EU Proposes Cloud and AI Development Act — Sovereign Cloud Framework with Four Assurance Levels
On June 3, the European Commission published the Cloud and AI Development Act (CADA), the centerpiece of its Technological Sovereignty Package. CADA introduces a four-level sovereignty assurance framework for cloud procurements by EU public authorities: Level 1 requires EU-hosted servers; Level 2 prohibits third-country data access or kill-switch authority; Level 3 requires the provider not be sub
BY FRONTIER DESK · JUNE 29, 2026 · 1 MIN READ
On June 3, the European Commission published the Cloud and AI Development Act (CADA), the centerpiece of its Technological Sovereignty Package. CADA introduces a four-level sovereignty assurance framework for cloud procurements by EU public authorities: Level 1 requires EU-hosted servers; Level 2 prohibits third-country data access or kill-switch authority; Level 3 requires the provider not be subject to third-country control (effectively excluding U.S.-incorporated entities from high-sensitivity contracts); Level 4 adds hardware sovereignty requirements. A conditional derogation at Level 3 is available for "associated third countries" holding GDPR adequacy decisions — but only if those countries do not compel data access or service disruption. This legislation directly targets the market position of AWS, Google Cloud, Microsoft Azure, and similar hyperscalers in European public-sector contracting. Law firms advising clients on EU public procurement, government contracts, or cloud vendor agreements must treat CADA as a live compliance variable from its anticipated formal adoption in late 2026.