How Public is the Public Cloud?

Benton Institute for Broadband & Society

Wednesday, September 9, 2026

Digital Beat

How Public is the Public Cloud?

Join the conversation! On September 24th, Dr. Amelia Acker will present a lightning talk about the public cloud and the resilience of this critical infrastructure. The Benton Institute for Broadband & Society will bring together leaders from industry, government, academia, and the public-interest community for A New Compact for Connectivity: Internet Infrastructure in the Public Interest. You can join us online or in-person in Washington, D.C.

Amelia Acker
          Acker

This past spring, Canvas, the learning management system software I use to teach courses at Rutgers University, was hit by a global security breach that affected thousands of colleges and universities. The company that operates Canvas rolled back features while it addressed the breach. The timing of the hack couldn’t have been worse. For several days, software rollbacks prevented students from accessing course materials and kept instructors from proctoring exams and uploading final grades during the last weeks of the spring semester.[1]

Two weeks before, the infrastructure Rutgers owns failed when the university’s data center lost power for most of a day, and nearly all our cloud-based software systems, from course registration to payroll and financial aid, were inaccessible. The campus-wide wireless internet networks and Rutgers’ Clinical Research Data Warehouse were also impacted.[2] For students, staff, researchers, and faculty at a university serving tens of thousands of people, most work stopped due to the outage.

I teach archives, digital curation, and public interest technology to graduate students training to become public librarians and archivists. I work at one of the oldest (and largest) public research institutions in the U.S. The word “public” means many different things today, and we can see these differences depending on how it’s applied and by whom. Public can mean the way that Benjamin Franklin’s post office meant public: a service any person could use to reach any other person. Public can also mean a resource held in common, funded collectively by a geographically connected community, open to whoever walks in the doors, the way we might understand our local libraries.

Public can also mean the ways that corporate firms serve people online. For platform owners like Elon Musk and Mark Zuckerberg, public means the online “town square” that millions of Americans use every day and that firms can reconfigure at will. Importantly for the computing services sector, the modifier public in “public cloud” does not mean public ownership, or universal access, or public governance with obligations to act in the public interest. So, when I ask how public the public cloud really is, I’m asking us to think about which definition applies to our computing infrastructure, and at the same time, I am pointing to how dependent our institutions have become on this technology to meet obligations to their stakeholders.

As a library and information science professor, I experienced these failures last semester in two ways. One involved infrastructure that Rutgers owns and operates. The other involves software that we license from a vendor under contract. In both cases, our dependence on the cloud underscores how critical and interconnected the stack is when large organizations face crises. But from the perspective of our mission as the State University of New Jersey, the difference between these two different types of cloud-driven failures, private and public, is less meaningful. Either way, Rutgers is responsible for educating students, paying employees, managing research projects, preserving knowledge, and maintaining access to federally funded scientific data whether the servers are in New Brunswick or in Northern Virginia. Both private and public cloud failures impeded our public mission. When an institution’s infrastructure fails, it can hold itself accountable. But when a vendor’s infrastructure fails, customers can only wait and see.

Anyone who has worked at an institution lately can recognize these headaches. In some parts of the country, massive power outages and software hacks are common occurrences for organizations leveraging public cloud technologies. Procurement contracts and service-level agreements with Big Tech firms such as Amazon, Microsoft, Oracle, and Google govern much of the cloud. “Public cloud” services are the networking, storage, and computing resources operated by third-party providers and shared across customers.[3]

Today, public universities, public libraries, public hospitals, national research laboratories, public schools, and local governments fulfill public obligations to manage critical data resources using digital infrastructure they do not own and, in many cases, cannot build or maintain themselves. Governments allocate resources to these institutions so they can provide services we consider essential, and for many, this government support drives specific obligations to their publics.

Rutgers’ two cloud failures on campus illustrate a peculiar problem hiding in plain sight: Institutions now rely on the public cloud to meet their obligations, but the public cloud carries no comparable obligations. So, what happens when the public cannot work without this critical digital infrastructure?

What Makes Infrastructure Public: From the Postal Service to Cloud Services

When I teach my students the significance of cloud infrastructure in contemporary information technology, we usually start with a much older information network—the U.S. Postal Service (USPS). Just like our digital data today, a mailed letter is accepted, sorted, and stored, then routed and transmitted across a physical network for delivery. Each of these information processes that support mail delivery requires physical facilities, technical standards, security practices, trained workers, and policy about who gets served and under what conditions. Since the Postal Service Act of 1792, federal policy has attached public obligations to those processes because Americans came to depend on those networked services for information, news, and commerce.[4]

Telecommunications policy has also followed a similar path. Concepts such as universal service, privacy, ensuring continuity, and reasonable access all grew out of fights over who controlled communications infrastructure and what that control required of commercial operators.[5] Just like the USPS mail system, communication networks are critical to participating in society. The Communications Act of 1934 created the Federal Communications Commission to make, as possible, wire and radio communication available to all the people of the U.S. with adequate facilities at reasonable charges. The Telecommunications Act of 1996 later codified universal service formally in Section 254.

The stack of IT services we call “the cloud” is a lot like what the USPS does with our mail. The cloud stores information, moves it across locations, authenticates users, routes and verifies requests, runs applications, and determines who can access data and how. But importantly, storage and transmission increasingly happen inside the stack in ways that make users dependent on these services. This drift towards enclosure and dependency on cloud computing services is sometimes called the generative entrenchment of platforms. A teacher’s entire course can be built in Canvas, a legal contract is shared in Microsoft Outlook and kept in OneDrive, a patient’s medical history is stored in a healthcare records portal. Each is incredibly convenient, but they are all vulnerable to system-wide outages, and portability options vary, making it harder to leave the longer you stay.  

The history of postal and telecommunications policy shows that once an intermediary becomes critical to communication, society begins to build expectations around it and attach obligations to its position in the network as a public good. In his book The Master Switch: The Rise and Fall of Information Empires, legal scholar Tim Wu analyzes the Telecommunications Act of 1996 as part of a recurring historical cycle where open communications systems inevitably consolidate into centralized monopolies that policy needs to interrupt.[6] A similar pattern is now happening with “hyperscalers”[7] like Amazon, Microsoft, and Google, as these firms are accumulating market dominance like telecommunications firms once held.[8]

For infrastructure studies scholars like Ryan Ellis, histories of critical infrastructure—such as telecommunications networks and the electrical grid—show how security crises and outages can bring together publics—workers, corporations, regulators, communities, and governments—whose interests become bound in a shared system.[9] These “infrastructure publics” relate to one another, each with competing interests as they face crises, technology adoption, and regulatory efforts, among other social forces. The global Canvas software hack is a case in point. The software outage showed what securing infrastructure means on the ground and whose interests should receive priority when a shared network system fails its users.

Security crises and failures allow infrastructure publics to redefine interests and governance over the critical technologies they depend on. Ellis argues that these arrangements may seem inevitable because of technology adoption. Still, crises can spur debates that reopen infrastructure to public scrutiny and accountability, forcing operators to consider interests beyond their own bottom line.

What obligations should be attached to infrastructure once entire sectors of public life depend on it? To answer this question, it’s worth reminding ourselves how public organizations came to depend on corporate computing services. Historians have argued that reliance on corporate computing and contracted storage services in government reaches back to the 1970s.[10] As computing systems became larger and more complex, private contractors could provide technical expertise, support larger economies of scale, and lower costs while governments and businesses adopted automated systems. In her history of this transition, Helen Margetts found that by the 1990s, the U.S. government had contracted out roughly half of its information technology work. As public institutions contracted out computing services for longer and longer periods, they could lose organizational technical expertise and the qualified personnel needed to supervise those contracts.[11] IT outsourcing changed how many organizations (not just governments) managed their information flows. Over time, institutions can become less capable of replacing, managing, or reclaiming the systems they had contracted out. For many organizations, once outsourcing computing services becomes entrenched, it is not easily reversible.

My own research suggests a similar transition is happening in archiving federally funded research data for public access. My colleagues and I found that scientists increasingly plan to use commercial platforms and cloud services to preserve and provide access to their research data.[12] The policy questions around data storage obligations become even more urgent because the cloud computing market is highly concentrated and the AI boom is accelerating the dominance of a few players. In their recent report on “Big Cloud” investments, David Widder and Nathan Kim estimate that Amazon, Microsoft, and Google now control approximately two-thirds of global cloud compute market share.[13] They also found that Big Cloud extends well beyond server capacity, as all three companies have invested across the tech ecosystem, distributing discounted cloud credits for usage, bundling services, and entering into contracts that make adoption easy but, like the Hotel California, make checking out hard.

We’re also seeing the same pattern as the AI boom hits higher education. In a recent study on hyperscalers in universities, Britt S. Paris and I found that cloud providers like Google and Microsoft can quickly pull back storage services and force new AI features across campuses, creating a form of functional sovereignty over the information technology now integral to teaching and research.[14] When hyperscalers change their cloud services, institutions have no choice but to scramble to align their organizational policies. I’d rather that our hospitals, universities, public utilities, and emergency services have a say in the systems they depend on to fulfill their obligations than remain at the mercy of cloud providers, as we do now.

AI, Data Centers, and the Case for a Public Cloud Policy

Public institutions have already transitioned to the cloud, but AI-driven data centers are creating space for new infrastructure publics to debate how we govern and regulate them. AI services sit on top of data centers and storage infrastructure, drawing enormous amounts of power from the electrical grid. Communities across the country are pushing back and fighting the arrival of large data centers, and the electricity, transmission infrastructure, water, and tax incentives to build them.

State policymakers are beginning to respond. They understand that if public life increasingly depends on data centers and hyperscalers’ infrastructure, then cloud policy needs to be created. We’re seeing progress in different ways at the state level. For example, New Jersey has begun developing a regulatory framework to offset the costs of these facilities after they are built. Governor Sherrill’s May 2026 framework requires data-center operators to 1) fund their own energy needs, 2) report transparently on energy and water use, 3) sign community benefit agreements, and 4) meet local-labor requirements.[15] The New Jersey Legislature moved in parallel, with one bill proposing a tariff on data centers drawing more than 100 megawatts (S731) and one law (S3379) requiring biannual reporting of energy and water use to the New Jersey Board of Public Utilities.[16]

California lawmakers have started considering whether compute resources should be understood as a public service. In September 2025, Governor Newsom signed the Transparency in Frontier Artificial Intelligence Act (SB 53), which requires large AI developers to publish safety frameworks and report critical safety incidents.[17] SB 53 also includes a smaller, more interesting idea supporting public compute infrastructure called ‘CalCompute.’ CalCompute will be a publicly owned cloud computing cluster housed at the University of California, designed to give researchers and the public an alternative to relying entirely on commercial compute for AI systems. The law’s transparency and incident-reporting rules took effect immediately, but funds for the CalCompute public cloud haven’t been appropriated yet.

Inspired by these examples from New Jersey and California, public cloud policy for public institutions could include:

  • meaningful, actionable portability and exit requirements, so that moving data is technically and financially realistic for financially constrained organizations,
  • interoperability for designated critical services and clear rules governing the secondary use of institutional data, which right now is negotiated contract by contract, and
  • continuity obligations when providers discontinue critical services or substantially change prices and storage limits.

Workforce training remains an issue for managing and maintaining critical infrastructure. Public institutions could be required (and funded) to retain enough technical expertise to maintain systems, audit vendors, oversee migrations, and operate emergency alternatives during outages and security incidents. Right now, only the most well-resourced institutions have the staffing and expertise to do this. Regulators could also examine the concentration and redundancy needed across regions and sectors to support public cloud resources.

The bottom line is that we need a world where storing, moving, and accessing information is always available, governed by basic public policy, a different world from the one we have now, where there is great dependence on cloud infrastructure, primarily governed by service contracts between vendors and clients.

Conclusion: Making the Public Cloud Public

Today, the public cloud’s infrastructure publics include providers, universities, hospitals, governments, workers, regulators, utilities, and the communities living alongside and depending on data centers. Their interests are not always aligned. But critical services for healthcare, education, economic productivity, and public safety need a shared floor of reliability and access that does not depend on any single provider’s business decisions. The moment is right to gather these infrastructure publics with the momentum and pushback around AI data centers. We should use this moment to trace the networked dependencies that bind us together and untangle our competing interests in ways that better serve the institutions carrying out public missions with the cloud.

Critics will say that the market has already given us a solution, that hyperscalers are dominant because they provide great services. The current political climate might also give us pause, given that a presidential administration that is hostile to statewide AI policies could just as easily weaponize a public cloud framework.

To be sure, none of these policy recommendations would have necessarily prevented either of the campus cloud failures Rutgers faced last spring. But my goal here is not to promise that regulation would have stopped either failure. It’s to spur a conversation about what current policy is missing when it comes to public obligations and our dependencies on the cloud.

I’m not arguing that the government needs to build an American version of Amazon Web Services. But CalCompute is one example of what states can do when we treat compute as a public resource. Policy experts have warned that prolonged cloud contracts diminish organizations’ technical expertise, making institutions less capable of overseeing the localized IT services they depend on.[18] The Rutgers power outage could have happened inside a public cloud, and Canvas could still have been hacked. We know infrastructure like this fails. But the policy question concerns what happens after failure, particularly who bears responsibility, who has the capacity to respond, and whether institutions retain meaningful choices once dependence on cloud infrastructure becomes required to operate and meet their obligations.

I want to end where I began. Public institutions have obligations that their infrastructure providers do not. These obligations are measured in decades, possibly centuries, while IT firms are driven by quarterly business earnings and three-year contract cycles.

We crafted policy for telecommunications, electricity, railroads, banking, and broadcasting because Americans became so dependent on these services that they had become emblematic of what it means to participate in public life and belong to society. Public interest regulation should focus on dependencies, because dependence creates obligations to users that extend beyond any contract.

What “public” really means is the question underneath all of this. Writing in 2006, the philosopher and librarian Ed D’Angelo warned that markets, when left to govern information on their own, tend toward “the monopoly capitalism of a few major players.”[19] A market can coordinate consumption. But it cannot decide what a society owes its members.

For decades, telecommunications policy has confronted how Americans should be connected to networks. The next compact must focus on what happens after they connect.


Amelia Acker is an Associate Professor of Library and Information Science at Rutgers, The State University of New Jersey. Acker currently serves as an editor of the Journal of Cultural Analytics and co-editor of the Sage Handbook of Data and Society. Her research is known for exploring the intersection between digital technologies, information infrastructure, and cultural memory in contemporary society.

References

Acker, Amelia, and Britt S. Paris. “Hyper-Scaling from the Cloud to the Tower: Platform Enclosure and GenAI Capture in Higher Education.” Information, Communication & Society 0, no. 0 (2026): 1–20. https://doi.org/10.1080/1369118X.2026.2717382.

Acker, Amelia, Thomas Struett, Yubing Tian, and Megan Finn. “Platformization of Research Data Infrastructure: A Decadal Analysis of Scientific Data Management Plans.” Big Data & Society 13, no. 2 (2026): 20539517261431593. https://doi.org/10.1177/20539517261431593.

Campbell-Kelly, Martin, William Aspray, Nathan Ensmenger, and Jeffrey R. Yost. Computer: A History of the Information Machine. 3rd ed. Routledge, 2019. https://doi.org/10.4324/9780429495373.

Cath, Corinne. Clouds Over the Netherlands: Preserving Public Interest Internet Governance in the Era of Hyperscaler Clouds. Zenodo, 2025. https://doi.org/10.5281/ZENODO.15230914.

D’Angelo, Ed. Barbarians at the Gates of the Public Library: How Postmodern Consumer Capitalism Threatens Democracy, Civil Education and the Public Good. Library Juice Press, 2006. 361964. https://research.ebsco.com/plink/f66d22ee-9d81-39bc-b0eb-e548b833251b.

Ellis, Ryan. Letters, Power Lines, and Other Dangerous Things: The Politics of Infrastructure Security. 1st ed. Infrastructures. The MIT Press, 2020. https://doi.org/10.7551/mitpress/10541.001.0001.

Goyal, Sumit. “Public vs Private vs Hybrid vs Community - Cloud Computing: A Critical Review.” International Journal of Computer Network and Information Security 6, no. 3 (2014): 20–29. https://doi.org/DOI:10.5815/ijcnis.2014.03.03.

Haigh, Thomas. “How Data Got Its Base: Information Storage Software in the 1950s and 1960s.” IEEE Annals of the History of Computing 31, no. 4 (2009): 6–25. https://doi.org/10.1109/MAHC.2009.123.

Instructure. “Security Incident Update & FAQs.” July 21, 2026. https://www.instructure.com/incident_update.

“Issues with Network Connectivity and IT Services.” Rutgers University Information Technology, April 27, 2026. https://it.rutgers.edu/alerts/2026/04/27/issues-with-network-connectivit....

John, Richard R. Network Nation: Inventing American Telecommunications. Belknap Press: An Imprint of Harvard University Press, 2010.

Margetts, Helen. Information Technology in Government: Britain and America. 1st ed. Routledge Research in Information Technology and Society 2. Routledge, 1999. https://doi.org/10.4324/9780203020944.

Narayan, Devika. “Platform Capitalism and Cloud Infrastructure: Theorizing a Hyper-Scalable Computing Regime.” Environment and Planning A: Economy and Space 54, no. 5 (2022): 911–29. https://doi.org/10.1177/0308518X221094028.

“Nationwide Security Breach Involving Canvas.” Rutgers University Information Technology, May 4, 2026. https://it.rutgers.edu/alerts/2026/05/04/nationwide-security-breach-invo....

New Jersey Legislature. “NJ Legislature.” Accessed August 30, 2026. https://njleg.state.nj.us/bill-search/2026/S731/bill-text?f=S1000&n=731_I1.

New Jersey State Legislature. “New Jersey S3379.” LegiScan, August 27, 2026. https://legiscan.com/NJ/bill/S3379/2026.

Ruediger, Dylan. Big Data Infrastructure at the Crossroads. Ithaka S+R. Ithaka S+R, 2021. https://sr.ithaka.org/publications/big-data-infrastructure-at-the-crossr....

“Ruiz, Mukherji Bill to Hold Data Centers Accountable for Water and Energy Use Signed into Law.” Accessed August 30, 2026. http://www.njsendems.org/m/newsflash/Home/Detail/1451.

“SB 53- CHAPTERED.” Accessed August 20, 2026. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=20....

Shaw, Christopher W., and Ralph Nader. First Class: The U.S. Postal Service, Democracy, and the Corporate Threat. City Lights Publishers, 2021.

State of New Jersey. “Governor Sherrill Announces Comprehensive Plan on Data Centers.” Governor Mikie Sherrill, May 27, 2026. https://www.nj.gov/governor/news/2026/20260527a.shtml.

Widder, David Gray, and Nathan Kim. “How Big Cloud Becomes Bigger: Scrutinizing Google, Microsoft, and Amazon’s Investments.” SSRN Scholarly Paper No. 5377426. Social Science Research Network, July 31, 2025. https://doi.org/10.2139/ssrn.5377426.

Wu, Tim. The Master Switch: The Rise and Fall of Information Empires. Vintage, 2011.

Notes

[1] “Nationwide Security Breach Involving Canvas,” Rutgers University Information Technology, May 4, 2026, https://it.rutgers.edu/alerts/2026/05/04/nationwide-security-breach-invo... “Security Incident Update & FAQs,” Instructure, July 21, 2026, https://www.instructure.com/incident_update.

[2] “Issues with Network Connectivity and IT Services,” Rutgers University Information Technology, April 27, 2026, https://it.rutgers.edu/alerts/2026/04/27/issues-with-network-connectivit....

[3] Sumit Goyal, “Public vs Private vs Hybrid vs Community - Cloud Computing: A Critical Review,” International Journal of Computer Network and Information Security 6, no. 3 (2014): 20–29, https://doi.org/DOI:10.5815/ijcnis.2014.03.03.

[4] Christopher W. Shaw and Ralph Nader, First Class: The U.S. Postal Service, Democracy, and the Corporate Threat (City Lights Publishers, 2021).

[5] Richard R. John, Network Nation: Inventing American Telecommunications (Belknap Press: An Imprint of Harvard University Press, 2010).

[6] Tim Wu, The Master Switch: The Rise and Fall of Information Empires (Vintage, 2011).

[7] Hyperscaler refers to firms’ ability to serve customers through scalable distributed infrastructure.

[8] Devika Narayan, “Platform Capitalism and Cloud Infrastructure: Theorizing a Hyper-Scalable Computing Regime,” Environment and Planning A: Economy and Space 54, no. 5 (2022): 911–29, https://doi.org/10.1177/0308518X221094028.

[9] Ryan Ellis, Letters, Power Lines, and Other Dangerous Things: The Politics of Infrastructure Security, 1st ed., Infrastructures (The MIT Press, 2020), https://doi.org/10.7551/mitpress/10541.001.0001.

[10] Martin Campbell-Kelly et al., Computer: A History of the Information Machine, 3rd ed. (Routledge, 2019), https://doi.org/10.4324/9780429495373; Thomas Haigh, “How Data Got Its Base: Information Storage Software in the 1950s and 1960s,” IEEE Annals of the History of Computing 31, no. 4 (2009): 6–25, https://doi.org/10.1109/MAHC.2009.123.

[11] Helen Margetts, Information Technology in Government: Britain and America, 1st ed., Routledge Research in Information Technology and Society 2 (Routledge, 1999), https://doi.org/10.4324/9780203020944.

[12] Amelia Acker et al., “Platformization of Research Data Infrastructure: A Decadal Analysis of Scientific Data Management Plans,” Big Data & Society 13, no. 2 (2026): 20539517261431593, https://doi.org/10.1177/20539517261431593.

[13] David Gray Widder and Nathan Kim, “How Big Cloud Becomes Bigger: Scrutinizing Google, Microsoft, and Amazon’s Investments,” SSRN Scholarly Paper no. 5377426 (Social Science Research Network, July 31, 2025), https://doi.org/10.2139/ssrn.5377426.

[14] Amelia Acker and Britt S. Paris, “Hyper-Scaling from the Cloud to the Tower: Platform Enclosure and GenAI Capture in Higher Education,” Information, Communication & Society 0, no. 0 (2026): 1–20, https://doi.org/10.1080/1369118X.2026.2717382.

[15] “Governor Sherrill Announces Comprehensive Plan on Data Centers,” Governor Mikie Sherrill, State of New Jersey, May 27, 2026, https://www.nj.gov/governor/news/2026/20260527a.shtml.

[16] “New Jersey S3379,” LegiScan, New Jersey State Legislature, August 27, 2026, https://legiscan.com/NJ/bill/S3379/2026; “NJ Legislature,” New Jersey Legislature, accessed August 30, 2026, https://njleg.state.nj.us/bill-search/2026/S731/bill-text?f=S1000&n=731_I1; “Ruiz, Mukherji Bill to Hold Data Centers Accountable for Water and Energy Use Signed into Law,” accessed August 30, 2026, http://www.njsendems.org/m/newsflash/Home/Detail/1451.

[17] “SB 53- CHAPTERED,” accessed August 20, 2026, https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=20....

[18] Corinne Cath, Clouds Over the Netherlands: Preserving Public Interest Internet Governance in the Era of Hyperscaler Clouds (Zenodo, 2025), https://doi.org/10.5281/ZENODO.15230914; Dylan Ruediger, Big Data Infrastructure at the Crossroads, Ithaka S+R (Ithaka S+R, 2021), 41, https://sr.ithaka.org/publications/big-data-infrastructure-at-the-crossr....

[19] Ed D’Angelo, Barbarians at the Gates of the Public Library: How Postmodern Consumer Capitalism Threatens Democracy, Civil Education and the Public Good (Library Juice Press, 2006), 92, 361964, https://research.ebsco.com/plink/f66d22ee-9d81-39bc-b0eb-e548b833251b.

 

The Benton Institute for Broadband & Society is a non-profit organization dedicated to ensuring that all people in the U.S. have access to competitive, High-Performance Broadband regardless of where they live or who they are. We believe communication policy - rooted in the values of access, equity, and diversity - has the power to deliver new opportunities and strengthen communities.


© Benton Institute for Broadband & Society 2026. Redistribution of this email publication - both internally and externally - is encouraged if it includes this copyright statement.


For subscribe/unsubscribe info, please email headlinesATbentonDOTorg

Kevin Taglang

Kevin Taglang
Executive Editor, Communications-related Headlines
Benton Institute
for Broadband & Society
1041 Ridge Rd, Unit 214
Wilmette, IL 60091
847-220-4531
headlines AT benton DOT org

Share this edition:

Benton Institute for Broadband & Society Benton Institute for Broadband & Society Benton Institute for Broadband & Society

Benton Institute for Broadband & Society

Broadband Delivers Opportunities and Strengthens Communities