Protectionism in the name of digital sovereignty
At the heart of the Cloud and AI Development Act is the concept of digital sovereignty. The proposal translates this idea into a four-tier framework that classifies cloud and AI providers by ownership, legal jurisdiction, and operational control. The higher the tier, the stricter the requirements, with the highest levels reserved primarily for European-owned and European-controlled providers. In practice, this means that governments would increasingly favor European-controlled providers when purchasing cloud services for sensitive sectors such as healthcare, finance, energy, defense, and public administration.
The rationale behind this approach is Europe’s growing concern over its dependence on foreign technology providers. Policymakers fear that foreign laws—especially the US CLOUD Act—could allow authorities outside the European Union to access sensitive European data. Yet CADA moves well beyond narrowly defined security safeguards. Rather than evaluating providers primarily on measurable standards such as encryption, cybersecurity certification, operational resilience, and independent audits, the proposal places considerable weight on nationality, ownership, corporate headquarters, and even personnel citizenship.
Security should be judged by outcomes, not nationality. Providers should qualify by demonstrating that their systems are secure, reliable, and resilient—not simply because their owners or employees are European. A European company with weaker safeguards should not receive an automatic advantage over a rigorously audited American, Japanese, or British provider offering stronger protection.
This emphasis on nationality also extends to CADA’s public procurement rules. Providers receive additional credit for their “Union added value,” including the European share of their research, hardware, and supply chains. As a result, public contracts would increasingly be awarded not only on price, quality, reliability, and security, but also on where a company is based.
Supporters argue that this approach is necessary to curb the dominance of Amazon Web Services, Microsoft Azure, and Google Cloud, which together control about
























