The EU Cloud and AI Development Act (CADA): What It Is and Why It Matters
The Cloud and AI Development Act (CADA) is the European Commission's proposed framework for expanding Europe's computing capacity while reducing its dependence on non-European cloud and technology providers.
By John Wroath, Editor
Published 29 July 2026
The Cloud and AI Development Act (CADA) is the European Commission's proposed framework for expanding Europe's computing capacity while reducing its dependence on non-European cloud and technology providers.
Proposed on 3 June 2026 as part of the wider European Technology Sovereignty Package, CADA addresses the infrastructure beneath AI: data centres, cloud platforms, software supply chains and public-sector procurement. Unlike the EU AI Act, it is not primarily concerned with regulating how AI systems behave. It is concerned with ensuring that Europe has the physical capacity, technology and operational control required to run them.
The European Commission describes CADA as having three central objectives: supporting research and innovation, accelerating the deployment of data-centre capacity and establishing a common European framework for cloud and AI sovereignty.
1. Building more European computing capacity
The Commission wants to at least triple the EU's data-centre capacity within five to seven years and ensure that European businesses and public administrations have access to sufficient capacity by 2035.
To support this expansion, Member States would establish data-centre acceleration zones. These zones would bring together:
Data-centre projects that support essential public services, integrate highly sustainable technology, strengthen the electricity system or address regional shortages in computing capacity could also receive EU strategic project status.
The full proposed regulation therefore treats data centres not simply as commercial property, but as strategic infrastructure supporting Europe's economic security, public services and technological autonomy.
2. Establishing a legal framework for sovereign cloud
One of CADA's most significant elements is a common EU-wide framework for assessing cloud sovereignty. It proposes four Union assurance levels for cloud services supplied to EU institutions and public-sector bodies.
Public-sector organisations would normally have to use services recognised at Level 1 or above. Activities connected with public order or highly sensitive functions—such as defence, healthcare, public safety, justice, border management and critical infrastructure—would require Level 2, 3 or 4, depending on a formal risk assessment.
The Commission's overview of the sovereignty framework makes clear that sovereignty would no longer be judged purely by where data is stored. The assessment would also consider:
This is an important distinction: data residency is one part of sovereignty, but it is not sovereignty by itself.
3. Using public procurement to develop a European market
CADA would use public-sector purchasing power to stimulate demand for European cloud, AI and infrastructure services.
The proposal includes:
It would also establish a EuroCloud Federation, allowing participating EU institutions and public-sector bodies to share and procure data-centre and cloud resources through a common European platform.
What CADA does not do
CADA does not propose a general ban on American or other non-European cloud providers. Nor would every private European company automatically be required to use a European-controlled cloud.
Its strongest immediate requirements concern public-sector procurement and services supporting public-order or highly critical functions. Private organisations operating in sectors covered by NIS2 could initially conduct similar sovereignty assessments voluntarily, although the Commission would have powers to introduce mandatory assessments and mitigation measures in specific circumstances.
The proposal therefore keeps most of the European cloud market open while creating more demanding sovereignty requirements for sensitive workloads.
Why CADA matters
CADA represents a notable change in European digital policy. Previous legislation has frequently concentrated on data protection, competition, cybersecurity or the responsible use of technology. CADA focuses on whether Europe possesses the underlying capacity and operational control needed to remain resilient.
It formally recognises that digital sovereignty depends on several layers:
In other words, sovereignty starts below the cloud. Cloud sovereignty cannot be separated from the data centres, networks, energy systems and operational teams on which cloud services depend.
For European data-centre operators, cloud providers and infrastructure companies, this could create substantial opportunities. Providers able to demonstrate European operations, resilient supply chains, energy efficiency and protection from extraterritorial control would be better positioned to support sensitive public-sector and critical-infrastructure workloads.
CADA and the earlier SEAL framework
CADA's four categories are described in the proposal as Union assurance levels. They are not labelled as Sovereignty Effectiveness Assurance Levels, or SEALs, in the legislative text.
The proposed CADA system should therefore not yet be presented as a direct replacement for, or one-to-one continuation of, the earlier Cloud Sovereignty Framework used by the Commission in its sovereign-cloud procurement. The relationship between the two frameworks may become clearer as CADA is negotiated and the Commission develops the supporting delegated and implementing acts.
Current legislative status
As of 1 August 2026, CADA remains a European Commission proposal rather than enacted law. It is proceeding through the EU's ordinary legislative procedure and must be negotiated and agreed by the European Parliament and the Council.
If adopted in its current form, the regulation would generally apply one year after entering into force. Its provisions could still change substantially during the legislative process. The latest formal status is available through the EU's legislative procedure file for 2026/0138(COD).
End of article
Related reading
The SEAL framework, decoded: what the eight objectives actually measure, and why almost nobody scores clean.
The EU Cloud Sovereignty Framework scores cloud providers against eight objectives, each rated SEAL-0 to SEAL-4. A tender sets a minimum SEAL per objective, and missing even one floor rejects the bid outright.
John Wroath
AI needs a sovereign layer too. Can federated infrastructure deliver it?
AI raises sovereignty stakes beyond cloud alone: training data provenance, model weight custody, and GPU supply chains all carry jurisdictional exposure that cloud sovereignty frameworks were not built to answer on their own. Federated infrastructure is one credible response, and Europe is already building it institutionally.
John Wroath
What is European Sovereign Infrastructure? A working definition.
European Sovereign Infrastructure is digital infrastructure that operates under European jurisdiction and control. We set out a three-layer definition, test it against the frameworks Europe is now using to score sovereignty claims, and give buyers the questions that separate sovereign infrastructure from sovereign marketing.
John Wroath
Primary sources
- European Commission: Proposal for the Cloud and AI Development Act, European Commission
- EUR-Lex: Full proposed regulation, COM(2026) 502, EUR-Lex
- European Commission: Cloud and AI Development Act overview, European Commission
- EUR-Lex: Legislative procedure 2026/0138(COD), EUR-Lex
Disclosure: The EU Cloud and AI Development Act (CADA): What It Is and Why It Matters is published as part of Edition 01 of European Sovereign Infrastructure. The publication is editorially independent. No source cited in this article had sight of the copy before publication.