SkarpSkarp

Chapter 1 of 17

Why Europe Proposes a Cloud and AI Development Act

Europe’s computing infrastructure is concentrated, capacity-constrained, and dependent on a small number of non-EU providers. Opening with the proposal’s institutional status and structure, this module examines the Commission’s diagnosis, objectives, and positioning within the wider EU digital policy landscape.

20 min readen

1. Start Here: A Proposal, Not Yet a Binding Regulation

Document identity

COM(2026) 502 final, dated 3 June 2026, is a Commission proposal for the Cloud and AI Development Act under procedure 2026/0138(COD).

Status matters

On 20 July 2026, the procedure is ongoing. Teach this text as a proposal, not as a final Regulation already in force.

What this extract does

The Explanatory Memorandum's Section 1 explains the Commission's diagnosis, objectives, ecosystem design, and consistency with other EU policies.

Reading discipline

Do not treat proposed measures as current duties. Where the supplied text does not specify a detail, deadline, or legal effect, do not invent one.

2. The Commission's Diagnosis: Compute Has Become Strategic

The causal chain

AI increases demand for computation. Cloud supplies the compute, software building blocks, and interfaces that make efficient AI development and deployment possible.

A strategic resource

The memorandum says computing infrastructure is no longer merely technical: it is critical to economic security, sovereignty, resilience, and competitiveness.

Five connected domains

The AI Continent Action Plan links computing infrastructure, data, skills, AI development and adoption, and regulatory simplification.

Why cloud capacity matters

AI factories and gigafactories provide high-capacity compute, but the proposal says broader AI diffusion also needs more cloud and data-centre capacity.

3. Capacity Constraint: Why Data Centres Become an AI Policy Issue

A practical workload

A connected factory using real-time AI quality control illustrates a workload that may need low-latency compute capacity close enough to support fast decisions.

The diagnosed constraint

The text says limited EU data-centre capacity can force enterprises to route critical workloads through foreign hyperscaler infrastructure.

The policy objective

The proposal says: It aims to triple EU capacity in the next five-to-seven years and reach the needed capacity by 2035.

Strategic projects

The framework would identify and support projects with built-in innovation and sustainability, or projects helping balance capacity across Member States.

4. Dependence, Concentration, and the Meaning of Sovereignty

EU-provider share

the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.

Hyperscaler concentration

Currently, three non-EU hyperscalers control over 70% of the European cloud market. The supplied extract does not formally define "hyperscaler."

Why jurisdiction matters

The memorandum highlights third-country laws with extraterritorial effects, including possible mandated data access and transfer.

Sovereignty is broader

the notion of sovereignty goes beyond data transfers and relates to operational autonomy too. It also concerns continuity of service and dependency.

5. Map the Proposal's Ecosystem Response

Thought exercise: classify each measure

The memorandum says the proposal uses a coordinated "ecosystem approach". It combines:

  • supply-side measures to boost domestic capabilities;
  • demand-side measures to drive adoption;
  • enablers for innovation and investment.

Classify the following elements before revealing the suggested mapping:

  1. Research and innovation initiatives integrating networks, cloud, AI, and software.
  2. A framework to simplify and harmonise data-centre deployment.
  3. A sovereignty framework that lets services be assessed and formally recognised at a particular sovereignty level.
  4. Procurement tools enabling contracting authorities to make informed purchasing decisions and use buying power to lower dependencies.
  5. Specific emphasis on open source as a lever for technological sovereignty.

Suggested mapping

  • Item 1 is mainly a supply-side capability measure. It addresses energy-efficient compute infrastructure, autonomy across the cloud stack, advanced AI capabilities, and public/private adoption.
  • Item 2 is an investment and deployment enabler with supply-side effects.
  • Item 3 is a trust and market-uptake enabler: it supplies a common way to assess sovereignty characteristics.
  • Item 4 is a demand-side measure because public purchasing can shape what services are adopted.
  • Item 5 operates across categories. Open source is presented as a lever for sovereignty and as part of the EU Open Source Strategy's effort to promote open European alternatives across the technology stack.

The text gives particular prominence to large-scale, cross-sectoral initiatives called "grand challenges." They are intended to address strategic technological and industrial challenges, demonstrate feasibility, and create conditions for investment in next-generation infrastructure and technologies. The supplied extract lists four areas: energy-efficient compute infrastructure; autonomy across the cloud stack; advanced EU capabilities in frontier AI, physical AI, and industrial AI; and adoption across public and private sectors.

6. Quiz: Identify the Commission's Capacity Claim

Choose the statement that accurately reflects the capacity objective in the supplied text.

Which statement matches the proposal's stated capacity objective?

  1. It aims to triple EU capacity in the next five-to-seven years and reach the needed capacity by 2035.
  2. It requires every Member State to triple its data-centre capacity by 2030.
  3. It sets a binding EU target of 70% market share for EU cloud providers by 2035.
  4. It requires AI factories to replace all commercial cloud providers by 2035.
Show Answer

Answer: A) It aims to triple EU capacity in the next five-to-seven years and reach the needed capacity by 2035.

The text states exactly: "It aims to triple EU capacity in the next five-to-seven years and reach the needed capacity by 2035". It does not state a Member State-by-Member State target, a market-share target, or a replacement requirement.

7. The Sovereignty Framework and Public-Sector Demand

The framework's exact description

It provides a harmonised and auditable set of criteria at different levels of sovereignty of cloud computing services.

What the text specifies

Services may be assessed and formally recognised at a sovereignty level. The supplied extract does not list the levels or every criterion.

Member State risk assessments

Member States would identify sub-sectors and use cases needing aligned services to protect confidentiality, operational autonomy, and public order.

Procurement as leverage

Contracting authorities would receive decision support, sector-specific EU-added-value award criteria, and common procurement tools to lower dependencies.

8. Policy Fit: What Existing EU Instruments Do and Do Not Do

Data Act

The Data Act opens the path towards a possible reduction of dependencies on non-EU providers but does not build the road towards a more sovereign and trusted EU cloud computing sector.

DMA

the DMA has different objectives and does not contain measures that would actively promote the uptake of sovereign cloud computing services.

AI Act

The AI Act ensures a high level of protection of health, safety and fundamental rights. It does not cover aspects of sovereignty.

Digital Decade and NIS2

The programme has a target for monitoring the deployment of edge nodes. NIS2 focuses on technical cybersecurity rather than broader sovereignty.

Preparedness, transfers, autonomy

Article 29 risk assessments support preparedness, while the text stresses that sovereignty also concerns operational autonomy, not only data transfers.

9. Flashcards: Core Terms and Distinctions

Flip each card and test whether you can connect the term to the proposal's specific role.

Cloud and AI Development Act
The proposed Regulation in COM(2026) 502 final. As of 20 July 2026, it remains an ongoing legislative proposal, not a finally adopted Regulation.
EU provider market-share finding
the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.
Hyperscaler concentration finding
Currently, three non-EU hyperscalers control over 70% of the European cloud market.
Sovereignty framework
a harmonised and auditable set of criteria at different levels of sovereignty of cloud computing services.
Operational autonomy
A sovereignty concern beyond data transfer rules: it concerns dependence on external actors for continuing service operation.
Data Act's role
An enabler through switching and interoperability, but not a measure that itself builds a sovereign and trusted EU cloud sector.
NIS2's limitation in this memorandum
It improves technical cybersecurity risk management but does not boost uptake and use of services or address broader sovereignty considerations.
Article 29
The proposal's risk assessment mechanism, described as contributing directly to the digital preparedness dimension of the Preparedness Union Strategy.

10. Final Quiz: Match the Instrument to Its Gap

Use the Commission's distinctions carefully. Several instruments relate to cloud, AI, security, or data transfers, but the memorandum assigns them different functions.

According to the memorandum, why does the proposal complement the EU-US Data Privacy Framework?

  1. Because the Framework has been repealed and no longer governs transatlantic data transfers.
  2. Because the Framework addresses transatlantic data transfers but does not remove sovereignty concerns about dependence on third-country providers.
  3. Because the Framework requires all cloud services to be operated only by EU-owned companies.
  4. Because the Framework is a financial-sector instrument applying only to critical third-party providers.
Show Answer

Answer: B) Because the Framework addresses transatlantic data transfers but does not remove sovereignty concerns about dependence on third-country providers.

The memorandum says the proposal is consistent with GDPR and the EU-US Data Privacy Framework. However, it says that the Framework addresses transatlantic data transfers without removing sovereignty concerns about dependence on third-country providers. The stated reason is that sovereignty goes beyond data transfers and relates to operational autonomy too.

Key Terms

CSA2
The proposed revision of the Cybersecurity Act, described in the text as addressing supply-chain risks and complementing the proposal's sovereignty focus.
EUCS
European Cybersecurity Certification Scheme for Cloud Services. The memorandum says it had not yet been adopted and could, once finalised, help demonstrate that an audited service meets the highest cybersecurity standards.
Data centre
Infrastructure for data storage and processing. The proposal's memorandum connects its deployment to AI workloads, sustainability, grid capacity, and geographic balance.
Hyperscaler
A term used in the extract for very large non-EU cloud market incumbents. The supplied extract does not provide a formal definition.
Multi-cloud
A user strategy combining offers from different cloud providers; the memorandum identifies the Data Act as enabling this choice.
Vendor lock-in
A condition in which a cloud user faces barriers to switching providers. The memorandum says Data Act switching and interoperability rules seek to remove key sources of it.
Cloud computing
In this memorandum, the source of computational resources, software building blocks, and interfaces necessary for efficient AI development and deployment.
Compute capacity
The available capability to store, process, and run computational workloads. The supplied text does not provide a formal definition or numerical baseline.
Grand challenges
Large-scale, cross-sectoral initiatives aimed at the most strategic technological and industrial challenges, intended to demonstrate feasibility and encourage next-generation investment.
Operational autonomy
The ability to avoid unacceptable dependence on external actors for continuing operation of cloud and AI services; in the memorandum, it is part of sovereignty beyond data-transfer issues.
Contracting authority
A public purchasing body. The proposal would provide a framework to help such authorities make informed cloud purchasing decisions and reduce dependencies.
Sovereign cloud computing service
A cloud service assessed against the proposed EU-wide sovereignty framework and potentially formally recognised at a particular sovereignty level.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself