Cloud and AI Development Act: data hosting in Europe is no longer sufficient

TL;DR — On June 3, 2026, the European Commission published the Cloud and AI Development Act (CADA, COM(2026) 502). The proposed regulation establishes four sovereign assurance levels for cloud services and AI infrastructure. Level 4—the most demanding—requires that neither the provider nor its software supply chain be subject to the effective control of a third country. The physical location of servers within Europe is no longer sufficient to establish sovereignty. For neo-cloud providers serving customers in regulated industries, this framework already redefines the criteria used to select infrastructure operators.

On June 3, 2026, the European Commission published a proposed regulation that will apply directly across all twenty-seven EU Member States. The Cloud and AI Development Act (CADA, COM(2026) 502) addresses two long-standing and well-documented challenges: Europe’s shortage of AI computing capacity and its structural dependence on a small number of non-European cloud providers. Final adoption is expected by the end of 2027. Nevertheless, its core principles are already shaping the drafting of ongoing public procurement tenders.

The CADA does not operate as a prohibition. Instead, it conditions access to public procurement contracts on progressively stricter compliance requirements, depending on the sensitivity of the intended workload. In doing so, it builds on the logic of ANSSI’s SecNumCloud framework while elevating it into binding European legislation. Its key conceptual shift is straightforward: data residency and the provider’s legal control structure are now treated as two distinct qualification criteria.

The Cloud and AI Development Act’s Four-Level Assurance Framework

From Infrastructure Location to Ownership and Control

The CADA classifies cloud services and AI infrastructure into four assurance levels, numbered from 1 to 4. The lower levels impose familiar requirements: legal establishment within the European Union, data residency in Europe, transparency regarding subcontracting arrangements, and disclosure of data flows. These levels remain accessible to providers from a variety of backgrounds, including the European subsidiaries of U.S. cloud operators.

The intermediate levels introduce independent assessments, enhanced cybersecurity controls, and greater transparency across the software supply chain, particularly through the use of Software Bills of Materials (SBOMs). The framework fundamentally changes at Level 4. At this highest assurance level, providers must not be controlled by a third country, must hold at least a “High” level European cybersecurity certification, and must retain effective control over their entire software stack. Consequently, no third country may exert influence over the design, development, maintenance, or evolution of any software component.

Level 4 is primarily intended for the most sensitive use cases, particularly in defense and national security. Public-sector entities are required to conduct risk assessments to determine the appropriate assurance level. In practice, however, the compliance requirement extends throughout the supply chain: a neo-cloud provider serving institutional customers subject to Level 4 requirements must itself meet equivalent standards in order to remain eligible as a qualified supplier.

SecNumCloud: The Precedent—and Its Known Limitations

The CADA is explicitly inspired by ANSSI’s SecNumCloud framework, version 3.2 of which was published in 2022. That framework includes immunity requirements against extraterritorial legislation—most notably the U.S. CLOUD Act and FISA Section 702—which effectively exclude the European subsidiaries of U.S. cloud providers from certification for sensitive public-sector systems. ANSSI itself has nevertheless acknowledged the limitations of certifications granted to French legal entities that remain technologically dependent on an American hyperscaler for their infrastructure or software layers. This is precisely the gap that Level 4 of the CADA seeks to address by adding the requirement for effective control over the entire software supply chain.

The U.S. CLOUD Act and the Limits of Technological Dependence

A Well-Documented Extraterritorial Reach

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was enacted in the United States in 2018. It authorizes U.S. authorities to require any company subject to U.S. jurisdiction to provide access to data that it possesses or controls, regardless of where that data is physically stored. This obligation applies to any company whose parent organization is incorporated in the United States, irrespective of the location of its servers.

During parliamentary hearings in France, representatives of major U.S. cloud providers acknowledged that their European subsidiaries could not guarantee immunity from disclosure orders issued under the CLOUD Act. As a result, hosting data within Europe remains a necessary compliance requirement for CADA Levels 1 through 3, but it is no longer sufficient to satisfy the requirements of Level 4.

Why a European Subsidiary Is Not Enough

A U.S. cloud provider may establish a French legal entity, appoint European directors, and host all customer data exclusively in France. Such measures are sufficient to comply with CADA Levels 1 through 3. They do not, however, satisfy the requirements of Level 4, because the provider’s ownership and control structure ultimately remains subject to U.S. law. Furthermore, if the provider relies on software components developed and maintained by its U.S. parent company, Level 4 compliance is also unattainable from a software sovereignty perspective.

As a result, certification is no longer determined solely by where data is stored. It now depends on two cumulative conditions: the absence of effective control by a third country over the legal entity itself, and the absence of dependence on a third country for the provider’s software supply chain. These two requirements form the legal foundation of Level 4 under the Cloud and AI Development Act.

Preparing for CADA in Infrastructure Decisions

The CADA proposal is still under review by the European Parliament. Nevertheless, many organizations are already incorporating its requirements into their supplier selection processes. This reflects a simple operational reality: infrastructure commitments in the data center industry typically span several years. An agreement signed in 2026 is likely to remain in force when the regulation comes into effect. Anticipating the required compliance level today helps organizations avoid costly infrastructure migrations driven by future regulatory obligations.

For this reason, the applicable CADA assurance level is already becoming an evaluation criterion for neo-cloud providers developing their medium-term infrastructure strategies. In practice, this means determining today whether the ownership and control structure of an infrastructure operator is compatible with the requirements of the provider’s most highly regulated customers, and documenting that compliance within its own supplier qualification process.

Voltekko and CADA Level 4 Compliance

Voltekko is a French colocation provider specializing in high-density AI infrastructure. Its financial backing is provided by REED, a subsidiary of Société Générale Group. Its operational partner is EQUANS, a subsidiary of Bouygues. Both organizations are incorporated under French law and are not subject to any foreign extraterritorial jurisdiction. Voltekko does not rely on any non-European hyperscaler for its operations or software supply chain. As a result, its organizational structure is compatible with the control requirements established by Level 4 of the Cloud and AI Development Act.

Frequently Asked Questions

What is the Cloud and AI Development Act?

The Cloud and AI Development Act (CADA, COM(2026) 502) is a proposed European regulation with direct applicability, published on June 3, 2026. It establishes four sovereign assurance levels for cloud services and AI infrastructure. This framework conditions access to public procurement contracts on increasingly stringent requirements relating to security, resilience, and sovereignty. Final adoption is expected by the end of 2027, but its principles are already influencing ongoing provider qualification processes.

Is hosting servers in Europe sufficient to achieve CADA Level 4?

No. The physical location of servers within Europe is required for the lower assurance levels, but it is not sufficient for Level 4. At this level, the CADA requires that the provider is not controlled by a third country and that no third country exercises effective control over its software supply chain. A provider whose parent company is based in the United States remains subject to the CLOUD Act, regardless of where its infrastructure is physically located. It therefore does not meet the requirements for Level 4.

Does the CADA apply only to public procurement contracts?

The CADA proposal directly conditions access to public contracts according to the required assurance level. However, its impact extends beyond this scope. Neo-cloud providers whose institutional customers are subject to high assurance requirements must themselves meet equivalent criteria in order to remain qualified suppliers. As a result, CADA compliance will progressively propagate upstream through the value chain of cloud services and AI infrastructure intended for regulated organizations.

Contact Voltekko to learn more about our infrastructure and sovereign compliance.

This article might interest you as well Announced Gigawatts vs. Connected Megawatts: what RTE reveals about AI colocation providers?