Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Skip to content
S
Regulation Daily Brief

EU Proposes Cloud and AI Development Act: What CADA's Sovereignty Framework Means for US Providers in Public Sector...

3 min read European Commission DG CONNECT Partial Strong S
The European Commission formally adopted a legislative proposal for the Cloud and AI Development Act (CADA) on June 3, 2026, a sovereignty-oriented framework that would restructure how EU public institutions procure cloud and AI services. The proposal isn't law yet, but its four-level assessment system and open-source mandate signal where EU public sector procurement is heading regardless of trilogue outcome.
EU data center target, 3× in 5–7 years

Key Takeaways

  • European Commission formally adopted the CADA legislative proposal on June 3, 2026, a four-tier sovereignty framework for public cloud and AI procurement
  • CADA is a proposal requiring trilogue, not binding law, but signals EU public sector procurement direction regardless of final outcome
  • The "Free Software First" open-source mandate would require publicly funded software to be available for reuse, disadvantaging proprietary vendors
  • BSA and CCIA Europe oppose the proposal as protectionist; three key market statistics cited in coverage lack confirmed methodology sources

Analysis

CADA is not the EU AI Act. Audiences arriving via EU AI regulation search terms should know: CADA is a separate legislative instrument focused on cloud infrastructure, public procurement sovereignty, and open-source mandates. It supplements, and in procurement contexts, intersects with, the EU AI Act, but it's a distinct proposal with its own legislative timeline.

EU Public Sector Cloud Procurement: Before and After CADA (If Enacted)

Current rules
Public procurement follows general EU procurement directives, price, capability, and security criteria; no formal sovereignty assessment tier
Under CADA (proposed)
Four-level sovereignty assessment adds infrastructure location, software supply chain control, and corporate ownership structure as evaluation criteria for public AI and cloud contracts

CADA is a proposal. Not a regulation. That distinction belongs in the first paragraph of every piece of coverage it receives, and it belongs here too. What the European Commission adopted on June 3 is the opening move in a legislative process that requires European Parliament and Council agreement before any provision becomes binding. That process, trilogue, typically takes 12 to 36 months for complex digital legislation.

But proposals reveal intent. And CADA’s intent is structural.

According to the Commission’s proposal, CADA aims to accelerate EU data center permitting with a stated goal of tripling EU infrastructure capacity over the next five to seven years. More consequentially for US providers, the proposal reportedly introduces a four-tier sovereignty assessment framework governing public sector procurement, evaluating cloud and AI services on infrastructure location, software supply chain control, and corporate ownership structure. The Commission published the proposal through DG CONNECT as part of a broader Technological Sovereignty Package.

CADA Stakeholder Positions

European Commission (DG CONNECT)
for
Proposing authority, frames CADA as digital sovereignty and infrastructure resilience measure
BSA (Business Software Alliance)
against
Filed June 3 characterizing proposal as protectionist, represents US software vendors
CCIA Europe
against
June 3 press release calls proposal discriminatory, represents US tech companies in EU market
Free Software Foundation Europe
for
Public Money? Public Code! principle forms basis of open-source mandate

The open-source mandate is the provision most likely to reshape procurement behavior early. The proposal reportedly requires that publicly funded software be made available for reuse, aligned with the Free Software Foundation Europe’s “Public Money? Public Code!” principle. FSFE has campaigned for this principle across multiple EU legislative cycles. If adopted as written, it would create a meaningful procurement disadvantage for proprietary software vendors competing for EU public sector contracts.

Industry reaction was immediate. The BSA characterized CADA as protectionist in a June 3 policy filing. CCIA Europe called it discriminatory in a same-day press release. Both organizations represent vendors with direct financial interest in opposing sovereignty-oriented procurement rules, their characterizations are stakeholder positions, not neutral assessments. That said, the substance of their concern maps to a real market question: US-based hyperscalers hold a substantial share of the European cloud market by most analyst estimates, and a four-tier sovereignty framework that evaluates corporate ownership structure could systematically disadvantage non-EU-headquartered providers at the public sector procurement stage.

Three statistics cited in coverage of this proposal require qualified framing. A figure of approximately 70% US hyperscaler market share in European cloud has been widely cited but lacks a named methodology source in available materials. A 15% baseline from 2022 has the same sourcing gap. A figure of approximately €264 billion in annual EU public IT spending appears to reference an EC document but the specific source hasn’t been confirmed in . All three are directionally consistent with publicly available cloud market data but shouldn’t be treated as established figures without named sourcing.

What to Watch

EU member state position statements on sovereignty procurement mandateQ3 2026
Trilogue opening, Parliament and Council position adoption12–18 months
FSFE open-source mandate survival through Parliament industry blocsTrilogue phase

The catch is timing. CADA enters a crowded EU legislative queue. The AI Act is still in implementation. The Digital Omnibus amendments are in progress. Member state governments, particularly those with established hyperscaler relationships, will have opinions about sovereignty procurement mandates that may reshape the proposal during trilogue. As prior hub coverage has documented, compliance teams building for EU digital regulation now operate in a landscape where proposals and their final enacted forms can diverge significantly.

What to watch

whether any EU member state issues an early position on CADA’s sovereignty framework, whether the trilogue pace accelerates given the EC’s Digital Decade timeline pressure, and whether FSFE’s open-source mandate survives contact with Parliament’s industry-aligned blocs. Organizations doing EU public sector work should begin mapping their services against the four-tier framework now, not to comply, but to understand their exposure if CADA passes in current form.

View Source
More Regulation intelligence
View all Regulation

Related Coverage

Stay ahead on Regulation

Get verified AI intelligence delivered daily. No hype, no speculation, just what matters.

Explore the AI News Hub