From the journal

European Commission Proposes Cloud and AI Development Act to Establish EU AI Sovereignty Criteria, 2 July 2026

The European Commission formally proposed the Cloud and AI Development Act (CADA) on 2 July 2026 as part of the Tech Sovereignty Package. CADA aims to triple EU data centre capacity within five to seven years and introduces EU-wide CADA Assurance Levels for cloud and AI services, which will serve as a procurement criterion for public-sector and regulated-sector buyers across EU member states.

3 min read

The European Commission formally proposed the Cloud and AI Development Act (CADA) on 2 July 2026 as part of the broader Tech Sovereignty Package. CADA is a legislative proposal submitted to the European Parliament and Council under the ordinary legislative procedure and does not yet carry a binding effective date; adoption is expected across the 2026-2027 legislative cycle. The package also includes a Chips Act 2.0 proposal, an Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy.

CADA proposes two principal regulatory mechanisms. First, it establishes streamlined permitting procedures for deploying sustainable data centre infrastructure across EU member states, aiming to reduce build timelines through faster planning approvals and grid connection processes. Second, it introduces the CADA Assurance Level system, which grades cloud and AI services by degree of EU operational control, data residency, and supply chain transparency. Assurance Levels are designed to function as a market access criterion for public-sector procurement contracts and for buyers in regulated sectors, including financial services, healthcare, and critical infrastructure.

The CADA Assurance Level system directly affects cloud and AI providers supplying EU regulated-sector clients. Providers seeking to serve EU public authorities, financial institutions subject to the Digital Operational Resilience Act (Regulation (EU) 2022/2554), or crypto asset service providers regulated under the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) will need to demonstrate compliance with the applicable Assurance Level. The specific requirements for each level will be defined through delegated acts after CADA is adopted; the proposal establishes the grading system and authorises the Commission to set the detailed technical standards.

Several aspects of the proposal remain open. Draft Assurance Level criteria have not been published; these will emerge through the delegated act process after primary legislation is enacted. The proposal states explicitly that CADA is not designed to exclude non-EU cloud providers: firms from outside the EU that meet the applicable Assurance Level criteria may qualify for public-sector and regulated-sector procurement. The treatment of existing cloud contracts and legacy data processing arrangements during any transitional period is not addressed in the proposal.

Licentium monitors CADA's progress through the EU legislative process and advises regulated firms and technology providers on existing cloud governance and data residency obligations under the Digital Operational Resilience Act, MiCAR, and the EU AI Act. If your firm is making cloud infrastructure decisions that may be affected by the emerging CADA Assurance Level criteria, we can assist with forward planning. Work we undertake includes cloud and data governance reviews for regulated entities, DORA and MiCAR operational resilience compliance, EU AI Act infrastructure requirement analysis, and data sovereignty planning for financial services firms.

Source: European Commission, Proposal for the Cloud and AI Development Act (CADA), 2 July 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

Foreign Ownership of a Delaware or Wyoming Entity: Federal Tax Classification, Information Reporting, Withholding, and State Duties

A non-U.S. person may own a Delaware or Wyoming LLC or a Delaware corporation, yet formation alone does not settle the federal tax result, the reporting burden, confidentiality, or the right to work in the country. This part takes the U.S. entity as chosen and examines classification, Form 5472 reporting, source and effectively connected income, partner and shareholder withholding, tax residence and immigration, duties beyond the formation state, real property and estate exposure, and treaty and home-country dependencies.

Illia Prokopiev

Structuring Cross-Border Digital-Asset Ventures (Part 2)

A cross-border digital-asset group must allocate protocol stewardship, token issuance, customer-facing regulated services, pooled investment, treasury, and founder functions before it selects any jurisdiction. The question presented is where each of those functions can lawfully sit across sixteen jurisdictions and the European Union and EEA overlay, as of 27 August 2026.

Illia Prokopiev

Function-First Entity Design for Cross-Border Digital-Asset Ventures

Cross-border digital-asset ventures often separate several legal roles. Those roles include the venture issuer, operating company, customer-facing licensee, token issuer, pooled vehicle, treasury body, and protocol administrator. The Question Presented is which roles eight jurisdictions can support as of 27 August 2026.