The Cloud and AI Development Act (CADA) is a proposed European Union regulation, published by the European Commission in June 2026, that aims to expand data center and computing capacity in the EU and to create a single EU-wide framework for assessing the sovereignty of cloud and AI services, with four assurance levels that public bodies would use according to risk. It is a proposal, not law: the European Parliament and the Council must agree a final text before any of it applies, and its content may change. This entry is an overview for buyers, not legal advice.
At a glance
- CADA is a Commission proposal, not adopted law; Parliament and Council negotiations will decide its final form.
- It is built on three pillars: research and innovation, data center and compute capacity, and autonomy.
- The autonomy pillar proposes four cloud sovereignty assurance levels for public-sector procurement, from an EU-established provider keeping data in the EU up to no third-country control.
- It is meant to complement the pending EUCS cloud security certification and a revised Cybersecurity Act.
- For buyers, it could shape which cloud providers qualify for EU public-sector and critical workloads.
What problem it solves
The Commission points to two problems. First, demand for AI and cloud is growing faster than Europe can build data centers, held back by long permitting, and limited access to energy, land and financing. Second, heavy reliance on non-EU cloud providers is seen as a risk to Europe’s autonomy and resilience, including exposure to foreign laws with extraterritorial reach, such as the US CLOUD Act for providers under US jurisdiction.
National answers such as France’s SecNumCloud differ, and the planned EU cloud certification, EUCS, stalled over sovereignty requirements. CADA proposes one EU-wide way to define and assess cloud sovereignty, so public buyers could specify a level and providers could be recognized against common criteria.
How it works
Capacity and research. The Commission aims to at least triple EU data center capacity within five to seven years. The proposal includes member-state data center acceleration zones with simpler permitting, better access to energy, land, water and financing, and support for cloud and AI research.
Sovereignty framework. As proposed, public bodies buying cloud services would have to use services recognized at least at Level 1. Member states and EU bodies would run risk assessments, and where an activity has public-order relevance, only services recognized at Levels 2, 3 or 4 could be procured, with narrow exceptions. For Level 1, the provider would carry out a conformity self-assessment, publish an EU statement of conformity and submit it with evidence to the national competent authority where it is established; for Levels 2 to 4, it would submit an independent third-party audit report and opinion instead. That authority, after review by other member states, would issue an EU-wide recognition decision; statements from small and medium-sized providers would be recognized automatically.
Procurement. It proposes a common EU procurement framework so public administrations can pool purchasing power, along with criteria that reward EU-based innovation and supply chain resilience.
Proposed assurance levels
As proposed, each level has its own list of cumulative criteria in an annex, and a provider audited at a higher level must also meet every lower level’s criteria. The summary below is not exhaustive, and the criteria may change before adoption.
| Proposed level | Main criteria (summary, non-exhaustive) | How it would be shown | What a provider might show |
|---|---|---|---|
| Level 1 | Provider established in the EU; its and its subcontractors’ infrastructure and assets in the EU; customer data, including metadata and telemetry, kept in the EU unless the public body requires otherwise; safeguards for support outsourced outside the EU; state-of-the-art cybersecurity standards; full transparency and oversight of subcontractors; for a provider controlled from outside the EU, no home-country duty to report unexploited vulnerabilities to that country’s authorities | Provider self-assessment and public EU statement of conformity; for most providers, submitted to the national competent authority for an EU-wide recognition decision, while an SME’s statement would be recognized automatically without that prior decision | Statement of conformity (plus the recognition decision for non-SMEs), subcontractor list, data location commitments covering metadata and telemetry |
| Level 2 | Level 1 criteria plus: provider and subcontractors established in the EU, with personnel in the EU; an EU cloud certificate at least at substantial (national schemes until one exists); support performed within the EU; software bill of materials and supply chain controls; if controlled from outside the EU, measures preventing third-country access to customer data, service disruption and enforced foreign sanctions | Independent third-party audit, then recognition | Audit opinion, certificate, SBOM, recognition decision |
| Level 3 | Level 2 criteria plus: personnel who are EU citizens, with security clearance where needed; support by EU residents; no third-country control, unless the Commission has recognized the third country and extra safeguards apply | Independent third-party audit, then recognition | Ownership and control structure, audit opinion, recognition decision |
| Level 4 | Level 3 criteria plus: no third-country control, with no exception; an EU cloud certificate at the high level; effective control over the design and maintenance of software components | Independent third-party audit, then recognition | Software control evidence, high-level certificate, recognition decision |
An EU region of a non-EU provider would not meet Level 1 on its own: the proposal requires an EU-established provider and the other Level 1 criteria.
When it matters for buyers
- When you sell to or serve EU public bodies. Tenders may eventually ask for a CADA level; watch how the final text treats your providers.
- When choosing a cloud provider for critical EU workloads. Ownership, control and supply chain could matter as much as location.
- When planning EU data center or colocation capacity. Permitting changes, if adopted, could affect timelines.
- When building a data sovereignty strategy. CADA would add a common EU vocabulary for sovereignty levels.
Our public cloud overview covers how provider selection fits into wider cloud planning.
Questions to ask vendors
- How do you expect your services to map to the proposed CADA assurance levels, and which levels are you targeting?
- Which legal entity operates the service, who owns and controls it, and where is it headquartered?
- Where is our data stored, and who can be compelled to disclose it, including under non-EU law?
- How transparent is your software supply chain, and which components are controlled from outside the EU?
- Do you plan to certify under EUCS once adopted, and do you hold national schemes such as SecNumCloud?
How it differs from EUCS
EUCS is a pending security certification for cloud services under the EU Cybersecurity Act, with basic, substantial and high assurance levels about technical and organizational security. CADA’s proposed levels are about sovereignty: where services run, who owns and controls the provider, and whether third countries can interfere. As proposed, Levels 2 to 4 would require a European cloud cybersecurity certificate at the substantial or high level, the kind EUCS is meant to provide, so the two are meant to fit together. Other EU rules address related questions: the EU Data Act requires cloud providers to guard non-personal data against unlawful non-EU government access, the e-Evidence Regulation governs EU criminal-case orders, GDPR limits foreign orders for personal data, and data residency covers location alone.
