From the journal

European Commission Proposes Cloud and AI Development Act to Establish EU AI Sovereignty Criteria, 2 July 2026

The European Commission formally proposed the Cloud and AI Development Act (CADA) on 2 July 2026 as part of the Tech Sovereignty Package. CADA aims to triple EU data centre capacity within five to seven years and introduces EU-wide CADA Assurance Levels for cloud and AI services, which will serve as a procurement criterion for public-sector and regulated-sector buyers across EU member states.

3 min read

The European Commission formally proposed the Cloud and AI Development Act (CADA) on 2 July 2026 as part of the broader Tech Sovereignty Package. CADA is a legislative proposal submitted to the European Parliament and Council under the ordinary legislative procedure and does not yet carry a binding effective date; adoption is expected across the 2026-2027 legislative cycle. The package also includes a Chips Act 2.0 proposal, an Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy.

CADA proposes two principal regulatory mechanisms. First, it establishes streamlined permitting procedures for deploying sustainable data centre infrastructure across EU member states, aiming to reduce build timelines through faster planning approvals and grid connection processes. Second, it introduces the CADA Assurance Level system, which grades cloud and AI services by degree of EU operational control, data residency, and supply chain transparency. Assurance Levels are designed to function as a market access criterion for public-sector procurement contracts and for buyers in regulated sectors, including financial services, healthcare, and critical infrastructure.

The CADA Assurance Level system directly affects cloud and AI providers supplying EU regulated-sector clients. Providers seeking to serve EU public authorities, financial institutions subject to the Digital Operational Resilience Act (Regulation (EU) 2022/2554), or crypto asset service providers regulated under the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) will need to demonstrate compliance with the applicable Assurance Level. The specific requirements for each level will be defined through delegated acts after CADA is adopted; the proposal establishes the grading system and authorises the Commission to set the detailed technical standards.

Several aspects of the proposal remain open. Draft Assurance Level criteria have not been published; these will emerge through the delegated act process after primary legislation is enacted. The proposal states explicitly that CADA is not designed to exclude non-EU cloud providers: firms from outside the EU that meet the applicable Assurance Level criteria may qualify for public-sector and regulated-sector procurement. The treatment of existing cloud contracts and legacy data processing arrangements during any transitional period is not addressed in the proposal.

Licentium monitors CADA's progress through the EU legislative process and advises regulated firms and technology providers on existing cloud governance and data residency obligations under the Digital Operational Resilience Act, MiCAR, and the EU AI Act. If your firm is making cloud infrastructure decisions that may be affected by the emerging CADA Assurance Level criteria, we can assist with forward planning. Work we undertake includes cloud and data governance reviews for regulated entities, DORA and MiCAR operational resilience compliance, EU AI Act infrastructure requirement analysis, and data sovereignty planning for financial services firms.

Source: European Commission, Proposal for the Cloud and AI Development Act (CADA), 2 July 2026

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.