Skip to main content
Cloud★ Featured

The Current

The Current #10 — The Cloud Is Sold Out. Your Quota Won't Save You.

The cloud's capacity promise expired — plus the CMMC Phase 2 pause, EU AI Act transparency enforcement, and the HIPAA Security Rule delay.

Charles Redding, Founder, DLegendDigital6 min read

In late July the CEO of Amazon said $220 billion won't buy enough data-center capacity to meet 2026 demand — that's the blog this cycle: the cloud's oldest promise, "as much as you want, whenever you want it," has quietly expired. The rest of the issue is the same lesson from other directions: one compliance regime arrived on schedule (EU AI transparency rules) while two you may have been sprinting toward just slid (CMMC assessments, the HIPAA security overhaul). Every item below changes a plan someone in your org made this year.

The Cloud Is Sold Out — and Your Quota Was Never a Guarantee#

On July 30, 2026, Amazon CEO Andy Jassy told analysts that roughly $220 billion of 2026 capital spending still won't cover all the demand AWS has this year — and that two large customers tried to buy all of Amazon's Graviton computing capacity for the entire year. Two days earlier, Microsoft's CFO said, for the fourth straight quarter, that Azure demand exceeds supply. And on July 27–28, PJM — operator of America's largest power grid — proposed deliberately cutting power to large data centers during shortages, starting June 2027.

Your cloud quota is not a capacity reservation — Microsoft's own documentation now says so plainly. A quota is a fishing license: it permits you to fish, it doesn't promise there are fish in the lake. For fifteen years that distinction never mattered. In 2026, customers with approved quotas are hitting allocation failures, and new deployments in prime regions are being rationed.

Stop treating capacity as weather and start treating it as a supplier relationship. Three cheap moves: write down your footprint (regions, instance families, which quotas are backed by reservations versus on-demand hope); run one real restore test in your failover region and watch for allocation failures; and convert your most critical workload to reserved capacity — reservations are now an availability mechanism, not just a discount. The full Monday-morning checklist is in this cycle's blog post, linked below — that's the one to read before your next capacity conversation.

The Pentagon Hit Pause on CMMC Phase 2 — Don't Stand Your Program Down#

On July 13, 2026, the Department of War (formerly the Department of Defense) suspended Phase 2 of CMMC — the Cybersecurity Maturity Model Certification, which requires defense contractors to get third-party audits of their cybersecurity — set to start appearing in contracts November 10, 2026. A CMMC Reform Task Force reports back in mid-September; an industry request-for-feedback closed August 14. What did not pause: Phase 1 self-assessments and the DFARS 252.204-7012 contract clause, which still obligates every defense contractor to protect covered defense information.

Thousands of contractors were mid-sprint toward certification audits — some had paid five figures for assessments booked this fall. The reflex is "great, we can stop." That's the trap: the safeguarding obligations remain in force, the underlying NIST SP 800-171 requirements haven't changed, and a reformed program will almost certainly ask for the same controls with different paperwork.

Keep implementing the controls and keep your self-assessment score current — pause only the audit-scheduling spend until the September report lands. If you'd booked a third-party assessment for late 2026, call your assessor about deferral terms this week, not after the money is forfeit.

EU AI Act Enforcement Is Live — and the Part That Applies Now Isn't the Part You Prepped For#

On August 2, 2026, the European Commission's AI Office and national authorities began enforcing the EU AI Act, and the Act's Article 50 transparency obligations took effect. If your product talks to users or generates text, images, audio, or video, it must now tell users they're dealing with AI and mark synthetic content as artificially generated — regardless of whether the system counts as "high-risk." The high-risk obligations were pushed back (as covered in Issue #8) to December 2, 2027 and August 2, 2028. Transparency fines run up to 15 million euros or 3% of worldwide turnover.

A lot of US teams filed "EU AI Act" under delayed after the omnibus news and stopped tracking it. The delay only covered the high-risk tier. The transparency tier arrived on schedule, applies to ordinary chatbots and content generators, and is now enforceable against any company serving EU users.

If anything you ship reaches EU users, run one narrow check this month: does every AI touchpoint disclose itself, and is generated media marked? That's an afternoon of product review, not a compliance program — and it's the difference between a checkbox and a fine while everyone's attention is parked on 2027.

The HIPAA Security Overhaul Slipped to 2027 — the Threats It Answers Didn't#

In its July 2026 regulatory agenda, the Department of Health and Human Services moved final action on the proposed HIPAA Security Rule overhaul — mandatory encryption of patient data, required multi-factor authentication (MFA — the second login step beyond a password), 72-hour incident reporting, annual penetration testing — to its long-term agenda, with July 2027 now the earliest expected date. Separate HIPAA Privacy Rule changes are still expected as early as August 2026.

Health-sector IT teams budgeted 2026 around this rule, and some finance departments will read the delay as permission to defer the encryption and MFA line items. But the existing Security Rule remains fully enforceable, breach-driven enforcement hasn't slowed, and every control in the proposal is one regulators already cite as the difference between a defensible program and a negligent one.

Keep the MFA and encryption projects funded — they were never really about the rule. Re-sequence only the paperwork-heavy tail (formal inventories, documentation rewrites) the new rule would mandate. Say that distinction out loud in your next budget review before someone else frames the whole program as deferrable.

How This Impacts Your Organization#

The principle doesn't change with company size: schedules other people control — a capacity queue, a regulatory effective date — moved in both directions this month, and the cost lands on whoever planned around the old date. What changes by size is which schedule hits you first, your slack to absorb the whiplash, and where your leverage sits.

Large Enterprises (1,000+ employees)

Your risk is organizational — these four schedule changes land in four different inboxes: infrastructure, the federal business unit, legal, the healthcare division — and nobody reconciles what just accelerated versus what just slipped. Your leverage is scale: you can get capacity assurances in writing at your next cloud negotiation, something smaller firms can't demand. The organizational move this quarter: put all four dates in one external-change register with a named owner, and have that owner test — not believe — the assumption your disaster-recovery plan makes about spinning up capacity in an alternate region.

Mid-Size Organizations (100–999 employees)

You feel the whiplash fastest — one or two people own all four areas, and re-planning is unpaid overtime. The overcorrection to avoid this issue: treating the two delays as free budget. Cutting the 800-171 controls work or the healthcare MFA project because "the deadline moved" trades real risk reduction for paper savings — both rules are coming back with the same controls inside. Three moves, no platform team required: reserve capacity for your two or three critical workloads; keep control implementation funded, pausing only audit-scheduling fees; run the one-afternoon EU AI transparency check if you ship to EU users.

Small & Growing Organizations (under 100 employees)

Honest counsel: three of these four reach you as ripples, not waves. You're likely not a defense prime or a covered health entity, and small workloads fit in the cracks of a constrained cloud market. Don't launch a multi-cloud project or a compliance sprint off this issue. Three lightweight things: write down which cloud region and instance types you run on (it fits on an index card); know your second-choice region before you need it; and — if your product has a chatbot or generates content for anyone in the EU — add the "you're talking to AI" disclosure now, because that one does apply at your size. Everything else here is worth one eye, not a budget line.

  1. The Cloud Is Sold Out — and Your Quota Was Never a Guarantee (companion blog post) — dlegenddigital.com/blog
  2. Amazon Q2 2026 earnings call transcript — fool.com
  3. Microsoft FY26 Q4 earnings — microsoft.com/investor
  4. PJM data-center curtailment plan — techcrunch.com
  5. Azure previous-gen VM capacity limitations — learn.microsoft.com
  6. Pentagon suspends CMMC Phase 2 — wilmerhale.com
  7. CMMC phase two suspension — federalnewsnetwork.com
  8. CMMC: what still applies — crowell.com
  9. Commission starts enforcing AI Act rules August 2 — digital-strategy.ec.europa.eu
  10. EU AI Act transparency obligations now in force — goodwinlaw.com
  11. Omnibus postponement of high-risk deadlines — gibsondunn.com
  12. HHS delays HIPAA Security Rule until 2027 — alston.com
  13. HIPAA Security Rule update delayed — clarkhill.com

Four schedules moved this month and none asked permission. The companies that get hurt are the ones that turned someone else's date into a load-bearing assumption. The fix is the same boring muscle every time: know which dates you depend on, and check them before they check you.

On the blog this cycle: The Cloud Is Sold Out — and Your Quota Was Never a Guarantee — what capacity-constrained cloud means at your size, and the Monday-morning checklist.

Hit reply and tell me what you're wrestling with — I read every one.

— Charles Redding, Founder, DLegendDigital

Paired long-form

The Cloud Is Sold Out — and Your Quota Was Never a Guarantee

Amazon says $220 billion won't buy enough capacity for 2026. Microsoft has said "demand exceeds supply" four quarters running. The cloud's oldest promise just expired — here's what that means at your size.

Read the full article

The Current

Get the next one before anyone else.

Twice a month. ~5 min read. No spam, no upsells buried in footnotes.

Free. Unsubscribe any time.

More issues

Full archive →