Launcher

Type to filter results. Use arrow keys to navigate, Enter to select.

Preferences

You've reached the end of the results

The European Commission's proposal for a Cloud and AI Development Act (CADA) aims to strengthen the European Union's cloud and AI capacity, competitiveness and technological sovereignty. It addresses the infrastructure and industrial-policy aspects of Europe's digital economy, including sustainable data-centre development, computing capacity and sovereign cloud services.

CADA should be considered alongside, but distinguished from: the AI Act, which regulates AI systems according to their risks and uses; DORA, which establishes digital operational-resilience requirements for the financial sector; NIS2, which establishes cybersecurity risk-management and reporting requirements across critical sectors; and EuroHPC and related initiatives, which support European high-performance computing and AI development.

N.B.: CADA remains a legislative proposal. Its provisions may change during negotiations between the European Parliament and the Council.

  • Main Elements of the CADA Proposal
    1. Sustainable data-centre and computing capacity

    CADA is intended to support the expansion of sustainable data-centre, cloud and AI computing capacity within the EU. The proposal addresses areas such as:

    • The development of data-centre and computing infrastructure;
    • Planning and administrative processes;
    • Access to suitable sites and energy;
    • Energy efficiency and environmental sustainability;
    • Investment in advanced computing capacity; and
    • The resilience of European digital infrastructure.

    The final legal and administrative requirements will depend on the outcome of the legislative process and their implementation at EU and national levels.

    2. Union assurance framework for sovereign cloud services

    CADA proposes four Union assurance levels for sovereign cloud services. The framework covers several dimensions of cloud sovereignty, including: the location and processing of data; exposure to third-country control or access laws; operational control and autonomy; software and supply-chain dependencies; and the ability to maintain services under adverse circumstances. The assurance process would become progressively more demanding at the higher levels:

    Union assurance levelProposed assessment approach
    Level 1Based largely on provider self-assessment against the applicable criteria.
    Level 2Requires independent auditing and recognition by the relevant national authority.
    Level 3Requires independent auditing and recognition against more demanding sovereignty criteria.
    Level 4Represents the highest proposed level, with independent auditing and recognition against the most demanding criteria.

    Services recognised under the framework would be included in an EU repository. Recognition would apply to the relevant cloud service and assurance level. It should not be interpreted as a general certification of every service offered by the provider. The detailed requirements for each level are set out in the proposal and its annexes. Terms such as EU-hosted, secure, resilient and sovereign should not be treated as equivalent:

    • Data location concerns where data is stored and processed.
    • Jurisdictional exposure concerns the laws applicable to the provider and its corporate group.
    • Operational sovereignty concerns control over administration, support, encryption keys, updates and continuity.
    • Technological sovereignty concerns dependencies on software, hardware and supply chains.

    Hosting data in the EU does not, by itself, eliminate exposure to third-country laws or non-European technology dependencies.

    3. Public procurement and highly critical sectors

    CADA would introduce sovereignty assessments and related requirements for certain public-sector cloud procurements. The applicable requirements would depend on the sensitivity of the data or workload and the relevant sovereignty risks. Procurement assessments may therefore consider:

    • Data location and processing arrangements;
    • Exposure to third-country laws and access requests;
    • Provider ownership and control;
    • Privileged access and encryption-key management;
    • Subcontractors and software supply chains;
    • Operational continuity;
    • Portability and interoperability; and
    • Exit and transition arrangements.

    Article 31 of the proposal would also allow similar sovereignty assessments to be applied to certain private entities operating in highly critical sectors covered by NIS2. This could include banks and certain financial market infrastructures, subject to the scope, conditions and final wording of the adopted legislation. CADA does not currently establish a general obligation for private financial institutions to migrate to sovereign cloud services.

  • Relevance for Luxembourg

    Luxembourg has data-centre, connectivity and advanced computing capabilities supported by several public- and private-sector initiatives. These capabilities may be relevant to the development of European cloud and AI infrastructure. However, certification, sovereignty and regulatory compliance must be assessed separately for each provider, service and facility. The presence of infrastructure in Luxembourg or elsewhere in the EU does not, on its own, demonstrate compliance with a particular CADA assurance level.

    Financial institutions and financial market infrastructures

    For Luxembourg's financial sector, CADA may become relevant to: cloud-provider selection and due diligence; third-country legal and operational exposure; ICT concentration-risk management; contractual audit and access rights; supply-chain transparency; continuity and resilience arrangements; data and application portability; and cloud exit and transition strategies.

    The proposed CADA framework would complement rather than replace DORA. Financial entities would continue to be responsible for meeting DORA requirements concerning ICT third-party risk, contractual arrangements, concentration risk, operational resilience and exit planning. Recognition under a CADA assurance level should not automatically be treated as evidence of full DORA compliance. The financial entity would still need to assess the service in the context of its own workloads, risks and regulatory obligations.

    NIS2 sectors

    Entities within the relevant NIS2 sectors must already address supply-chain security as part of their cybersecurity risk-management measures. Depending on the final CADA text, certain private entities in highly critical sectors may also become subject to, or be affected by, sovereignty assessments. Relevant considerations may include: the security controls of the cloud provider; applicable jurisdictions; dependence on critical suppliers; subcontracting arrangements; vulnerabilities and incident history; business continuity; and exit and recovery capabilities. The potential application of CADA should be assessed separately from an entity's existing NIS2 obligations.

    Public-sector organisations

    Luxembourg public-sector organisations may need to incorporate CADA sovereignty assessments into relevant cloud procurement and workload-classification processes. This may affect: the selection of cloud services; the assurance level required for sensitive workloads; tender specifications and evaluation criteria; documentation of sovereignty risks; contractual controls; and monitoring throughout the service lifecycle.

    Cloud and data-centre operators

    Cloud and data-centre operators may need to demonstrate that individual services satisfy the criteria for a particular Union assurance level. This could require: documenting corporate ownership and control; identifying applicable jurisdictions; mapping subcontractors and technology dependencies; demonstrating operational control; supporting independent audits; providing evidence to national authorities; and maintaining assurance throughout the service lifecycle. Operators should avoid applying assurance claims made for one service, facility or configuration to their entire portfolio.

  • Relationship with Other EU Legislation
    InstrumentStatus and relevance
    Proposed Cloud and AI Development ActEuropean Commission proposal to expand sustainable cloud and AI computing capacity and establish a Union assurance framework for sovereign cloud services. It remains subject to negotiation and amendment.
    Regulation (EU) 2022/2554 - DORAEstablishes digital operational-resilience and ICT third-party risk requirements for the financial sector. CADA would complement, not replace, these requirements.
    Directive (EU) 2022/2555 - NIS2Establishes cybersecurity risk-management, supply-chain security and incident-reporting requirements for essential and important entities. Article 31 of the CADA proposal may be relevant to certain private entities in highly critical sectors.
    Regulation (EU) 2024/1689 - AI ActEstablishes the EU's risk-based regulatory framework for AI systems. It is distinct from CADA's infrastructure and cloud-sovereignty provisions.
    EuroHPC framework and related initiativesSupport European high-performance computing and AI capacity. These initiatives have their own legal and funding bases and should not automatically be presented as CADA requirements.
    Key point for organisations

    CADA does not currently require all organisations to use sovereign cloud services or to move existing workloads away from international cloud providers. Its practical effect is more likely to depend on: whether an organisation falls within a relevant public or highly critical sector; the sensitivity and criticality of the workload; the assurance level required for the intended use; the organisation's exposure to third-country control and supply-chain risks; and the final text adopted by the European Parliament and the Council. Organisations should therefore follow a risk-based approach: identify their most sensitive workloads, understand their cloud and AI dependencies, and determine where stronger sovereignty, resilience or portability controls may be justified.

  • Reference Resources