Brubru Deep Dive Library
Cloud and AI Development Act (CADA)
Try Brubru Free

Cloud and AI Development Act: Europe's Sovereign Compute Bet

The centrepiece of the Tech Sovereignty Package, read article by article. CADA pairs a capacity push (triple EU data-centre capacity by 2030) with a single, audited cloud sovereignty framework of four Union assurance levels, so Europe runs more of its own compute and can choose sovereign services for its most critical use cases. Adopted by the College on 3 June 2026.

COM(2026) 502 2026/0138(COD) adopted 3 June 2026 EVP Virkkunen, DG CNECT
x3
EU data-centre capacity by 2030
>70%
EU cloud held by 3 non-EU hyperscalers
4
Union assurance levels
8
grand challenges (Annex I)
Contents

1. Why CADA?

Too little compute, too dependent on a few providers

Two structural problems

EU computing capacity is limited and geographically concentrated, holding back competitiveness and the adoption of AI, especially low-latency workloads. At the same time, three non-EU hyperscalers control over 70% of the European cloud market, and EU providers' share fell from 29% in 2017 to 15% in 2022. Dependence on providers under third-country jurisdiction creates risks to control over data and operational continuity. National policies fragment deployment. The Draghi report called for regaining control over data and cloud, expanding domestic compute, and building a financial and talent flywheel.

Part of a bigger package

CADA is the centrepiece of the European Technological Sovereignty Package adopted on 3 June 2026, alongside Chips Act 2.0, the EU Open Source Strategy and the Strategic Roadmap for Digitalisation and AI in Energy. It operationalises the AI Continent Action Plan and the Apply AI Strategy, including AI factories and AI gigafactories.

2. Two legal bases, four objectives

A deliberately split instrument

CADA rests on a dual legal basis, which gives it two distinct general objectives:

  • Article 173(3) TFEU (industrial competitiveness, no harmonisation) carries the Cloud and AI Leadership Initiatives.
  • Article 114 TFEU (internal market, harmonisation) carries the cloud sovereignty framework and data-centre rules.
The four policy objectives

1 increase EU computing capacity through innovative and sustainable technologies.

2 ensure attractive conditions for that deployment.

3 reduce overall reliance on non-sovereign cloud and AI services.

4 protect public order by making cloud and AI supply resilient, in particular in the public sector.

3. Article-by-article map

48 articles across five titles, plus three annexes

TitleWhat it covers
I. General (Arts 1-2)Subject matter (5 measures); definitions (cloud service = NIS2; AI system = AI Act; software/SBOM = Cyber Resilience Act).
II. Cloud + AI Leadership Initiatives (Arts 3-9)8 operational objectives; Centres for AI (Art 5); implementation via grand challenges (Art 6); national strategies within 1 year (Art 7); frontier AI priority projects (Art 8); EuroHPC compute matching (Art 9).
III. Data-centre capacity (Arts 10-15)Acceleration zones (Art 10); conditions (Art 11); single information points (Art 12); 12-month permitting (Art 13); strategic projects (Art 14); capacity-gap monitoring (Art 15).
IV. Autonomy (Arts 16-44)Sovereignty framework + 4 assurance levels (16-28); demand-side procurement (29-33); EuroCloud Federation (34-36); Commission procurement (37-40); open source (41-44).
V. Final (Arts 45-48)Delegated + implementing acts; review at 4 years then every 5 (Art 47); entry into force + application (Art 48).
AnnexesI grand challenges; II criteria for the four assurance levels; III audit evidence (11 criteria).

4. Cloud and AI Leadership Initiatives

The industrial-support engine (Article 173(3) TFEU)

The Cloud Leadership Initiative and the AI Leadership Initiative pursue eight operational objectives: energy-efficient data-centre tech, autonomous cloud stacks, frontier AI, physical AI, industrial AI, AI-agent platforms, public-sector AI, and regional/local adoption. Key instruments:

  • Centres for AI (Art 5): each Member State sets up Experience and Acceleration Centres for AI, built on the former European Digital Innovation Hubs.
  • National cloud and AI strategies (Art 7): adopted within one year, following the "AI first" principle.
  • Frontier AI priority projects (Art 8): recognised by the Commission, run by an EDIC with at least three Member States pooling compute.
  • EuroHPC compute matching (Art 9): the Union at least matches the AI compute Member States contribute to frontier AI priority projects.

5. The 8 grand challenges (Annex I)

How the initiatives are delivered in practice

1. Sustainable data centres
Average PUE of 1.15 across the EU; server utilisation toward 50%; EU chips + quantum; security.
2. Cloud stacks
End-to-end EU hardware + software cloud stacks; AI servers on EU semiconductors and quantum.
3. Frontier AI
Next-generation multimodal frontier models and systems, advanced reasoning and agentic capabilities.
4. Physical AI
Autonomous robots, industrial systems and drones operating safely in unstructured environments.
5. Industrial AI
Sector-specific models (automotive, manufacturing, healthcare, energy, agri-food, defence).
6. Cooperative industrial models
Confidentiality-preserving collaboration (federated training, secure execution).
7. AI agents platform
A European AI-agent orchestration framework and middleware for agents at scale.
8. Public sector AI
Models on high-quality public data for health, public administration, law and crisis management.

6. Tripling data-centre capacity

Acceleration zones, faster permits, strategic projects (Title III)

CADA aims to triple EU data-centre capacity by 2030 (an intermediate target; the explanatory memorandum frames it as five to seven years) and to meet the EU's needs by 2035, with balanced geographic deployment. Each Member State must designate at least one data-centre acceleration zone within six months (Art 10), set up single information points (Art 12), and issue an aggregated baseline permit so that permitting in a zone takes no more than 12 months (Art 13). A separate target sets all data-centre permits at under 18 months by 2030. Brownfield sites are preferred, waste-heat reuse and power purchase agreements are encouraged, and sustainability KPIs follow Delegated Regulation (EU) 2024/1364.

Data-centre strategic projects (Art 14)

The Commission can designate a project as strategic if it meets at least two of five criteria: it supports essential public-sector functions; it is highly sustainable or innovative; it strengthens grid stability or co-locates clean energy; it integrates EU-designed or EU-made chips, processors or quantum computers; or it addresses a compute shortage. Strategic projects receive the competitiveness seal under the European Competitiveness Fund.

7. The four Union assurance levels (Annex II)

The core innovation: graded, auditable cloud sovereignty

LevelVerified byKey criteria (cumulative)
Level 1Provider self-assessment + public EU statement of conformityEU establishment; EU data and infrastructure residency (unless the customer asks otherwise); state-of-the-art cybersecurity; full subcontractor transparency. SME statements are auto-recognised across the EU.
Level 2Independent third-party audit+ EU-located personnel; EU cybersecurity certificate "substantial" (EUCS); customer data never used to train third-country AI; software bill of materials and source-code audits; EU-only technical support; legal separation of the EU parent from any third-country subsidiary.
Level 3Independent third-party audit+ EU-citizen personnel (with national security clearance for classified information); provider not under third-country control (save the associated-third-country derogation); EU-resident support only; may host EU classified information.
Level 4Independent third-party audit (highest)+ cybersecurity certificate "high"; risk-assessed sensitive data kept in the EU; no third-country effective control over the design, maintenance or evolution of software components.
Associated third countries (Art 18)

A provider under third-country control can still reach Level 3, but only if the Commission designates that third country as "associated": it must have a GDPR adequacy decision, no laws compelling data access, service disruption or sanctions, an open market, and reciprocal access to its public procurement.

8. Recognition and audit

One audit, valid EU-wide, to end "sovereign-washing"

A provider applies to the national competent authority of establishment (Art 17), which has 60 days to assess and then notifies the other Member States for a 60-day review; disputes go to the Commission for a binding decision. Level 1 rests on a self-assessment (Art 19); Levels 2 to 4 require an independent third-party audit at the provider's expense (Art 20), with strict auditor-independence rules (no non-audit services 12 months before or after, no audit work in the prior 10 years, no contingent fees) and annual re-review. Recognised services are listed in a public central repository (Art 22). Annex III lists 11 audit-evidence criteria: Union establishment, location of infrastructure and personnel, data localisation, Union citizenship, EU cybersecurity certification, no third-country AI training, absence of third-country control (a 5% ownership and ultimate-owner test), EU-only support including the SOC and NOC, software-supply-chain transparency, open source, and third-country subsidiary separation.

9. Procurement, EuroCloud and open source

Turning public demand into European supply

MechanismWhat it does
Risk assessments (Art 29)Member States and Union entities map public-order activities to required assurance levels, within one year then every two years.
Public procurement (Art 30)Non-public-order bodies use at least Level 1; public-order activities (NIS2 sectors, national security, defence, justice, law enforcement, border management) use Levels 2 to 4.
Private essential entities (Art 31)Entities in NIS2 Annex I sectors may run the same assessments.
Union added value (Art 32)Non-price award criteria for EU supply chain and EU-made hardware (suggested maximum 15 of 120 points).
Innovation procurement (Art 33)Member States aspire to award at least 25% of cloud and AI innovation procurement to innovative SMEs.
EuroCloud Federation (Arts 34-36)A public-sector-only federation to pool and share idle compute, free of charge or at cost, outside procurement rules.
Commission procurement (Arts 37-40)The Commission may act as a central purchasing body for Union entities and Member State authorities (framework contracts, dynamic purchasing systems).
Open source first (Arts 41-44)Open-source-first for public bodies; an EU Open Source Solutions Catalogue on the Interoperable Europe portal; an OSPO network.

10. Scope and the EU digital stack

CADA does not stand alone

The mandatory measures reach the public sector and private essential entities in the sectors of Annex I of NIS2 (Directive (EU) 2022/2555): energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space.

InstrumentRelationship to CADA
Data ActCloud switching and interoperability reduce lock-in, making it easier to move to EU services; CADA builds the sovereign road the Data Act opens.
DMAThree market investigations into cloud services and gatekeeper designation were opened on 18 November 2025.
EUCS / Cybersecurity Act revision (CSA2)Provide the cybersecurity certification CADA's assurance levels rely on; CADA fills the sovereignty gap.
Cyber Resilience ActDefines the software bill of materials (SBOM) CADA audits require.
AI Continent Action Plan / AI factoriesCADA supplies the broad cloud and data-centre capacity AI factories and gigafactories need.
EU Open Source StrategyA sibling instrument in the same package; CADA carries several of its open-source measures.

11. Timeline and next steps

Where CADA stands in the ordinary legislative procedure

September 2024
Draghi report calls for control over data and cloud and more domestic compute.
2025 to 2026
AI Continent Action Plan and Apply AI Strategy set the ambition (AI factories, gigafactories).
3 June 2026
College adopts CADA (COM(2026) 502, 2026/0138(COD)) within the Tech Sovereignty Package.
Next
European Parliament (lead committee ITRE expected) and Council positions, then trilogues.
Entry into force
20 days after publication; the Regulation applies one year later. Member State sovereignty risk assessments and acceleration zones follow.
Review
Commission evaluation 4 years after entry into force, then every 5 years.

12. Official sources

Ask Brubru

Brubru tracks CADA across Chat, the Legislative Tracker and your My Files workspace. Ask "What are the four Union assurance levels in CADA?" or "Who is in scope of the Cloud and AI Development Act?" and Brubru answers from the verified record, then links you straight to the file.