CADA, the Cloud and AI Development Act, is a proposed EU regulation currently moving through the European Parliament. It aims to reduce Europe’s structural dependence on non-European cloud infrastructure, establish a legal definition of sovereign cloud, and expand EU data centre capacity ahead of 2030. A rapporteur was appointed in mid-2026 to lead Parliament’s negotiations with the Council and the Commission.

CADA is not yet law. It is a legislative proposal under negotiation. However, it addresses a set of infrastructure questions that are already live compliance issues for organisations subject to the EU AI Act, GDPR, and DORA. The sovereignty definition CADA establishes will determine whether existing cloud arrangements satisfy regulatory requirements under those instruments, making it material to compliance planning now, not only after adoption.

This guide explains what CADA proposes, why it matters, how it interacts with the CLOUD Act, the EU AI Act, and other EU digital regulation, and what organisations should be tracking.

Key Definitions

TermDefinition
CADACloud and AI Development Act. Proposed EU regulation aimed at digital sovereignty, sovereign cloud definition, and EU AI infrastructure expansion
Sovereign cloudCloud infrastructure operating under EU jurisdiction with no exposure to extraterritorial foreign legal authority. Definition subject to CADA negotiations
CLOUD ActClarifying Lawful Overseas Use of Data Act. 2018 US federal law enabling US authorities to compel American technology companies to produce data stored anywhere in the world
Data localisationThe requirement that data be stored and processed within a specific geographic territory
Jurisdictional controlLegal authority over infrastructure and data, determined by the nationality and ownership of the infrastructure operator rather than physical location of servers
HyperscalerA large-scale cloud service provider operating global infrastructure, typically referring to AWS, Microsoft Azure, and Google Cloud
EU AI ActRegulation (EU) 2024/1689 on artificial intelligence. The world’s first comprehensive AI regulation
GPAI modelGeneral-purpose AI model. A foundation model capable of a wide range of tasks. Subject to obligations under Chapter V of the EU AI Act
Data ActRegulation (EU) 2023/2854. Governs access to and sharing of data generated by connected products and services
DORADigital Operational Resilience Act. Regulation (EU) 2022/2554. Governs ICT risk management for EU financial entities

What Is CADA

CADA, the Cloud and AI Development Act, is a proposed EU regulation published as part of the European Technological Sovereignty Package released by the European Commission on 3 June 2026. The package addresses Europe’s strategic dependence on non-European technology providers across the AI supply chain, cloud infrastructure layer, and digital services market.

CADA has three primary objectives. First, it aims to reduce Europe’s structural dependence on non-European cloud providers, particularly US hyperscalers, by establishing legal and technical standards for what qualifies as sovereign cloud infrastructure. Second, it targets a significant expansion of EU data centre capacity ahead of 2030, addressing the infrastructure gap that constrains European AI development. Third, it establishes an open-source AI strategy positioning European-developed models as a strategic alternative to US and Chinese foundation models.

The regulation is currently in Parliament following rapporteur appointment in mid-2026. Formal negotiations between Parliament, the Council, and the Commission are expected to run through 2026 and 2027, with adoption potentially by end of 2027.

CADA sits within a cluster of related EU initiatives. It operates alongside the EU AI Act, which governs AI system obligations. It interacts with GDPR and the Data Act on data governance questions. It addresses the infrastructure layer that DORA’s ICT risk management requirements depend on. And it responds directly to the CLOUD Act problem that the EU-US Data Privacy Framework has failed to fully resolve.

The Problem CADA Is Designed to Solve

Europe’s Cloud Dependency

The European cloud market is dominated by three US hyperscalers: Amazon Web Services, Microsoft Azure, and Google Cloud. Most EU organisations running AI workloads, processing personal data, or operating critical digital services do so on infrastructure that is ultimately owned and controlled by US-incorporated entities.

This creates three interlocking problems.

The first is jurisdictional. US-incorporated entities are subject to US law regardless of where their infrastructure is physically located. The CLOUD Act, discussed in detail below, means US federal authorities can compel AWS, Microsoft, or Google to produce data stored on European servers without the data subject, the data controller, or the European supervisory authority being notified or having an effective right to object.

The second is strategic. Europe’s AI development capacity depends on access to compute infrastructure. If that infrastructure is controlled by non-European entities, European AI providers are structurally dependent on the continued commercial goodwill of foreign companies whose obligations run to their own shareholders and their own government, not to European regulatory objectives.

The third is regulatory. The EU AI Act’s data governance requirements, GDPR’s data protection obligations, and DORA’s ICT resilience requirements all assume a level of control over data and infrastructure that is structurally compromised when that infrastructure is subject to extraterritorial foreign jurisdiction.

The Sovereignty Gap

The concept of digital sovereignty has been present in EU policy since the GDPR debates of 2015 to 2016. What has been missing is a legal definition of what sovereign cloud actually means and a regulatory framework that enforces it.

Data localisation, the requirement that data be stored within EU territory, has been the most common policy response to the sovereignty concern. But data localisation addresses only the physical location of data, not the jurisdictional control over the infrastructure holding it. A data centre in Frankfurt operated by a US company remains subject to US extraterritorial jurisdiction regardless of its physical location in Germany.

CADA is designed to close this gap by establishing sovereignty standards that address jurisdictional control, ownership, and governance of cloud infrastructure, not merely the geographic location of servers.

The CLOUD Act Problem

What the CLOUD Act Does

The CLOUD Act, enacted by the US Congress in 2018, clarifies the legal basis for US government access to data stored by US technology companies on servers located anywhere in the world. Under the Act, US law enforcement and intelligence agencies can compel US-incorporated companies to produce stored communications and data through existing legal process, including warrants, subpoenas, and national security letters, regardless of whether the data is stored in the United States.

The CLOUD Act also creates a framework for bilateral executive agreements between the United States and foreign governments that would modify these requirements for cross-border access. As of August 2026, the US has concluded CLOUD Act agreements with the UK and Australia, among others.

Why the CLOUD Act Conflicts with EU Data Sovereignty

The CLOUD Act creates a direct conflict with EU data protection law in two respects.

First, it enables US government access to personal data of EU residents stored by US cloud providers without going through the mutual legal assistance treaty process that EU law recognises as the appropriate channel for cross-border law enforcement data requests. GDPR Article 48 provides that transfers of personal data to third countries pursuant to foreign court judgments or decisions of administrative authorities are only recognised and enforceable if based on an international agreement such as a mutual legal assistance treaty. A CLOUD Act warrant does not satisfy this requirement.

Second, it means that the sovereignty premise underlying adequacy decisions and other data transfer mechanisms is structurally qualified. The EU-US Data Privacy Framework’s adequacy decision rests partly on the premise that the FTC provides independent supervision of US privacy commitments. The US Supreme Court’s ruling in Trump v. Slaughter (2026) undermined that premise. But even if FTC independence were fully restored, the CLOUD Act’s access mechanism would remain in place regardless of adequacy status.

What CADA Proposes on CLOUD Act Exposure

CADA’s sovereignty definition is intended to address CLOUD Act exposure by requiring sovereign cloud infrastructure to be operated by entities that are not subject to extraterritorial foreign legal authority that could compel disclosure of EU data without EU legal process.

In practical terms, this means sovereign cloud infrastructure under CADA cannot be provided by US-incorporated entities or their subsidiaries, regardless of where the servers are physically located. A data centre in Amsterdam operated by a US company would not qualify as sovereign under the definition CADA is developing. A data centre in Amsterdam operated by a Dutch, French, or Estonian company with no US corporate nexus would qualify.

This is a materially stricter definition than data localisation alone and would, if adopted, exclude the major US hyperscalers from the sovereign cloud tier.

How CADA Interacts with the EU AI Act

The Infrastructure Layer of AI Act Compliance

The EU AI Act imposes obligations on providers and deployers of AI systems, including data governance requirements under Article 10, technical documentation under Annex IV, and human oversight requirements under Article 14. These obligations assume a level of control over the AI system and its underlying infrastructure that is harder to demonstrate where that infrastructure is subject to foreign extraterritorial jurisdiction.

The data governance obligations under Article 10 require providers of high-risk AI systems to implement appropriate practices for training, validation, and testing datasets. Where those datasets are processed on infrastructure subject to CLOUD Act authority, the governance claim is qualified: data processed under those conditions may be subject to access mechanisms that the controller cannot contractually prevent.

The GPAI model obligations under Article 53 require providers to make technical documentation available and to implement copyright compliance policies for training data. Where GPAI models are trained on US infrastructure, the jurisdictional questions around training data access compound the copyright transparency obligations.

Sovereign Cloud and AI Act Conformity Assessment

CADA’s sovereign cloud definition, once adopted, will affect how conformity assessments under the EU AI Act are conducted for high-risk AI systems. A conformity assessment that relies on infrastructure demonstrably subject to CLOUD Act jurisdiction will face harder questions from notified bodies and market surveillance authorities about the adequacy of data governance and security measures.

Annex IV technical documentation for high-risk AI systems must cover data governance practices and the security measures implemented. A provider whose AI system runs on infrastructure subject to CLOUD Act authority must address this exposure in its technical documentation and its risk management system under Article 9.

GPAI Models and EU AI Infrastructure

CADA’s open-source AI strategy is directly relevant to the GPAI model framework under the EU AI Act. The European Technological Sovereignty Package of which CADA forms part positions European-developed open-source foundation models as a strategic alternative to US API providers. EU AI Act obligations for GPAI model providers, including the GPAI Code of Practice requirements under Article 56, will apply equally to European open-source models placed on the market.

However, providers of European open-source GPAI models operating on EU sovereign infrastructure would be in a structurally stronger position for compliance than providers whose models are trained and served on US hyperscaler infrastructure subject to CLOUD Act authority. CADA is designed to make that structural advantage commercially viable by expanding EU compute capacity.

How CADA Interacts with GDPR

The Sovereignty Gap in GDPR Transfers

GDPR’s international transfer framework under Chapter V assumes that the controller can assess and control the protection available to personal data in the destination country or with the destination recipient. Standard Contractual Clauses, Binding Corporate Rules, and the EU-US Data Privacy Framework all operate on the premise that contractual commitments and adequacy assessments can provide essentially equivalent protection to the GDPR’s standards.

The CLOUD Act creates a structural flaw in this assumption. A controller transferring personal data to a US cloud processor under SCCs has contractually required the processor not to process the data outside the controller’s instructions. But if a US federal authority compels the processor to produce that data under a CLOUD Act warrant, the processor has no effective legal ability to refuse, and the controller has no contractual remedy that overrides US federal law.

CADA addresses this by creating a sovereign cloud tier where the infrastructure operator is not subject to CLOUD Act jurisdiction. Data processed on sovereign cloud infrastructure within the meaning of CADA would not be exposed to CLOUD Act compulsion, which removes the structural flaw in GDPR transfer compliance that the existing framework cannot resolve.

GDPR and Data Centre Expansion

CADA’s data centre expansion objective interacts with GDPR in a more straightforward way. Expanding EU data centre capacity operated by EU-established entities increases the availability of infrastructure that is compliant with GDPR transfer requirements without the need for SCCs or adequacy decisions. This reduces the friction in GDPR compliance for organisations that currently rely on US hyperscalers because no EU alternative is commercially viable at the scale required.

How CADA Interacts with DORA

DORA’s ICT risk management framework for EU financial entities, under Article 6, requires organisations to establish a comprehensive ICT risk management framework covering all ICT assets including cloud infrastructure. Article 29 requires financial entities to assess and manage concentration risk arising from excessive dependence on individual ICT third-party providers.

The concentration of EU financial sector workloads on three US hyperscalers is one of the most significant systemic ICT concentration risks in the EU financial system. DORA requires financial entities to assess this risk and develop mitigation strategies. CADA’s sovereign cloud tier and data centre expansion objective provide the infrastructure alternatives that would make genuine concentration risk mitigation commercially viable.

CADA’s sovereignty definition will also affect how DORA’s ICT third-party risk management requirements under Article 28 apply to cloud providers. Where a cloud provider qualifies as sovereign under CADA, the jurisdictional risk that DORA requires financial entities to assess is materially reduced. Where a cloud provider does not qualify as sovereign because it is subject to CLOUD Act authority, that jurisdictional exposure must be addressed in the financial entity’s third-party risk assessment and mitigation strategy.

What CADA Means for AI Compliance Infrastructure

Organisations building AI governance infrastructure, whether for EU AI Act compliance, GDPR compliance, or DORA compliance, face a decision about the infrastructure layer on which that infrastructure runs.

Compliance documentation, audit trails, technical documentation under Annex IV, and operational logs under Articles 12 and 19 of the EU AI Act represent some of the most sensitive regulatory data an organisation holds. Where that data is stored on infrastructure subject to CLOUD Act authority, the regulatory record itself is exposed to foreign government access without the organisation’s knowledge or consent.

This is not a theoretical risk. CLOUD Act warrants are issued under national security authority in circumstances where the target organisation is not notified. A supervisory authority requesting access to an organisation’s AI Act compliance records held on US cloud infrastructure could find that those records have already been accessed by US authorities under processes the organisation cannot legally disclose.

CADA addresses this directly by providing the regulatory framework for infrastructure that is genuinely outside CLOUD Act jurisdiction. Organisations using Grecta for AI governance and compliance management should assess the infrastructure layer of their compliance programme as part of their broader CADA readiness assessment.

The Open-Source AI Strategy

CADA’s open-source AI strategy is the least understood component of the European Technological Sovereignty Package. It is not a policy preference for open-source licensing as such. It is a strategic response to the single-vendor dependency that characterises European enterprise AI adoption.

The current market structure means that European AI providers access foundation model capabilities primarily through API agreements with a small number of US companies. This creates supply chain dependency, pricing dependency, and jurisdictional dependency simultaneously. CADA’s open-source strategy aims to develop European foundation models trained on European infrastructure, available to European providers under open-source licences that do not create the same dependencies.

Under the EU AI Act, open-source GPAI models benefit from partial exemptions under Article 53(2) from certain technical documentation and transparency obligations. CADA’s open-source strategy, if successful, would increase the availability of EU AI Act-compliant foundation models that European downstream providers can integrate into their own products without triggering the full range of GPAI provider obligations.

Timeline and Current Status

DateDevelopment
3 June 2026European Technological Sovereignty Package published by Commission, including CADA proposal
Mid-2026Rapporteur appointed in European Parliament’s Internal Market Committee
2026-2027Trilogue negotiations between Parliament, Council, and Commission
End of 2027 (anticipated)Potential adoption of CADA
2028-2029 (anticipated)Application of CADA obligations, subject to implementation periods

CADA is not yet law. The obligations described in this guide reflect the Commission’s proposal and the policy direction established by the rapporteur’s mandate. The final text may differ materially from the current proposal depending on the outcome of trilogue negotiations. The Council’s position on sovereignty definitions, data centre obligations, and open-source strategy has not yet been formally adopted.

What Organisations Should Do Now

CADA is not yet in force, but the compliance questions it addresses are live now under existing regulation. Organisations should take the following steps without waiting for CADA’s adoption.

Map your cloud infrastructure against CLOUD Act exposure. Identify which of your cloud providers are US-incorporated entities subject to CLOUD Act authority and which workloads, particularly those involving personal data, AI training data, and compliance documentation, are processed on that infrastructure.

Assess your EU AI Act technical documentation infrastructure. Where does your Annex IV technical documentation sit? Where are your Article 12 logs held? Where is your post-market monitoring data stored? If the answer is US hyperscaler infrastructure, your regulatory record is CLOUD Act-exposed.

Review DORA third-party concentration risk assessments. Financial entities should assess whether their existing concentration risk assessments adequately address CLOUD Act jurisdictional exposure as a component of third-party risk, not merely geographic concentration.

Monitor CADA negotiations. The sovereignty definition being negotiated in CADA will have direct implications for how EU AI Act conformity assessments, GDPR transfer compliance, and DORA third-party risk assessments are conducted for organisations using cloud infrastructure. Track the rapporteur’s position and the Council’s emerging stance.

Consider European sovereign cloud alternatives. Several European cloud providers offer infrastructure that is not subject to CLOUD Act authority, including OVHcloud, Hetzner, Exoscale, and Deutsche Telekom’s T-Systems. Assessing the commercial viability of migrating workloads to sovereign infrastructure now, before CADA creates regulatory pressure to do so, positions organisations ahead of the compliance curve.

FAQ

What does CADA stand for?

CADA stands for Cloud and AI Development Act. It is a proposed EU regulation published as part of the European Technological Sovereignty Package in June 2026. It is currently in the European Parliament negotiation phase and has not yet been adopted.

Is CADA already law?

No. CADA is a legislative proposal under negotiation between the European Parliament, the Council of the EU, and the European Commission. Adoption is anticipated no earlier than end of 2027, with obligations likely applying from 2028 or 2029 subject to implementation periods.

What is the difference between data localisation and digital sovereignty under CADA?

Data localisation requires that data be stored within a specific geographic territory. Digital sovereignty under CADA goes further by requiring that the infrastructure operator is not subject to extraterritorial foreign legal authority that could compel disclosure of that data without EU legal process. A US company operating a data centre in Frankfurt achieves data localisation but not digital sovereignty, because the CLOUD Act still applies to the US company regardless of where its servers are located.

How does CADA relate to the EU AI Act?

CADA addresses the infrastructure layer on which EU AI Act compliance is built. The EU AI Act’s data governance requirements under Article 10, technical documentation under Annex IV, and operational logging under Articles 12 and 19 all assume a level of control over infrastructure that is compromised where that infrastructure is subject to CLOUD Act authority. CADA’s sovereign cloud definition will affect how AI Act conformity assessments address infrastructure jurisdiction questions.

Does CADA affect GPAI model providers?

Yes. CADA’s open-source AI strategy is designed to increase the availability of European-developed GPAI models trained on EU sovereign infrastructure. This affects the practical landscape within which EU AI Act GPAI obligations under Articles 51 to 56 apply. CADA also affects the infrastructure jurisdiction questions relevant to GPAI model training data governance and GPAI Code of Practice compliance.

What is the CLOUD Act and why does CADA address it?

The CLOUD Act is a 2018 US federal law enabling US authorities to compel American technology companies to produce data stored anywhere in the world. It creates jurisdictional exposure for data processed on US cloud infrastructure regardless of physical location. CADA addresses it by establishing a sovereign cloud tier whose operators are not subject to CLOUD Act authority, removing the structural conflict between CLOUD Act jurisdiction and EU data protection obligations.

Does CADA replace GDPR for data protection purposes?

No. CADA is infrastructure legislation addressing the sovereignty and jurisdictional layer of cloud computing. GDPR continues to govern the processing of personal data. CADA complements GDPR by providing the infrastructure framework within which GDPR obligations can be met without CLOUD Act exposure. The two instruments operate at different layers and neither replaces the other.

How does CADA interact with DORA for financial entities?

DORA requires EU financial entities to assess and manage concentration risk arising from excessive dependence on individual ICT third-party providers. CADA’s sovereign cloud tier and data centre expansion objective provide the infrastructure alternatives that would make genuine concentration risk mitigation viable. CADA’s sovereignty definition will also affect how DORA’s ICT third-party risk assessments treat cloud providers whose CLOUD Act exposure is currently a component of third-party risk.

Will CADA require organisations to move data off US hyperscalers?

CADA is unlikely to mandate a universal migration away from US hyperscalers for all workloads. The more probable outcome is a tiered framework in which sovereign cloud is required for specific categories of sensitive workload, including those involving personal data, critical infrastructure AI systems, and government data, while other workloads may continue on non-sovereign infrastructure. The specific scope of any mandatory sovereign cloud requirements will depend on the outcome of trilogue negotiations.

How does Grecta help organisations prepare for CADA?

Grecta’s AI governance platform operates at the product and system level, providing the compliance infrastructure that CADA’s regulatory context requires. Grecta maps AI system obligations across the EU AI Act, GDPR, and DORA simultaneously, maintains technical documentation and audit trails, and supports the classification and risk assessment processes that CADA’s infrastructure sovereignty questions feed into. Organisations assessing their CADA readiness should begin with a systematic mapping of their AI systems, their data processing infrastructure, and their applicable regulatory obligations across all three instruments.

This guide reflects the European Commission’s CADA proposal published in June 2026 and the legislative context as of August 2026. CADA has not yet been adopted. The obligations described reflect the Commission’s proposal and may change materially during trilogue negotiations. This guide is published by Grecta for general informational purposes and does not constitute legal advice. Organisations should obtain advice specific to their infrastructure, AI systems, and regulatory obligations.

Back to Blog