
Deep Dive into the EU Cloud and AI Development Act Proposal
This course follows the European Commission’s proposed Cloud and AI Development Act from its explanatory memorandum and operative articles through its financial statement, digital implementation plan, and technical annexes. Learners will be able to interpret the proposal’s capacity-building, sovereignty, procurement, open-source, enforcement, financing, and audit mechanisms as an integrated Union regulatory framework.
Course Content
17 modules · 6h 2m total
Why Europe Proposes a Cloud and AI Development Act
Europe’s computing infrastructure is concentrated, capacity-constrained, and dependent on a small number of non-EU providers. Opening with the proposal’s institutional status and structure, this module examines the Commission’s diagnosis, objectives, and positioning within the wider EU digital policy landscape.
Legal Authority, Evidence, Resources, and the Article Map
What gives the Union authority to establish this framework, and why is a directly applicable regulation considered necessary? The memorandum moves from legal justification and consultation evidence to staffing, monitoring, and a consolidated map of the operative provisions.
From Legislative Rationale to Cloud and AI Leadership
The formal proposal turns the memorandum’s policy case into legislative reasoning. Its opening recitals frame technological sovereignty and then set an ambitious agenda spanning sustainable infrastructure, autonomous cloud technology, advanced AI, skills, and public-sector adoption.
Implementation Architecture and Accelerated Data-Centre Deployment
Ambition requires institutions, financing, national coordination, and places where infrastructure can be built quickly. These recitals connect Centres for AI and frontier projects to acceleration zones, grid planning, sustainability indicators, permitting reform, and capacity-gap monitoring.
The Sovereignty Risk Model and Public-Sector Demand
Foreign control, extraterritorial law, concentration, and disruption become the basis for a four-level Union assurance system. The recitals then translate those risks into audits, supervision, public-sector assessments, procurement requirements, and a carefully qualified route for some third-country-controlled providers.
Federation, Common Purchasing, Open Source, and General Rules
The proposal couples sovereignty requirements with practical market-shaping tools: a public-sector cloud federation, Commission-led purchasing, and reusable open-source software. The closing recitals and Title I also establish the principles, objectives, and definitions needed to interpret every later obligation.
Operational Leadership and Europe’s Capacity Build-Out
The operative articles turn leadership goals into assigned responsibilities, national strategies, priority projects, and infrastructure procedures. Learners follow the path from a grand challenge or frontier AI project to a designated acceleration zone and possible strategic-project status.
Proving and Enforcing Cloud Sovereignty
A sovereignty label has value only if evidence is credible and enforcement works across borders. These articles specify self-assessment, independent audits, repository disclosures, penalties, competent-authority powers, cooperation, and the procurement consequences of assigned assurance levels.
Building a Shared Public-Sector Cloud Market
The proposal seeks not merely to regulate cloud purchasing but to aggregate it, share public resources, and steer demand toward European value and innovative firms. This module examines procurement quality criteria, the EuroCloud platform, central purchasing governance, open-source reuse, and the final legal machinery.
Policy Ambitions, Performance Indicators, and Management Controls
The legislative financial statement restates the proposal as a programme that must be financed, measured, and controlled. Its targets reach toward 2030 and 2035, while its management model anticipates startup risks, direct Commission administration, fraud controls, and fee-supported operations.
Appropriations, Staffing, and the New Administrative Workload
Policy commitments become concrete in budget lines, staffing tables, and task assignments. This module examines the projected appropriations for 2028–2034, the 25-FTE model, and how officials and external staff divide policy, enforcement, platform, procurement, and project-management work.
Fee Revenue and the Proposal’s Digital Requirements
Joint procurement and EuroCloud are designed to finance substantial parts of their own administration, but participation and cost recovery introduce uncertainty. Alongside that revenue model, the proposal creates a broad inventory of digital processes involving applications, notifications, audits, repositories, and platforms.
Data Governance, Operational Flows, and Interoperable Platforms
The framework depends on information moving reliably among providers, auditors, national authorities, the Commission, public bodies, and the public. This module traces those flows and evaluates the planned repository, federation, procurement, and open-source systems against EU data, cybersecurity, identity, and interoperability principles.
Legal Sourcework and the Eight Grand Challenges
The references reveal the dense legal and policy environment in which the proposal sits, while Annex I turns strategic ambition into eight defined technology missions. Together they show both where the framework comes from and which capabilities it aims to produce.
Assurance Levels 1 and 2: The Baseline Sovereignty Tests
Annex II makes the abstract assurance framework operational through cumulative legal, technical, and organizational criteria. Levels 1 and 2 establish the baseline tests for Union establishment, data location, cybersecurity, operational autonomy, foreign influence, and software integrity.
Assurance Levels 3 and 4 and the Evidence Behind Them
The highest assurance levels demand increasingly deep Union control over infrastructure, personnel, support, data, and software. Annex III then begins the auditor’s evidence trail, showing how genuine establishment, localization, assets, personnel, and Union-citizen support capacity may be tested.
Auditing Control, Software Integrity, and Operational Separation
The final audit criteria probe beneath formal corporate structures into ownership chains, governance rights, financial dependence, technical support, software features, and foreign-government access. Closing the course, this module uses that evidence framework to consolidate how the proposal combines industrial expansion, sovereign assurance, public demand, and enforceable technical controls.
Read the Textbook
Read every chapter for free, right here in your browser.
Institutional status and reading map
The document is COM(2026) 502 final, dated 3 June 2026, and numbered 2026/0138(COD). It is a Commission proposal for a Regulation establishing a framework of measures for strengthening Europe's cloud and AI ecosystem, called the Cloud and AI Development Act.
Currency check As of 20 July 2026, the ordinary legislative procedure for 2026/0138(COD) is listed as ongoing. Therefore, this module teaches the Commission's proposed text and explanatory memorandum; it does not describe a Regulation that has already been finally adopted, amended, or entered into force.
Study Flashcards
Key concepts from this course as flashcard pairs.
Why Europe Proposes a Cloud and AI Development Act
Cloud and AI Development Act
The proposed Regulation in COM(2026) 502 final. As of 20 July 2026, it remains an ongoing legislative proposal, not a finally adopted Regulation.
EU provider market-share finding
the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.
Hyperscaler concentration finding
Currently, three non-EU hyperscalers control over 70% of the European cloud market.
Sovereignty framework
a harmonised and auditable set of criteria at different levels of sovereignty of cloud computing services.
Operational autonomy
A sovereignty concern beyond data transfer rules: it concerns dependence on external actors for continuing service operation.
Data Act's role
An enabler through switching and interoperability, but not a measure that itself builds a sovereign and trusted EU cloud sector.
+2 more flashcards
Legal Authority, Evidence, Resources, and the Article Map
What is the internal-market legal basis?
The legal basis for this proposal is Article 114 of the Treaty on the Functioning of the European Union (TFEU).
What is the industrial legal basis?
The proposal draws on Article 173(3) TFEU.
How many consultation responses were received?
436 total: 243 for the consultation survey and 193 for the call for evidence.
What was the impact assessment opinion?
On 8 May 2026, the Board issued a positive opinion accompanied by a request for further improvements.
What is the total staffing requirement?
25 FTEs: 9 establishment plan posts and 16 contract agent posts.
When must Member States adopt national cloud and AI strategies?
Within one year of the Regulation's entry into force, under Article 7.
+3 more flashcards
From Legislative Rationale to Cloud and AI Leadership
Treaty bases in the formal preamble
"in particular Article 114 and Article 173(3) thereof"
Strategic priority in recital (4)
"Reinforcing the Union's capacity to develop and deploy cloud and AI technologies within its territory has become a strategic priority"
What is excluded from the recital (10) cloud-service definition?
The AI system itself and its underlying model. The definition covers only delivery and making available of the AI system.
Leadership objective in recital (11)
"increase the cloud and data centre capacity of the Union, while advancing cutting-edge cloud and AI technologies together with broad cloud and AI adoption"
Physical AI
"AI systems and models capable of perceiving the physical environment and executing complex actions within that environment"
Public-sector adoption objective
"increase the development and adoption of AI models and systems across the Union's public sector."
Implementation Architecture and Accelerated Data-Centre Deployment
EuroCloud Federation
The European public-sector cloud federation supported under the Regulation to facilitate sharing of secure and resilient public-sector data-centre services and cloud-computing services.
Centres for AI
Experience and acceleration centres for AI that Member States should establish with appropriate territorial coverage to accelerate uptake and deployment of AI, cloud and other advanced technologies.
AI first principle
A principle defined in the Apply AI Strategy: organisations should reflect on business processes, consider AI needs and opportunities, and take potential risks into account.
Frontier AI priority project
A designated project supporting development and scale-up of frontier AI technologies, requiring a collaborative Union-level approach and broad participation across the Union.
Data centre acceleration zone
A designated area intended to facilitate development, expansion or modernisation of data centres at scale and speed within a clear and streamlined regulatory framework.
Aggregated baseline permit
A permit reflecting the characteristics of an acceleration zone and covering permits commonly required for activities in the area, excluding grid connection permits.
+1 more flashcards
The Sovereignty Risk Model and Public-Sector Demand
Dependency risk
The recital's core diagnosis is: "The Union still remains critically dependent on a limited number of cloud computing service providers subject to the control of third countries".
Union assurance levels
A four-level framework of trusted offers. It is intended to support proportionate protection of public order and public-sector control and agency.
Level 1 evidence route
The provider has sole responsibility for conformity self-assessment, using documented evidence, internal control procedures, and continuous monitoring.
Levels 2-4 evidence route
Applicable criteria are verified by third-party independent experts through an independent audit, report, and opinion.
Positive audit opinion
It should be given where all evidence shows that the provider complies with the applicable audit criteria and obligations.
Public-order risk assessment
Member States and Union entities should determine which public-sector activities concern public order and what assurance level is appropriate.
+2 more flashcards
Federation, Common Purchasing, Open Source, and General Rules
EuroCloud purpose
It should "facilitate the sharing of such capabilities between Union entities and public-sector bodies."
Who may participate directly in EuroCloud?
"Participation within the EuroCloud Federation should be limited to public entities, without direct participation of a private party."
Intermediate-entity activity threshold
More than 80% of its activities must be carried out in performing tasks entrusted to it by the sharing entity.
EuroCloud cost-recovery rule
Charges are permitted only where "the charges are limited strictly to what is necessary and proportionate to recover the costs incurred by the sharing entity" for the beneficiary using entity.
Minimum approval for the procurement agreement
It enters into force under its provisions, "subject to the approval of at least two Member States."
Why does the text support open source?
"Access to the source code enables auditability, fosters collaboration and reuse and reduces dependency on a single vendor".
+2 more flashcards
Operational Leadership and Europe’s Capacity Build-Out
Centres for AI
Article 5 requires: "Each Member State shall establish Experience and Acceleration Centres for AI". They build on European digital innovation hubs and support adoption, skills, expertise transfer, and start-up scaling.
National strategy deadline
"By [same day as entry into force plus one year], Member States shall establish national cloud and AI strategies". The supplied proposal leaves the entry-into-force date unspecified.
Frontier AI participation threshold
For an Article 8 project, "it involves the participation of at least three Member States;". Participating Member States also pool computing time and other relevant resources.
Union compute matching
"The Union shall at least match the AI computing resources contributed by Member States" where sufficient capacity is available in the Union share of European HPC access time.
Acceleration-zone permit
"Member States shall prepare and issue an aggregated baseline permit authorising the deployment of data centres in that acceleration zone." Installation-specific permits remain outside it.
Strategic-project threshold
A project must "fulfil at least two of the following criteria:" in Article 14, after selection through an open call for expressions of interest.
+2 more flashcards
Proving and Enforcing Cloud Sovereignty
What evidence route applies to Union assurance level 1?
Article 19 requires provider conformity self-assessment against Annex II level 1 criteria, followed by an EU statement of conformity made publicly available.
What assurance levels require independent third-party audits?
Levels 2, 3, and 4. The provider undergoes the audit at its own expense to obtain an audit report and audit opinion.
What does cumulative compliance mean in Article 20?
A provider audited at a higher level must meet all applicable lower-level criteria. Failure on any lower-level requirement precludes higher-level conformity.
What is the auditor's long rotation restriction?
The auditor must not have provided Article 20 auditing services to the provider or a connected legal person during the 10-year period before the audit begins.
How long must revocations remain in the central repository?
Five years. This applies to the specified revocation of an audit report and opinion or revocation of recognition.
Which authority normally enforces a provider's compliance?
The competent authority in the Member State of the provider's main establishment, which has exclusive competence for enforcing this Chapter.
+1 more flashcards
Building a Shared Public-Sector Cloud Market
EuroCloud Federation participation
It is voluntary for Union entities and public sector bodies. They may request the Commission to join.
Sharing entity
A EuroCloud member that shares services. It must own the relevant hardware directly or indirectly and provide the service; indirect ownership requires control over the intermediate legal entity.
Using entity
A EuroCloud member receiving data centre or cloud-computing services from a sharing entity.
Sharing-service fee limit
"The amount of the fee shall be limited to the costs that the sharing entity incurs in relation to the sharing of the service" and must not constitute a pecuniary interest under the cited rules.
Minimum Article 38 agreement
The Commission and at least two Member States must enter into an agreement before Chapter IV procurement activity.
Dynamic purchasing system late-access ceiling
Cumulative requests must not exceed 50% of the initial estimated quantities of envisaged purchases.
+4 more flashcards
Policy Ambitions, Performance Indicators, and Management Controls
What is the proposal's short title?
Short title: "The Cloud and AI Development Act (CADA)"
What is the 2030 data-centre capacity objective?
By 2030, the EU should at least triple its current data centre capacity
What is the 2030 permitting objective?
By 2030, operators should be able to obtain all permits to build and run a data centre in less than 18 months throughout the EU
What is the 2035 critical-use objective?
By 2035, highly critical use cases in the public sector should be operated using sovereign cloud and AI computing services
When should application begin under section 1.5.1?
The entry into application should be within one year of publication
How many FTEs are estimated overall, and how many are redeployable?
25 FTEs are estimated overall. 15 of the 25 estimated FTEs could be covered through redeployment.
+2 more flashcards
Appropriations, Staffing, and the New Administrative Workload
What is the source's voted operational total for 2028-2034?
EUR "9.323" million in commitments, with the same grand total for payments.
What is the total administrative appropriation under Heading 4?
EUR "25.228" million, entirely attributed to human resources in the table.
What is the fee-financed operational total?
EUR "54.326" million for EuroCloud and Joint Cloud Procurement.
How many FTEs are forecast each year from 2028 through 2034?
25 FTEs each year: 11 establishment-plan posts and 14 external staff.
How many requested FTEs are already in place and redeployed?
15 FTEs: 5 establishment-plan posts and 10 external staff.
What distinguishes officials' work from external staff work in this source?
Officials handle programme design, legal and governance work, guidance, monitoring, and enforcement coordination. External staff handle recurring project management, studies, support, procurement operations, and contractor oversight.
+1 more flashcards
Fee Revenue and the Proposal’s Digital Requirements
When does collection of both fees start?
The stated starting date is 2029, allowing an initial setup process.
What cost ceiling applies to Joint Procurement fees?
"The fees charged to the participating contracting authorities shall not exceed the verifiable costs incurred by the Commission."
What average Joint Procurement fee rate is projected?
"an average annual fee rate of 2% applied to the spending per authority."
What are the EuroCloud membership-fee reference points?
"the membership fee could be set at around EUR 75 000 per member" and "reach around EUR 30 000 per member once full capacity is achieved."
How long must a recognition revocation remain published?
5 years in the central register.
Which Article 34 action is mandatory?
"The Commission shall establish a platform for the EuroCloud Federation."
+2 more flashcards
Data Governance, Operational Flows, and Interoperable Platforms
Audit-data quality
Data quality: sufficiently complete and reliable; minimum content for audits.
National-strategy notification deadline
Member States notify the European Commission within three months of the adoption of a national strategy; the flow occurs per adoption or revision.
Once-only principle
The once-only principle has been duly considered and will systematically be enforced wherever relevant.
FAIR-style implementation
Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data.
Cross-border response
The competent authority of origin sends the assessment outcome to requestors and the Commission within two months of a request being made.
Risk-assessment frequency
Bi-annually.
+4 more flashcards
Legal Sourcework and the Eight Grand Challenges
PUE target
Grand Challenge 1 seeks "an average Power Usage Effectiveness (PUE) of 1.15 across the Union."
Server-utilisation direction
Grand Challenge 1 calls for "raising average server utilisation rates across the Union’s data centres towards 50%".
Cloud stacks
"Building end-to-end hardware and software cloud stacks, including AI tools, infrastructure, services and management layers" is Grand Challenge 2.
Cooperative model safeguard
Grand Challenge 6 enables industrial-scale collaboration "without exposing commercially sensitive data between participants."
Public Sector AI
"Developing AI models and systems, based on high-quality data from the public sector targeting critical domains" is Grand Challenge 8.
Differentiated appropriations
"Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations."
+1 more flashcards
Assurance Levels 1 and 2: The Baseline Sovereignty Tests
Cumulative criteria
Every listed criterion for the relevant assurance level must be met; satisfying only some criteria is insufficient.
Level 1 data residency
Customer data, including metadata and telemetry data, must remain exclusively within the Union unless the public sector body explicitly requires otherwise, including before, during, and after configuration or use.
Level 1 outsourced support
Support outside the Union may occur only with legal, technical, and organisational measures for traceability, security, and governance that do not compromise operational autonomy.
Level 2 cybersecurity
The specified European certificate must be at least assurance level substantial when the relevant Union scheme has been established and is available.
SBOM
A complete and up-to-date software bill of materials, plus relevant identified dependencies, must be documented and made available to the auditing organisation at Level 2.
Level 2 support
Technical and operational support for the audited service, including subsequent sub-outsourcing, must be initiated and performed exclusively within the Union.
Assurance Levels 3 and 4 and the Evidence Behind Them
Level 3 personnel rule
the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens
Level 3 baseline control rule
are not subject to the control of a third country or a legal entity established in a third-country.
Level 4 cybersecurity threshold
a European cybersecurity certificate of at least assurance level 'high'
Level 4 sensitive-data residency
remain exclusively within the Union and at any time
Effective software control
Effective control includes the ability to materially influence the technical evolution, maintenance priorities, security remediation, and long-term continuity of the component;
Annex III evidence status
This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.
+2 more flashcards
Auditing Control, Software Integrity, and Operational Separation
What does Criterion E require as its primary certification evidence?
A valid European cybersecurity certificate issued by a competent conformity assessment body, showing assessment and compliance at basic, substantial, or high assurance under an established European scheme adopted under Regulation (EU) 2019/881.
What is the exact AI purpose-limitation clause in Criterion F?
data are processed solely for the delivery of the audited service and not for service improvements or model or system enhancements or any other secondary purpose.
What is the ownership disclosure threshold in section 7.1?
hold, directly or indirectly, at least 5% of the capital or at least 5% of the voting rights
What five factor groups must be considered when assessing control?
ownership structures and specific rights, corporate governance, commercial links conferring control, financial links conferring control and any other sources of control.
What does Criterion H say about where support activities occur?
all support, administration, maintenance, monitoring, incident response, and operational activities must be initiated and performed exclusively in the Union.
What source-code right is mandatory under Criterion I?
the third-party independent auditor is granted the right to access and audit the source code of such software.
+1 more flashcards