Search

Digital or EU sovereignty has so far largely been a promise made by service providers. The draft Cloud and AI Development Act (CADA) aims to turn that promise into verifiable criteria. These requirements are intended to become binding in public procurement, while knock-on effects are also likely for companies operating in critical sectors. We explain what businesses should prepare for and what steps they can already take today.

In a nutshell

  • The Cloud and AI Development Act (CADA) is currently available as a Commission proposal dated 3 June 2026 and must now proceed through the EU legislative process.
  • CADA forms part of the broader European digital regulatory framework, which also includes the Data Act, the Digital Markets Act (DMA), the NIS2 Directive and the Digital Operational Resilience Act (DORA).
  • The proposal provides for four graduated Union Assurance Levels, to be assessed by independent auditors.
  • The private sector is expected to be affected primarily in its capacity as a supplier or service provider to the public sector.

Why is there growing demand for EU-sovereign cloud services?

The debate around “EU-only” solutions is not merely a matter of political sentiment, but a response to measurable market developments. According to the explanatory material accompanying the Commission proposal, the market share of European cloud providers in the EU fell from 29% in 2017 to 15% in 2022 and has since stagnated. Three non-European hyperscalers are said to control more than 70% of the European cloud market.

Despite broadly comparable economic output, the EU accounts for only around 20% of installed global data-centre capacity, compared with approximately 42% in the United States.

The Commission derives two distinct risks from this dependency.

  • The first concerns control over data, because providers based in third countries may be subject to legal regimes with extraterritorial effect.
  • The second concerns operational autonomy, namely whether a service remains available where a third country takes unilateral action.

The second point is the genuinely new aspect. The issue is no longer limited to access to data, but extends to operational continuity.

Recent developments have illustrated the practical relevance of this risk.

In June 2026, an export-control order issued by the US Department of Commerce prohibited foreign nationals from using Anthropic’s most capable AI models. Because users could not reliably be distinguished by nationality, the company temporarily disabled the affected models worldwide. European companies and research institutions consequently lost access, from one day to the next, to services already in productive use. The restriction was lifted after several days, but the incident illustrated a broader pattern: a service may become unavailable as the result of a decision in which neither the customer nor its contractual counterparty has any involvement.

A second example concerns conventional workplace IT. After the US Government imposed sanctions in February 2025 on the then Prosecutor of the International Criminal Court, he lost access to his official Microsoft email account. Microsoft emphasised that services provided to the Court as an institution had at no time been suspended. Nevertheless, the case had significant implications because it demonstrated that third-country sanctions law can directly affect the operational capability of a European organisation.

Politically, the Cloud and AI Development Act proposal was prepared, among other things, by the Draghi Report on European competitiveness and by the Council conclusions of December 2025, which expressly called for common criteria for sovereign cloud services. CADA is intended to translate those demands into legislative requirements for the first time.

What rules already exist alongside CADA?

The CADA proposal does not stand in isolation but supplements an already dense regulatory framework.

The Data Act regulates switching between data-processing services and their interoperability, thereby removing barriers to provider switching. It does not, however, itself create a European supply of cloud services.

The Digital Markets Act (DMA) identifies cloud-computing services as a category of potential core platform service subject to specific obligations. To date, however, no provider has been designated as a gatekeeper in this area. On 18 November 2025, the Commission nevertheless opened three market investigations, including into whether the DMA is capable of addressing competition concerns in the cloud market effectively. According to the Commission’s preliminary view, Amazon Web Services (AWS) and Microsoft Azure may qualify for designation as gatekeepers.

On the cybersecurity side, the NIS2 Directive requires cloud providers and data centres to implement risk-management measures. The Digital Operational Resilience Act (DORA) addresses digital operational resilience and ICT outsourcing in the financial sector, while the Cybersecurity Act is currently under review.

The long-awaited European Cybersecurity Certification Scheme for Cloud Services (EUCS) has still not been adopted. The CADA proposal refers to it in several places and provides for transitional arrangements in case the scheme is not yet available when CADA starts to apply.

There are also national developments, such as the German Administrative Cloud, as well as requirements imposed by individual supervisory authorities concerning the EU sovereignty of services used.

A similar trend can also be observed outside Europe. In July 2025, the United States used the AI Action Plan and the Executive Order “Promoting the Export of the American AI Technology Stack” to promote the export of complete US technology stacks comprising hardware, cloud infrastructure, AI models and security components. China has pursued this approach consistently for years, combining localisation requirements for operators of critical information infrastructure with security reviews for data exports and the targeted expansion of domestic providers. Saudi Arabia is investing in its own state-backed AI infrastructure through the USD 100 billion “Project Transcendence” programme. India has required payment-system data to be stored domestically since 2018 and is simultaneously expanding its own data-centre capacity.

What would CADA require in practice?

The central element of the proposal is a uniform framework for assessing the EU sovereignty of cloud services based on four Union Assurance Levels. The requirements are intended to increase cumulatively, with each level incorporating and strengthening the requirements of the preceding level.

  • Level 1 would require the provider to be established in the EU. Customer data, including metadata and telemetry data, would also have to remain within the EU, and there would have to be full transparency regarding subcontractors. Compliance could be demonstrated by means of a self-assessment.
  • Level 2 would additionally require infrastructure and personnel to be located in the EU, technical support to be provided exclusively from within the EU, a software bill of materials (SBOM) to be available, and data not to be used to train AI systems from third countries. Providers controlled from third countries could still potentially achieve this level, but would have to demonstrate effective separation and safeguards.
  • Level 3 would require providers and subcontractors not to be subject to the control of a third country, while personnel would be required to hold Union citizenship. An exception would only be available where the Commission determined, by means of an implementing act, that a third country provides sufficient guarantees.
  • Level 4 would add certification at the “high” assurance level and require evidence that no third country exercises effective control over the development, maintenance or further development of the software components used.

Levels 2 to 4 would not be based on self-declaration. Instead, they would have to be assessed by independent audit organisations and recognised by a competent national authority. Recognised services would be entered in a central Commission register. The proposal thereby seeks to address the problem of providers advertising “EU sovereignty” without an objectively verifiable basis, an issue highlighted by market participants during the consultation process.

The framework is intended to become binding through public procurement law. Under Article 29 of the proposal, Member States and Union institutions would be required to carry out risk assessments to determine which public-sector activities serve the maintenance of public order. Article 30 would require public contracting authorities to procure services meeting at least Level 1. For activities relating to public order in sectors covered by the NIS2 annexes, as well as areas such as internal security, defence, justice and law enforcement, only services meeting Levels 2, 3 or 4 would be permitted.

The proposal also contains provisions intended to accelerate the establishment of data centres and to strengthen the role of open-source software in public administration.

What would CADA mean for private companies?

Under the proposal in its current form, private companies would not be directly subject to mandatory requirements. The binding provisions are principally directed at the public sector. However, two mechanisms could extend their practical impact beyond public authorities.

First, Article 31 would allow entities listed in Annex I to the NIS2 Directive to conduct comparable assessments voluntarily. At the same time, the Commission would be empowered, by means of delegated acts, to require companies in highly critical sectors to carry out such assessments. What begins as an option could therefore become a legal obligation without the Regulation itself having to be amended.

Second, procurement requirements are likely to exert pressure throughout the supply chain. Businesses supplying the public sector or regulated entities are likely to be asked which infrastructure their own services rely on. A software provider whose service runs on a platform without the required recognition could therefore lose access to a significant market segment, irrespective of whether the provider itself is directly subject to CADA.

What steps can businesses already take towards CADA compliance?

CADA remains, for the time being, a Commission proposal. It must go through the ordinary EU legislative procedure and individual levels, deadlines and exemptions may still change. In its impact assessment, the Commission itself anticipates that negotiations could be completed by the end of 2027, with the Regulation beginning to apply around 2029.

Nevertheless, preparatory measures can already be worthwhile, not least because they can improve data protection and business continuity.

A sensible first step is to take stock of the cloud services currently in use and determine which business processes depend on them and what impact an outage or access restriction would have. This provides an initial basis for identifying applications with such a high protection requirement that they should be operated using an EU-sovereign cloud service. According to the assumptions used in the impact assessment, this is likely to concern only a relatively small proportion of applications.

A simple question can help identify those applications: What would happen if this service were unavailable tomorrow, or if a third country were able to obtain access to the data processed through it?

The systems most likely to be affected are those that directly support operational continuity or process particularly sensitive data. Examples include control systems used by energy and water utilities, payment and core-banking systems, clinical information systems, engineering data and product formulas, and identity and access-management systems on which access to other systems depends.

Communications infrastructure may also fall into this category, as illustrated by the International Criminal Court example discussed above.

By contrast, marketing tools, appointment-scheduling systems, public website content or test environments without live data will typically be less critical. The most critical systems, however, are also likely to incur the highest migration costs and require the longest lead times, because interfaces, operational processes and certifications may all need to be migrated alongside the technology itself.

The contractual dimension is equally important. Businesses should examine existing contract terms and notice periods, exit clauses and whether data export and portability work effectively in practice. The Data Act already strengthens customers’ position when switching providers. Businesses that understand these rights and reflect them in their contractual arrangements can preserve strategic flexibility before regulatory deadlines make action unavoidable.

Finally, it is advisable to incorporate EU-sovereignty requirements into current procurement projects rather than attempting to retrofit them later. Designing a new system for EU-sovereign operation from the outset is likely to be significantly less burdensome than migrating it at a later stage.

How can activeMind.legal support companies preparing for CADA?

Assessing cloud services against EU-sovereignty criteria requires expertise at the intersection of data protection, information security and IT architecture.

Our experts can support businesses throughout this process, from taking stock of existing services and assessing the protection requirements of individual applications to reviewing existing contracts for exit and portability provisions.

Because the requirements arising from CADA, NIS2, DORA and the Data Act overlap, preparatory work can be structured in such a way that it contributes to compliance with several legislative frameworks at the same time.

Conclusion: EU sovereignty is intended to become verifiable

The key innovation in the proposal is not a prohibition on particular providers, but the intention to translate the EU sovereignty of a cloud service into graduated, auditable criteria. This would bring to an end — or at least substantially reduce — the period in which digital or EU sovereignty could be used merely as a marketing claim.

For businesses, the main implication is a need for forward planning: they should identify which applications have sufficiently high protection requirements to justify the use of an EU-sovereign service, and align contract durations and architectural decisions accordingly.

Compliance management system

Build trust with business partners, employees, and customers - through proven compliance in all areas!

Contact us!

Haben Sie die Entgelttransparenz­richtlinie schon umgesetzt?

Online-Training
mit Praxistipps 

10. Juni 2026 (10-12 Uhr)

Secure the knowledge of our experts!

Subscribe to our free newsletter: