European Commission Publishes Proposal for Act to Reduce Reliance on Foreign Cloud and AI
Summary
On June 3, 2026, the European Commission (EC) released its first draft of the Cloud and AI Development Act (CADA) proposal, aiming to bolster the EU's digital infrastructure and decrease reliance on non-EU cloud providers. This initiative seeks to strengthen EU cloud, AI, and computing capabilities by tripling the EU's data center capacity within five to seven years and supporting EU-developed technology. CADA introduces a cloud sovereignty framework requiring public-sector bodies to conduct risk assessments and adhere to four levels of selection criteria for cloud services, ranging from basic safeguards to protection against foreign control and legal risks. While primarily impacting the public sector, the proposal also encourages similar practices for critical private entities and incentivizes EU-based cloud and AI investment.
Key takeaway
For legal professionals and consultants advising companies operating in the EU, CADA signals a significant shift in digital service procurement and risk assessment. You should monitor CADA's legislative development closely, as its criteria for "sovereignty" will likely influence vendor due diligence, contracting, and strategic cloud architecture decisions beyond public procurement. Prepare to assess your cloud and AI infrastructure for data localization, foreign legal risks, and supply chain security to ensure future compliance and market access.
Key insights
The EU's CADA proposal aims to reduce foreign cloud reliance and boost domestic digital sovereignty through new public-sector procurement rules.
Principles
- Digital infrastructure is critical.
- Public sector needs foreign control protection.
- EU-based investment is encouraged.
Method
Public bodies must conduct risk assessments, then select cloud services based on four assurance levels, with higher sensitivity requiring independent third-party audits and EU-based staff/data.
In practice
- Assess cloud services against CADA's four assurance levels.
- Implement multi-cloud or multi-vendor strategies.
- Prioritize EU-designed software/hardware.
Topics
- Cloud and AI Development Act
- EU Digital Sovereignty
- Public Sector Procurement
- Data Center Capacity
- Cybersecurity Act
- Digital Operational Resilience Act
Best for: CTO, Executive, VP of Engineering/Data, Legal Professional, Policy Maker, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by The Data Advisor.