Skip to main content
ExplainerCloud SovereigntyExplainerAug 25, 2026, 7:51 PM· 7 min read· in guides

The New EU Cloud Reality: A Guide to the Cloud and AI Development Act (CADA), Sovereignty Levels, and the Public Sector Mandate

The European Commission's proposed Cloud and AI Development Act (CADA) introduces a four-tier sovereignty framework that will reshape how public sector bodies procure cloud services. The mandate aims to reduce reliance on US hyperscalers by reserving the most sensitive contracts for EU-owned and controlled providers.

By Hui Lin

European Policymakers 35%US Cloud Providers 25%European Cloud Providers 25%Open Source Advocates 15%
European Policymakers
Argue that CADA is essential for digital autonomy and securing critical infrastructure.
US Cloud Providers
Warn that overly strict sovereignty requirements could fragment the market and limit access to cutting-edge AI.
European Cloud Providers
View the legislation as a necessary market intervention to help domestic companies scale.
Open Source Advocates
Celebrate the 'open source first' mandate as a victory for transparency and interoperability.

Key terms

Cloud and AI Development Act (CADA)
A proposed EU regulation establishing a four-tier sovereignty framework for cloud services and aiming to triple European data center capacity.
Union Assurance Levels (UAL)
The four-tier classification system in CADA that grades cloud providers on their degree of digital sovereignty and independence from foreign control.
US CLOUD Act
A United States federal law that allows US law enforcement to compel American tech companies to provide requested data, regardless of whether the data is stored in the US or on foreign soil.
Hyperscaler
A massive cloud service provider, such as Amazon Web Services, Google Cloud, or Microsoft Azure, that dominates the global market through immense scale and infrastructure.
Open Source First
A CADA mandate requiring EU public sector bodies to prioritize open standards and open-source software in their digital procurement.

Key points

  • CADA introduces a four-tier Union Assurance Level (UAL) framework to grade the sovereignty of cloud providers.
  • US hyperscalers are structurally blocked from Levels 3 and 4 due to the extraterritorial reach of the US CLOUD Act.
  • The European Commission estimates 90 percent of public contracts will only require Level 1 or Level 2, keeping the market largely open.
  • The top 10 percent of sensitive contracts will be ring-fenced for EU-owned and controlled providers.
  • CADA mandates an 'open source first' principle for all EU public sector digital procurement.
  • The legislation aims to triple the European Union's data center capacity over the next five to seven years.

Europe's public sector runs on American cloud infrastructure, creating a direct conflict between the continent's desire for digital independence and the reality of US market dominance. Three American hyperscalers—Amazon Web Services, Google Cloud, and Microsoft Azure—currently control more than 70 percent of the European cloud market. For years, European policymakers have warned that relying on a consolidated group of foreign providers to host the continent's most critical public services and enterprise data creates an unacceptable strategic dependency. This structural imbalance has driven a decade-long push for technological sovereignty, culminating in a legislative effort to rewrite the rules of digital procurement from the ground up.[1]

The tension peaks where data privacy meets foreign law. Under the US CLOUD Act, American authorities can compel US-based companies to hand over data, regardless of where those servers sit geographically. For European governments managing citizen data, defense logistics, and critical infrastructure, that extraterritorial reach is a structural vulnerability they can no longer accept. A provider subject to the CLOUD Act cannot credibly guarantee that a third country will never interfere with its operations. This jurisdictional clash has transformed cloud hosting from a purely technical and financial decision into a high-stakes geopolitical compliance exercise.[1]

The resolution arrives in the form of the Cloud and AI Development Act (CADA). Proposed by the European Commission on June 3, 2026, CADA serves as the centerpiece of a broader Tech Sovereignty Package. The legislation aims to scale EU-based cloud and AI infrastructure while simultaneously establishing a unified, EU-wide framework to grade the sovereignty of cloud providers. By codifying what "digital sovereignty" actually means in verifiable stages, the European Commission is moving away from marketing jargon and toward strict, auditable procurement standards for the public sector.

The actionable takeaway for enterprise and public-sector IT buyers is immediate: cloud procurement now requires mapping workloads against geopolitical risk. Public sector bodies, critical infrastructure operators, and entities procuring services under public contracts must categorize their systems by sensitivity and align them with CADA's new sovereignty tiers. While the legislation is still moving through the European Parliament, its framework is already shaping procurement expectations in regulated industries. Organizations cannot afford to wait for final adoption to begin auditing their infrastructure and planning potential migrations.[2]

Instead of a binary system that simply approves or bans foreign providers, the CADA framework grades cloud services across four Union Assurance Levels (UAL 1 through UAL 4). Each level dictates which types of government and critical infrastructure workloads a provider is legally permitted to host, based on criteria such as infrastructure location, supply chain transparency, and corporate ownership. This tiered approach allows the European Union to secure its most sensitive data without entirely locking itself out of the global technology ecosystem.

Level 1 (UAL 1) serves as the baseline for doing business with the European public sector. It requires that data processing and storage happen entirely within EU-located infrastructure. There are no additional requirements regarding corporate ownership, personnel citizenship, or the software supply chain. This is a floor that US hyperscalers can easily clear using their existing European data center regions, ensuring they remain eligible for the vast majority of standard government contracts without restructuring their corporate entities.

Level 2 (UAL 2) introduces operational complexity. Providers must demonstrate verifiable independence from third countries and maintain full transparency over their software supply chains. US providers can generally achieve this tier by partnering with European telecommunications or IT firms to act as operational firewalls. By decoupling the day-to-day management and technical support from the US parent company, these joint ventures neutralize the jurisdictional reach of foreign laws while still allowing European customers to leverage hyperscaler technology.

Providers must demonstrate verifiable independence from third countries and maintain full transparency over their software supply chains.

The structural wall hits at Level 3 (UAL 3). To qualify for this tier, a cloud provider must be based in the EU, EU-owned, and under EU control. It also introduces strict citizenship requirements for personnel handling the infrastructure. Because of the extraterritorial reach of the US CLOUD Act, American hyperscalers are structurally locked out of this tier, regardless of where their data centers are built or how they structure their local partnerships.[1]

Level 4 (UAL 4) represents complete digital sovereignty. It demands full transparency and control over the software supply chain, with absolute guarantees against third-country interference. This is the highest degree of digital independence recognized by the regulatory framework, reserved exclusively for the most sensitive national security, defense, border management, and justice workloads. Only a fraction of European providers currently possess the infrastructure and security controls necessary to meet this demanding standard.[1]

For IT leaders, the cost and complexity of compliance will depend entirely on workload classification. The European Commission estimates that roughly 70 percent of public contracts will only require Level 1, and another 20 percent will require Level 2. This pragmatic approach means that global hyperscalers will remain eligible for 90 percent of government business, preventing a sudden disruption of services and allowing public administrations to continue utilizing cutting-edge AI and cloud tools.[2]

However, the remaining 10 percent of contracts—those requiring Level 3 or 4—will be strictly ring-fenced for European providers like OVHcloud, STACKIT, and Scaleway. For these domestic players, CADA provides a protected market to help them scale against American giants. By reserving highly lucrative, security-sensitive workloads for EU-owned companies, the legislation acts as a targeted industrial policy designed to nurture a competitive domestic cloud ecosystem that can eventually rival foreign alternatives.[2]

Beyond the tiering system, CADA mandates an "open source first" principle for the EU public sector. Government entities must prioritize open standards and software released under open-source licenses when building their cloud and AI ecosystems. This mandate is designed to prevent vendor lock-in, increase interoperability between member states, and ensure that public money funds code that can be freely reused and audited by the public. For developers, this represents a massive shift in how government contracts will be awarded.

This procurement shift poses a direct challenge to proprietary software models. Software developed by or for public bodies will now be centralized in an EU Open Source Solutions Catalogue. A network of Open Source Programme Offices will be established to facilitate cooperation, ensuring that a custom application built for a municipality in France can be seamlessly deployed by a regional government in Germany without recurring licensing fees. The goal is to create a shared digital commons across the entire continent.

The legislation also aims to address the physical constraints of the AI boom. Recognizing that sovereignty requires actual hardware, CADA sets an aggressive target to at least triple the EU's data center capacity over the next five to seven years. The act streamlines the deployment of data centers by identifying suitable sites, simplifying permitting processes for sustainable projects, and improving access to critical resources like energy, land, and financing to support the continent's growing computational needs.

While CADA is currently a legislative proposal moving through the trilogue negotiations between the European Commission, Parliament, and Council, its trajectory is clear. Final adoption is targeted for late 2027, but the procurement signals are already reshaping the market. Major European tenders are already utilizing the framework's principles to evaluate bids, signaling that the era of unregulated cloud procurement has officially ended and a new compliance-driven reality has begun.[2]

European organizations must begin auditing their cloud architectures today. The immediate step is to categorize existing workloads by sensitivity and map them against the proposed UAL tiers. IT leaders must identify any critical systems currently hosted on Level 1 or Level 2 infrastructure that will need to migrate to a Level 3 European provider. By treating sovereignty as a core architectural requirement now, enterprises can avoid forced, expensive migrations when the mandate fully takes effect.[2]

Sources

Source coverage

2 outlets

4 viewpoints surfaced

European Policymakers 35%US Cloud Providers 25%European Cloud Providers 25%Open Source Advocates 15%
  1. [1]LawfareUS Cloud Providers

    The EU Cloud and AI Development Act

    Read on Lawfare
  2. [2]Factlen Editorial TeamEuropean Policymakers

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.