SkarpSkarp
Deep Dive into the EU Cloud and AI Development Act Proposal
💻 TechnologyAdvanced6h 2m17 modules

Deep Dive into the EU Cloud and AI Development Act Proposal

This course follows the European Commission’s proposed Cloud and AI Development Act from its explanatory memorandum and operative articles through its financial statement, digital implementation plan, and technical annexes. Learners will be able to interpret the proposal’s capacity-building, sovereignty, procurement, open-source, enforcement, financing, and audit mechanisms as an integrated Union regulatory framework.

by Skarp_officialen

Course Content

17 modules · 6h 2m total

1

Why Europe Proposes a Cloud and AI Development Act

Europe’s computing infrastructure is concentrated, capacity-constrained, and dependent on a small number of non-EU providers. Opening with the proposal’s institutional status and structure, this module examines the Commission’s diagnosis, objectives, and positioning within the wider EU digital policy landscape.

20 min
2

Legal Authority, Evidence, Resources, and the Article Map

What gives the Union authority to establish this framework, and why is a directly applicable regulation considered necessary? The memorandum moves from legal justification and consultation evidence to staffing, monitoring, and a consolidated map of the operative provisions.

23 min
3

From Legislative Rationale to Cloud and AI Leadership

The formal proposal turns the memorandum’s policy case into legislative reasoning. Its opening recitals frame technological sovereignty and then set an ambitious agenda spanning sustainable infrastructure, autonomous cloud technology, advanced AI, skills, and public-sector adoption.

20 min
4

Implementation Architecture and Accelerated Data-Centre Deployment

Ambition requires institutions, financing, national coordination, and places where infrastructure can be built quickly. These recitals connect Centres for AI and frontier projects to acceleration zones, grid planning, sustainability indicators, permitting reform, and capacity-gap monitoring.

24 min
5

The Sovereignty Risk Model and Public-Sector Demand

Foreign control, extraterritorial law, concentration, and disruption become the basis for a four-level Union assurance system. The recitals then translate those risks into audits, supervision, public-sector assessments, procurement requirements, and a carefully qualified route for some third-country-controlled providers.

23 min
6

Federation, Common Purchasing, Open Source, and General Rules

The proposal couples sovereignty requirements with practical market-shaping tools: a public-sector cloud federation, Commission-led purchasing, and reusable open-source software. The closing recitals and Title I also establish the principles, objectives, and definitions needed to interpret every later obligation.

29 min
7

Operational Leadership and Europe’s Capacity Build-Out

The operative articles turn leadership goals into assigned responsibilities, national strategies, priority projects, and infrastructure procedures. Learners follow the path from a grand challenge or frontier AI project to a designated acceleration zone and possible strategic-project status.

22 min
8

Proving and Enforcing Cloud Sovereignty

A sovereignty label has value only if evidence is credible and enforcement works across borders. These articles specify self-assessment, independent audits, repository disclosures, penalties, competent-authority powers, cooperation, and the procurement consequences of assigned assurance levels.

23 min
9

Building a Shared Public-Sector Cloud Market

The proposal seeks not merely to regulate cloud purchasing but to aggregate it, share public resources, and steer demand toward European value and innovative firms. This module examines procurement quality criteria, the EuroCloud platform, central purchasing governance, open-source reuse, and the final legal machinery.

22 min
10

Policy Ambitions, Performance Indicators, and Management Controls

The legislative financial statement restates the proposal as a programme that must be financed, measured, and controlled. Its targets reach toward 2030 and 2035, while its management model anticipates startup risks, direct Commission administration, fraud controls, and fee-supported operations.

20 min
11

Appropriations, Staffing, and the New Administrative Workload

Policy commitments become concrete in budget lines, staffing tables, and task assignments. This module examines the projected appropriations for 2028–2034, the 25-FTE model, and how officials and external staff divide policy, enforcement, platform, procurement, and project-management work.

16 min
12

Fee Revenue and the Proposal’s Digital Requirements

Joint procurement and EuroCloud are designed to finance substantial parts of their own administration, but participation and cost recovery introduce uncertainty. Alongside that revenue model, the proposal creates a broad inventory of digital processes involving applications, notifications, audits, repositories, and platforms.

21 min
13

Data Governance, Operational Flows, and Interoperable Platforms

The framework depends on information moving reliably among providers, auditors, national authorities, the Commission, public bodies, and the public. This module traces those flows and evaluates the planned repository, federation, procurement, and open-source systems against EU data, cybersecurity, identity, and interoperability principles.

20 min
14

Legal Sourcework and the Eight Grand Challenges

The references reveal the dense legal and policy environment in which the proposal sits, while Annex I turns strategic ambition into eight defined technology missions. Together they show both where the framework comes from and which capabilities it aims to produce.

22 min
15

Assurance Levels 1 and 2: The Baseline Sovereignty Tests

Annex II makes the abstract assurance framework operational through cumulative legal, technical, and organizational criteria. Levels 1 and 2 establish the baseline tests for Union establishment, data location, cybersecurity, operational autonomy, foreign influence, and software integrity.

15 min
16

Assurance Levels 3 and 4 and the Evidence Behind Them

The highest assurance levels demand increasingly deep Union control over infrastructure, personnel, support, data, and software. Annex III then begins the auditor’s evidence trail, showing how genuine establishment, localization, assets, personnel, and Union-citizen support capacity may be tested.

20 min
17

Auditing Control, Software Integrity, and Operational Separation

The final audit criteria probe beneath formal corporate structures into ownership chains, governance rights, financial dependence, technical support, software features, and foreign-government access. Closing the course, this module uses that evidence framework to consolidate how the proposal combines industrial expansion, sovereign assurance, public demand, and enforceable technical controls.

22 min

Read the Textbook

Read every chapter for free, right here in your browser.

Institutional status and reading map

The document is COM(2026) 502 final, dated 3 June 2026, and numbered 2026/0138(COD). It is a Commission proposal for a Regulation establishing a framework of measures for strengthening Europe's cloud and AI ecosystem, called the Cloud and AI Development Act.

Currency check As of 20 July 2026, the ordinary legislative procedure for 2026/0138(COD) is listed as ongoing. Therefore, this module teaches the Commission's proposed text and explanatory memorandum; it does not describe a Regulation that has already been finally adopted, amended, or entered into force.

Study Flashcards

Key concepts from this course as flashcard pairs.

Why Europe Proposes a Cloud and AI Development Act

Cloud and AI Development Act

The proposed Regulation in COM(2026) 502 final. As of 20 July 2026, it remains an ongoing legislative proposal, not a finally adopted Regulation.

EU provider market-share finding

the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.

Hyperscaler concentration finding

Currently, three non-EU hyperscalers control over 70% of the European cloud market.

Sovereignty framework

a harmonised and auditable set of criteria at different levels of sovereignty of cloud computing services.

Operational autonomy

A sovereignty concern beyond data transfer rules: it concerns dependence on external actors for continuing service operation.

Data Act's role

An enabler through switching and interoperability, but not a measure that itself builds a sovereign and trusted EU cloud sector.

+2 more flashcards

Legal Authority, Evidence, Resources, and the Article Map

What is the internal-market legal basis?

The legal basis for this proposal is Article 114 of the Treaty on the Functioning of the European Union (TFEU).

What is the industrial legal basis?

The proposal draws on Article 173(3) TFEU.

How many consultation responses were received?

436 total: 243 for the consultation survey and 193 for the call for evidence.

What was the impact assessment opinion?

On 8 May 2026, the Board issued a positive opinion accompanied by a request for further improvements.

What is the total staffing requirement?

25 FTEs: 9 establishment plan posts and 16 contract agent posts.

When must Member States adopt national cloud and AI strategies?

Within one year of the Regulation's entry into force, under Article 7.

+3 more flashcards

From Legislative Rationale to Cloud and AI Leadership

Treaty bases in the formal preamble

"in particular Article 114 and Article 173(3) thereof"

Strategic priority in recital (4)

"Reinforcing the Union's capacity to develop and deploy cloud and AI technologies within its territory has become a strategic priority"

What is excluded from the recital (10) cloud-service definition?

The AI system itself and its underlying model. The definition covers only delivery and making available of the AI system.

Leadership objective in recital (11)

"increase the cloud and data centre capacity of the Union, while advancing cutting-edge cloud and AI technologies together with broad cloud and AI adoption"

Physical AI

"AI systems and models capable of perceiving the physical environment and executing complex actions within that environment"

Public-sector adoption objective

"increase the development and adoption of AI models and systems across the Union's public sector."

Implementation Architecture and Accelerated Data-Centre Deployment

EuroCloud Federation

The European public-sector cloud federation supported under the Regulation to facilitate sharing of secure and resilient public-sector data-centre services and cloud-computing services.

Centres for AI

Experience and acceleration centres for AI that Member States should establish with appropriate territorial coverage to accelerate uptake and deployment of AI, cloud and other advanced technologies.

AI first principle

A principle defined in the Apply AI Strategy: organisations should reflect on business processes, consider AI needs and opportunities, and take potential risks into account.

Frontier AI priority project

A designated project supporting development and scale-up of frontier AI technologies, requiring a collaborative Union-level approach and broad participation across the Union.

Data centre acceleration zone

A designated area intended to facilitate development, expansion or modernisation of data centres at scale and speed within a clear and streamlined regulatory framework.

Aggregated baseline permit

A permit reflecting the characteristics of an acceleration zone and covering permits commonly required for activities in the area, excluding grid connection permits.

+1 more flashcards

The Sovereignty Risk Model and Public-Sector Demand

Dependency risk

The recital's core diagnosis is: "The Union still remains critically dependent on a limited number of cloud computing service providers subject to the control of third countries".

Union assurance levels

A four-level framework of trusted offers. It is intended to support proportionate protection of public order and public-sector control and agency.

Level 1 evidence route

The provider has sole responsibility for conformity self-assessment, using documented evidence, internal control procedures, and continuous monitoring.

Levels 2-4 evidence route

Applicable criteria are verified by third-party independent experts through an independent audit, report, and opinion.

Positive audit opinion

It should be given where all evidence shows that the provider complies with the applicable audit criteria and obligations.

Public-order risk assessment

Member States and Union entities should determine which public-sector activities concern public order and what assurance level is appropriate.

+2 more flashcards

Federation, Common Purchasing, Open Source, and General Rules

EuroCloud purpose

It should "facilitate the sharing of such capabilities between Union entities and public-sector bodies."

Who may participate directly in EuroCloud?

"Participation within the EuroCloud Federation should be limited to public entities, without direct participation of a private party."

Intermediate-entity activity threshold

More than 80% of its activities must be carried out in performing tasks entrusted to it by the sharing entity.

EuroCloud cost-recovery rule

Charges are permitted only where "the charges are limited strictly to what is necessary and proportionate to recover the costs incurred by the sharing entity" for the beneficiary using entity.

Minimum approval for the procurement agreement

It enters into force under its provisions, "subject to the approval of at least two Member States."

Why does the text support open source?

"Access to the source code enables auditability, fosters collaboration and reuse and reduces dependency on a single vendor".

+2 more flashcards

Operational Leadership and Europe’s Capacity Build-Out

Centres for AI

Article 5 requires: "Each Member State shall establish Experience and Acceleration Centres for AI". They build on European digital innovation hubs and support adoption, skills, expertise transfer, and start-up scaling.

National strategy deadline

"By [same day as entry into force plus one year], Member States shall establish national cloud and AI strategies". The supplied proposal leaves the entry-into-force date unspecified.

Frontier AI participation threshold

For an Article 8 project, "it involves the participation of at least three Member States;". Participating Member States also pool computing time and other relevant resources.

Union compute matching

"The Union shall at least match the AI computing resources contributed by Member States" where sufficient capacity is available in the Union share of European HPC access time.

Acceleration-zone permit

"Member States shall prepare and issue an aggregated baseline permit authorising the deployment of data centres in that acceleration zone." Installation-specific permits remain outside it.

Strategic-project threshold

A project must "fulfil at least two of the following criteria:" in Article 14, after selection through an open call for expressions of interest.

+2 more flashcards

Proving and Enforcing Cloud Sovereignty

What evidence route applies to Union assurance level 1?

Article 19 requires provider conformity self-assessment against Annex II level 1 criteria, followed by an EU statement of conformity made publicly available.

What assurance levels require independent third-party audits?

Levels 2, 3, and 4. The provider undergoes the audit at its own expense to obtain an audit report and audit opinion.

What does cumulative compliance mean in Article 20?

A provider audited at a higher level must meet all applicable lower-level criteria. Failure on any lower-level requirement precludes higher-level conformity.

What is the auditor's long rotation restriction?

The auditor must not have provided Article 20 auditing services to the provider or a connected legal person during the 10-year period before the audit begins.

How long must revocations remain in the central repository?

Five years. This applies to the specified revocation of an audit report and opinion or revocation of recognition.

Which authority normally enforces a provider's compliance?

The competent authority in the Member State of the provider's main establishment, which has exclusive competence for enforcing this Chapter.

+1 more flashcards

Building a Shared Public-Sector Cloud Market

EuroCloud Federation participation

It is voluntary for Union entities and public sector bodies. They may request the Commission to join.

Sharing entity

A EuroCloud member that shares services. It must own the relevant hardware directly or indirectly and provide the service; indirect ownership requires control over the intermediate legal entity.

Using entity

A EuroCloud member receiving data centre or cloud-computing services from a sharing entity.

Sharing-service fee limit

"The amount of the fee shall be limited to the costs that the sharing entity incurs in relation to the sharing of the service" and must not constitute a pecuniary interest under the cited rules.

Minimum Article 38 agreement

The Commission and at least two Member States must enter into an agreement before Chapter IV procurement activity.

Dynamic purchasing system late-access ceiling

Cumulative requests must not exceed 50% of the initial estimated quantities of envisaged purchases.

+4 more flashcards

Policy Ambitions, Performance Indicators, and Management Controls

What is the proposal's short title?

Short title: "The Cloud and AI Development Act (CADA)"

What is the 2030 data-centre capacity objective?

By 2030, the EU should at least triple its current data centre capacity

What is the 2030 permitting objective?

By 2030, operators should be able to obtain all permits to build and run a data centre in less than 18 months throughout the EU

What is the 2035 critical-use objective?

By 2035, highly critical use cases in the public sector should be operated using sovereign cloud and AI computing services

When should application begin under section 1.5.1?

The entry into application should be within one year of publication

How many FTEs are estimated overall, and how many are redeployable?

25 FTEs are estimated overall. 15 of the 25 estimated FTEs could be covered through redeployment.

+2 more flashcards

Appropriations, Staffing, and the New Administrative Workload

What is the source's voted operational total for 2028-2034?

EUR "9.323" million in commitments, with the same grand total for payments.

What is the total administrative appropriation under Heading 4?

EUR "25.228" million, entirely attributed to human resources in the table.

What is the fee-financed operational total?

EUR "54.326" million for EuroCloud and Joint Cloud Procurement.

How many FTEs are forecast each year from 2028 through 2034?

25 FTEs each year: 11 establishment-plan posts and 14 external staff.

How many requested FTEs are already in place and redeployed?

15 FTEs: 5 establishment-plan posts and 10 external staff.

What distinguishes officials' work from external staff work in this source?

Officials handle programme design, legal and governance work, guidance, monitoring, and enforcement coordination. External staff handle recurring project management, studies, support, procurement operations, and contractor oversight.

+1 more flashcards

Fee Revenue and the Proposal’s Digital Requirements

When does collection of both fees start?

The stated starting date is 2029, allowing an initial setup process.

What cost ceiling applies to Joint Procurement fees?

"The fees charged to the participating contracting authorities shall not exceed the verifiable costs incurred by the Commission."

What average Joint Procurement fee rate is projected?

"an average annual fee rate of 2% applied to the spending per authority."

What are the EuroCloud membership-fee reference points?

"the membership fee could be set at around EUR 75 000 per member" and "reach around EUR 30 000 per member once full capacity is achieved."

How long must a recognition revocation remain published?

5 years in the central register.

Which Article 34 action is mandatory?

"The Commission shall establish a platform for the EuroCloud Federation."

+2 more flashcards

Data Governance, Operational Flows, and Interoperable Platforms

Audit-data quality

Data quality: sufficiently complete and reliable; minimum content for audits.

National-strategy notification deadline

Member States notify the European Commission within three months of the adoption of a national strategy; the flow occurs per adoption or revision.

Once-only principle

The once-only principle has been duly considered and will systematically be enforced wherever relevant.

FAIR-style implementation

Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data.

Cross-border response

The competent authority of origin sends the assessment outcome to requestors and the Commission within two months of a request being made.

Risk-assessment frequency

Bi-annually.

+4 more flashcards

Legal Sourcework and the Eight Grand Challenges

PUE target

Grand Challenge 1 seeks "an average Power Usage Effectiveness (PUE) of 1.15 across the Union."

Server-utilisation direction

Grand Challenge 1 calls for "raising average server utilisation rates across the Union’s data centres towards 50%".

Cloud stacks

"Building end-to-end hardware and software cloud stacks, including AI tools, infrastructure, services and management layers" is Grand Challenge 2.

Cooperative model safeguard

Grand Challenge 6 enables industrial-scale collaboration "without exposing commercially sensitive data between participants."

Public Sector AI

"Developing AI models and systems, based on high-quality data from the public sector targeting critical domains" is Grand Challenge 8.

Differentiated appropriations

"Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations."

+1 more flashcards

Assurance Levels 1 and 2: The Baseline Sovereignty Tests

Cumulative criteria

Every listed criterion for the relevant assurance level must be met; satisfying only some criteria is insufficient.

Level 1 data residency

Customer data, including metadata and telemetry data, must remain exclusively within the Union unless the public sector body explicitly requires otherwise, including before, during, and after configuration or use.

Level 1 outsourced support

Support outside the Union may occur only with legal, technical, and organisational measures for traceability, security, and governance that do not compromise operational autonomy.

Level 2 cybersecurity

The specified European certificate must be at least assurance level substantial when the relevant Union scheme has been established and is available.

SBOM

A complete and up-to-date software bill of materials, plus relevant identified dependencies, must be documented and made available to the auditing organisation at Level 2.

Level 2 support

Technical and operational support for the audited service, including subsequent sub-outsourcing, must be initiated and performed exclusively within the Union.

Assurance Levels 3 and 4 and the Evidence Behind Them

Level 3 personnel rule

the personnel, including the personnel of the subcontractors which are involved in the provision of the audited service are Union citizens

Level 3 baseline control rule

are not subject to the control of a third country or a legal entity established in a third-country.

Level 4 cybersecurity threshold

a European cybersecurity certificate of at least assurance level 'high'

Level 4 sensitive-data residency

remain exclusively within the Union and at any time

Effective software control

Effective control includes the ability to materially influence the technical evolution, maintenance priorities, security remediation, and long-term continuity of the component;

Annex III evidence status

This Annex is indicative and does not limit the evidence that may be requested or considered by the auditing organisations.

+2 more flashcards

Auditing Control, Software Integrity, and Operational Separation

What does Criterion E require as its primary certification evidence?

A valid European cybersecurity certificate issued by a competent conformity assessment body, showing assessment and compliance at basic, substantial, or high assurance under an established European scheme adopted under Regulation (EU) 2019/881.

What is the exact AI purpose-limitation clause in Criterion F?

data are processed solely for the delivery of the audited service and not for service improvements or model or system enhancements or any other secondary purpose.

What is the ownership disclosure threshold in section 7.1?

hold, directly or indirectly, at least 5% of the capital or at least 5% of the voting rights

What five factor groups must be considered when assessing control?

ownership structures and specific rights, corporate governance, commercial links conferring control, financial links conferring control and any other sources of control.

What does Criterion H say about where support activities occur?

all support, administration, maintenance, monitoring, incident response, and operational activities must be initiated and performed exclusively in the Union.

What source-code right is mandatory under Criterion I?

the third-party independent auditor is granted the right to access and audit the source code of such software.

+1 more flashcards