Here’s a number that explains a lot about where European tech policy is headed right now: in 2017, European cloud providers held about 29% of their own home market. By 2022, that figure had fallen to roughly 15%, and it has barely moved since. Three American companies, Amazon, Microsoft, and Google, now account for around 70% of cloud computing across the continent. That erosion, playing out over just five years, is the backdrop for the European Commission’s newest and most ambitious attempt to change course: the proposed Cloud and AI Development Act, or CADA.
Published on June 3, 2026, as the centerpiece of the Commission’s wider Tech Sovereignty Package, CADA is the EU’s attempt to make its cloud and AI ecosystem, in the Commission’s own words, more competitive and resilient. Natallia Karniyevich, a cybersecurity partner at McDermott Will & Schulte, and Müge Fazlioglu, principal researcher for privacy law and policy at the IAPP, recently walked through what the proposal actually contains and why it deserves attention well beyond the usual circle of EU regulatory watchers. Their analysis is worth unpacking, because CADA isn’t really a data protection law or a cybersecurity law in the traditional sense. It’s an attempt to use the EU’s own purchasing power to reshape who gets to build the infrastructure Europe’s economy increasingly runs on.
What CADA is actually trying to fix
The Commission’s diagnosis of the problem has two parts. First, Europe doesn’t have enough of its own data center capacity to keep pace with demand, especially as AI workloads scale up. Second, and more politically charged, the continent has become dependent on a small handful of non-EU cloud providers for infrastructure that increasingly underpins everything from hospital records to defense systems. CADA tries to address both problems at once. On the supply side, it includes measures meant to expand European compute capacity. On the demand side, and this is the part getting most of the attention, it uses public procurement rules to steer government spending toward providers that meet certain sovereignty criteria. That second piece is where things get interesting for any business that sells cloud or AI services into the European public sector, or that supplies components to companies that do.The four assurance levels, explained plainly
At the heart of CADA sits a graduated system called the Union Assurance Levels, four tiers that link a cloud provider’s security, resilience, and sovereignty posture to how much of the EU public sector market it can actually serve. Here’s roughly how they break down:- Level 1 is the baseline. With only narrow exceptions, every cloud provider that wants to sell to the EU public sector will need to meet this floor, regardless of what it’s selling or to whom.
- Level 2 and Level 3 apply where a Member State or EU body determines, through a formal risk assessment, that a particular use case has what the proposal calls “public order relevance.” Level 3 goes further than most people expect. It sets EU citizenship as a baseline requirement for the staff who operate the service, not just a preference, and adds security clearance requirements where classified information is involved.
- Level 4 is reserved for the most sensitive categories, think defense and national security processing, and it’s a different kind of test entirely. At this tier, having servers physically located in the EU is no longer enough. The provider itself, along with its software supply chain, cannot be subject to the effective control of a non-EU country. That’s a much harder bar to clear than a data residency requirement, and it’s the one detail in CADA that has drawn the most pushback from global providers with EU subsidiaries.