Understand the Cloud and AI Development Act (CADA) Digital Sovereignty Opportunity 

CADA_ Sunset Over Ancient Shores

In The Odyssey, the Trojan War finally ends, and Odysseus is ready to begin the journey home. The European Commission has decided it’s time for European data to do the same. Read on for your essential guide to CADA with expert insight from specialist data and cyber lawyer, Marco Piana.

After years of perceived over reliance on non-EU Cloud service providers—including foreign hyperscalers—the Commission wants to beef up Europe’s domestic Cloud and AI capabilities in the name of digital autonomy and resilience. Enter the Cloud and AI Development Act (CADA).

Like Odysseus’ return to Ithaca to reclaim the throne, CADA is about re-establishing sovereignty.

Most significantly for CSPs, it introduces a new Europe-wide sovereignty framework for Cloud and AI, complete with new requirements for where and how data is transferred, processed and stored. And while this framework doesn’t seek to prohibit the participation of global hyperscalers in the European Cloud market, it certainly promises to shake up the rules of engagement.

Why bring European data home?

Odysseus was driven back to Ithaca by nostos, the ancient Greek notion of homecoming, identity and status.

For the European Commission, the motivation for reshoring Cloud service provision is a little less poetic—it’s all about data security and digital competitiveness.

Three non-EU hyperscalers currently control over 70% of the European Cloud market. That’s a whole lot of European data that finds itself subject to third-country jurisdictions, which could impose any number of access or transfer laws outside of EU control.

The Commission also aspires to at least triple EU data centre capacity in the next five to seven years under CADA. That kind of scale is going to be necessary to meet the rising demands of computing in general and AI in particular—and to handle the potential prodigal return of a large amount of European data.

And it can be home grown, says the Commission, by firing up Europe’s currently untapped research and development capabilities, open-source communities and industrial base in Cloud in AI.

Sovereignty enters the regulatory spotlight

CADA is part of the European Commission’s four-pillar EU Tech Sovereignty Package.

The other three components of the package touch on the EU’s semiconductor production capabilities (Chips Act 2.0), the open source tech ecosystem (EU Open Source Strategy) and the rollout of digital solutions for decarbonisation (Strategic Roadmap for Digitalisation and AI in Energy). The overall vision is to reduce Europe’s reliance on foreign tech. CADA is the Cloud layer.

Europe also has an existing battery of digital security regulations—the EU Data Act, the Cybersecurity Act, DORA and DMA, to name a few—but CADA is the first to establish a dedicated framework around Cloud sovereignty, where sovereignty becomes its own criterion for service provision.

Adopted as an Act in June 2026, CADA is expected to enter into force by 2029.

CADA’s sovereignty framework

At its heart, CADA wants three things: more tech innovation, more data centres, and more control over the Cloud.

The crux of the regulation is the establishment of a single framework to define digital sovereignty and create mandatory requirements for procurement of Cloud services for Europe’s public sector.

As data and cyber lawyer at Digiphile Marco Piana explains, it is the only component of the EU’s sovereignty package “that directly and immediately affects the day-to-day commercial and procurement decisions of Cloud service providers and their public sector customers”.

The framework’s four levels of assurance center on infrastructure localization and operational transparency. Its requirements increase in rigor, “from basic data-location requirements to full EU control over the provider, with no non-EU dependencies”, says Piana.

Member state assessments will determine the risk profile of each public sector body, which in will turn dictate which assurance level will apply.

To prove compliance at level 2 and above, a CSP must submit audit documentation to the national competent authority. The European Commission will keep a record of providers that have been recognised, and at what assurance level.

Alongside the framework requirements, CADA also “explicitly brings existing EU cybersecurity legislation into the procurement process” under the NIS2 Directive and the Cybersecurity Act, Piana adds.

Are you European enough? What CADA means for CSPs

By establishing a common procurement framework for public sector bodies, CADA “effectively elevates sovereignty to a measurable metric necessary to access the public sector market,” says Piana.

For Cloud computing service providers, its implementation calls for a close look at operations across the board, from physical location through governance to supply chain and organizational structuring.

At all levels, the provider must be established in the EU, and their data must be stored and processed in the EU. Anywhere above Level 1, there must also be legal, technical and organisational separation between European operations and any third-country subsidiaries. At higher levels, subcontractors must be established in the EU, too.

The framework doesn’t straightforwardly exclude non-EU providers, but it means a foreign hyperscaler would have some serious restructuring to do if it wanted to reach the highest assurance levels.

“Many providers, including larger non-EU ones or EU-based SMEs, will be able to satisfy the lower-level requirements, at least in principle,” says Piana.

The differentiation comes at the higher levels:

“At Levels 3 and 4, the requirements extend to exclusive EU ownership and control of the provider, personnel with EU-citizenship and security clearance, and full supply chain transparency and control,” he says.

“These criteria are likely to prove too challenging for many non-EU providers and most EU SMEs, giving competitive advantage to the largest, well-resourced providers, especially those in the EU.”

For smaller European providers, it’s not all bad news. “CADA does introduce mechanisms expressly designed to help SMEs,” Piana points out. This includes the ability to self-certify at Level 1, lowering barriers to entry. “However, the compliance burden may prove costly in practice for the higher levels,” says Piana.

CADA Framework
Graphic courtesy Marco Piana, Digiphile

The new rules of engagement

CADA is specifically designed to improve opportunities for sovereign Cloud offerings and support the entry to market of a more diverse array of Cloud and AI service providers—while supporting the growth of the addressable market.

“It is likely to create a level of commercial differentiation in the Cloud industry,” Piana predicts.

How this differentiation plays out in practice remains to be seen once the regulation is in place and the framework is being applied. For example, Piana notes, “the market will narrow or widen depending on how strict those [member state] assessments are”.

What can be expected is a shake-up of competitive dynamics—and with the introduction of some big new hurdles for global hyperscalers, opportunities will be created for European alternative Cloud providers that can flex their domestic, specialist, sovereign credentials.

CADA Q&A

What is Cloud and AI sovereignty?
CADA formalises a definition of Cloud and AI sovereignty. It introduces four levels of sovereignty, based on increasing levels of EU localization and supply chain transparency.

What is the aim of the Cloud and AI Development act?
CADA has three goals: to increase Cloud and AI innovation in Europe, to increase data centre capacity in Europe, and to introduce a sovereignty framework for Cloud and AI providers serving the European public sector.

How does CADA differ from existing Cloud and sovereignty regulation?
Within the EU Tech Sovereignty Package, CADA is the AI and Cloud-focused regulation. Compared to other data security legislation, it is the first to formally define Cloud sovereignty, and it will directly affect commercial decisions made by CSPs and procurers.

What is the sovereignty framework introduced by CADA?
There are four levels of assurance under the framework, increasing in rigor. The lowest level requires data to be processed and stored within the EU, while the highest requires full transparency into the software supply chain and no third-country interference.

Does CADA exclude foreign hyperscalers from the market?
CADA responds to the European Commission’s concerns about Europe’s over reliance on three global hyperscalers and aims to promote a more diverse AI and Cloud market in Europe. Foreign hyperscalers would be permitted under the framework, but they would have to significantly restructure operations to reach the highest assurance levels.

What does CADA mean for CSPs?
The regulation will shake up the commercial landscape for CSPs serving the European public sector. It turns sovereignty into a measurable, competitive factor in its own right. It may also introduce new barriers for non-EU and smaller EU providers.

Get to grips with the digital sovereignty opportunity at CloudFest. Registration is open and free to the core Cloud community.

Juliet Martin Avatar

This might also interest you