The Cloud and AI Development Act (CADA) is a proposed European regulation published on 3 June 2026 as part of the technological sovereignty package. It is directly applicable in all 27 Member States and applies to all public bodies and EU institutions that use cloud services.
It aims to develop European cloud and AI capabilities, accelerate the roll-out of data centres, provide the public sector with a certified sovereign cloud, and reduce critical digital dependencies.
Estimated date of entry into force: second quarter of 2029.
European public procurement did not include any legally binding criteria relating to digital sovereignty. The CADA has marked a profound shift in policy: public procurement now incorporates sovereignty as a selection criterion in its own right. The open-market approach is giving way to a proactive industrial policy, structurally directing demand towards European players.
| LEVEL | WHAT THIS MEANS IN PRACTICAL TERMS |
|---|---|
| Level 1 Self-assessment, EU declaration of conformity, without an external audit. | Minimum mandatory requirements for all public procurement of cloud services. The provider must be established within the EU, store its customers’ data there, and be accountable for its data processors. A non-European supplier could qualify for Level 1, subject to certain conditions. |
| Level 2 Mandatory independent audit. | A supplier under foreign control may be approved if it demonstrates that there is no impact on security, continuity and operational autonomy. «Substantial» EUCS certification or a national scheme (including SecNumCloud). Data may not be used to train AI models under foreign jurisdiction. |
| Level 3 Independent audit. Audits outside the European Union are excluded, with limited exceptions. | Staff who are EU citizens. Possible exceptions: recognition of third countries by the Commission, or the absence of a compliant tender for the public contracting authority. |
| Level 4 Independent audit. Any non-European influence is ruled out, with no exceptions. | No suppliers subject to foreign extraterritorial legislation are permitted, including those operating through a European subsidiary. «High» EUCS certification and full control of the software chain are required. |
The recognition procedure (Article 17) is conducted by the competent national authority within 60 days, with other Member States having the right to object; in the event of disagreement, the Commission shall issue a binding decision. Within one year of the entry into force, each Member State shall map its cloud usage and determine the level of assurance required for each type of usage. Operators in critical sectors as defined by NIS2 may voluntarily carry out impact assessments comparable to those of public entities — the Commission may make this exercise mandatory by means of a delegated act.
The substance of the proposal makes no secret of its French inspiration — it reflects the rationale behind the SREN Act, the architecture of the SecNumCloud, and the doctrine on digital sovereignty that France has been championing for several years. It is no longer up to European suppliers to justify their place in tender processes; rather, it is up to non-European suppliers to demonstrate their compliance with sovereignty requirements. It remains to be seen what the implementing regulations and exemptions under Articles 18 and 30 will entail: this is where the true scope of the legislation will be determined.
2026-2028 : European Parliament–Council trilogue
6 months on : designation by each Member State of acceleration zones for data centres
One year on : implementation of the regulation and adoption of national cloud and AI strategies
4 years on : the Commission’s first evaluation report, followed by a review every five years