Do you have a source for that?
I mean, the cloud business is the place with the most to lose from these kinds of issues, I am incredibly suspicious of the claim that cloud providers aren't patching their microcode.
Whether it's intels or their own modified variant of microcode I would fully expect them to be patched in some way.
They have much to lose from not applying these mitigations, especially if they're the people spending a fortune to find them.
I honestly doubt that claim however and haven't heard it before this thread.