1. Overview
On 3 June 2026, the European Commission published a proposal for a regulation establishing a framework of measures for strengthening Europe's cloud and AI ecosystem (Cloud and AI Development Act – "CADA"). The proposal forms part of the EU's broader strategy to strengthen European competitiveness, increase computing capacity available in the EU, support the development and deployment of AI, and reduce strategic dependencies on non-EU cloud providers. CADA complements other new initiatives, including the Chips Act 2.0 and the EU's open-source strategy.
The proposal introduces measures addressing both the supply side (e.g., data centre deployment and computing capacity) and the demand side (e.g., sovereign cloud requirements and public procurement measures). It also contains measures that have the goal to strengthen research and innovation, AI deployment, and the use of open-source software in the EU.
2. Why did the EU Commission propose CADA?
According to the EU Commission, three main developments prompted the proposal:
2.1 Growing demand for cloud and AI computing
The Commission considers cloud computing and AI to be essential components of the digital economy. The increasing deployment of AI systems is creating a rapidly growing demand for computing capacity, including cloud infrastructure and data centres.
2.2 Limited data centre capacity in the EU
The Commission argues that the supply of computing capacity within the EU is not expanding sufficiently quickly to meet demand. It also points to a concentration of data centre capacity in a limited number of locations, particularly Frankfurt, Paris, Amsterdam and Dublin.
2.3 Dependence on non-EU providers
The proposal is also driven by concerns regarding the EU's reliance on a limited number of non-EU cloud providers. According to the Commission, three non-EU hyperscalers currently account for more than 70% of the European cloud market. The Commission links this dependence to questions of resilience, operational continuity, economic security and technological sovereignty.
3. Who may be affected?
The proposal is relevant to
- cloud service providers,
- data centre operators,
- AI developers,
- public sector bodies,
- contracting authorities and
- organisations relying on cloud and AI services.
4. Key measures introduced by the proposal
The proposal introduces measures in three main areas:
4.1 Strengthening Europe’s cloud and AI ecosystem
At the core of the proposed CADA is a framework designed to support the development and deployment of cloud and AI technologies across the EU. This part of the proposal concerns research, development and deployment activities for the cloud and AI ecosystem (Title II CADA).
The key measures are as follows:
- Cloud and AI Leadership initiatives, which aim to support projects contributing to the development of the European cloud and AI ecosystem.
- Experience and acceleration centres for AI, which are intended to facilitate the testing, deployment and adoption of AI technologies.
- National cloud and AI strategies, which member states would be required to adopt in order to support the development of cloud and AI capabilities at national level.
- Frontier AI priority projects, which may benefit from dedicated support measures where they contribute to the Union's strategic objectives in the field of AI.
4.2 Increasing EU computing and data centre capacity
Furthermore, CADA addresses the availability of computing capacity in the Union. The draft introduces tools intended to facilitate the deployment of data centres, including data centre acceleration zones, strategic data centre projects and Union-level monitoring of computing capacity and demand (Title III CADA).
We have summarized key measures in Section 6 below.
4.3 Promoting sovereign and trusted cloud services
One of the most client-relevant aspects of the proposal is likely to be the new EU cloud computing sovereignty framework. This framework is intended to establish harmonised requirements for cloud computing services used in public sectors and to provide a mechanism for recognising services at different sovereignty-related assurance levels.
The framework consists of four union assurance levels, which we have summarized in Section 5 below (the “Union Assurance Levels”).
These assurance levels are supported by recognition procedures, conformity assessments, auditing requirements, a central repository of recognised services, as well as public-sector risk assessment and procurement mechanisms.
The proposal also establishes the European public sector cloud federation (the “EuroCloud Federation”), allowing Union institutions and national public bodies to share data centre and cloud capacities on a voluntary basis. Under certain conditions, services may be provided through intermediate legal entities controlled by the sharing public body.
(Title IV CADA)
5. EU cloud computing sovereignty framework
The proposal introduces the cloud computing sovereignty framework based on four Union Assurance Levels (Article 16)
These Levels are intended to measure the degree of sovereignty provided by a cloud service. The proposal links the levels to public-sector risk assessments, which may impact public sector procurement decisions.
While not mandatory to operate a as cloud provider in the EU, obtaining a certain “assurance level” recognition may become commercially relevant, where public-sector customers require a specific Assurance Level.
5.1 The four Union Assurance Levels
Level 1 – EU establishment, EU data location and basic sovereignty safeguards
To qualify for this level, the provider must be established in the EU, customer data must remain in the EU, and the provider must comply with baseline cybersecurity, subcontractor transparency and governance requirements.Level 2 – Additional safeguards against third-country influence
This level builds on Level 1 by requiring, in addition, an independent audit, EU-based infrastructure, assets and personnel, stronger cybersecurity requirements and safeguards against third-country access and influence. It also requires that service-generated data is not used to train AI systems operated by third countries or third-country entities.Level 3 – EU control and EU personnel requirements
This level introduces, in addition to the requirements set out in Level 1 and Level 2, stricter sovereignty requirements. Personnel involved in the service must generally be EU citizens and the provider and relevant subcontractors must generally not be controlled by a third country or a third-country entity. Limited exceptions may apply where the Commission has recognised a third country under the mechanism set out in the proposal.Level 4 – Strongest sovereignty requirements
This level is intended for the most sensitive use cases. In addition to stricter cybersecurity requirements, it requires that sensitive data remains exclusively within the EU, excludes third-country control and requires effective control over critical software components and supply chains.
5.2 Recognition and assessment process
Cloud providers seeking recognition at a Union Assurance Level must submit an application to the national competent authority of the member state in which they are established. The competent authority will need to be set out by each EU member state. The purpose of the process is to assess whether the cloud service meets the requirements of the relevant level.
The proposal distinguishes between two assessment routes:
- Level 1: conformity self-assessment by the provider.
- Level 2-4: assessment by an independent auditing organisation.
Once recognised, the cloud service may be included in the Commission's central repository of recognised services.
6. Measures to increase data centre capacity
Beyond the EU cloud computing sovereignty framework, the proposal also contains a range of measures intended to increase the availability of computing capacity within the Union.
6.1 Data centre acceleration zones
The proposal requires member states to identify and designate Data centre acceleration zones (Title III Chapter I). These zones are intended to facilitate the deployment of new data centres by bringing together relevant planning, environmental and permitting information in a single framework.
Within these zones, member states are encouraged to streamline administrative procedures and improve coordination between the authorities involved in project approval. The objective is to reduce administrative barriers and accelerate the development of data centre infrastructure.
6.2 Strategic data centre projects
The proposal also introduces the concept of strategic data centre projects (Title III Chapter II). Projects may be recognised as strategic where they are considered particularly important for increasing computing capacity, strengthening the resilience of the EU's digital infrastructure or supporting the development of the European cloud and AI ecosystem.
Recognised projects may benefit from specific support measures provided under the proposal and may receive priority treatment in certain administrative procedures.
6.3 Monitoring of computing capacity and demand
The EU Commission and member states plan to collect and analyse information relating to available computing resources, data centre capacity and projected demand for cloud and AI services (Title III Chapter III). The aim is to identify potential capacity shortages and support future policy and investment decisions.
7. Next steps
The proposal was published by the EU Commission on 3 June 2026. It will now be discussed by the European Parliament and the Council under the ordinary legislative procedure. The text remains subject to negotiation and may change during the legislative process before a final Regulation is adopted.



.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)




_11zon.jpg?crop=300,495&format=webply&auto=webp)


.jpg?crop=300,495&format=webply&auto=webp)


.jpg?crop=300,495&format=webply&auto=webp)