ANALYSIS

The EU Cloud and AI Development Act (CADA): What It Is and Why It Matters

The Cloud and AI Development Act (CADA) is the European Commission's proposed framework for expanding Europe's computing capacity while reducing its dependence on non-European cloud and technology providers.

By John Wroath, Editor

Published 29 July 2026

The Cloud and AI Development Act (CADA) is the European Commission's proposed framework for expanding Europe's computing capacity while reducing its dependence on non-European cloud and technology providers.

Proposed on 3 June 2026 as part of the wider European Technology Sovereignty Package, CADA addresses the infrastructure beneath AI: data centres, cloud platforms, software supply chains and public-sector procurement. Unlike the EU AI Act, it is not primarily concerned with regulating how AI systems behave. It is concerned with ensuring that Europe has the physical capacity, technology and operational control required to run them.

The European Commission describes CADA as having three central objectives: supporting research and innovation, accelerating the deployment of data-centre capacity and establishing a common European framework for cloud and AI sovereignty.

1. Building more European computing capacity

The Commission wants to at least triple the EU's data-centre capacity within five to seven years and ensure that European businesses and public administrations have access to sufficient capacity by 2035.

To support this expansion, Member States would establish data-centre acceleration zones. These zones would bring together:

  • Coordinated planning for electricity, grid capacity, water, connectivity and land.
  • A single administrative contact point for data-centre developers.
  • Aggregated baseline permits covering common planning and environmental requirements.
  • A maximum 12-month permitting process for qualifying projects.
  • Sustainability requirements covering energy efficiency, water use, cooling, carbon emissions and waste-heat reuse.

Data-centre projects that support essential public services, integrate highly sustainable technology, strengthen the electricity system or address regional shortages in computing capacity could also receive EU strategic project status.

The full proposed regulation therefore treats data centres not simply as commercial property, but as strategic infrastructure supporting Europe's economic security, public services and technological autonomy.

2. Establishing a legal framework for sovereign cloud

One of CADA's most significant elements is a common EU-wide framework for assessing cloud sovereignty. It proposes four Union assurance levels for cloud services supplied to EU institutions and public-sector bodies.

Assurance levelBroad meaning
Level 1The provider is established in the EU, with relevant infrastructure and customer data located in the EU, alongside baseline cybersecurity and supply-chain transparency requirements.
Level 2Relevant infrastructure, assets, personnel and operations are located in the EU, with stronger safeguards against third-country access, control or disruption.
Level 3The service is generally under EU ownership and control, supported by EU-citizen personnel, EU-based operations and greater transparency and control over the software supply chain.
Level 4The highest level of assurance, requiring no third-country control, high cybersecurity assurance and effective control over the software, operational and subcontractor supply chains.

Public-sector organisations would normally have to use services recognised at Level 1 or above. Activities connected with public order or highly sensitive functions—such as defence, healthcare, public safety, justice, border management and critical infrastructure—would require Level 2, 3 or 4, depending on a formal risk assessment.

The Commission's overview of the sovereignty framework makes clear that sovereignty would no longer be judged purely by where data is stored. The assessment would also consider:

  • Corporate ownership and legal control.
  • Exposure to extraterritorial legislation.
  • The location and citizenship of operational personnel.
  • The risk of third-country access to data.
  • Service continuity and the possibility of external disruption.
  • The treatment of metadata and telemetry data.
  • Subcontractors and software dependencies.
  • Whether customer data could be used to train third-country AI systems.

This is an important distinction: data residency is one part of sovereignty, but it is not sovereignty by itself.

3. Using public procurement to develop a European market

CADA would use public-sector purchasing power to stimulate demand for European cloud, AI and infrastructure services.

The proposal includes:

  • Common European procurement mechanisms for cloud, AI and data-centre services.
  • A central repository of services recognised under the four assurance levels.
  • Consideration of multi-cloud and multi-provider strategies to reduce dependency.
  • Non-price procurement criteria recognising European technology, research, open source and supply-chain resilience.
  • A target for Member States to award at least 25% of cloud and AI procurement to innovative SMEs.

It would also establish a EuroCloud Federation, allowing participating EU institutions and public-sector bodies to share and procure data-centre and cloud resources through a common European platform.

What CADA does not do

CADA does not propose a general ban on American or other non-European cloud providers. Nor would every private European company automatically be required to use a European-controlled cloud.

Its strongest immediate requirements concern public-sector procurement and services supporting public-order or highly critical functions. Private organisations operating in sectors covered by NIS2 could initially conduct similar sovereignty assessments voluntarily, although the Commission would have powers to introduce mandatory assessments and mitigation measures in specific circumstances.

The proposal therefore keeps most of the European cloud market open while creating more demanding sovereignty requirements for sensitive workloads.

Why CADA matters

CADA represents a notable change in European digital policy. Previous legislation has frequently concentrated on data protection, competition, cybersecurity or the responsible use of technology. CADA focuses on whether Europe possesses the underlying capacity and operational control needed to remain resilient.

It formally recognises that digital sovereignty depends on several layers:

  • The physical location and availability of data-centre capacity.
  • Access to reliable and sustainable energy.
  • Legal ownership and operational control.
  • Cloud and software supply chains.
  • The ability to operate services without third-country interference.
  • European expertise, research, technology and open-source capability.

In other words, sovereignty starts below the cloud. Cloud sovereignty cannot be separated from the data centres, networks, energy systems and operational teams on which cloud services depend.

For European data-centre operators, cloud providers and infrastructure companies, this could create substantial opportunities. Providers able to demonstrate European operations, resilient supply chains, energy efficiency and protection from extraterritorial control would be better positioned to support sensitive public-sector and critical-infrastructure workloads.

CADA and the earlier SEAL framework

CADA's four categories are described in the proposal as Union assurance levels. They are not labelled as Sovereignty Effectiveness Assurance Levels, or SEALs, in the legislative text.

The proposed CADA system should therefore not yet be presented as a direct replacement for, or one-to-one continuation of, the earlier Cloud Sovereignty Framework used by the Commission in its sovereign-cloud procurement. The relationship between the two frameworks may become clearer as CADA is negotiated and the Commission develops the supporting delegated and implementing acts.

Current legislative status

As of 1 August 2026, CADA remains a European Commission proposal rather than enacted law. It is proceeding through the EU's ordinary legislative procedure and must be negotiated and agreed by the European Parliament and the Council.

If adopted in its current form, the regulation would generally apply one year after entering into force. Its provisions could still change substantially during the legislative process. The latest formal status is available through the EU's legislative procedure file for 2026/0138(COD).


End of article

Related reading

ANALYSIS

AI needs a sovereign layer too. Can federated infrastructure deliver it?

AI raises sovereignty stakes beyond cloud alone: training data provenance, model weight custody, and GPU supply chains all carry jurisdictional exposure that cloud sovereignty frameworks were not built to answer on their own. Federated infrastructure is one credible response, and Europe is already building it institutionally.

John Wroath

ANALYSIS

What is European Sovereign Infrastructure? A working definition.

European Sovereign Infrastructure is digital infrastructure that operates under European jurisdiction and control. We set out a three-layer definition, test it against the frameworks Europe is now using to score sovereignty claims, and give buyers the questions that separate sovereign infrastructure from sovereign marketing.

John Wroath

Primary sources

Disclosure: The EU Cloud and AI Development Act (CADA): What It Is and Why It Matters is published as part of Edition 01 of European Sovereign Infrastructure. The publication is editorially independent. No source cited in this article had sight of the copy before publication.