In complex environments, change is never isolated.
For intricate structures, with so many intertwined elements and moving parts even the smallest update can change how things work for everybody involved. On a larger scale, a single shift can lead to another and another, creating an unstoppable momentum that gains strength as it ripples outwards into multiple ecosystems, bringing brand new challenges and opportunities to the surface.
Try as you might, when these pockets of large-scale momentum solidify, it’s pretty much always out of your hands. Instead, the ones making the choices are policymakers and elected officials who use this velocity to influence change. To make things more complicated, by the time anything is actioned the attitudes behind these policies have often already been living, growing and evolving inside of industry sentiment for a very long time. After all, it takes a while for rulings to be rolled out but it requires relatively little for people to form an opinion on what they believe is right and act upon it themselves.
Because of this, when a sentiment is baked into the zeitgeist we often see localised pockets of change happening long before sweeping legislation is passed. These separate pools of combined enthusiasm are then reinforced on the EU stage, reiterated, reworked and brought in line with existing policies and before you know it the dominos are falling and a cascade of change is underway. Better yet, it’s been underway for some time and it took a new enforcement for you to see the bigger picture that you are now, and always have been, very much a part of. This is a story that’s been told many times in many different ways where sentiment becomes action, action becomes policy, policy becomes expectancy.
We are currently seeing this play out in real time in the way that EU communications lives and breathes, but the first domino didn’t fall this year or even this decade. This cascade has been growing for a lot longer than you think and it’s now getting so big that it currently acts as both a delayed reaction to that market sentiment and a sign of things to come.
Make no mistake, I’m not saying that it’s too late for you to act. But even on a relatively short timeline how you adjust operationally is going to dictate your success going forward in very broad terms - from the people you can do business with, to how you’re able to set up and deploy your services even in your own country. In no uncertain terms, if you’re not ready for what’s coming you could see this particular cascade sink your operations at a European level.
CADA (The Cloud and AI Development Act) and the EU Tech Sovereignty Package are the latest items that will look to transform EU cloud (and these are the policies that you’ll need to learn about first) but the movement we’re now seeing isn’t isolated to these two things alone. This is because as more and more European organisations tie sovereignty directly to autonomy, risk management, resiliency and overall security, a lot of people are looking to ensure minimal non-EU influence as a baseline going forward. A baseline that they’re looking towards their providers to go above and beyond.
But what are the details of these EU-wide policies and the separate national reactions that together are looking to form the sovereign EU cloud? What’s happening outside of this legislation? What effects and impacts are we already seeing occur? What are some of the challenges and opportunities that communications providers can expect to arise because of all this?
If you haven’t done so already, now would be a good time for you to check out our full breakdown of both CADA and the EU Tech Sovereignty Package. They’re central to the latest part of the communications compliance cascade and the full context is definitely important.
If you’re happy with just the short version:
Our focus is on CADA and not the full tech sovereignty package for a reason - this is the act that will impact communications providers the most. Over the years, multiple rulings have served to strengthen EU digital sovereignty and add to the momentum of the European compliance cascade but CADA acts as the centrepiece which not only combines and magnifies their powers but aligns them closer with modern needs and gives them the infrastructure necessary to create change.
Depending on how you look at it, your idea of what rules have actually contributed to the current state of the European cloud may differ. There’s dozens out there but there is a solid line that can be drawn between now and a starting point of nearly a decade ago. Here’s the picture it draws:
2018 - It all starts with GDPR (the General Data Protection Regulation) which brings in strict rules around personal data processing
2019 - The EU Cybersecurity act follows the next year and grants agencies permanent powers to evaluate provider security and foreign ownership risks
2022 - A few years later the NIS2 directive expands cybersecurity and risk assessment to specific providers, with a judging gaze cast over non-EU influences
2024 - In 2024 the EU Data Act legally eradicates vendor lock-in and adds requirements for maximum cloud-to-cloud data portability. The EU AI Act also began this year with provisions for it still being rolled out.
2026 - CADA is then proposed on the 3rd June 2026, bringing with it plans to increase research, innovation and capacity as well as a digital sovereignty framework which will be mandatory for public sectors.
If there is one thing that you take away from all of this, it should be an understanding of why CADA is different from everything else that’s come before it.
GDPR, the EU cybersecurity act, NIS2, they all focus on building rules and regulations. They set ordinances that are far from toothless, but they’re simply not set up for today’s technological or geopolitical landscape. CADA is the muscle that enforces EU data sovereignty, and it’s backed by sovereign architecture and infrastructure which is immune to non-EU influence and political compulsions.
If you’re wondering what the fuss is all about around Europe wanting to become digitally sovereign, there are three statistics that you should be paying attention to:
For a good example of what this kind of ownership means for a digitally sovereign Europe you simply need to look at the proposals that didn’t make it through, not because of nationwide demands or local resistance but because of foreign influence.
Namely, in 2024 the European Union Cybersecurity Certification Scheme for Cloud Services (EUCS) was updated to bring it more in line with modern needs. Lots of complexity here but the long and short of it is, after multiple years of negotiation the choice to remove sovereignty filters from the EUCS was made. The main backers of this adjustment? Mostly US hyperscalers who would stand to lose some of their control over the EU cloud.
I say all of this only to highlight what happens when EU sentiment is only stopped from being policy because of Non-EU pressures – A process where change isn’t halted but the time between new compliance actually shortens with each new iteration:
To the surprise of very few, the Tech Sovereignty Package contains sovereignty filters that are eerily similar to the ones that were previously in the original 2024 EUCS update. Continuing this established pattern, if this package doesn’t make it through there will just be another proposal with similar demands, then another and another in shorter and shorter time spans until Europe has what it feels is necessary to achieve its sovereignty goals.
That’s the compliance cascade in motion.
But this isn’t all about Europe as a whole. With all of this happening on such a high stage, it’s no surprise that a lot of us overlooked the fact that individual countries don’t actually need EU legislation to make their own sovereignty decisions. In fact, three key regions are already taking steps towards becoming sovereign without waiting for EU policymakers:
All of this has been transpiring across the past year, and each instance shows a separate facet of how sovereignty can transform a digital landscape. This is because these changes don’t just reflect EU sentiment but also national makeup and overall principles, each of which you’ll have to consider if you’re looking to go into multiple European markets. For example, France has a more centralized approach and are able to enact massive singular motions which you’ll have to adjust to quickly. The Nordics? Their risk profile overall is minimal so they will look to take sovereignty measures one step further, something you’ll have to bear in mind when delivering services.
A world in which Europe has full operational sovereignty takes a long time to build. But if you take a step back you’ll realise two things - We’re not anywhere close to the start of this journey and the possible outcomes for the next 5-10 years have already started pointing in the same direction.
Here’s what has already come to pass in terms of the current EU sovereignty cascade:
If we plot a course from everything that has already transpired and extend it into the future, there are a few things that now seem likely:
So, with all this change on the horizon, how can providers prepare effectively? Unfortunately, there is no cut and dry answer as a lot depends on how you’re already set up, what your goals for the future are and where your organization plans to be in the next few years. A lot of it though boils down to two things – How you deliver services and how you manage them.
If you want to survive in the European markets, there are a number of things that you have to do to create a sovereign makeup. A rule of thumb is to ensure that you are not exposed to any non-EU laws such as the CLOUD Act and at the very least you need to be able to run at scale on European data centres with an eye on making your entire supply chain EU-native.
Are there ways to get around EU regulations for now? Yes absolutely, but the more workarounds you rely on, the more unstable your platform becomes as those loopholes start closing. There is also the national sovereignty levels that you should start considering if you’re operating in multiple countries – start thinking about how you’re going to be able to deliver your solution if you’re playing by multiple sets of rules simultaneously.
So you’ve got everything set up in a way that you can now deliver your services with nothing but European DNA running through your data-lines. Now you have to start thinking about the rules that surround how those services are managed because there is already an increasing focus not just on technical setups but practical ones as well. Is everyone you’re in partnership with headquartered in the EU, or the country that you’re delivering to? What about the staff that’s needed to run that service end-to-end? If your answer is no then you may need to start thinking about how much time and effort it’s going to take to insulate yourself from practical non-compliance.
Looking to figure out your EU sovereign future? Get in touch with the experts and start planning for your long-term success.