{slide.module_style.background.background_image.alt}

What is CADA?

CADA (the Cloud and AI Development Act) is a proposed EU regulation designed to strengthen Europe's cloud and AI ecosystem. The EU Commission, who is in charge of building CADA did so with two problems that it sees as strategic vulnerabilities in mind.

The first is a capacity deficit. Europe simply doesn't have enough data-centre capacity to meet its own future demand for cloud computing and AI, and much of what it does have is concentrated in a handful of locations. The second is dependence - A large share of European cloud workloads are currently handled by three US hyperscalers whose operations are ultimately subject to foreign law and interference. No European organisation owns more than 2% of EU cloud infrastructure, with EU companies owning less than 15% all put together.

To tackle both of these issues, CADA has three combined missions:

    • Research and innovation to support European capability in cloud and AI technologies.
    • Data-centre capacity to expand the physical infrastructure the EU can call its own.
    • Autonomy to reduce strategic dependence on providers outside the EU's legal reach.

That third mission is where the most talked-about mechanism lives – A four-level framework for classifying how sovereign a cloud service really is. We'll come back to it, because for most providers it's the part that’s of the utmost importance.

The four level sovereignty framework of CADA

This is the heart of CADA and the part most likely to affect your business directly. The proposal introduces an assurance framework that classifies cloud services into four levels of sovereignty. In broad terms:

    • Level 1 - Data is processed and stored on infrastructure located in the EU. This is the entry point, closest to today's data residency thinking.
    • Level 2 The provider must additionally demonstrate independence from third countries and provide transparency over its software supply chain.
    • Level 3 The service must be owned and controlled from within the EU, meeting further criteria such as personnel citizenship or clearance.
    • Level 4 The entire supply chain for a service must under no circumstances be open to interference of any kind from non-EU country.

These levels are assessed against a set of criteria that go well beyond where the servers sit: control over the service itself, control over the supply chain, how data is treated, the location of the infrastructure, and the provider's cybersecurity posture.

In no uncertain terms, with the introduction of CADA, sovereignty is no longer about geography, but rather control in every sense of the word. A provider can store every byte of data that even grazes their systems in an EU data centre and still fall short of the higher levels of assurance. Whereas this just affects public sector functions for now, which you may be willing to let slide, it’s only a matter of time before private enterprises also require certain assurances to shield themselves from external risk.

CADA as a part of the EU Tech Sovereignty Package

CADA isn’t being rolled out in solitude. It's one component of the much larger, and wide-reaching EU Tech Sovereignty Package, a coordinated agenda that spans the full technology stack. Alongside CADA, the package includes a Chips Act 2.0 aimed at semiconductor capability, an Open Source Strategy, initiatives around energy digitalisation, and a broader push to accelerate AI adoption across the European economy.

Throughout the entirety of this package, there is one idea that tightly connects everything – The overall idea of a digitally sovereign Europe. For years the EU has been calling for greater control over the infrastructure, data, and supply chains its society and economy depend on, rather than relying on foreign providers it cannot fully govern and CADA is a big part of making this happen. But digital independence isn't about shutting the door on global technology companies, it's about reducing the risk that comes with depending on systems subject to another country's laws, priorities, and geopolitics.

For providers, the takeaway is that CADA is part of a durable, long-term direction in European policy, not a one-off piece of legislation they can simply ignore.

Who is affected by CADA?

CADA targets providers of cloud and AI infrastructure services, with cloud communications being no exception. Importantly, larger providers and hyperscalers are not excluded but they will be subject to enhanced obligations tied to the assurance levels. Unlike other less impactful legislation however, CADA Certification is quickly becoming a likely condition of market access. Think of it this way – things like GDPR have set the legal rules around data, CADA is here to be the operational muscle that’s more attuned to modern technology and market demands. Right from the get-go, meeting the right assurance level will determine whether you're even allowed to bid for certain business.

CADA and the compliance cascade

CADA doesn't replace the existing web of EU digital regulation, it helps each disparate piece of legislation work seamlessly with the next. More importantly it prepares the way for more refined rulings in a compliance cascade. If you already navigate GDPR, the Data Act, the Digital Markets Act, the AI Act, NIS2, and DORA, CADA adds a sovereignty dimension that interacts with all of them, and it sits alongside the pending EU Cloud Services Scheme (EUCS) for cybersecurity certification.

As more and more of these policies emerge, providers are going to have to navigate more stringent rules, with ripple effects almost guaranteed to occur. This also may not be limited to single EU-wide legislation even in the near future, with national legislation already starting to emerge in markets such as Germany, the Netherlands and France.

Compliance Cascade Timeline (1)

What CADA means for the global communications market

For the communications sector, CADA and the tech package that it’s a part of signal a more assertive European digital policy which is now willing to use certain effective levers to reshape the market itself.

Going forward, how deeply European you are is a lot more likely to become a competitive moat if you build it correctly. Providers that can credibly demonstrate higher assurance levels will have access to business that others simply cannot touch, turning sovereignty into a differentiator rather than a cost.

Providers will face pressure to localise and restructure. Meeting anything but the lowest tiers may require changes to ownership, supply chains, data flows, and even staffing, all decisions with long lead times that reward early planning or working with the right partner.

There are even those that think the effects of CADA won't stay in Europe. As the EU sets expectations around control and jurisdiction, global cloud strategies will adapt to serve the European market, much as GDPR reshaped data practices far beyond the EU's borders.

For cloud and SaaS providers, the sensible response is to start now: map where your services fall against the four assurance levels, review your supply chains and data flows for third-country exposure, and identify the gaps between where you are and the level your target customers will require.

Not sure what to do about CADA? If you'd like to understand where your services stand and what to prioritise, book a consultation with our team. We'll help you map your compliance position and plan your next steps.