Cloud and AI Development Act: which level can your stack pass?

Full name
September 18, 2026
5 min read
Cloud and AI Development Act analysis
Cloud and AI Development Act: which level can your stack pass?
CADA converts sovereignty from a marketing claim into a procurement condition. Four Union assurance levels, a mandatory floor for public-sector supply and 27 national risk assessments will decide which cloud and AI services stay eligible.

CADA is not simply another cloud regulation. Published in June 2026 as the centrepiece of the EU Tech Sovereignty Package, it converts sovereignty from a marketing claim into a procurement condition: four Union assurance levels, a mandatory floor for all public-sector supply, and higher tiers reserved for workloads judged relevant to public order.

The decisive question is whether eligibility is settled by ownership or by verifiable safeguards. That single design choice determines whether hyperscalers can qualify through architectural separation, or whether European operators hold protected demand outright. Because each Member State runs its own risk assessment, the same service may qualify differently across markets. CADA is still a proposal in trilogue, but its qualification logic is already the planning basis for portfolio, partnership and European capacity decisions.

From sovereignty claim to procurement condition

The shift is from voluntary positioning to audited recognition. The stated objective is to strengthen Europe's strategic autonomy by scaling sovereign cloud and AI infrastructure, reducing critical dependencies and improving the EU's ability to compete in the global digital economy.

What changes in practice is the burden of proof. A sovereignty claim used to be a positioning statement. Under CADA it becomes a status that has to be demonstrated, audited and recognised before a service can be offered to parts of the public sector.

The four pillars of the proposal

CADA overview: four regulatory pillars, three hyperscaler obligations and the initial reactions from Google Cloud, AWS and Microsoft
CADA at a glance: four regulatory pillars, three obligations for hyperscalers, and the first reactions from Google Cloud, AWS and Microsoft. Source: Frenus analysis.
  • Common assurance levels. Four Union assurance levels create a shared language for sovereign cloud requirements.
  • Audit and recognition. Providers must show evidence. Higher levels rely on independent audits and national authority recognition.
  • Public-sector pull. Risk assessments can force sensitive workloads toward recognised sovereign cloud services.
  • EU added value. Open source, European supply-chain contribution and common procurement become differentiators.

What CADA asks of hyperscalers

Three obligations follow from the proposal, and each one touches the operating model rather than the marketing layer.

  • Repackage. Higher assurance levels may require dedicated EU entities, clearer operating boundaries and stronger continuity arrangements.
  • Prove. Claims must withstand audit evidence on software supply chain, operational continuity and jurisdictional exposure.
  • Partner. Local telecom, defence and cloud operators help bridge sovereignty gaps without replacing hyperscaler technology.

A fourth response runs alongside them. Global providers are lobbying for risk-based eligibility and against ownership-driven exclusion, localisation requirements and closed procurement.

Where the industry pushes back

Google Cloud supports Europe's sovereignty agenda but argues that CADA should recognise verifiable technical, operational and encryption controls rather than exclude trusted global providers by ownership.

We believe certain elements of the Cloud and AI Development Act should be changed to avoid unintended market isolation.
Giorgia Abeltino, Head of Government Affairs and Public Policy, Google Cloud EMEA, 18 June 2026

The endorsement is explicit on the objectives: Europe's aim to strengthen digital sovereignty, security and infrastructure capacity, harmonised EU sovereignty criteria with tiered compliance across Member States, open and interoperable cloud ecosystems that improve portability, faster permitting and grid access for sustainable data centres, and European partnerships that combine global technology with local operational and jurisdictional controls.

The demands are equally explicit:

  • CADA should not exclude trusted global providers solely because of corporate ownership.
  • Assurance levels should recognise verifiable technical, operational and encryption-based sovereignty controls.
  • Rigid geographic criteria could disrupt supply chains and constrain European customer choice.
  • Trusted non-EU partners should remain eligible where safeguards mitigate extraterritorial access risks.
  • Openness must extend across infrastructure, AI models and applications to prevent lock-in.
Google Cloud position on CADA: endorsements and demands on assurance levels and ownership-based eligibility
Google Cloud endorses the objectives and asks for verifiable controls instead of ownership-based exclusion. Source: Frenus analysis.

The other initial reactions follow the same line. AWS and CCIA warn that ownership-based assurance levels could fragment the EU cloud market. Microsoft and BSA support stronger resilience but oppose ownership restrictions and localisation mandates. The objection is narrow and shared: not the goal, but origin as the test.

What the market is saying

We reviewed 106 public commentaries on the proposal. The debate has moved past the sovereignty question itself. What is contested now is whether CADA can create competitive European capacity without weak assurance, insufficient demand or discriminatory access.

  • 51 percent read CADA as a mechanism for translating sovereignty ambitions into market demand and European capacity.
  • 42 percent support the objective but expect implementation choices to decide whether CADA delivers genuine sovereignty.
  • 7 percent warn that origin-based eligibility could restrict technology choice, investment and consistent EU-wide implementation.
Sentiment across 106 public commentaries on CADA, split into 51, 42 and 7 percent
Where the public debate stands: approval, conditional support and objection across 106 commentaries. Source: Frenus analysis.

Six themes carry the discussion, ranked by how often they came up:

  • Procurement becomes the sovereignty gatekeeper (80 mentions). Procurement is CADA's primary enforcement lever. Assurance levels and non-price criteria decide who may serve public bodies.
  • Ownership replaces simple data residency (70). EU data hosting alone is rejected as sovereignty. The focus turns to ownership, jurisdiction, encryption control and foreign dependence.
  • Assurance levels reshape cloud competition (54). A four-level framework segments the market by sensitivity and adds EU-control, third-country independence and supply-chain demands.
  • Open source becomes strategic infrastructure (41). Open source is treated as industrial policy, a lever to cut vendor lock-in and build interoperable, EU-rooted ecosystems.
  • Europe must build, not regulate (38). CADA is read as a shift from regulating foreign platforms to building EU capacity in cloud, data centres and AI compute.
  • AI access becomes geopolitical risk (32). Sovereignty expands beyond data to GPUs, foundation models and training frameworks, where reliance on non-EU suppliers is treated as a vulnerability.
Six themes in the CADA debate on LinkedIn with mention counts and representative quotes
The six themes carrying the CADA debate on LinkedIn, with mention counts and representative quotes. Source: Frenus analysis.
Achieving a Union assurance level becomes effectively mandatory for any cloud provider that wants to sell to the public sector.
Senior Director, Global Public Policy, global enterprise software provider
Most of the market will now default to one question: which level can this stack pass?
Chief Strategy Officer, technology strategy consultancy
How do you build sovereign infrastructure when GPU chips, foundation models and training frameworks are dominated by non-European firms?
Chief Product Officer and Board Member, European cloud provider

Portfolio economics: a two-speed cloud market

CADA and the Cloud Sovereignty Framework could turn sovereignty into a portfolio profit-and-loss decision.

  • The real impact is felt at service level. Hyperscalers may retain broad market access while losing eligibility for specific workloads where operational control, software dependencies or supply-chain exposure remain unresolved.
  • This forces harder portfolio segmentation. Providers will need to decide which services justify sovereign redesign, which can be delivered through controlled European environments, and which regulated opportunities are no longer commercially attractive.
  • The result could be a two-speed cloud market. Standard services continue to optimise for global scale, while sovereign variants carry higher delivery costs, slower release cycles and stricter limits on technology reuse.

For hyperscalers, the strategic response shifts from localisation to architectural separation. Local regions, European data residency and contractual safeguards may no longer provide sufficient differentiation once CADA and the CSF begin testing where authority actually sits. Deeper separation of administration, software updates, privileged access and service continuity is more disruptive than adding a sovereign label, because it challenges the operating model behind globally standardised cloud platforms.

Demand depends on 27 national judgements

  • Level 1 is the universal entry ticket and therefore creates no competitive advantage. Commercial upside exists only where a national risk assessment pushes a workload to level 2 or above.
  • Because that classification sits with Member States and Union entities under a Commission template, the addressable sovereign market is defined by 27 separate judgements rather than by the regulation itself.
  • Divergent national classification of comparable workloads could force providers to adapt and certify the same sovereign service in each Member State. Recognition portability, not certification count, decides EU-wide scale.
  • The first tenders that assign assurance levels to concrete workload categories will set the reference points later procurements reuse, and will determine where providers invest in separate European operations and supply-chain controls.

Sovereignty moves deeper into software and AI

The public debate is shifting from data residency towards control over software supply chains, operational continuity and dependence on non-European technology layers.

Open source strengthens auditability and substitutability, and CADA counts it as EU added value. It only becomes a credible public-sector option once maintenance and long-term operational responsibility are clearly assigned.

Sovereign environments still depend on non-European GPUs and development frameworks, and that gap will not close within this legislative cycle. Credibility will come from a disclosed dependency map with a dated reduction path, not from a claim of full independence.

What providers should do now

  • Plan for two segments. Standardised services will continue to serve most public-sector demand, while higher-assurance services will require a separate operating model and slower release cycles.
  • Engage while the criteria are open. The proposal is still in trilogue. Decisions on the assurance-level criteria, and on whether a recognition obtained in one Member State is accepted in another, will determine eligibility for several years.
  • Decide at service level. Establish which services justify investment in a sovereign variant, and which regulated opportunities are no longer commercially viable. Partnerships with hyperscalers will be assessed on the operational authority actually transferred to the European partner.
  • Prepare auditable evidence before bidding. Documented control over privileged access and over the integrity of software updates will determine eligibility in procurement, and should be ready before award rather than after it.
  • Watch the national layer. CADA establishes minimum requirements across the EU, but Member States retain discretion over architecture and over which workloads require higher assurance. Demand will also extend beyond public authorities.

In our workshops with ICT providers, the recurring question is no longer whether sovereignty matters. It is which of today's services already clear the emerging thresholds, and which need a different operating model or a different partner before procurement requirements harden.

The providers that win the first tenders will not be the ones with the loudest sovereignty claim. They will be the ones who can show, service by service, where the sovereign boundary sits and who holds authority inside it.

About Frenus

We are a market intelligence firm based in Stuttgart. We work with ICT providers and investors on the questions that decide market access: where a portfolio stands against emerging requirements, which submarkets are genuinely addressable, and what a competitor can actually prove. Every two weeks we track this debate with our community in the Cloud Insights and Sovereignty edition.

Talk it through

Marcel Blume leads our market advisory work with ICT providers. He is happy to walk through what the assurance-level logic means for a specific portfolio.

Marcel Blume, Director Market Advisory
Frenus GmbH, Zettachring 8, 70567 Stuttgart
[email protected]
+49 711 99529 610
Book a call

What We Have Learned