Search

Cloud and AI, a European Revolution: the CADA Regulation to Strengthen the EU’s Technology Ecosystem

Cloud and AI, a European Revolution: the CADA Regulation to Strengthen the EU’s Technology Ecosystem

By Paola Furiosi and Francesca Caliri

On 3 June 2026, the European Commission presented, as part of a broader digital sovereignty package, the proposal for Regulation known as the Cloud and AI Development Act (“CADA”), aimed at establishing a framework of measures for strengthening the cloud and artificial intelligence ecosystem at European level.

The proposal builds on the AI Continent Action Plan and the Apply AI Strategy, responding to the concerns highlighted in the Draghi Report on European competitiveness.

Why the CADA: Context and Challenges

The need for new regulation on cloud and artificial intelligence arises from the European Union’s growing dependence on a limited number of third-country cloud service providers. The market share of European providers currently stands at around 15%, while three non-EU hyperscalers control over 70% of the European cloud system.

This situation exposes the EU to significant risks, such as the extraterritorial application of third-country laws that may conflict with fundamental rights and the European data protection framework, the risks of operational discontinuity arising from unilateral decisions by non-European actors, as well as insufficient data centre capacity in the EU, forcing European enterprises to route enormous volumes of critical data through foreign infrastructure.

The Four Pillars of the Proposal

To address the above risks, the CADA proposal is structured around four main objectives:

  1. increasing computing capacity and AI development in the EU through the Cloud and AI Leadership Initiatives, which include: the development of energy-efficient data centre technologies; strengthening autonomy across the cloud stack; the development of advanced capabilities in frontier AI, physical AI and industrial AI; and widespread adoption of cloud and AI in the public and private sectors. The proposal provides for the creation of a network of Experience and Acceleration Centres for AI and the designation of “frontier AI priority projects” for the development of strategic technologies;
  2. accelerating sustainable data centre deployment through Member State designation of “data centre acceleration zones” with simplified permitting procedures, sustainability requirements and favourable conditions for connection to the energy grid. The objective is to triple EU capacity within 5-7 years and reach the required capacity by 2035. The Commission may designate “data centre strategic projects” eligible for support;
  3. establishing a harmonised EU cloud sovereignty framework with 4 levels of assurance setting increasingly stringent requirements for data confidentiality, operational autonomy and protection of public order, against which cloud providers will be required to apply for recognition by the competent national authority. Level 1 provides for a conformity self-assessment, while levels 2 to 4 require independent audits. Member States and European Union entities will be required to conduct risk assessments to determine the appropriate assurance level for different public-sector activities;
  4. reforming public procurement for cloud services by introducing EU added-value criteria in procurement procedures, creating the EuroCloud Federation for sharing cloud services among public bodies and establishing a joint procurement framework managed by the Commission. The proposal also promotes the use of open-source solutions in the public sector.

Relationship with Existing Legislation and the National Regulatory Framework Currently Applicable to Cloud

The CADA fits within a complex and complementary European regulatory ecosystem. It needs to be coordinated with the Data Act on cloud-service portability and switching, with the Digital Markets Act on market contestability and with the AI Act on the regulation of AI systems. It also complemented the revision of the Cybersecurity Act, addressing sovereignty risks that go beyond technical security.

At national level, pending the possible adoption of the CADA, Italy’s regulatory framework applicable to cloud services is already structured and multi-layered. The legal basis is represented by Article 33-septies of Decree-Law 179/2012, which assigns the strategy for the development of digital infrastructures and the adoption of the cloud model for public administration a guiding function that administrations are required to follow. Pursuant to paragraph 4 of this provision, the Italian National Cybersecurity Agency (“ACN”) adopted – in agreement with the Department for Digital Transformation – the Unified Regulation for Cloud Infrastructure and Services for the PA, which governs minimum levels of security, computing capacity, energy savings and reliability for public-administration digital infrastructures, as well as the quality, security, performance, scalability and portability requirements for cloud services and the procedures for qualification and migration.

This Regulation constitutes the technical-regulatory foundation of the Cloud Italia Strategy, which is structured around three pillars. The first concerns the establishment of the National Strategic Hub (Polo Strategico Nazionale, “PSN”), a high-reliability infrastructure located on national territory, intended to host data and services classified as strategic, namely those whose compromise could have an impact on national security. The second pillar is represented by the cloud provider and service qualification system, managed by the ACN, which defines the criteria for admitting cloud services for use by Public Administrations, based on the class of data processed (strategic, critical or ordinary). Finally, the third pillar consists of the classification of data and services of Public Administrations, aimed at determining the appropriate destination (PSN, suitable own infrastructure or qualified public cloud), in accordance with the risk profile and regulatory requirements.

In this regard, the Three-Year Plan for IT in the Public Administration 2024-2026 expressly refers to the Cloud Italia Strategy, the Cloud PA Regulation and ACN implementing determinations, confirming the obligation for administrations to migrate their services to compliant solutions.

The Sovereign Cloud

The regulatory framework described above – both at European and national level – converges on a cross-cutting theme that deserves specific examination: the sovereign cloud.

The expression “sovereign cloud” refers to a cloud service delivery model in which the infrastructure, data and operations are subject to the full jurisdiction and effective control of a State or supranational organisation, without third parties (in particular, entities established in third countries) being able to exercise legal, technical or operational influence over data processing or service continuity.

In practice, a cloud service may be defined as “sovereign” when it ensures that data is stored and processed within a given territory, that the provider operates under the exclusive jurisdiction of the individual Member State or the European Union, that there are no obligations to communicate or transfer data to third-country authorities under extraterritorial legislation, and that operational control over the infrastructure – including the management of encryption keys, access rights and updates – is exercised by entities not subject to the control of non-European bodies.

The sovereign cloud theme represents a common thread running through both the Cloud Italia Strategy and the CADA proposal. At national level, the PSN was conceived precisely as a response to the need to ensure that the most sensitive public administration data and services remain under the control of entities operating within the Italian and European legal perimeter, shielded from the extraterritorial application of third-country laws. Similarly, at European level, the CADA systematises this requirement through the abovementioned four-level cloud sovereignty framework, introducing for the first time harmonised criteria for assessing the degree of autonomy and control that a cloud service guarantees against external influences.

The CADA’s approach thus goes beyond the purely technical dimension of cybersecurity – already covered by the NIS2 Directive and the Cybersecurity Act – to embrace a broader notion of sovereignty, encompassing data localisation, operational control, supply chain transparency and protection from the extraterritorial application of third-country laws. For businesses and public administrations, this entails the need to rethink their cloud sourcing strategies, assessing not only security and compliance profiles but also the degree of effective sovereignty of the solutions adopted.

Conclusions

The CADA proposal represents a fundamental step in the European strategy for digital sovereignty, marking the Union’s most ambitious attempt to establish a comprehensive framework for strengthening the cloud and AI ecosystem. The Commission’s approach does not merely address the security and certification profiles of cloud services, but structurally intervenes on the continent’s computational capacity, on public procurement governance and on the promotion of European technological innovation.

In this context, Italy’s regulatory framework may find in the CADA a reference point for harmonisation at European level. Operators in the cloud computing and artificial intelligence sectors will therefore need to engage with a rapidly evolving regulatory environment, in which compliance with sovereignty, security and interoperability requirements will become an increasingly decisive competitive factor.

Paola Furiosi

Legal Partner | PwC Italy |  + posts