What Is CADA (Cloud and AI Development Act)?

Also called: EU Cloud and AI Development Act

Related problems: A public-sector customer may require an EU sovereign cloud level we can't yet name; Unsure whether our US-owned cloud provider will qualify for EU government work; Planning EU data center capacity and hearing about new permitting rules; Need to know which proposed EU cloud rules could affect our provider choice

The Cloud and AI Development Act (CADA) is a proposed European Union regulation, published by the European Commission in June 2026, that aims to expand data center and computing capacity in the EU and to create a single EU-wide framework for assessing the sovereignty of cloud and AI services, with four assurance levels that public bodies would use according to risk. It is a proposal, not law: the European Parliament and the Council must agree a final text before any of it applies, and its content may change. This entry is an overview for buyers, not legal advice.

At a glance

  • CADA is a Commission proposal, not adopted law; Parliament and Council negotiations will decide its final form.
  • It is built on three pillars: research and innovation, data center and compute capacity, and autonomy.
  • The autonomy pillar proposes four cloud sovereignty assurance levels for public-sector procurement, from an EU-established provider keeping data in the EU up to no third-country control.
  • It is meant to complement the pending EUCS cloud security certification and a revised Cybersecurity Act.
  • For buyers, it could shape which cloud providers qualify for EU public-sector and critical workloads.

What problem it solves

The Commission points to two problems. First, demand for AI and cloud is growing faster than Europe can build data centers, held back by long permitting, and limited access to energy, land and financing. Second, heavy reliance on non-EU cloud providers is seen as a risk to Europe’s autonomy and resilience, including exposure to foreign laws with extraterritorial reach, such as the US CLOUD Act for providers under US jurisdiction.

National answers such as France’s SecNumCloud differ, and the planned EU cloud certification, EUCS, stalled over sovereignty requirements. CADA proposes one EU-wide way to define and assess cloud sovereignty, so public buyers could specify a level and providers could be recognized against common criteria.

How it works

Capacity and research. The Commission aims to at least triple EU data center capacity within five to seven years. The proposal includes member-state data center acceleration zones with simpler permitting, better access to energy, land, water and financing, and support for cloud and AI research.

Sovereignty framework. As proposed, public bodies buying cloud services would have to use services recognized at least at Level 1. Member states and EU bodies would run risk assessments, and where an activity has public-order relevance, only services recognized at Levels 2, 3 or 4 could be procured, with narrow exceptions. For Level 1, the provider would carry out a conformity self-assessment, publish an EU statement of conformity and submit it with evidence to the national competent authority where it is established; for Levels 2 to 4, it would submit an independent third-party audit report and opinion instead. That authority, after review by other member states, would issue an EU-wide recognition decision; statements from small and medium-sized providers would be recognized automatically.

Procurement. It proposes a common EU procurement framework so public administrations can pool purchasing power, along with criteria that reward EU-based innovation and supply chain resilience.

Proposed assurance levels

As proposed, each level has its own list of cumulative criteria in an annex, and a provider audited at a higher level must also meet every lower level’s criteria. The summary below is not exhaustive, and the criteria may change before adoption.

Proposed level Main criteria (summary, non-exhaustive) How it would be shown What a provider might show
Level 1 Provider established in the EU; its and its subcontractors’ infrastructure and assets in the EU; customer data, including metadata and telemetry, kept in the EU unless the public body requires otherwise; safeguards for support outsourced outside the EU; state-of-the-art cybersecurity standards; full transparency and oversight of subcontractors; for a provider controlled from outside the EU, no home-country duty to report unexploited vulnerabilities to that country’s authorities Provider self-assessment and public EU statement of conformity; for most providers, submitted to the national competent authority for an EU-wide recognition decision, while an SME’s statement would be recognized automatically without that prior decision Statement of conformity (plus the recognition decision for non-SMEs), subcontractor list, data location commitments covering metadata and telemetry
Level 2 Level 1 criteria plus: provider and subcontractors established in the EU, with personnel in the EU; an EU cloud certificate at least at substantial (national schemes until one exists); support performed within the EU; software bill of materials and supply chain controls; if controlled from outside the EU, measures preventing third-country access to customer data, service disruption and enforced foreign sanctions Independent third-party audit, then recognition Audit opinion, certificate, SBOM, recognition decision
Level 3 Level 2 criteria plus: personnel who are EU citizens, with security clearance where needed; support by EU residents; no third-country control, unless the Commission has recognized the third country and extra safeguards apply Independent third-party audit, then recognition Ownership and control structure, audit opinion, recognition decision
Level 4 Level 3 criteria plus: no third-country control, with no exception; an EU cloud certificate at the high level; effective control over the design and maintenance of software components Independent third-party audit, then recognition Software control evidence, high-level certificate, recognition decision

An EU region of a non-EU provider would not meet Level 1 on its own: the proposal requires an EU-established provider and the other Level 1 criteria.

When it matters for buyers

  • When you sell to or serve EU public bodies. Tenders may eventually ask for a CADA level; watch how the final text treats your providers.
  • When choosing a cloud provider for critical EU workloads. Ownership, control and supply chain could matter as much as location.
  • When planning EU data center or colocation capacity. Permitting changes, if adopted, could affect timelines.
  • When building a data sovereignty strategy. CADA would add a common EU vocabulary for sovereignty levels.

Our public cloud overview covers how provider selection fits into wider cloud planning.

Questions to ask vendors

  • How do you expect your services to map to the proposed CADA assurance levels, and which levels are you targeting?
  • Which legal entity operates the service, who owns and controls it, and where is it headquartered?
  • Where is our data stored, and who can be compelled to disclose it, including under non-EU law?
  • How transparent is your software supply chain, and which components are controlled from outside the EU?
  • Do you plan to certify under EUCS once adopted, and do you hold national schemes such as SecNumCloud?

How it differs from EUCS

EUCS is a pending security certification for cloud services under the EU Cybersecurity Act, with basic, substantial and high assurance levels about technical and organizational security. CADA’s proposed levels are about sovereignty: where services run, who owns and controls the provider, and whether third countries can interfere. As proposed, Levels 2 to 4 would require a European cloud cybersecurity certificate at the substantial or high level, the kind EUCS is meant to provide, so the two are meant to fit together. Other EU rules address related questions: the EU Data Act requires cloud providers to guard non-personal data against unlawful non-EU government access, the e-Evidence Regulation governs EU criminal-case orders, GDPR limits foreign orders for personal data, and data residency covers location alone.

Frequently Asked Questions

Is the Cloud and AI Development Act law yet?
No. The European Commission published it as a proposal in June 2026, and the European Parliament and the Council must agree a final text before it can become binding. Its content may change during negotiations, so treat every provision as proposed and check the current status.
Would CADA ban US cloud providers from the EU public sector?
Not as proposed. Public bodies would choose a level according to risk. As proposed, Level 1 requires an EU-established provider, and Level 2 can be met by a provider controlled from outside the EU if it shows set safeguards; Level 3 generally requires no third-country control, with a possible exception for recognized countries, and Level 4 excludes it. Which providers qualify would depend on the final text and on recognition decisions.
How does CADA relate to the US CLOUD Act?
The proposal's explanatory text points to third-country laws with extraterritorial effect, including laws mandating data access and transfer, which is the concern the CLOUD Act raises for EU buyers. As proposed, providers controlled from outside the EU would need to show safeguards against third-country access to customer data at Level 2, would generally be excluded at Level 3 unless their country is recognized, and would be excluded at Level 4.
How does CADA relate to EUCS?
They are designed to work together. EUCS is a pending EU security certification for cloud services. As proposed, CADA Levels 2 and 3 would require a European cloud cybersecurity certificate at least at the substantial level, and Level 4 at the high level, with national schemes used until such an EU scheme exists.
Does CADA affect private companies?
Mainly indirectly as proposed. Its sovereignty levels are aimed at public-sector procurement, and its capacity measures affect data center builders and operators. The proposal also lets entities in the sectors covered by the NIS2 Directive's first annex carry out similar assessments, the Commission could require this for some highly critical sectors, and private buyers may use the levels as a reference. Confirm with counsel; this is not legal advice.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.