NVDA 212.06 ▲2.30%GOOGL 342.09 ▼1.46%MSFT 390.34 ▼1.86%AMD 552.33 ▲1.45%INTC 102.62 ▼2.68%TSMC 421.21 ▼0.80%AMZN 244.85 ▼1.09%META 627.17 ▼2.58%AAPL 325.89 ▼0.56%PLTR 124.57 ▼6.10%
Markets at last close

Infrastructure

EU cloud sovereignty plan faces proportionality test

·1 min read

The European Commission’s proposed Cloud and AI Development Act, or CADA, sits within the European Commission’s Technological Sovereignty Package and aims to reduce reliance on non-European cloud providers while expanding domestic cloud and AI infrastructure. Its main tools include support for research and adoption, faster data centre permitting, better access to energy and financing, and a cloud sovereignty framework that classifies services by European control.

The sovereignty model places heavy weight on ownership, establishment, jurisdiction and provider control. That approach may be relevant for highly sensitive workloads, but it risks treating provider nationality as a proxy for resilience in a global technology ecosystem built on cross-border hardware, software, personnel, subcontractors and support functions. Extraterritorial legal exposure is also broader than the U.S. CLOUD Act, with examples cited in the EU, UK, Canada and EU Member States.

A more proportionate framework would assess practical safeguards alongside corporate status. Relevant controls include legal challenge mechanisms, customer notification, encryption, customer-controlled key management, data residency commitments, access restrictions, supply chain resilience, continuity planning, portability and independent assurance. Risk-based regimes in the United States, Singapore, Australia and the UK offer alternatives that pursue security and sovereignty through audited controls rather than nationality-based exclusion.

Originally reported by cms.lawRead the source →
Related coverage