eu regulationcloud computingai developmentdata sovereigntydigital independencecompliance

EU Cloud & AI Act: Prepare Now for July 2026 Publication

Regulations.ai (AI-assisted)•

The European Union is on the cusp of a significant legislative milestone with the upcoming publication of the Cloud and AI Development Act in the Official Journal of the EU on July 15, 2026. While its full provisions will roll out gradually, this publication marks the official start of the countdown, making it imperative for businesses to begin their preparations now to navigate the complex landscape of cloud sovereignty and AI infrastructure.

What's changing

At its core, the Regulation (EU) 2026/XXXX, known as the Cloud and AI Development Act, is designed to bolster Europe's digital independence and fortify its AI infrastructure. It introduces a comprehensive set of new rules that will profoundly impact cloud service providers, AI developers, and public sector users across the European Union. The Act applies broadly to any company offering cloud services—including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)—as well as those developing and deploying artificial intelligence systems within the EU.

A cornerstone of this regulation is the pioneering four-tier cloud sovereignty framework. This framework classifies cloud providers based on stringent criteria such as the location of their infrastructure within the EU, their operational independence, and crucially, their EU ownership and control. Public sector bodies and critical infrastructure operators will be mandated to use this framework to assess risks and guide their cloud procurement decisions, ensuring that sensitive data remains under European control. This tiered approach means that while the law formally takes effect on August 4, 2026, the first tier of cloud sovereignty requirements will apply from February 2028, with the highest tier becoming mandatory by August 2029. The complexity of meeting the higher tiers, which demand not just EU data location but also demonstrable EU ownership, control, and full transparency over the software supply chain, presents a significant hurdle for many providers and a detailed assessment for users.

Beyond sovereignty, the Act also aims to triple the EU's data center capacity. It seeks to achieve this by streamlining permitting processes and improving access to essential resources for new data centers, signaling a clear intent to build robust physical infrastructure within the Union. Furthermore, the regulation reinforces existing obligations from the EU Data Act regarding data portability and interoperability for cloud providers, ensuring greater flexibility and control for users over their data. Non-compliance with these new sovereignty requirements, data center obligations, or transparency rules can lead to substantial administrative fines, potentially reaching a percentage of a company's global annual turnover, underscoring the serious implications of the Act.

Who is affected

The Cloud and AI Development Act casts a wide net, impacting a diverse range of entities operating within or offering services into the European Union. Primarily, it targets:

  • Cloud Service Providers: This includes all providers of IaaS, PaaS, and SaaS, irrespective of their global headquarters, if they offer services to customers within the EU. They will need to meticulously review their infrastructure, operational models, and ownership structures against the new four-tier sovereignty framework.
  • AI Developers and Deployers: Companies involved in the development and deployment of artificial intelligence systems within the EU will find their underlying cloud infrastructure choices heavily influenced by this Act, particularly concerning data residency and sovereignty requirements.
  • Public Sector Bodies: National, regional, and local government entities, as well as public administrations across the EU, are directly affected. They must integrate the cloud sovereignty framework into their procurement processes for cloud services, prioritizing providers that meet higher tiers for sensitive data.
  • Critical Infrastructure Operators: Entities managing essential services (e.g., energy, transport, health) that rely on cloud services are also in scope. Their procurement of cloud solutions will be subject to the same rigorous risk assessments and sovereignty considerations as public bodies.

Essentially, any organization that either provides cloud services or utilizes them to process data and develop AI within the EU will need to understand and adapt to this new regulatory environment. The Act's jurisdiction is the entire European Union, meaning its provisions will apply uniformly across all member states.

Three things to do this week

With the official publication date fast approaching, businesses should not delay in initiating their compliance journey. Here are three concrete actions to take immediately:

  1. Assess Your Cloud Strategy and Data Footprint: Begin by conducting a thorough audit of your current cloud service providers, identifying where your data is stored and processed, and understanding the operational control mechanisms in place. Map this against the upcoming four-tier cloud sovereignty framework. For public sector entities and critical infrastructure operators, this means evaluating existing contracts and future procurement plans to align with the framework's requirements for sensitive data.

  2. Engage Key Stakeholders and Legal Counsel: Convene your internal IT, legal, procurement, and compliance teams. Start an open dialogue about the implications of the Cloud and AI Development Act on your current contracts, future technology investments, and internal policies. Seek expert legal advice to understand specific obligations and potential risks, especially concerning the complex ownership and control criteria of the higher sovereignty tiers.

  3. Prepare for Enhanced Transparency and Interoperability: For cloud service providers, begin reviewing your capabilities to demonstrate EU ownership, operational independence, and transparency over your software supply chain. For all users of cloud services, assess your current data portability and interoperability agreements with providers. The Act reinforces these aspects, so understanding your ability to move data between services and providers will be crucial for future compliance and operational flexibility.

Related context

The Cloud and AI Development Act does not operate in a vacuum; it is a critical piece of the EU's broader digital strategy, complementing and reinforcing other significant regulations. Most notably, it works in tandem with Regulation (EU) 2024/1689, the EU AI Act. While the AI Act focuses on the safety, ethical development, and deployment of AI systems, the Cloud and AI Development Act addresses the underlying infrastructure and data governance that enable these systems. It ensures that the cloud environments where AI is built and run meet specific sovereignty and security standards, thereby creating a robust and trustworthy ecosystem for AI in Europe.

Further demonstrating the EU's comprehensive approach, the Proposal for a Digital Omnibus on Artificial Intelligence Amending Regulation (EU) 2024/1689 signals ongoing legislative efforts to refine and expand AI regulation. This indicates that the regulatory landscape is dynamic and businesses should anticipate continuous evolution. Additionally, national initiatives like the Uitvoeringswet AI-verordening in the Netherlands highlight how these overarching EU regulations are translated and implemented at the member state level, often with specific national nuances that businesses must also consider.

Note: this article was drafted by AI - Google Gemini