered services continuously against a dataset built from thousands of real outage events.

Cumulus Re cloud outage catastrophe bond growing from $13.75 million in 2024 to $20 million in 2025 to $35 million for 2026 to 2027, a 75% increase in a single renewal

Sit with what that means. Cloud downtime is now a modeled, underwritten, tradeable peril. It has an actuarial price, a risk curve, and a growing pool of capital-market investors willing to take the other side. Reinsurers do not write catastrophe bonds against risks they consider immaterial, and investors do not upsize them three years running against a peril they think is fading.

The primary market moved too. Mantas came out of stealth in January with $1.77 million in seed funding to sell parametric insurance for cloud downtime. Parametrix's enterprise product pays within fifteen days of a verified trigger, with low waiting periods and no cash deductible, aimed at fintechs, SaaS platforms, e-commerce, airlines, and regulated enterprises.

Compare the two instruments sitting on the same risk. One is a parametric policy that pays a predetermined amount, automatically, on measured downtime, in fifteen days. The other is your cloud provider's SLA, which pays a percentage of one month's fee for that service, only if you detect the breach, document it, and file inside a window that typically runs 30 to 60 days. Both are pricing the same event. Only one of them was designed to actually compensate you for it.

What the Regulators Are Saying

The third market to reprice this doesn't trade anything. It legislates.

On November 18, 2025, the European Supervisory Authorities published the first list of critical ICT third-party providers under the Digital Operational Resilience Act. Nineteen firms were designated, including Amazon Web Services EMEA, Google Cloud EMEA, and Microsoft Ireland Operations. Designation is not a label. It puts those providers under direct ESA supervision, with inspection rights, documentary evidence requirements, and binding recommendations issued to the provider itself rather than to its customers.

The reasoning behind it is the same concentration math everyone else keeps arriving at. Regulators found that more than 65% of EU financial entities rely on at least two of AWS, Azure, and Google Cloud for critical functions. DORA's Article 28 requires entities to assess concentration risk directly, and Article 30 requires contracts for critical functions to include workable exit and transition provisions. In other words, a European regulator has decided that "we use the big three, they're reliable" is not an acceptable answer, and has made documenting provider performance a legal obligation rather than an operational nicety.

Regulation of this kind rarely stays in its original jurisdiction, and it rarely stays in one sector. Financial services is simply where it starts, because that's where the systemic argument is easiest to make.

Meanwhile, the Risk Itself Got Worse

All of this repricing is happening against a backdrop that has genuinely deteriorated, in ways that have nothing to do with anyone's architecture diagram.

On March 1, drone strikes physically destroyed data center capacity in AWS's Middle East regions, taking out two of three availability zones in ME-CENTRAL-1 and degrading or disabling more than 109 services. Fire authorities ordered a full power shutdown of the affected facility, backup generators included. AWS waived all usage charges in the region for March. Months later the regions were still not fully restored, and The Register reported a further strike on the Bahrain facility on July 21. I don't know how to describe that as anything other than a category shift. Cloud concentration risk is now partly a geopolitical exposure, and no multi-AZ design accounts for a munition.

The routine failures picked up pace too. On July 24, AWS lost network connectivity between the us-west-2 region and the Seattle metro. Traffic that started and ended inside the region was fine; anything crossing the boundary timed out. Ten services were affected, including Direct Connect, API Gateway, EC2, and Elastic Load Balancing. Most customers saw about twenty minutes of impact, Direct Connect customers through one Seattle exchange saw an hour and seventeen. Apple Pay, Reddit, Hulu, DoorDash, and PlayStation Network all went down with it.

Twenty minutes sounds survivable, and the headline duration is exactly what makes this case instructive. Downstream recovery ran far longer than the incident: one affected vendor remained degraded until 21:28 UTC, more than nine hours after AWS restored routing, as backoff mechanisms and queued processing worked through the backlog. Another needed 90 minutes just to clear mail queues. The provider's incident was twenty minutes. Its customers' incidents were most of a day.

And it was the third distinct AWS reliability event in eleven weeks, each at a different layer: physical cooling and hardware in May, a third-party network provider in June, a network boundary in July. Three incidents, three layers, one quarter. Google Cloud had its own power and cooling failure in europe-west4-a on July 15 and 16, hitting VMware Engine, Bare Metal Solution, and NetApp Volumes.

Three markets repriced cloud dependency in twelve months: capital markets through a 77% capex increase and depreciation scrutiny, reinsurers through a 75% larger cloud outage cat bond, and regulators through DORA critical provider designations, while enterprise remedy remains a percentage of one month's service fee

The One Contract That Hasn't Repriced

So: the people financing this infrastructure have repriced it. The people insuring it have repriced it. The people regulating it have repriced it. The physical and operational risk has measurably increased.

And the standard cloud SLA is essentially the document it was a decade ago. Credits scale as a percentage of the monthly fee for the affected service, typically 10% below 99.99% availability, 25% below 99.0%, 100% only in extreme cases below 95.0%. The remedy is capped by what you pay. Your loss is capped by nothing: it scales with your revenue, your own customer commitments, and everything you built on top. Analysis of the October 2025 AWS US-East-1 outage found that SLA credits covered roughly 8% of the actual business loss enterprises absorbed.

The asymmetry in one line

A reinsurer pays a predetermined sum on measured downtime within 15 days, with no proof of loss required.

Your cloud provider pays a percentage of one month's service fee, only if you detect the breach, assemble the evidence, and file inside a 30 to 60 day window that nobody owns internally.

Both instruments cover the same outage.

Part of that 8% gap is structural. No process closes the distance between a credit capped at monthly spend and a loss measured in lost revenue, and I'd be selling you something dishonest if I claimed otherwise. But a meaningful portion of it is not structural at all. It is simply money that was contractually owed and never claimed, because detecting a breach across every provider you use, mapping it to specific SLA terms, and filing before the window closes is nobody's actual job. That part is fixable, and it is the cheapest risk-adjusted return available in this entire picture.

Where This Goes Next

If three markets have already repriced this and one hasn't, the interesting question is what closing that gap looks like. A few things I expect over the next two years.

Reliability moves from engineering into procurement and finance. It has to. Once a regulator requires a documented register of provider performance and an insurer prices your premium off measured downtime, provider reliability becomes a number that finance reports, not a chart an SRE keeps. The organizations that handle this well will have one owner for it, the way they have one owner for tax exposure or FX risk.

Degradation gets measured, and eventually gets priced. Today's SLAs measure whether an endpoint answered. The failures that cost enterprises real money are throttling, latency, and quality regressions that never trip an availability clock. Insurers pricing this peril will want telemetry that reflects what customers actually experienced, and once that data exists and is trusted, it becomes negotiable in contracts. The first large enterprises to bring measured performance data to a renewal are going to do noticeably better than the ones bringing a status page screenshot.

Independent measurement becomes table stakes. A provider's own status page is a self-report by an interested party, and 2026 has repeatedly shown it lagging the customer experience. Regulators requiring documented performance, insurers requiring verified triggers, and boards asking for concentration exposure all converge on the same need: a measurement layer nobody involved in the outage controls.

Concentration exposure lands on the risk register. Not as an IT line item. As a first-order enterprise risk, with the same seriousness as counterparty exposure, because that's precisely what it is.

Things To Think About

The case for treating cloud reliability as a financial exposure is no longer something you have to make from first principles. Three independent markets have already made it, with real capital, in the past twelve months. Reinsurers are underwriting it. Regulators are supervising it. Investors are discounting for it.

The remaining question is whether your organization prices it before something forces the issue: a regulator, an insurer, a customer's own resilience questionnaire, or a Tuesday where the status page stays green while your revenue doesn't.

Outages are inevitable, and the build-out is going to keep straining under its own weight for a while yet. What isn't inevitable is absorbing the full cost of both while leaving the money you're already owed sitting uncollected. That's the gap Next Signal exists to close, and it's the one part of this entire picture you can fix without anyone else's permission.

Frequently Asked Questions

What is a cloud outage catastrophe bond?

It is a security that transfers cloud downtime risk to capital-market investors. Parametrix's Cumulus Re series, sponsored by Hannover Re, pays out on a parametric trigger when sustained downtime hits AWS, Azure, or Google Cloud in specified US and EU regions, with no claims adjustment required. It has grown from $13.75 million in 2024 to $35 million for the 2026 to 2027 period.

Which cloud providers are designated critical under DORA?

On November 18, 2025, the European Supervisory Authorities designated 19 critical ICT third-party providers, including Amazon Web Services EMEA, Google Cloud EMEA, and Microsoft Ireland Operations. Designated providers face direct ESA supervision, inspection rights, and binding recommendations.

How much are hyperscalers spending on AI infrastructure in 2026?

Amazon, Microsoft, Alphabet, and Meta are guiding to roughly $725 billion in capital expenditure for 2026, up about 77% from $410 billion in 2025, with capital intensity running at 45% to 57% of revenue.

How much of an outage loss does an SLA credit actually cover?

Analysis of the October 2025 AWS US-East-1 outage found SLA credits covered roughly 8% of the real business loss on average. Credits are capped as a percentage of your monthly spend on the affected service, while your loss scales with revenue and customer commitments.

How many major AWS incidents happened in mid-2026?

Three distinct reliability events in eleven weeks, each at a different layer: a physical cooling and hardware failure in May, a third-party network provider failure in June, and a region-boundary network failure on July 24 that took down Apple Pay, Reddit, Hulu, DoorDash, and PlayStation Network.

Sources

Industry data and reporting cited in this article: