Factlen ExplainerCloud SovereigntyExplainerJul 3, 2026, 7:37 PM· 5 min read· #3 of 3 in technology

How the EU's New 'Cloud Sovereignty' Framework Could Exclude US Tech Giants From Government Contracts

The European Commission's proposed Cloud and AI Development Act introduces a four-tier security system that effectively requires local ownership for sensitive public-sector data. The framework sets up a direct jurisdictional clash with US surveillance laws, forcing a structural shift in how cloud infrastructure is procured.

By Factlen Editorial Team

European Digital Sovereigntists 45%Global Hyperscalers 35%Enterprise Security Analysts 20%
European Digital Sovereigntists
Argue that relying on foreign cloud infrastructure for critical government functions is an unacceptable national security risk that must be mitigated through strict jurisdictional control.
Global Hyperscalers
Contend that the framework is protectionist, artificially limits European access to best-in-class technology, and will slow the continent's digital transformation.
Enterprise Security Analysts
View the framework as a massive compliance shift that will force multinational corporations to redesign their cloud architectures to meet new public-sector supply chain requirements.

What's not represented

  • · Private sector enterprise customers
  • · Non-EU, non-US cloud providers (e.g., Chinese tech firms)

Why this matters

For years, cloud sovereignty was treated as a geographic problem solved by building local data centers. The EU's new framework redefines it as a jurisdictional problem, meaning US cloud providers could soon be legally barred from hosting Europe's most sensitive public data regardless of where their servers are located.

Key points

  • The EU's proposed Cloud and AI Development Act (CADA) introduces a four-tier sovereignty framework for public-sector cloud contracts.
  • The highest tiers (UAL 3 and 4) require European corporate ownership and mandate that all personnel be EU citizens.
  • The rules are designed to counter the US CLOUD Act, which allows American law enforcement to access data stored globally by US companies.
  • US hyperscalers like AWS, Google Cloud, and Azure will likely be locked out of Europe's most sensitive government contracts.
  • The framework hands a massive structural advantage to domestic European cloud providers like OVHcloud and T-Systems.
80%
EU digital products originating from non-EU providers
4
Union Assurance Levels (UALs) in the new framework

For the past decade, the global cloud computing market has operated on a geographic compromise: US tech giants could serve European governments as long as they built data centers physically located within European borders. That era is coming to a close. With the introduction of the Cloud and AI Development Act (CADA), the European Commission is fundamentally redefining what it means to control digital infrastructure.[2]

CADA is the centerpiece of the broader European Technological Sovereignty Package, a sweeping legislative blueprint unveiled in June 2026. The package is driven by a stark mathematical reality: the European Union currently relies on non-EU providers for more than 80 percent of its digital products, services, and intellectual property. Brussels now views this reliance not merely as an economic imbalance, but as a critical strategic vulnerability comparable to its former dependence on Russian natural gas.

To correct this, CADA introduces a mechanism known as the Union cloud computing sovereignty framework. Outlined in Article 16 of the proposed regulation, the framework establishes four distinct "Union Assurance Levels" (UAL 1 through 4). These tiers dictate exactly which cloud providers are legally permitted to host different categories of public-sector data, shifting the focus from where data is stored to who legally controls the company storing it.[2]

The four tiers of the Union cloud computing sovereignty framework dictate which providers can host sensitive government data.
The four tiers of the Union cloud computing sovereignty framework dictate which providers can host sensitive government data.

The tier system operates as a graduated filter. Union Assurance Level 1 (UAL 1) serves as the new baseline for all public-sector cloud procurement. It requires that the provider be established in the EU and that all customer data, including metadata and telemetry, remains physically within the Union unless a public body explicitly grants an exception. Most major international cloud providers can meet this baseline today.[2]

Union Assurance Level 2 (UAL 2) tightens the net. It demands that both the audited provider and all subcontractors maintain their infrastructure, assets, and personnel exclusively within the EU. Furthermore, it prohibits the training of artificial intelligence models on customer usage data outside of European borders, establishing a robust defense against extra-territorial data transfer.[2]

The structural roadblocks for foreign tech giants begin at Union Assurance Level 3 (UAL 3). At this tier, all personnel involved in managing the cloud service must be EU citizens, holding national security clearances if they handle classified information. Crucially, the provider and its subcontractors must not be subject to corporate control by a third country, effectively locking out subsidiaries of foreign multinationals unless specific, narrow derogations are granted.

Union Assurance Level 4 (UAL 4) is the absolute ceiling, designed exclusively for the most sensitive government workloads—such as defense, national security, justice, and border management. UAL 4 mandates full EU-only control with zero exceptions. It requires European corporate ownership, European infrastructure, and mandatory EU citizenship for anyone with physical or logical access to the systems. Under these criteria, no US-headquartered hyperscaler can currently qualify.[2]

It requires European corporate ownership, European infrastructure, and mandatory EU citizenship for anyone with physical or logical access to the systems.

The exclusion of US tech giants from the top tiers is not an accident of the drafting process; it is a direct response to the US CLOUD Act. Passed by the US Congress in 2018, the CLOUD Act grants American law enforcement the legal authority to compel US-based technology companies to hand over data regardless of where those servers are physically located in the world.[1]

The Tech Sovereignty Package aims to reverse Europe's overwhelming reliance on foreign digital infrastructure.
The Tech Sovereignty Package aims to reverse Europe's overwhelming reliance on foreign digital infrastructure.

European regulators have long argued that the US CLOUD Act creates an irreconcilable conflict with European data protection laws. Because a hyperscaler operating a data center in Frankfurt remains subject to the laws governing its American parent company, European officials argue that US providers inherently hold a jurisdictional "kill switch" over European public-sector data.

By codifying the four-tier system, CADA transforms this theoretical legal conflict into a hard procurement disqualifier. Article 30 of the proposed act requires member states to conduct mandatory risk assessments on their public-sector workloads. Activities deemed critical to "public order" must be assigned to UAL 3 or UAL 4, legally barring US providers from bidding on those contracts.[2]

This creates a structural ceiling for companies like Amazon Web Services, Google Cloud, and Microsoft Azure. While these hyperscalers possess the capital to build endless localized data centers across Europe, they cannot alter their ultimate corporate ownership or shield themselves from the jurisdictional reach of US federal law without fundamentally restructuring their global businesses.[1]

Conversely, the framework hands a massive structural advantage to domestic European cloud operators. Companies such as France's OVHcloud and Scaleway, or Germany's T-Systems, are perfectly positioned to qualify for UAL 3 and UAL 4. For these firms, CADA represents an unprecedented opportunity to capture high-value government contracts without having to outspend American rivals on raw infrastructure.[2]

The US CLOUD Act allows American authorities to compel data access globally, creating an irreconcilable conflict with CADA's top sovereignty tiers.
The US CLOUD Act allows American authorities to compel data access globally, creating an irreconcilable conflict with CADA's top sovereignty tiers.

CADA does not exist in a vacuum. It is flanked by the Chips Act 2.0, which grants the European Commission emergency powers to override commercial semiconductor contracts during supply crises, and a new EU Open Source Strategy that elevates community-maintained software to the status of critical national infrastructure.[1]

The legislative battle is now shifting to the European Parliament and the Council of the EU. US providers and international trade groups are actively lobbying to soften the definitions of "operational autonomy" in the final text, hoping to carve out a compliance pathway that would allow them to reach UAL 3 through localized joint ventures or technical ring-fencing.[2]

While CADA technically only applies to public-sector procurement, enterprise security analysts warn of massive spillover effects. Private companies that operate critical infrastructure—such as energy grids, telecommunications, and financial services—will likely face intense regulatory and contractual pressure to align their own cloud architectures with the new UAL tiers.

Under UAL 3 and UAL 4, all personnel with physical or logical access to the infrastructure must be EU citizens.
Under UAL 3 and UAL 4, all personnel with physical or logical access to the infrastructure must be EU citizens.

Ultimately, the Tech Sovereignty Package marks the moment Europe stopped treating digital independence as an abstract political aspiration and began writing it into the mathematical logic of procurement law. Whether it succeeds in incubating a competitive domestic cloud industry, or simply fragments the global internet, will depend entirely on how strictly the four tiers are enforced.[2]

How we got here

  1. March 2018

    The United States passes the CLOUD Act, granting law enforcement the power to compel data from US companies globally.

  2. September 2023

    The EU enacts the original Chips Act, beginning a legislative push to reduce reliance on foreign semiconductor supply chains.

  3. June 3, 2026

    The European Commission formally proposes the Tech Sovereignty Package, including the Cloud and AI Development Act (CADA).

  4. Late 2026

    The CADA proposal enters trilogue negotiations between the European Parliament, the Council of the EU, and the Commission.

Viewpoints in depth

European Policymakers

View the framework as a necessary defense mechanism to protect critical infrastructure from foreign legal interference.

For European regulators, the CADA framework is about closing a glaring loophole in national security. Policymakers argue that as long as European hospitals, energy grids, and defense ministries run on infrastructure controlled by foreign corporations, the EU remains vulnerable to extra-territorial laws like the US CLOUD Act. By enforcing strict Union Assurance Levels, they aim to guarantee that a foreign government can never legally compel the handover of Europe's most sensitive public-sector data, nor hold a 'kill switch' over its critical digital infrastructure.

US Cloud Providers

Argue the tier system is a protectionist measure that will cut Europe off from the most advanced cloud and AI technologies.

American hyperscalers and international trade groups view the UAL 3 and UAL 4 requirements as an artificial market barrier designed to protect uncompetitive European domestic providers. They argue that by locking out the companies that invest the most in cutting-edge cybersecurity and AI research, European governments will be forced to rely on inferior, more expensive legacy systems. Lobbyists are currently pushing to redefine 'operational autonomy' to allow US firms to compete for higher-tier contracts through localized joint ventures or advanced encryption ring-fencing.

European Cloud Operators

See the framework as a long-overdue market correction that rewards genuine jurisdictional sovereignty.

Domestic European cloud providers like OVHcloud, Scaleway, and T-Systems argue that true sovereignty cannot be achieved simply by renting server space from an American multinational. They view CADA as a vital leveling of the playing field, ensuring that public procurement dollars flow to companies that actually pay taxes in Europe, employ European citizens, and operate exclusively under European law. For these firms, the four-tier system is the catalyst needed to finally scale a competitive domestic cloud industry.

What we don't know

  • Whether US hyperscalers will successfully lobby the European Parliament to soften the definitions of 'operational autonomy' before the law passes.
  • How strictly member states will classify their workloads, and whether some nations will exploit loopholes to keep using US providers for convenience.
  • Whether European domestic cloud providers have the actual technical capacity to absorb the massive influx of government workloads required by UAL 3 and 4.

Key terms

CADA
The Cloud and AI Development Act, a proposed EU regulation aimed at expanding European data center capacity and enforcing strict sovereignty rules for public-sector cloud procurement.
Union Assurance Levels (UAL)
A four-tier classification system proposed by the EU that dictates the security, ownership, and jurisdictional requirements a cloud provider must meet to host government data.
US CLOUD Act
A 2018 United States federal law that allows US law enforcement to compel American technology companies to provide requested data regardless of whether the data is stored in the US or on foreign soil.
Hyperscaler
A massive, global cloud service provider—typically referring to US tech giants like Amazon Web Services (AWS), Google Cloud, and Microsoft Azure—that dominates the enterprise computing market.
Data Residency vs. Jurisdictional Control
Data residency refers to the physical location of a server; jurisdictional control refers to which country's laws can legally compel the company owning that server to hand over the data.

Frequently asked

Does CADA ban US cloud providers from Europe?

No. US providers can still operate in Europe and serve private businesses. However, they will be structurally locked out of hosting the most sensitive public-sector workloads (like defense and justice data) under the higher UAL tiers.

Can US companies comply by building more European data centers?

No. While data residency is required for the lower tiers, the highest tiers (UAL 3 and 4) require operational autonomy and European corporate ownership to shield the data from the US CLOUD Act.

Will this affect private companies?

Directly, CADA only applies to public-sector procurement. However, private companies that supply software or services to European governments will likely be forced to adopt these sovereignty tiers to maintain their contracts.

When does this framework take effect?

CADA is currently a legislative proposal. It must be negotiated and approved by the European Parliament and the Council of the EU, a process that typically takes several years before enforcement begins.

Sources

Source coverage

2 outlets

3 viewpoints surfaced

European Digital Sovereigntists 45%Global Hyperscalers 35%Enterprise Security Analysts 20%
  1. [1]TechRepublicGlobal Hyperscalers

    The EU's tech sovereignty package targets cloud, chips, AI infrastructure, and open source

    Read on TechRepublic
  2. [2]Factlen Editorial TeamEnterprise Security Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.