The EU Proposed a Cloud Regulation with Four Sovereignty Tiers
The EU Proposed a Cloud Regulation with Four Sovereignty Tiers — Here Is What Each One Actually Means
The Cloud and AI Development Act, proposed June 3 2026, defines exactly what “cloud sovereignty” means in EU binding regulation for the first time. At Level 3, cloud providers must be owned and controlled within the EU. At Level 4, no third-country interference of any kind. As the proposal stands, US cloud providers face structural barriers at both levels — though a discretionary carve-out exists and its scope is contested. The Act is still a proposal — but what it defines is already shaping procurement decisions.
How this was reported: the CADA facts in this article come from the European Commission’s own policy page for the Cloud and AI Development Act and the Commission’s Communication on European Tech Sovereignty (COM(2026) 503), both published June 3 2026, both read in full. Legal analysis from Osborne Clarke LLP was used for context on the FSFE open source procurement obligation. This is not legal advice. The Act is a proposed regulation at the time of writing — it has not yet passed into law.
The Cloud and AI Development Act (CADA) was proposed by the European Commission on June 3 2026 as part of its Technological Sovereignty Package. Most coverage described it in a sentence: Europe wants to triple data centre capacity and reduce reliance on US cloud providers. That is accurate but misses the part that actually matters for any technology company selling into European governments — CADA introduces, for the first time as binding EU-wide regulation, a precise four-level definition of cloud sovereignty. Previous attempts — notably the European Cybersecurity Certification Scheme for Cloud Services (EUCS), which proposed similar sovereignty tiers under ENISA — had been stalled since 2021 by political disagreement between member states. CADA resolves that deadlock by putting sovereignty tiers into proposed legislation rather than a voluntary certification scheme. Reading those four definitions reveals a structural reality the press release did not announce plainly: at the two highest levels, the ownership-and-control requirements create structural barriers that US cloud providers, as currently constituted, would struggle to meet.
Overview of the EU’s Cloud and AI Development Act and the broader Tech Sovereignty Package published June 3 2026. Independent production, not a Wangdoo or European Commission production.
What CADA Actually Is
CADA is a proposed EU regulation — meaning, if passed, it becomes binding law across all 27 member states without needing to be transposed into national legislation separately. It is not yet law. It needs approval from the European Parliament and the Council of the EU, a process that recent comparable regulations suggest takes two to four years — the AI Act took three, GDPR took four. But what a proposed regulation defines matters from the day it is published, because it signals exactly what direction binding law is heading, and businesses and governments plan around that signal.
The Act has three main areas. The first is research and innovation — supporting frontier AI, industrial AI, and physical AI development, with what the Commission calls “grand challenges” to drive R&D effort. The second is capacity — specifically, a target to at least triple the EU’s data centre capacity within five to seven years, with simplified permitting and improved access to energy, land, water, and financing. Permitting delays and energy access are documented bottlenecks to data centre deployment in Europe, and the Act directly addresses them.
The third area — autonomy — is the one that carries the most operational consequence and has received the least specific coverage.
The Four Sovereignty Levels — In the Commission’s Own Words
The Commission’s own policy page defines the four levels precisely. They are designed to be used by public sector bodies based on their risk assessments, with cloud providers qualifying for recognition at each level after undergoing an audit by a member state. The definitions are:
CADA’s four cloud sovereignty levels — verbatim from the EU Commission
- Level 1: where data is processed and stored in infrastructure located in the Union
- Level 2: where providers must demonstrate independence from third countries and transparency over their software supply chain
- Level 3: where providers must be owned and controlled from the EU and meet additional criteria, such as personnel citizenship. The Commission can recognise third-country providers
- Level 4: where providers have full transparency and control over their software supply chain and no interference from a third country
Level 1 is achievable by any cloud provider with EU-located data centres — AWS, Azure, and Google Cloud all operate EU-located infrastructure and would qualify here. Level 2 adds independence from third-country jurisdiction and supply chain transparency, which creates complications for US providers subject to the US CLOUD Act’s extraterritorial reach — but does not categorically exclude them. Levels 3 and 4 are different in kind, not just degree.
At Level 3, providers must be owned and controlled from the EU. AWS is owned by Amazon, a Delaware corporation headquartered in Seattle. Azure is owned by Microsoft, a Delaware corporation headquartered in Redmond. Google Cloud is owned by Alphabet, a Delaware corporation headquartered in Mountain View. As currently structured, none of these can meet an EU ownership-and-control requirement regardless of where their data centres are located. The Commission’s carve-out — “the Commission can recognise third-country providers” — introduces a discretionary exception whose significance is genuinely contested. Critically, the Commission’s own primary source states that CADA’s autonomy pillar aims to accelerate cloud and AI deployment “while ensuring the vast majority of the market remains open to our partners” — the Commission’s own framing of the regulation as market-shaping rather than market-closing. Hogan Lovells, reading the same text, describes CADA as “allowing continued participation of global hyperscalers subject to enhanced compliance obligations” rather than excluding them. Whether the carve-out becomes a genuine pathway for US providers depends entirely on how the Commission defines recognition criteria — which it has not yet done. Without those criteria, the exception is undefined rather than accessible. Readers making compliance decisions should consult their own legal counsel; this article reflects one reading of an evolving proposal, not settled law.
Level 4 — full supply chain transparency and no third-country interference — goes further still. US cloud providers are legally required under the CLOUD Act to respond to US government demands for data stored anywhere in the world, including in EU data centres. That legal obligation constitutes a form of third-country interference by definition. Level 4 may be structurally unreachable for any provider subject to extraterritorial access law, regardless of ownership.
The Procurement Obligation
Alongside the sovereignty tiers, CADA establishes a common EU-level procurement framework for public administrations. The Free Software Foundation Europe flagged what this means in practice: the Act introduces what it describes as a “Free Software first principle for public cloud and AI software procurement,” requiring public administrations to make software purchased with public money publicly available as open source. The Commission’s own language is more cautious — it describes “promoting open source solutions to reinforce resilience” in the autonomy section — but the direction of travel is consistent across both readings.
The practical implication: European public bodies procuring cloud and AI software would face a presumption toward open-source solutions, with proprietary alternatives requiring justification. This is a reversal of the current default, where proprietary software is the baseline and open source is the exception requiring specific rationale. For major software vendors whose government revenue depends on European public sector contracts, this is a more significant commercial change than the sovereignty tiers — because it applies at Level 1, not just at the higher levels where US providers face structural barriers.
What Is Not Yet Known
Several consequential details are absent from the published proposal and have not been defined.
The audit mechanism — how cloud providers will be assessed and recognised at each sovereignty level — is not yet specified. The Commission says member states will conduct these audits, but the methodology, the bodies responsible, the timeline for initial recognitions, and the appeals process are all to be determined. Without an audit framework, the sovereignty levels are definitional rather than operational.
The third-country recognition process at Level 3 is also undefined. The Commission has reserved the right to recognise non-EU providers, but under what criteria and through what process is not in the current text. For US cloud providers hoping to serve Level 3 European government workloads through some form of recognised exception, the answer is: not yet determined.
The timeline is genuinely uncertain. CADA now enters the legislative process — review by the European Parliament’s relevant committees, negotiation with the Council, potential amendment, and eventually a final vote. The AI Act took approximately three years from proposal to adoption. CADA is a different type of regulation with different political dynamics, but a 2028–2029 implementation date is a reasonable working assumption for planning purposes — not a confirmed figure from any official source.
Why This Matters Now, Not in 2028
Regulations shape procurement decisions before they are law. The context makes clear why the EU is moving on this. The Commission’s own Tech Sovereignty page states directly that the EU currently relies on non-EU countries for over 80% of key digital products, services, infrastructure, and intellectual property — the Commission’s own framing of the dependency it is trying to reduce. European public sector bodies with long procurement cycles — multi-year IT contracts, infrastructure decisions, platform migrations — are already making choices that will be in place when CADA comes into force. A government IT department that commits to an AWS-hosted platform in 2026 on a five-year contract may find that platform unable to qualify for Level 3 or 4 sovereign workloads under a law that could be in force before the contract expires.
The Anthropic export ban in June 2026 — which switched off Fable 5 and Mythos 5 for all foreign users for eighteen days — demonstrated in real time what theoretical dependency on non-sovereign infrastructure looks like in practice. CADA is the legislative response to that category of risk, applied to cloud infrastructure rather than AI models. The timing is not coincidental. The Commission has been developing this framework since before the export ban, but the export ban arrived as a live illustration of exactly the problem CADA exists to address. As the UAE’s Federal AI Authority is discovering on its own digital sovereignty trajectory, defining sovereignty in law is considerably easier than building the infrastructure to make it real.
My Take — Mr Wangdoo
Reading CADA’s four sovereignty levels directly rather than from a press release summary reveals something the headlines have not captured. This is not primarily a data localisation law — Level 1 handles that, and the EU has had GDPR for that purpose since 2018. What CADA introduces is a structural definition of sovereignty that makes ownership and control the criteria, not location. That distinction matters enormously. A US company can locate servers in Frankfurt. It cannot be owned and controlled from the EU. Those are different things, and CADA’s Levels 3 and 4 treat them as different things explicitly for the first time in EU regulation.
Whether that distinction survives the legislative process intact — whether the third-country recognition mechanism at Level 3 gets expanded under lobbying pressure from US cloud providers, whether Level 4 gets softened — is the question worth tracking. The proposal as published is the most ambitious version of this framework. What emerges from Parliament and Council will tell you how much political will actually exists behind it. The proposal itself is a clear statement of intent. Whether it becomes operational law at the same level of ambition is a different question.
Frequently Asked Questions
Is CADA already law?
No. CADA was proposed by the European Commission on June 3 2026. It is now working through the EU’s legislative process — review by the European Parliament, negotiation with the Council of the EU, potential amendment, and a final vote. The AI Act took three years from proposal to adoption; GDPR took four. A two-to-four year window is the realistic comparator. It is not in force and no compliance deadline has been set.
Can AWS, Azure, or Google Cloud qualify under CADA?
At Levels 1 and 2, yes — with conditions. All three operate EU-located data centres (Level 1). Level 2 requires demonstrating independence from third-country jurisdiction, which creates complications given the US CLOUD Act’s extraterritorial reach, but does not categorically exclude them. At Level 3, the EU ownership-and-control requirement cannot be met by US-incorporated companies through their current structures. At Level 4, the requirement for no third-country interference of any kind is likely structurally incompatible with US legal obligations under the CLOUD Act. The Commission has reserved a discretionary exception at Level 3 for third-country providers, but the criteria for that exception are not yet defined.
What is the US CLOUD Act and why does it matter here?
The Clarifying Lawful Overseas Use of Data Act (CLOUD Act), signed into US law in 2018, requires US-based cloud providers to comply with US government demands for data stored anywhere in the world, including in data centres physically located in the EU. This means that even if a US provider stores European government data in a Frankfurt data centre, it remains legally obligated to hand that data to US authorities if required. CADA’s Level 4 requires no third-country interference of any kind — a standard that is difficult to meet while simultaneously being subject to the CLOUD Act.
What does the open source procurement obligation mean for businesses?
CADA introduces a presumption toward open-source solutions in European public sector cloud and AI procurement. In practice this means public bodies would need to justify choosing proprietary software over open-source alternatives, reversing the current default where proprietary is the baseline. For software vendors whose business model depends on European government contracts, this is a meaningful commercial change. The precise scope and enforcement mechanism are not yet defined in the proposal.
When would CADA realistically come into force?
Based on the EU’s legislative track record with comparable regulations — GDPR took approximately four years from proposal to adoption (proposed January 2012, adopted April 2016, with a further two-year implementation period before enforcement began in May 2018), the AI Act took approximately three years — a realistic planning window is 2028 to 2029 for CADA to enter into force, followed by a further implementation period before compliance is required. Neither of these figures is confirmed by any official source. What is certain is that CADA will shape procurement decisions before it is law, because long-term government IT contracts being signed now will still be running when it passes.
Sources
- Cloud and AI Development Act — official EU Commission policy page — European Commission (primary source, read in full)
- Communication on European Tech Sovereignty — COM(2026) 503 — European Commission, June 3 2026 (primary source, read in full)
- The new EU Open Source Strategy — legal analysis — Osborne Clarke LLP (legal context on CADA open source procurement obligations)
- EU Tech Sovereignty: A milestone for Public Code? — Free Software Foundation Europe (FSFE analysis of the “Free Software first” procurement principle in CADA)
- The EU’s Cloud and AI Development Act — towards a sovereignty-focused framework — Hogan Lovells LLP (competing legal interpretation of Level 3 carve-out cited in body)
- The European Union reveals details of its tech sovereignty package — Engadget, June 2026 (context)