Authors
1. Introduction
The rapid expansion of cloud computing and artificial intelligence (AI) has transformed digital infrastructure from a purely commercial enabler into a matter of strategic importance. Across Europe, policymakers increasingly view cloud infrastructure as a foundational layer for economic productivity, national security, and technological autonomy. The European Commission’s proposed Cloud and AI Development Act (CADA) reflects this shift, positioning cloud and AI capacity as critical to Europe’s long-term competitiveness and resilience.
CADA is part of the European Commission’s Technological Sovereignty Package (ETSP), a strategic initiative designed to address EU dependence on non-European technology providers across semiconductors, artificial intelligence, cloud infrastructure, and open source software. The package comprises four measures:
- Chips Act 2.0;
- CADA;
- the EU Open Source Strategy; and
- a Strategic Roadmap for Digitalisation and AI in Energy.
The rationale is clear. Europe relies heavily on non-European cloud providers, particularly U.S. hyperscalers.[1] This has brought increased focus to jurisdictional exposure, supply chain resilience and systemic dependency, including under extraterritorial regimes such as the U.S. Clarifying Lawful Overseas Use of Data (CLOUD) Act. While these issues have shaped the policy debate, the practical impact of such regimes is generally understood to be constrained by applicable legal safeguards and the relatively limited number of publicly reported cases.
At the same time, Europe faces a significant capacity gap in cloud infrastructure and computing power, driven by constraints on energy access, construction permitting and capital deployment. The challenge is therefore to build domestic capacity while managing strategic interdependency.
As a central component of the ETSP, CADA seeks to achieve both through a focus on infrastructure investment, regulatory intervention and procurement reform. The central question is whether through CADA, Europe can achieve sovereignty and resilience in an effective and proportionate way, without undermining openness, competition or partnership.[2]
This whitepaper posits that Europe need not choose between sovereignty and openness. The better path is to calibrate regulation so that it strengthens security and resilience without weakening innovation, competition or global integration.
2. The Cloud and AI Development Act: objectives and mechanisms
At its core, CADA focuses on three interrelated pillars: innovation support, capacity expansion, and sovereignty assurance.
First, CADA promotes research, development and adoption of cloud and AI technologies, including next-generation computing and deployment in strategic sectors.
Second, it seeks to accelerate the expansion of European data centre capacity by making construction permitting faster and more efficient, improving access to energy and financing, and incentivising investment in sustainable infrastructure.
Third, CADA introduces a European Union cloud computing sovereignty framework to classify cloud and AI services by their degree of European control.
Together, these mechanisms signal a more interventionist industrial policy model and a shift from assessing how services operate to who controls them.
3. Assessing the Framework
3.1 Effectiveness: ownership and jurisdiction
While the research and development and data centre capacity components of CADA are important, from a technology provider and technology consumer standpoint, a key assessment criterion is whether CADA’s sovereignty model is effective in achieving its aims. The framework relies heavily on ownership, establishment, jurisdiction and provider control as assessment tools.[3] These factors are important to take into consideration, especially for highly sensitive workloads, but in the context of the interconnected nature of the world’s technology ecosystem, they are blunt – arguably ineffective - mechanisms for addressing sovereignty risk.
CADA introduces a tiered (four-level[4]) sovereignty framework that classifies actual cloud and AI services based on risk of external control or interference. Higher levels require progressively stronger guarantees of EU jurisdictional control, independence from third-country laws and supply chain autonomy – the European Commission has also proposed a new cybersecurity regulation, Cybersecurity Act 2.0, which complements CADA,[5] and similarly focusses on the assessment of non-technical risks affecting key ICT assets. As such, CADA imposes conditions on foreign providers by embedding third-country legal exposure into a sovereignty classification system, making that classification determinative for procurement eligibility, and allowing participation at lower levels, but restricting access to more sensitive workloads.
The attention given to extraterritorial legal frameworks, particularly in relation to the U.S. CLOUD Act, is understandable in the context of evolving discussions on jurisdictional considerations. But the legal position is more nuanced than a simple EU/non-EU divide. As explored in our recent whitepaper, the U.S. CLOUD Act demands are subject to legal limits and challenge mechanisms, and providers will likely offer technical, contractual and operational controls to reduce disclosure risk.
Importantly, extraterritorial reach of laws is not unique to the United States. The EU GDPR applies to certain non-EU entities;[6] the UK Crime (Overseas Production Orders) Act can reach data stored overseas; and other jurisdictions, including Canada[7] and EU Member States,[8] have cross-border access mechanisms. Treating the U.S CLOUD Act as disqualifying risks overstating one exposure while underplaying the wider reality of the extraterritorial nature of regulation.
Further, while European ownership can reduce certain dependencies, certain connections to the U.S. - such as providing products or services to U.S. customers - may still result in an organisation falling within the scope of the U.S. CLOUD Act or other laws which have extraterritorial reach. The OVHcloud case is one example illustrating that extraterritorial data access powers are not unique to the U.S.[9]. A Canadian court ordered a Canadian subsidiary of a French-headquartered cloud provider to produce account data linked to IP addresses, despite arguments that the data was stored outside Canada and not accessible to the subsidiary. The case shows that an EU corporate structure and EU provider nationality does not eliminate extraterritorial exposure as a risk factor.
Cloud infrastructure is inherently global. Dependencies span hardware, software, networks, personnel, subcontractors and supply chains. Even European-owned or locally established providers will likely rely on external inputs such as semiconductors, software, operational tooling or group services. Assessing sovereignty based on provider nationality can therefore create the appearance of sovereignty without reflecting the reality of the interdependent and interconnected nature of the global technology ecosystem or necessarily improving resilience, security or customer control.
As explored below, a more effective sovereignty framework should focus less on the passport of the provider and more on the controls that determine whether customers can maintain practical, legal and technical control over their data and workloads.
3.2 Proportionality and market impact: balancing Risk and Intervention
A second challenge with CADA concerns proportionality. Although CADA is motivated by risks affecting more highly sensitive workloads, in practice the sovereignty assessment criteria (focused on ownership, establishment, jurisdiction) could have wider systemic effects on the broader digital ecosystem including a spillover from the public sector into other industries including financial services, healthcare, defence and other regulated industries. The further effects could be:
- reduced market access, choice and security compromise – procurement criteria based on provider origin or perceived legal exposure may exclude capable providers to public sector and regulated markets, reducing competition, limiting customer access to established, highly secure, resilient, and best-in-class cloud and AI services, and slowing the deployment of new features. Given the strategic importance of the public sector, it is imperative that governments can embrace the most advanced and secure digital services;
- fragmented procurement – consumers of technology may be forced into fragmented procurement models, using multiple providers or architectures to meet varying EU sovereignty requirements across use cases. Organisations that operate globally may be forced to adopt dedicated EU architecture, which may not align with their global technology infrastructure models;
- higher costs – dedicated infrastructure, personnel, governance and legal separation requirements may operate as a hidden tariff on digital services, with costs passed through to customers, which could have a significant impact on already strained budgets; and
- barriers to entry – smaller providers may struggle to meet infrastructure and compliance requirements and costs, entrenching incumbents and further limiting innovation.
4. Comparative Analysis: global approaches to Cloud sovereignty
A comparison with other jurisdictions highlights alternative approaches to assessing and managing risks.
The United States adopts a model, underpinned by a data governance and classification framework that differentiates requirements based on the sensitivity of data and systems. This is operationalised through certification regimes such as Federal Risk and Authorization Management Program (FedRAMP), which standardises security assessment for cloud services. Notably, FedRAMP does not exclude or disqualify providers solely on the basis of country of origin, instead focusing on compliance with defined security and risk management controls.
Singapore adopts a model, centred on its Multi-Tier Cloud Security (MTCS) standard. Like FedRAMP, MTCS is a government-backed certification framework that assesses cloud security based on tiered data sensitivity levels and independently audited control requirements. The regime is open to global providers and does not restrict participation on the basis of a provider’s country of origin, instead focusing on demonstrable compliance with security and governance standards.
Australia similarly adopts a risk-based approach through its Information Security Registered Assessors Program (IRAP), which provides a framework for assessing the security of cloud service providers against Australian Government standards. Like FedRAMP, IRAP focuses on compliance with defined security controls and assurance processes, rather than the nationality or location of the provider.
In the UK, cloud security is assessed against the National Cyber Security Centre’s Cloud Security Principles, a risk-based framework that evaluates providers against defined security outcomes. Again, the UK regime does not exclude or disqualify providers based on location. The UK has also proposed a Cyber Security and Resilience (Network Information Systems) Bill,[10] which would enable the government to regulate essential activities and critical suppliers from a cybersecurity perspective, and it is anticipated that such Bill will rely on a more flexible regulatory framework as compared with the more prescriptive EU approach.
These successful and proven approaches illustrate that sovereignty objectives can be achieved through risk mitigation, governance, and technical safeguards, rather than through ownership-based restrictions.
5. Recommendation: a proportionate alternative framework
To achieve its objectives, the EU could adopt a proportionate sovereignty framework built around evidence-based risk controls.
5.1 Risk-Based Sovereignty
CADA should move from a provider-status model to a risk-based sovereignty framework. Ownership, establishment and jurisdiction may be relevant, especially for sensitive workloads, but should not be determinative. Providers should be assessed alongside practical, technical and operational controls, as cloud services depend on global supply chains and because extraterritorial legal exposure is not confined to non-European providers. More preferable would be an outcomes focused sovereignty framework centred on sovereign-by-design architectures, which would take into consideration:
- legal exposure, including the existence of foreign legal demand regimes, the provider’s ability to challenge requests, customer notification processes and transparency reporting;
- technical controls, including encryption, customer-controlled key management, data residency commitments, access restrictions, access logging, and workload segregation;
- operational control, including personnel access, support models, administrative privileges, incident response processes, and personnel credentials;
- supply chain resilience, including dependencies on subcontractors, hardware, software, maintenance support and cross-border service functions; contingency plans for supply chain interruptions, on-hand inventory, and
- resilience and recovery mechanisms, including continuity planning, portability, exit arrangements, redundancy and independent assurance.
A sovereignty assessment framework that combines ownership-related criteria with risk-based controls would more effectively achieve the stated objectives of CADA. Such an approach would also be more consistent with principles of transparency, equal treatment, non-discrimination and proportionality, including in public procurement and under international procurement commitments.[11] It would further align with emerging international industry initiatives that seek to define trust through objective and verifiable controls rather than provider nationality[12].
6. Conclusion
CADA marks an important shift in European digital policy, recognising that cloud and AI capability are central to economic and strategic resilience.
However, the effectiveness of CADA will depend on how its objectives are implemented. A framework that relies too heavily on ownership, jurisdiction and exclusion, without complementary risk-based controls, risks mistaking formal control for substantive resilience, while also undermining competition, innovation and global integration.
Other jurisdictions show that sovereignty can be pursued and achieved through risk-based governance, technical safeguards and cooperation, rather than nationality-based exclusion.
Europe’s goal should not be digital isolation, but rather the ability to operate securely, competitively and openly and as part of the global technology ecosystem.
[1] The Draghi report on EU competitiveness and Communication from the Commission ‘State of Digital Decade 2025: Keep building the EU’s sovereignty and digital future’. For Cloud, see also European Cloud Providers’ Local Market Share Now Holds Steady at 15% | Synergy Research Group.
[2] Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee of the Regions on the European Tech Sovereignty, accompanied by an EU Open Source Strategy, see page 1.
[3] Article 16 in CADA. Annex II identifies the criteria for the assurance levels. Union assurance level 4 states that cloud computing service providers must meet various cumulative criteria including (without limitation): (a) the audited provider, and the subcontractors which are involved in the provision of the audited service, being established in the EU; (b) the infrastructure, assets, and personnel of the audited provider, including the subcontractors , which are involved in the provision of the service, being located in the EU; (c) the personnel, including the personnel of the subcontractors , which are involved in the provision of the audited service, are EU citizens; and (d) the technical and operational support or assistance related to the audited service, including subsequent sub-outsourcing arrangements, are initiated and performed exclusively within the EU, by personnel that are EU residents, and by third parties that are not subject to the control of a third country or a legal entity established in a third country.
[4] The four levels are: Level 1: where data is processed and stored in infrastructure located in the Union; Level 2: where providers must demonstrate independence from third countries and transparency over their software supply chain; Level 3: where providers must be owned and controlled from the EU and meet additional criteria, such as personnel citizenship. The Commission can recognise third-country providers; Level 4: where providers have full transparency and control over their software supply chain and no interference from a third country.
[5] The European Commission’s proposal on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881, page 3.
[6] Under Article 3, the EU GDPR applies to non-EU entities whenever certain connections to the EU exist (e.g. such non-EU entity is: (a) offering goods or services to customers in the EU; or (b) monitoring the behaviour of EU data subjects).
[7] The Royal Canadian Mounted Police issued a production order in April 2024: https://www.theregister.com/off-prem/2025/11/27/canadian-data-order-risks-blowing-a-hole-in-eu-sovereignty/2615140
[8] A new EU e-evidence package consisting of a legal regulation and a legal directive (to be implemented into national laws), will apply across all EU Member States (except Denmark) from 18 August 2026. The e-evidence package aims to make it easier and faster for EU Member State law enforcement agencies to obtain (via a European Production Order) electronic evidence from other EU Member States, in order to investigate criminal offences. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1543&qid=1692970814736#tit_1 and https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023L1544#tit_1
[9] https://www.theregister.com/off-prem/2025/11/27/canadian-data-order-risks-blowing-a-hole-in-eu-sovereignty/2615140 and https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-France-must-hand-over-user-data-11092029.html
[10] The Bill had its first reading in the House of Lords on 17 June 2026: https://bills.parliament.uk/bills/4035/stages/20847
[11] WTO Government Procurement Agreement (WPA). The WPA is a plurilateral agreement within the framework of the World Trade Organization (WTO), meaning that not all WTO members are parties to the agreement. The fundamental aim of the WPA is to mutually open government procurement markets among its parties. The WPA contains rules requiring that open, fair and transparent conditions of competition be ensured in government procurement.
[12] The Trusted Tech Alliance a coalition of global technology providers launched in 2026, has adopted a comparable risk-based approach to trusted technology, emphasising transparent corporate governance, operational transparency, secure development, supply chain oversight, resilience, data protection and adherence to the rule of law.