SkarpSkarp
Reading the EU Cloud and AI Development Act
💻 TechnologyIntermediate2h8 modules

Reading the EU Cloud and AI Development Act

This course examines the Commission's proposed Cloud and AI Development Act, COM(2026) 502 final, through its operative articles and annexes rather than relying only on policy summaries. It covers the proposal's three pillars, sovereignty assurance levels, data centre acceleration measures, public procurement rules, and practical organisational preparation. As of July 19, 2026, CADA remains a proposal under the ordinary legislative procedure and is not yet binding EU law. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/SV/HIS/?uri=celex%3A52026PC0502&utm_source=openai))

1 learnersby Skarp_officialen

Course Content

8 modules · 2h total

1

From Political Headline to Legislative Text

A proposal called an "Act" can easily be mistaken for legislation already in force. The opening module maps COM(2026) 502 final, its legal bases, definitions, titles, annexes, legislative status, and proposed application timeline. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
2

Pillar One: Building European Cloud and AI Capability

Behind the innovation pillar lies an industrial-policy programme spanning efficient data centres, open cloud stacks, frontier AI, physical AI, industrial AI, agents, and public-sector adoption. Articles 3 to 9 and Annex I reveal how the proposed Leadership Initiatives would convert these ambitions into operational objectives, grand challenges, national strategies, and priority projects. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
3

Pillar Two: Data Centre Acceleration Zones

Faster deployment does not simply mean removing permits. Articles 10 to 13 create a place-based model combining grid planning, connectivity, waste-heat reuse, sustainability, brownfield preferences, single information points, baseline permits, and a proposed twelve-month permitting ceiling. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
4

Strategic Projects and the Capacity Gap

Some data centre developments could receive a second layer of strategic recognition. Articles 14 and 15 connect project selection with essential public functions, sustainability, grid stability, EU-designed technology, and continuous monitoring of compute supply and demand. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
5

Pillar Three: How Sovereignty Recognition Would Work

The proposal turns the contested idea of cloud sovereignty into a recognition system administered through national authorities and a Union-wide repository. Articles 16 to 28 establish self-assessment for Level 1, independent audits for Levels 2 to 4, cross-border recognition, transparency duties, supervision, and enforcement. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
6

Inside the Four Union Assurance Levels

The decisive requirements are buried in Annexes II and III, where establishment, infrastructure, personnel, data, control, support operations, cybersecurity, AI training, and software supply chains are tested cumulatively. The progression from Level 1 to Level 4 is therefore more complex than a simple data-residency ladder. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
7

Public Procurement as the Adoption Engine

CADA would make public purchasing the principal demand-side lever for sovereign cloud services. Articles 29 to 40 link recurring risk assessments to minimum assurance levels, migration decisions, EU-added-value criteria, SME participation, the EuroCloud Federation, and Commission-led joint procurement. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A502%3AFIN))

15 min
8

Preparing Before the Text Becomes Law

The proposal may change during negotiations, but waiting for the final regulation could leave organisations without the evidence, contracts, architecture maps, or procurement data needed to respond. A role-based readiness plan separates prudent no-regret actions from investments that should await the final text and secondary legislation.

15 min

Read the Textbook

Read every chapter for free, right here in your browser.

From Political Headline to Legislative Text

The first rule: a name is not a legal status

The phrase Cloud and AI Development Act may sound like a law already in force. It is not. As of July 19, 2026, COM(2026) 502 final is an ongoing Commission proposal in procedure 2026/0138(COD), under the ordinary legislative procedure.

Study Flashcards

Key concepts from this course as flashcard pairs.

From Political Headline to Legislative Text

COM(2026) 502 final

The Commission document number for the proposed Cloud and AI Development Act; it is not a final regulation number.

2026/0138(COD)

The procedure number. COD indicates the ordinary legislative procedure.

Recital

A numbered statement explaining context, reasons, and legislative logic. It is distinct from the operative articles.

Operative provision

An article or annex provision that would set legal rules if the proposed regulation were adopted and applicable.

Delegated act

A later Commission act that may supplement or amend specified non-essential elements, subject to Parliament and Council control.

Implementing act

A later Commission act setting uniform conditions for implementing an adopted EU act, typically through a committee procedure.

+2 more flashcards

Pillar One: Building European Cloud and AI Capability

Cloud and AI Leadership Initiatives

The proposed Article 3 to 6 framework for building EU cloud and AI research, infrastructure, technology, and adoption capability.

Operational objective

A specific proposed capability target. Article 3 lists eight, including efficient data centres, open cloud stacks, frontier AI, physical AI, industrial AI, agents, public-sector AI, and adoption.

Grand challenge

A proposed large-scale, cross-sector initiative that implements operational objectives. Annex I contains eight grand challenges.

Centre for AI

A proposed Experience and Acceleration Centre for AI that supports adoption, skills, infrastructure access, regional knowledge transfer, and links between organisations and providers.

Open cloud stack

An interoperable set of layers spanning hardware, edge, connectivity, compute, storage, middleware, data and AI tools, backend systems, and services.

Physical AI

AI models and systems that perceive and act in the physical world, such as robots, autonomous vehicles, and drones.

+2 more flashcards

Pillar Two: Data Centre Acceleration Zones

Data centre acceleration zone

A proposed designated area where a Member State prepares planning, infrastructure, sustainability, and administrative conditions to facilitate data-centre deployment.

Brownfield preference

The Article 10 preference for reusing previously developed land rather than using greenfield land when designating a zone.

Anticipatory grid investment

Planning or investing in grid infrastructure ahead of fully materialised demand where evidence indicates that future system needs will require it.

Single information point

A proposed lifecycle coordination and guidance channel for operators seeking authorisations in an acceleration zone; it does not automatically replace permit authorities.

Aggregated baseline permit

A proposed zone-level permit covering commonly required authorisations after zone-level procedures and assessments, excluding installation-specific and grid-connection permits.

Installation-specific permit

An approval still needed for a condition or activity unique to an individual data-centre project and not covered by the zone's baseline permit.

+1 more flashcards

Strategic Projects and the Capacity Gap

Data centre strategic project

A project the Commission may designate under proposed Article 14 through an open call, if it fulfils at least two of five strategic criteria.

Acceleration zone

A Member State-designated area intended to facilitate data-centre deployment through coordinated planning and permitting arrangements.

Capacity gap

The difference between demand for suitable data-centre capacity and the capacity available to meet that demand.

Underserved area

An area identified through Commission and Member State monitoring as lacking sufficient compute capacity; it could subsequently be used as an acceleration zone.

Essential public-sector functions

Functions directly supported by infrastructure, including research and education, healthcare, public safety, and security.

Grid contribution

A contribution to electricity-grid security, safety, stability, or identified system needs, assessed by the relevant system operator.

Pillar Three: How Sovereignty Recognition Would Work

Union assurance level

One of four proposed levels in the Union cloud computing sovereignty framework. The criteria would be set out in Annex II.

Conformity self-assessment

The Level 1 pathway in which a provider assesses compliance and issues a public EU statement of conformity.

EU statement of conformity

A provider declaration that Level 1 compliance has been demonstrated; issuing it makes the provider responsible for that claim.

Independent third-party audit

The required pathway for Levels 2, 3, and 4, producing an audit report and a positive or negative audit opinion.

National competent authority of establishment

The authority in the Member State of the provider's main establishment that evaluates recognition and has exclusive competence for enforcement under the proposed chapter.

Central repository

The proposed public Commission-maintained repository of recognised cloud services, including published revocations.

+2 more flashcards

Inside the Four Union Assurance Levels

Cumulative criteria

Requirements that must all be met. A higher Union assurance level includes applicable lower-level requirements; one failed criterion can prevent conformity.

Metadata and telemetry

Service-derived information such as logs of users, times, functions, identities, configurations, and usage. The proposed framework treats it as customer data.

SBOM

Software bill of materials: an up-to-date inventory of software components. Annex II also expects a documented list of relevant dependencies.

Third-country control

Control that may arise through ownership, voting rights, vetoes, board appointments, commercial dependency, financial links, or other durable influence over management and resources.

Level 2 cybersecurity threshold

At least substantial assurance under a relevant European cloud cybersecurity scheme when available; interim national or highest-applicable-Union-law evidence may apply under the proposal.

Level 3 personnel rule

Relevant personnel, including relevant subcontractor personnel, must be Union citizens. Necessary Member State security clearance is also required where classified information is handled.

+2 more flashcards

Public Procurement as the Adoption Engine

Public-order risk assessment

A proposed Article 29 assessment that identifies relevant public activities and determines whether Union assurance level 2, 3, or 4 is appropriate.

Union assurance level 1

The proposed minimum for in-scope public-sector activities that have not been identified as contributing to preservation of public order.

Exceptional derogation

A narrowly available, duly justified departure where specified conditions such as lack of a suitable recognised service, failed prior procurement, or disproportionate cost apply.

Union added value

Non-price quality evaluation of a tenderer's contribution to the European cloud and AI ecosystem in innovative cloud and AI procurement.

EuroCloud Federation

A proposed voluntary federation through which Union entities and public-sector bodies could share eligible public-sector cloud and data-centre services.

Common procurement

Commission-led purchasing that could use framework contracts, dynamic purchasing systems, a common platform, and central purchasing support.

Preparing Before the Text Becomes Law

No-regret action

A reversible or broadly useful action, such as building inventories, preserving evidence, or improving change notifications, that does not depend on one draft rule surviving.

Evidence register

A controlled list linking each claim to a document or system record, scope, owner, version, date, retention period, and refresh trigger.

Data-flow inventory

A map of where data, metadata, logs, telemetry, backups, prompts, outputs, and administrator access travel across services and organisations.

Delegated act

A non-legislative act that the Commission may adopt only if the final Regulation grants that power, subject to the controls specified by EU law.

Implementing act

An act used to establish uniform conditions for implementing EU law where the final Regulation gives the Commission that authority.

Decision gate

A defined point at which an organisation decides whether to make a costly or irreversible investment after new legal, technical, or procurement information becomes available.