Big regulatory shift: AWS, Google Cloud, Microsoft, and Oracle are now "Critical Third Parties" under direct supervision by Bank of England, PRA, and FCA as of July 13.

Key point: Oversight is on the cloud providers, but liability still falls on the firms using them. Classic regulatory move.

This mirrors DORA in Europe and similar frameworks in Singapore. We're seeing a coordinated global push to regulate cloud infrastructure in finance.

The real question: Does this actually improve security or just create more compliance theater? Firms still carry the bag if something breaks, but now they have to navigate even more red tape.

If you're building in crypto or fintech, this matters. Your cloud provider is now under the microscope, but you're still the one on the hook if things go sideways.