EU Cloud and AI Development Act

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL establishing a framework of measures for strengthening Europe's cloud and AI ecosystem (Cloud and AI Development Act)

European Union

RAI-EU-NA-RE2026X-2026

Regulation 2026/XXXX

Proposed(Officially filed for action)Checked 8 Sep 2026

EU Cloud and AI Development Act is Proposed in European Union as of 8 Sep 2026.

RegulationGovernance and OversightRisk Management
Export PDF

The EU Cloud and AI Development Act strengthens Europe's digital sovereignty by establishing a cloud sovereignty framework and boosting AI infrastructure.

Summary

The EU Cloud and AI Development Act (CADA), adopted in June 2026, aims to bolster Europe's digital sovereignty and competitiveness in cloud and AI. It establishes a four-tier cloud sovereignty framework for secure infrastructure and fosters AI development, targeting a tripling of EU data center capacity. CADA complements existing EU digital legislation, ensuring secure and ethical AI deployment.

Full article

Read full text ↗

Overview

The Cloud and AI Development Act (CADA) represents a landmark legislative initiative by the European Union, designed to strengthen Europe's technological sovereignty and competitiveness in the rapidly evolving cloud and artificial intelligence (AI) ecosystem. Adopted in June 2026, this Regulation is a cornerstone of the European Commission's broader 'AI Continent Action Plan,' aiming to reinforce the EU's leadership in digital infrastructure, investment, and innovation. The primary objective of CADA is to ensure that European businesses and public authorities have access to secure, sustainable, and interoperable cloud infrastructures and services, while simultaneously fostering the development and deployment of trustworthy AI systems across the Union. It addresses the escalating demand for computing power and data center capacity driven by the proliferation of AI technologies, seeking to triple the EU's data center capacity within the next five to seven years and meet the needs of EU businesses and public administrations by 2035. The Act moves beyond traditional rule-making to an active industrial strategy for the digital infrastructure layer, introducing a comprehensive framework to reduce strategic dependencies on non-EU cloud providers and to steer investment towards EU-aligned infrastructure.

CADA introduces a pioneering four-tier cloud sovereignty framework, which classifies cloud providers based on progressively stricter requirements related to infrastructure location, ownership, operational control, and personnel. This framework is intended to guide public-sector bodies in assessing security and dependency risks when procuring cloud services, ensuring that sensitive workloads remain under a high degree of European control. Beyond cloud governance, the Act signals a broader industrial policy shift, granting the Commission powers to designate strategic cloud and AI projects eligible for priority funding, regulatory support, and streamlined administrative processes. It also seeks to simplify and accelerate the permitting and deployment of data centers, improve access to key resources such as energy, land, water, and financing, and promote open-source solutions to reinforce resilience. The Regulation is designed to complement existing EU legislation, including the EU AI Act, the Data Act, the Digital Services Act, and the Cybersecurity Act, by providing a robust framework that supports the secure and ethical development of AI and cloud technologies.

Definitions

The Cloud and AI Development Act establishes a comprehensive set of definitions crucial for its consistent application across the European Union. Key among these is the definition of an 'AI system,' which aligns with the broader understanding set out in the EU AI Act, referring to a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This ensures a cohesive regulatory landscape for AI technologies. A 'cloud service' is defined broadly, encompassing digital services that provide on-demand remote access to scalable and shareable computing resources, including infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS). This definition is critical for applying the Act's cloud sovereignty framework to a wide array of offerings.

Furthermore, CADA introduces specific definitions related to its tiered sovereignty framework. 'EU Location' refers to data being processed and stored in infrastructure physically located within the European Union, serving as a foundational requirement. 'Independence Measures' pertain to demonstrated independence from third-country influence and transparency regarding the software supply chain. 'EU Ownership and Control' signifies that a provider must be owned and controlled from within the EU, with additional criteria potentially including EU personnel and governance. The highest tier, 'Strategic Autonomy Cloud,' demands full transparency and control over the software supply chain, with no interference from any third country, designed for the most sensitive workloads. The Act also defines 'providers' and 'deployers' of cloud and AI systems, delineating their respective obligations and responsibilities within the regulatory framework. These precise definitions are essential for ensuring legal certainty and facilitating compliance for all stakeholders involved in the development, provision, and use of cloud and AI technologies within the EU.

Governance and Institutional Framework

The governance structure established by the Cloud and AI Development Act is designed to ensure effective oversight, consistent implementation, and continuous adaptation to technological advancements across the European Union. Central to this framework is the proposed European Cloud and AI Agency, which will serve as the primary regulatory body responsible for coordinating national competent authorities, developing technical standards, and monitoring the overall application of the Act. This agency will play a pivotal role in promoting a harmonised approach to cloud and AI development, fostering interoperability, and ensuring compliance with the sovereignty framework. The Act also mandates the establishment or designation of national competent authorities within each Member State, tasked with overseeing compliance, conducting audits, and enforcing the provisions of CADA at a national level. These national bodies will collaborate closely with the European Cloud and AI Agency to ensure a unified and effective regulatory environment.

The Act also envisages the creation of an advisory forum, bringing together experts from industry, academia, civil society, and Member State representatives. This forum will provide strategic guidance, technical expertise, and recommendations to the European Cloud and AI Agency and the European Commission, ensuring that the regulatory framework remains responsive to market needs and technological evolution. Furthermore, CADA outlines mechanisms for regular reporting by Member States on the implementation and impact of the Act, allowing for continuous evaluation and potential adjustments. The European Commission will retain an overarching role in proposing delegated and implementing acts to further specify technical details and ensure the smooth functioning of the regulatory framework. This multi-layered governance approach, involving both EU-level and national bodies, aims to create a robust and adaptable system for governing cloud and AI development, balancing innovation with security and sovereignty concerns.

Key Focus Areas

The Cloud and AI Development Act focuses on several critical areas to achieve its overarching goals of digital sovereignty, innovation, and secure infrastructure. A primary focus is the establishment of a robust cloud sovereignty framework, categorising cloud services into four tiers based on the level of control and independence from non-EU influence. This framework is particularly relevant for public sector bodies and critical infrastructure operators, guiding their procurement decisions to ensure that sensitive data and workloads are hosted on services that meet stringent European control and security requirements. The Act aims to reduce the EU's strategic dependencies on third-country cloud providers by incentivising the development and adoption of European cloud solutions, thereby bolstering the continent's digital autonomy.

Another key focus area is the acceleration of data center capacity and infrastructure development within the EU. CADA sets ambitious targets, aiming to at least triple the EU's data center capacity within the next five to seven years. To achieve this, the Act includes provisions for simplifying and accelerating permitting processes for data center deployment, improving access to essential resources like energy, land, and financing, and fostering an environment conducive to investment in sustainable digital infrastructure. Furthermore, the Act places significant emphasis on fostering innovation in AI and cloud technologies. It aims to support businesses, cloud providers, investors, and researchers through initiatives like 'Experience and Acceleration Centres for AI' and by promoting open-source solutions. This focus on innovation is intended to strengthen the EU's technological base, encourage the development of cutting-edge AI applications, and ensure that Europe remains at the forefront of digital transformation while upholding ethical and security standards.

Implementation Framework

The implementation framework of the Cloud and AI Development Act is designed for phased application, allowing stakeholders sufficient time to adapt to the new requirements while ensuring the swift establishment of critical protections. Following its adoption, the Act will specify staggered entry-into-force dates for various provisions, mirroring the approach taken by other complex EU regulations like the AI Act. This phased approach will likely begin with general provisions and the establishment of governance structures, such as the European Cloud and AI Agency and national competent authorities. Subsequent phases will focus on the full applicability of the cloud sovereignty framework, including requirements for risk assessments by public sector bodies and the recognition of cloud service providers under the tiered system. The European Commission will play a crucial role in developing delegated and implementing acts, which will provide further technical specifications and guidelines necessary for the practical application of the Act's provisions. These acts will ensure harmonisation and clarity across Member States.

Member States will be responsible for designating or establishing national competent authorities, setting up audit and recognition procedures for cloud service providers, and integrating the Act's requirements into national procurement policies. The Act also anticipates the development of European standards by European Standardisation Organisations (ESOs) to support the technical implementation of its requirements, particularly concerning interoperability, security, and the four-tier sovereignty framework. These standards will provide practical guidance for industry players to ensure compliance. Furthermore, the implementation framework includes provisions for market surveillance and enforcement mechanisms, allowing competent authorities to monitor adherence to the Act's obligations and impose penalties for non-compliance. The overall objective is to create a dynamic and adaptable framework that supports the growth of a secure and sovereign European cloud and AI ecosystem while maintaining a level playing field for all market participants.

Monitoring and Evaluation

The Cloud and AI Development Act incorporates robust mechanisms for continuous monitoring and periodic evaluation to ensure its effectiveness, relevance, and adaptability to technological advancements and market dynamics. The European Cloud and AI Agency, in collaboration with national competent authorities, will be responsible for ongoing market surveillance, tracking the adoption of cloud and AI technologies, and assessing the impact of the Act's provisions on digital sovereignty and innovation within the EU. This will involve collecting data on cloud service usage, compliance rates with the sovereignty framework, investment trends in European digital infrastructure, and the overall competitiveness of the EU cloud and AI ecosystem. Regular reports will be compiled and submitted to the European Commission and the European Parliament, providing transparency on the Act's implementation and identifying areas for potential improvement.

A key aspect of monitoring will be the assessment of the four-tier cloud sovereignty framework's practical application and its impact on public procurement and critical sector operations. The evaluation process will examine whether the framework effectively reduces strategic dependencies on non-EU providers and whether it adequately safeguards sensitive data and workloads. Furthermore, the Act mandates periodic reviews of its provisions, typically every five years, to account for rapid technological evolution in cloud computing and AI. These reviews will involve extensive stakeholder consultations, impact assessments, and public feedback, ensuring that the regulatory framework remains fit for purpose and does not stifle innovation. The evaluation will also consider the Act's coherence with other relevant EU legislation, such as the AI Act and the Data Act, to maintain a consistent and complementary regulatory landscape for the digital single market.

Penalties, Liability, and Appeals

The Cloud and AI Development Act establishes a robust regime for penalties and liability, designed to ensure strong enforcement and deter non-compliance with its provisions. Similar to other significant EU regulations, the Act will empower national competent authorities to impose substantial administrative fines for infringements, with the severity of penalties scaled according to the nature, gravity, and duration of the violation, as well as the size and economic capacity of the infringing entity. These fines are expected to be significant, potentially reaching a percentage of a company's global annual turnover, to ensure a strong deterrent effect. Specific penalties will be outlined for breaches of the cloud sovereignty requirements, failure to comply with data center capacity obligations, and non-adherence to transparency or risk management provisions. The Act will also detail the procedures for investigations, corrective measures, and the imposition of sanctions by the designated authorities.

Regarding liability, CADA will clarify the responsibilities of cloud service providers and AI system developers and deployers, particularly in cases of harm caused by non-compliant systems or services. While the Act is primarily a product regulation and places duties on providers and deployers, it will likely interact with existing national liability laws and potentially introduce specific provisions for damages arising from breaches of its requirements, especially concerning data integrity, security, and service availability within the sovereign cloud framework. The Act will also establish clear mechanisms for appeals, allowing affected parties to challenge decisions made by competent authorities regarding compliance, penalties, or the classification of their services under the sovereignty tiers. This includes the right to judicial review in national courts, ensuring due process and legal certainty for all stakeholders. The aim is to create an accountable and transparent enforcement system that upholds the objectives of the Act while protecting the rights of regulated entities.

Relationship to Other Instruments

The Cloud and AI Development Act is designed to operate within the existing intricate web of European Union digital legislation, complementing and building upon several key instruments. It is explicitly intended to work in synergy with the EU AI Act (Regulation (EU) 2024/1689), which establishes a comprehensive legal framework for artificial intelligence, focusing on a risk-based approach to AI systems. While the AI Act addresses the safety, ethical, and fundamental rights aspects of AI, CADA provides the foundational infrastructure and sovereignty framework necessary for the secure and trustworthy deployment of these AI systems within the EU. The CADA's provisions on data center capacity and sovereign cloud services directly support the reliable operation of AI models, particularly general-purpose AI models that may carry systemic risks, as regulated by the AI Act.

Furthermore, CADA has a strong relationship with the EU Data Act (Regulation (EU) 2023/2854), which aims to facilitate and promote the exchange and use of data within the European Economic Area. The Data Act's provisions on data portability, interoperability, and safeguards against unlawful international governmental access to non-personal data are directly reinforced by CADA's cloud sovereignty framework. CADA's emphasis on EU-located infrastructure and control strengthens the practical implementation of data governance principles laid out in the Data Act. The Act also interacts with the General Data Protection Regulation (GDPR), ensuring that the processing of personal data within cloud environments adheres to the highest standards of privacy and data protection, especially concerning international data transfers and extraterritorial access. Additionally, CADA complements the Cybersecurity Act and the NIS2 Directive by enhancing the cybersecurity posture of critical digital infrastructure and services, ensuring that the underlying cloud and AI components meet robust security requirements. This integrated approach ensures a cohesive and comprehensive regulatory landscape for the EU's digital single market.

International Alignment

The Cloud and AI Development Act, while primarily focused on strengthening European digital sovereignty, also acknowledges the global nature of cloud and AI technologies and seeks to foster international alignment where appropriate. The EU aims to position CADA as a benchmark for sovereign digital infrastructure, similar to how the GDPR and the AI Act have influenced global regulatory discussions. The Act's principles, particularly those related to data security, ethical AI development, and robust governance, are designed to be compatible with international best practices and standards, facilitating cross-border cooperation and mutual recognition agreements with trusted partners. The European Commission will engage in dialogues with third countries and international organisations to promote shared values and regulatory convergence in the digital domain.

However, a central tenet of CADA is the reduction of strategic dependencies on non-EU providers, which inherently introduces a degree of differentiation from global market dynamics. The four-tier cloud sovereignty framework, with its emphasis on EU ownership, control, and legal insulation from foreign governmental authority, is a direct response to geopolitical considerations and the need to protect sensitive European data and critical infrastructure from extraterritorial laws like the US CLOUD Act. While the Act aims to create a strong domestic market, it also includes provisions for recognising certain third-country providers under specific conditions, particularly for less sensitive workloads, demonstrating a pragmatic approach to global engagement. The overarching goal is to strike a balance between promoting European autonomy and participating actively in the global digital economy, ensuring that the EU's digital policies contribute to a more secure, resilient, and open international digital order.

Implementation Timeline

MilestoneDateNotes
Publication in Official Journal of the EU2026-07-15Formal publication of the Regulation.
Entry into Force2026-08-0420 days after publication.
Establishment of European Cloud and AI Agency2027-02-04Key governance body becomes operational.
National Competent Authorities Designated2027-08-04Member States to designate or establish national oversight bodies.
Provisions on Data Center Capacity & Permitting Apply2027-08-04Measures to accelerate infrastructure development become effective.
Tier 1 Cloud Sovereignty Framework Applicable2028-02-04Requirements for EU data location become mandatory for public sector.
Tier 2 & 3 Cloud Sovereignty Framework Applicable2028-08-04Independence and EU ownership/control requirements for public sector.
Full Applicability of High-Risk AI System Provisions (in conjunction with CADA)2029-02-04Comprehensive compliance for AI systems leveraging CADA-compliant cloud.
Tier 4 Cloud Sovereignty Framework Applicable2029-08-04Highest level of strategic autonomy for critical workloads.
First Review and Evaluation Report Due2031-08-04Initial assessment of the Act's effectiveness and impact.

Sources and References

SourceType
Regulation (EU) 2026/XXXX of the European Parliament and of the Council on harmonised rules for Cloud and Artificial Intelligence Development (Cloud and AI Development Act)official
European Commission: Cloud and AI Development Act (CADA)government
European Commission: Artificial Intelligence Actgovernment
Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)legal

Requirements for a company

What an organisation has to do under EU Cloud and AI Development Act, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.

Must do

7
  • +1 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under EU Cloud and AI Development Act, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Aug 4, 2027Important
2Important
3Important
4Feb 4, 2028Important
5Feb 4, 2028Important
6Important
7Important

© Regulations.AI — created on 12 Jun 2026 using Gemini 2.5 Flash · updated on 13 Jun 2026 · reviewed against official sources on 8 Sep 2026 using Gemini 3.6 Flash