EU Cloud and AI Development Act | Updates, Compliance


What is the EU Cloud and AI Development Act?

The proposed EU Cloud and AI Development Act aims to strengthen Europe's leadership in cloud computing and artificial intelligence (AI), by establishing a robust regulatory framework for high-performance computing resources and digital infrastructure. It seeks to address the growing demands of AI applications while promoting innovation, interoperability, and a competitive internal market, ensuring Europe's technological sovereignty and long-term economic resilience.

The proposed Act complements existing EU regulations, such as the Artificial Intelligence Act (AI Act), which provides a legal framework for AI development and use within the EU.


3 June 2026, we have the proposal for a regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem (Cloud and AI Development Act).



3 June 2026, the proposal for a regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem (Cloud and AI Development Act).

Article 1, Subject matter.

1. This Regulation establishes a framework for strengthening the cloud and AI ecosystem at Union level, in particular through the following measures:

(a) establishing the Cloud Leadership Initiative and the AI Leadership Initiative (‘the Cloud and AI Leadership Initiatives’);

(b) setting the framework for the accelerated deployment of data centres across the Union;

(c) enabling the availability of a sovereign cloud and artificial intelligence (AI) offer to safeguard the Union’s public order;

(d) reducing dependencies on critical technologies;

(e) fostering the adoption of cloud computing services across the public sector.


2. The first general objective of this Regulation is to ensure the conditions necessary for the competitiveness and innovation capacity of the Union’s cloud and AI ecosystem.


3. The second general objective, separate from and complementary to the first general objective in paragraph 2, is to improve the functioning of the single market by laying down a uniform Union legal framework for increasing the Union’s resilience and strategic autonomy in cloud and AI technologies.


8 June 2026, the proposed Cloud and AI Development Act (CADA) | Opinion, legal intelligence.

The proposed CADA feels like a notable departure from the legislative approach that has characterized many recent European digital regulations. Previous initiatives were often centered on consumer protection, data governance, compliance obligations, market transparency, or the protection of fundamental rights. In the Cloud and AI Development Act, the centre of gravity is competitiveness, sovereignty, and strategic autonomy.

This shift is evident from the first recital of the proposal. The European Commission states that the Union should advance its innovation capabilities, strengthen its competitiveness and security of supply, and reinforce its technological sovereignty and strategic autonomy in cutting edge digital technologies. These are fundamental policy objectives that justify legislative action.

Article 1 establishes a framework for strengthening the Union's cloud and AI ecosystem through a series of measures. Sovereignty and strategic autonomy are part of the subject matter and objectives of the Regulation.

The Commission explicitly identifies a dependence on a limited number of third country cloud providers and highlights concerns arising from extraterritorial legal regimes, operational dependencies, and the potential vulnerability of critical digital infrastructure.

The CADA reflects an emerging policy doctrine that places cloud infrastructure, artificial intelligence, data centre capacity, and related technologies alongside other areas of strategic importance, such as semiconductors, energy security, and critical supply chains.

The Cloud and AI Development Act is likely to attract significant attention beyond the European Union, as the objectives pursued by the proposal extend beyond traditional digital regulation and touch directly upon issues of technological sovereignty, strategic autonomy, and the structure of global technology markets. While the proposal does not target any specific country, several of its underlying assumptions and policy objectives create the potential for friction between the European Union and the United States.

The objectives of the CADA will attract particular attention in the United States, because the global cloud and AI market is currently dominated by a small number of large American technology companies. Measures intended to reduce European dependencies affect providers headquartered in the United States. The policy objective of increasing European technological autonomy will be perceived as an effort to shift market share, investment, and strategic influence away from existing non European providers.

We do not expect that Europe will abandon sovereignty objectives because of U.S. pressure. Also, we do not expect that the United States will passively accept measures that materially disadvantage American technology providers. We expect, as the first step, a prolonged negotiation over definitions, eligibility criteria, governance requirements, and market access.

At the second step, Washington may strengthen its own policies. Policymakers could seek to strengthen the competitive position of U.S. technology providers through a range of industrial, investment, procurement, and innovation policies designed to preserve American leadership in strategically important sectors.

Such measures could include increased incentives for domestic cloud computing infrastructure, artificial intelligence development, semiconductor manufacturing, advanced data centre deployment, and related technologies. These initiatives could be justified on the grounds of national security, competitiveness, and technological leadership.

These measures could have significant competitive effects. Enhanced subsidies, tax incentives, research funding, public procurement preferences, or regulatory support mechanisms may strengthen the position of U.S. based firms relative to non U.S. providers. As a result, European companies competing in cloud computing, artificial intelligence, semiconductors, or digital infrastructure markets could face a more challenging competitive environment within the United States and globally.

Given the strategic direction of the Regulation, we recommend preparing for two plausible stress tests.

Stress Test 1: Progressive transatlantic regulatory divergence. This scenario assumes that European sovereignty and strategic autonomy objectives become increasingly embedded in procurement, certification, funding, and critical infrastructure frameworks. The United States responds through industrial policy measures, investment incentives, procurement preferences, and other actions designed to strengthen domestic cloud and AI providers. Market access formally remains open, but competitive conditions become progressively less neutral. Organizations operating globally face growing complexity as they navigate diverging regulatory, governance, and operational expectations across jurisdictions.

Key Board Question: How resilient is the organization's business model if Europe and the United States increasingly favour their respective technology ecosystems?


Stress Test 2: Strategic fragmentation. This severe but plausible scenario assumes that cloud computing, artificial intelligence, semiconductors, and digital infrastructure become central elements of geopolitical competition. Sovereignty requirements become more restrictive, strategic technologies are increasingly subject to industrial policy interventions, and access to certain sectors, procurement opportunities, funding mechanisms, or critical infrastructure projects becomes linked to jurisdiction specific criteria. Multinational organizations are required to operate increasingly distinct regional structures, governance models, technology stacks, and supply chains.

Key Board Question: Could the organization continue to operate effectively if cloud and AI markets evolve into fragmented regional ecosystems characterized by competing sovereignty, resilience, and strategic autonomy requirements?


23 April 2026, European Institutions agree Roadmap - The EU Cloud and AI Development Act is scheduled for Q4 2027



With a Joint Roadmap, the European Parliament, the Council of the European Union, and the European Commission commit to achieving One Europe, One Market, through decisive progress in 2026 and by the end of 2027 at the latest across the following five strategic building blocks:

(1) simplifying rules;

(2) a more integrated Single Market including by removing the ten most harmful barriers;

(3) championing strong trade;

(4) reducing energy prices and decarbonising; and

(5) driving the digital and AI transformation.

The Roadmap is a political and operational commitment: it sets out in its annex key legislative and policy initiatives across the five strategic building blocks and corresponding timelines for agreement.

https://commission.europa.eu/document/download/5445de81-9481-4335-9902-9756159ba614_en?filename=one-europe-one-market-roadmap.pdf

Our note: The timeline in the Commission roadmap is indicative and not a formal legal schedule. “Q4 2027” should be understood as a target window. It does not specifically refer to publication in the Official Journal or legal entry into force. Formal legal steps will follow afterward and may extend beyond this date. These timelines should be treated as strategic planning guidance.


May 14, 2026. Jurisdictional Conflict and Geopolitical Fragmentation

We are expecting the EU Cloud and AI Development Act, that reflects the European Union’s broader strategy of achieving digital sovereignty, strategic autonomy, and resilience in critical technological infrastructure.

From the U.S. perspective, restrictive European rules are disguised industrial protectionism directed against American firms. The practical economic effect will disproportionately impact U.S. providers such as Amazon, Microsoft, and Google.

Cloud governance is becoming a Board-level strategic challenge involving operational resilience, geopolitical exposure, sanctions vulnerability, regulatory continuity, and sovereign dependency assessments. The traditional procurement driven cloud analysis model is becoming obsolete.

Boards, legal, risk and compliance must consider geopolitical infrastructure dependency risk. These concepts (historically peripheral) are now becoming central supervisory concerns. This is especially acute in the financial sector.

Multinational organizations will face contradictory pressures from different jurisdictions. The United States favor open transnational cloud ecosystems and market driven technological integration. The European Union increasingly prioritizes sovereign operational control, resilience, and strategic autonomy. China already follows a far more territorially controlled digital governance model.

Multinational enterprises may find themselves operating within partially incompatible regulatory architectures.

We recommend a Board-level strategic review regarding emerging EU digital sovereignty, cloud governance, AI infrastructure, and geopolitical operational resilience developments that may materially affect operational architecture, outsourcing strategy, and regulatory exposure.





The possible SCENARIOS of a transatlantic clash over the EU Cloud and AI Development Act:

1. Managed coexistence. The European Union and the United States negotiate a pragmatic accommodation in which sovereign European requirements are recognized politically, while American providers adapt operationally. U.S. hyperscalers may increasingly create European sovereign cloud structures with localized governance models, EU only operational teams, enhanced cryptographic segregation, regionalized data processing, and contractual commitments designed to satisfy European sovereignty concerns. In practice, this would produce a partially compartmentalized but still interconnected transatlantic cloud ecosystem.

2. Gradual digital fragmentation. Europe incrementally develops a parallel sovereign digital ecosystem. Sensitive sectors such as government, defense, healthcare, energy, finance, telecommunications, and critical infrastructure become increasingly restricted to European-controlled or “trusted sovereignty-certified” infrastructures. Non sensitive commercial workloads may remain globally integrated, but strategically important sectors would migrate toward European-controlled operational environments.

3. Regulatory escalation and retaliatory measures. Technology regulation leads to broader transatlantic economic disputes involving semiconductors, AI exports, cybersecurity requirements, data transfers, digital taxation, competition law, and industrial subsidies. Organizations face conflicting obligations between EU sovereignty requirements and U.S. legal obligations. Compliance functions would become increasingly geopolitical.

4. Digital spheres of influence. The world gradually reorganizes into jurisdictionally distinct digital ecosystems. Global corporations increasingly need region specific cloud architectures, AI governance models, compliance systems, and data strategies. For risk professionals, this creates an entirely new category of geopolitical operational risk.





A hybrid stress test must integrate legal conflict analysis, operational resilience, cloud dependency mapping, AI governance disruption, sanctions escalation, regulatory fragmentation, and systemic concentration risk.

Step 1 (now): A complete infrastructure dependency mapping exercise. Organizations often do not fully understand the extent of their dependence on a small number of hyperscalers, subcontractors, SaaS ecosystems, AI APIs, identity providers, and integrated cloud services. They must identify primary cloud providers and hidden dependency chains involving managed service providers, compliance tooling, AI systems, analytics platforms, identity infrastructures, development pipelines, backup systems, and external operational interfaces.

The objective is to answer a fundamental governance question: Which critical business functions become impaired if geopolitical or regulatory conflict affects specific cloud ecosystems?

Step 2: Jurisdictional conflict simulation. This is one of the most important and least developed areas of modern operational resilience testing. Organizations should model a scenario in which European regulatory expectations and U.S. legal obligations become partially incompatible. Many multinational enterprises currently lack governance frameworks for resolving geopolitical legal conflicts involving digital infrastructure.

Step 3: Regulatory fragmentation stress scenarios. Organizations should model divergence, including EU AI governance obligations, U.S. deregulation initiatives, Chinese localization requirements, sector-specific resilience obligations, and sovereignty oriented procurement rules.

The goal is to assess whether the enterprise can maintain a coherent global operating model under fragmented regulatory architectures.

This is especially important for financial institutions, critical infrastructure operators, healthcare entities, defense contractors, telecommunications firms, and multinational technology companies.






October 20, 2025, Commission work programme 2026, planned timing of the Commission’s proposal for a Cloud and AI Development Act: Q1 2026





In the Commission work programme (CWP), every initiative has:

1. A type (“legislative”, “non-legislative”, “evaluation”),

2. A legal basis (here, Article 114 TFEU), and

3. An indicative timing (like Q1 2026).

When an item is marked “legislative”, it means the Commission intends to present a legislative proposal to the European Parliament and the Council during that quarter, in this case, between January and March 2026.


09 April 2025 - 04 June 2025, European Commission, CALL FOR EVIDENCE FOR AN IMPACT ASSESSMENT, EU Cloud and AI Development Act

This document aims to inform the public and stakeholders on the Commission's future legislative work so they can provide feedback on the Commission's understanding of the problem and possible solutions and give any relevant information that they may have, including on possible impacts of the different options.

Current estimates and projections of European computing infrastructure point to a gap between available capacity and needs, in particular to accommodate the demands stemming from AI. The 2024 Draghi report recognizes the importance of increasing computational capacity in the EU as a critical component of a mature data economy which underpins many established and emerging digital use cases, particularly for AI development. Against this backdrop, the Cloud and AI Development Act is one of the headline digital policies outlined in the 2025 Competitiveness Compass and listed in the Mission letter to Executive Vice-President Henna Virkkunen alongside a single EU-wide cloud policy for public administrations and public procurement. This initiative is part of the actions foreseen in the AI Continent Action Plan.

Training, fine-tuning, and running AI models demand massive computational resources. While training requires large centralised computational capacity, the more decentralised cloud and edge computing are key enablers of smaller fine-tuning operations and of inference. Data centres play a key role in housing and running the necessary devices and equipment. The EU currently lags behind the US and China in terms of available data centre capacity. The initiative aims to tackle the currently unfavourable conditions for the private sector to close this capacity gap in a way that prioritises highly sustainable solutions.

To this end, the initiative seeks to address the problems that currently inhibit the expansion of the EU’s data centre capacity. These include difficulties in accessing natural resources (energy, water, land), as well as complicated and slow permitting processes, with approaches differing between Member States. The construction process is highly capital-intensive, creating barriers of entry for new players, and can be negatively affected by difficulties in obtaining technology components and capital. The energy and water consumption of data centres is rising and expanding capacity can further strain such resources, particularly in view of the current strong geographical concentration of data centres in the North-West of the EU. Technological innovation in data centre equipment and operations promises significant resource savings but remains underexploited. At the same time, high energy prices negatively affect the competitiveness of the sector in the EU.

Another problem that the initiative seeks to tackle is the lack of a competitive EU-based offer of cloud computing services at sufficient scale to serve highly critical use cases with particularly high security needs, as found in various economic sectors and the public sector.

09 April 2025 - 04 June 2025, European Commission, CALL FOR EVIDENCE FOR AN IMPACT ASSESSMENT, EU Cloud and AI Development Act


The EU Cloud and AI Development Act in the Draghi report on EU competitiveness

On September 17, 2024, Mario Draghi, former President of the European Central Bank and Prime Minister of Italy, presented his report on the future of European competitiveness to the European Parliament in Strasbourg. The event was a significant moment, marking a comprehensive assessment of Europe's economic standing and offering strategic recommendations to enhance its global position.

The event was attended by Members of the European Parliament (MEPs), European Commission President Ursula von der Leyen, and other high-ranking EU officials. European Parliament President Roberta Metsola extended the invitation to Draghi and facilitated the session.

Draghi was commissioned by the European Commission to provide an independent analysis of Europe's competitiveness. His report aimed to diagnose current challenges and propose actionable strategies to ensure sustainable economic growth and resilience in the face of global shifts.

Draghi highlighted that Europe faces a rapidly changing global landscape, with slowing world trade, geopolitical fragmentation, and accelerated technological change. He emphasized that Europe's openness and dependencies make it particularly vulnerable to these shifts.

To address these challenges, Draghi proposed focusing on three main areas:
- closing the innovation gap with the United States and China,
- implementing a cohesive plan for decarbonization and competitiveness, and
- enhancing security while reducing dependencies.

He stressed the need for coordinated industrial policies, significant investments, and streamlined decision-making processes.

Draghi emphasized the necessity for the European Union to enhance its technological infrastructure and reduce dependencies on non-EU cloud service providers. He proposed the establishment of an EU Cloud and AI Development Act to create a unified framework aimed at bolstering Europe's capabilities in high-performance computing, artificial intelligence, and quantum technologies. This initiative seeks to harmonize cloud architecture requirements and procurement processes across member states, fostering a more competitive environment for European businesses.




Henna Virkkunen’s confirmation hearing, and the EU Cloud and AI Development Act.

A confirmation hearing is a formal procedure in which a nominated candidate for a high-level public position is questioned by a legislative body before being approved for the role. These hearings are commonly used to ensure that nominees are qualified, competent, and aligned with the policies and goals of the organization they will serve.

In the European Union, nominees for the Commission, including Executive Vice-Presidents and Commissioners, must be vetted by the European Parliament to assess their ability to perform their roles. Each nominee presents their vision and policy priorities during a public hearing. Members of the European Parliament (MEPs) ask questions about their policy focus, potential conflicts of interest, and strategy for implementing EU goals. A vote of confidence follows, determining whether the nominee can take office.

Henna Virkkunen’s confirmation hearing was an opportunity for MEPs to evaluate her qualifications, policies on AI, quantum technology, and cybersecurity, and her overall fitness for the role.

As of February 21, 2025, Henna Virkkunen serves as the Executive Vice-President for Tech Sovereignty, Security, and Democracy in the European Commission. She assumed this role on December 1, 2024, under the leadership of President Ursula von der Leyen.

In this capacity, Virkkunen is responsible for enhancing the European Union's technological independence, securing critical digital infrastructure, and promoting democratic values in the digital realm. Her portfolio includes overseeing digital and frontier technologies, implementing strategies to achieve Europe's 2030 Digital Decade targets, and developing initiatives such as the EU Cloud and AI Development Act.

According to Virkkunen, key technologies that will shape our future are AI, quantum, cloud, semiconductors and space technologies. She said: "To improve cloud services and to upscale our high‑performance computing capacity in an energy‑efficient way, I will propose the EU Cloud and AI Development Act. The Act will allow even the smallest businesses to access advanced AI services."






George Lekatis

This website is developed and maintained by Cyber Risk GmbH as part of its professional activities in the fields of risk management and regulatory compliance.

Cyber Risk GmbH specializes in supporting organizations in understanding, navigating, and implementing complex European, U.S., and international risk related regulatory frameworks.

Content is produced and maintained under the professional responsibility of George Lekatis, General Manager of Cyber Risk GmbH, a well known expert in risk management and compliance. He also serves as General Manager of Compliance LLC, a company incorporated in Wilmington, NC, with offices in Washington, DC, providing risk and compliance training in 58 countries.

Cyber Risk GmbH, some of our clients