Chapter 10 of 17
Policy Ambitions, Performance Indicators, and Management Controls
The legislative financial statement restates the proposal as a programme that must be financed, measured, and controlled. Its targets reach toward 2030 and 2035, while its management model anticipates startup risks, direct Commission administration, fraud controls, and fee-supported operations.
1. Reading the Financial Statement as a Policy Blueprint
A programme, not just a vision
A Legislative Financial and Digital Statement turns a proposal into an operational programme: it connects policy objectives to indicators, staffing, financing, controls, reporting, and risk management.
Identity of the proposal
Section 1.1 gives the exact short title: Short title: "The Cloud and AI Development Act (CADA)". The proposal is framed as a Regulation with EEA relevance.
Status matters
As of July 20, 2026, CADA is a Commission proposal published on June 3, 2026, not a final adopted Regulation. Study the proposal's design, not assumed binding obligations.
How to navigate the extract
The extract substantively covers the framework and management measures. It lists later financial and digital sections, but does not supply their detailed budget tables or digital assessments.
2. The General Objective and Four Specific Objectives
General objective
Section 1.3.1 combines two aims: a functioning internal market for cloud computing services, and conditions for Union competitiveness and strategic autonomy.
Objective 1: capacity
By 2030, the EU should at least triple its current data centre capacity. The proposal treats this as an intermediate step toward meeting EU computing needs by 2035.
Objective 2: permits
By 2030, operators should be able to obtain all permits to build and run a data centre in less than 18 months throughout the EU. Land, energy access, and connectivity are expressly included.
Objectives 3 and 4
Objective 3 seeks less reliance on non-European services. Objective 4 says: By 2035, highly critical use cases in the public sector should be operated using sovereign cloud and AI computing services.
Highly critical use cases
The text identifies uses of systemic importance that underpin essential functions or process sensitive data. Sovereignty is tied to confidentiality, operational autonomy, and service continuity.
3. Turning Ambitions into Performance Indicators
Indicators are evidence
Section 1.3.4 distinguishes an objective from the evidence used to track it. Indicators make progress visible, but the extract does not provide every formula, baseline, or reporting frequency.
Capacity needs more than MW
Objective 1 includes MW IT load and FLOPs, but also utilisation, PUE, WUE, emissions, clean energy, waste-heat reuse, investment, and deployment outside existing hubs.
A permitting example
A fall in average permitting time to 16 months would point toward the 18-month objective. Yet administrative burden, delayed projects, simplified frameworks, and cost competitiveness also matter.
Reliance and resilience
Objectives 3 and 4 track revenue and ownership shares, public authorities served, idle capacity, audits at levels 2, 3, and 4, scheme compliance, procurement value, and open-source uptake.
4. Indicator Design Lab: One Facility, Several Outcomes
Your task
A new data centre opens in an underserved region. It increases installed MW IT load and uses a high share of clean energy. However, it has a low utilisation rate during its first year and does not reuse waste heat.
Choose the best assessment:
- It is automatically a complete success because installed capacity increased.
- It is automatically a failure because utilisation is low.
- It shows mixed evidence across the proposal's Objective 1 indicators.
- It cannot be assessed because the proposal contains no indicators.
Think before revealing the answer
The best answer is 3. Section 1.3.4 deliberately uses a dashboard rather than a single metric. This facility may show positive movement on installed capacity, clean-energy share, and geographic balance. It may show weaker performance on utilisation and waste-heat reuse. Its overall evaluation needs the full set of relevant indicators.
This exercise also illustrates a management principle embedded in the statement: avoid treating a policy objective as a single number. Capacity expansion is linked to sustainability, efficiency, investment, and geographical distribution.
A data centre raises MW IT load in an underserved region and uses clean energy, but has low utilisation and no waste-heat reuse. What is the strongest conclusion under section 1.3.4?
- It is a complete success because capacity rose.
- It is a failure because utilisation is low.
- It shows mixed evidence across several Objective 1 indicators.
- It cannot be assessed because no indicators are listed.
Show Answer
Answer: C) It shows mixed evidence across several Objective 1 indicators.
Objective 1 includes capacity, utilisation, environmental measures, clean energy, waste-heat reuse, investment, and geographic distribution. The proposal's indicator design requires a multi-factor assessment.
5. Timing, EU Added Value, and Lessons from Earlier Measures
Entry into force versus application
Section 1.5.1 separates two moments: expected entry into force within 20 days of Official Journal publication, and The entry into application should be within one year of publication.
What added value means here
EU added value is additional value beyond what Member States would create alone. The document identifies fragmentation, uneven capacity, divergent standards, and procurement barriers.
The document's conclusion
EU action is expected to have a clear added value in addressing the problem of limited and geographically concentrated availability of computing capacity.
Lessons, not assumptions
The text says compliance safeguards and data localisation were insufficient to change dependency fully. It separates cybersecurity requirements from sovereignty requirements.
6. Financing Logic: Synergies, Redeployment, Fees, and New Posts
Funding synergies
FP10 is described as supporting upstream research and innovation, while the ECF is described as the main deployment instrument. The text also names IPCEIs, EDICs, cohesion funding, and InvestEU.
The 25-FTE model
Implementation is estimated at 25 FTEs. Eight DG DIGIT posts and seven DG CNECT posts are identified for redeployment: 15 of the 25 estimated FTEs could be covered through redeployment.
What requires new money
The remaining 10 FTEs would require additional financing because the tasks are new or substantially expanded and go beyond current workload assumptions.
Why fees appear
The model combines redeployment, fee-based financing, and limited additional resources. Fees are envisaged for common procurement and EuroCloud Federation administration.
7. Checkpoint Quiz: Resources and Timelines
Choose the statement that matches the source text
This question combines the implementation timetable with the staffing assessment. Read closely: the proposal distinguishes entry into force from application, and it distinguishes redeployed staff from additionally financed staff.
Which statement is accurate according to sections 1.5.1 and 1.5.5?
- Application is expected within 20 days of publication, and all 25 FTEs require new financing.
- Entry into force is expected within 20 days of Official Journal publication; application should be within one year of publication; 15 of 25 FTEs could be redeployed.
- The Act applies immediately on publication, and fees are the only proposed financing source.
- The proposal fixes a five-year duration and provides no staffing estimate.
Show Answer
Answer: B) Entry into force is expected within 20 days of Official Journal publication; application should be within one year of publication; 15 of 25 FTEs could be redeployed.
The text expects entry into force within 20 days from Official Journal publication, says application should be within one year of publication subject to exceptions, and states that 15 of 25 FTEs could be covered through redeployment.
8. Duration and Budget Implementation: Who Manages What?
Unlimited duration
Section 1.6 marks the initiative as unlimited in duration. It is not presented as a finite pilot or a measure with a fixed end date.
Staged implementation
The text states: Implementation with a start-up period from 2028 to 2030, followed by full-scale operation. The supplied extract does not break that period into yearly actions.
Primary budget method
Section 1.7 selects Direct management by the Commission. It also identifies Commission departments, including staff in Union delegations, as the direct-management route.
Do not confuse roles
Member States still matter in reporting, procurement oversight, and voluntary federation participation. But the form does not select shared management as the planned budget method.
9. Monitoring, Reporting, Payments, and Additional Commission Staffing
Five-year review
Section 2.1 says the Regulation will be reviewed and evaluated five years from entry into force. The Commission must report the findings to Parliament and the Council.
Information from Member States
For consistent implementation and monitoring, Member States should make relevant information about their activities available to the Commission in a timely manner.
Additional staffing
Section 2.2.1 specifies 6 additional FTEs for the DG CNECT and 4 FTEs for DG DIGIT. This matches the 10 posts requiring additional financing.
Payments and controls
The text uses annual commitments and payments, fee contributions, ex ante checks, ex post audits, performance monitoring, and reporting under the Commission's internal control framework.
10. Risk Controls, Procurement Oversight, Federation Security, and Fraud Prevention
Execution-risk monitoring
Commission staff are envisaged for guidance, delegated acts, dependency assessments, comitology support, implementation oversight, and KPI and milestone monitoring to identify risks promptly.
Procurement Steering Committee
For common procurement, the Committee includes the Commission and Member State representatives. It provides strategic oversight and safeguards transparent, non-discriminatory accession conditions.
Federation security design
The planned sharing platform includes secure access and incident management: shared identity management, mutual authentication, incident reporting, service monitoring, allocation, activation, and performance tools.
Error and fraud
Control intensity is risk-based. The stated target is the aim is to maintain this below the 2% threshold. Existing Commission fraud-prevention measures cover additional appropriations.
11. Flashcards: Numbers, Dates, and Governance Terms
Recall the exact thresholds and institutional choices
Flip each card, answer from memory, then compare your wording with the source text. Precision matters in legislative financial statements: a target, an indicator, a staffing estimate, and a management method are different kinds of claims.
- What is the proposal's short title?
- Short title: "The Cloud and AI Development Act (CADA)"
- What is the 2030 data-centre capacity objective?
- By 2030, the EU should at least triple its current data centre capacity
- What is the 2030 permitting objective?
- By 2030, operators should be able to obtain all permits to build and run a data centre in less than 18 months throughout the EU
- What is the 2035 critical-use objective?
- By 2035, highly critical use cases in the public sector should be operated using sovereign cloud and AI computing services
- When should application begin under section 1.5.1?
- The entry into application should be within one year of publication
- How many FTEs are estimated overall, and how many are redeployable?
- 25 FTEs are estimated overall. 15 of the 25 estimated FTEs could be covered through redeployment.
- How many additional FTEs and which Directorates-General?
- The remaining 10 FTEs would require additional financing: 6 additional FTEs for the DG CNECT and 4 FTEs for DG DIGIT.
- What are the implementation and error-rate phrases?
- Implementation with a start-up period from 2028 to 2030, followed by full-scale operation; the aim is to maintain this below the 2% threshold.
12. Final Quiz: Match the Control to the Risk
Apply the statement's management logic
The final question tests whether you can connect a risk to the control mechanism that the document actually specifies. Focus on section 2.2.2 rather than relying on general assumptions about public procurement.
Which mechanism does the statement assign strategic oversight of common procurement activities, including transparent and non-discriminatory conditions for contracting authorities to join?
- A Steering Committee composed of the Commission and representatives of Member States
- A shared-management authority controlled only by Member States
- An automatic annual audit conducted by private contractors
- The European public sector cloud federation platform alone
Show Answer
Answer: A) A Steering Committee composed of the Commission and representatives of Member States
Section 2.2.2 states that a Steering Committee, composed of the Commission and representatives of Member States, shall be established for strategic oversight of common procurement. The federation platform has a different role: supporting secure sharing of capacity and interoperable services.
Key Terms
- FTE
- Full-time equivalent: a staffing measure expressing workload as the equivalent of one full-time post.
- PUE
- Power Usage Effectiveness, listed as an environmental and efficiency-related measure for data centres.
- WUE
- Water Usage Effectiveness, listed as an environmental measure for data centres.
- CADA
- The proposal's short title: "The Cloud and AI Development Act (CADA)".
- FLOPs
- Floating-point operations; the text uses this as a measure of aggregate general-purpose and AI-optimised compute.
- MW IT load
- Installed computing capacity measured by the information-technology power load of data-centre equipment.
- EU added value
- Value resulting from EU action that is additional to value that Member States alone would otherwise have created.
- ex ante checks
- Controls conducted before expenditure or payment decisions.
- ex post audits
- Controls conducted after expenditure or payment activity.
- direct management
- The selected planned budget-implementation method: Direct management by the Commission.
- Steering Committee
- A body composed of the Commission and Member State representatives that provides strategic oversight of common procurement activities.
- EuroCloud Federation
- The named federation-related activity for sharing idle capacity among interested Member States; the text envisages fee-supported administration and a secure sharing platform.
- highly critical use cases
- Use cases of particular systemic importance that underpin essential functions or involve processing sensitive data.
- sovereign cloud and AI computing services
- Services used for highly critical public-sector cases to support data confidentiality, operational autonomy, and protection against third-country policies that could cause data access or service interruptions.