MICKAI®ArticlesWhat is the EU Cloud and AI Devel…
Article · 22 July 2026

What is the EU Cloud and AI Development Act?

A European Commission proposal adopted on 3 June 2026 that grades cloud sovereignty on a four-tier ladder, still in the legislative process.

Author
Micky Irons
Published
22 July 2026
Follow Micky Irons
LinkedInX
sovereign aieu cloud and ai development actcloud sovereigntyeu regulationdata sovereignty

The EU Cloud and AI Development Act is a European Commission legislative proposal adopted on 3 June 2026 as the centrepiece of the Commission's tech sovereignty package. It aims to triple EU data centre capacity, reduce reliance on non-EU cloud providers, and introduce a four-tier cloud sovereignty ladder that public authorities and critical sectors can use as measurable procurement criteria. It is a proposal moving through the EU legislative process, not law in force.

The question matters because sovereignty has moved from rhetoric to procurement. If the text is adopted in its current shape, the tiers would phase in over the coming years, and every supplier selling cloud or AI into the EU public sector would be scored against a ladder that measures control, not marketing.

What does the proposal actually contain?

Three headline moves, on the Commission's own framing. First, a large expansion of European data centre and compute capacity, with the stated ambition of tripling it. Second, measures to reduce dependence on non-EU cloud providers for public and critical workloads. Third, the sovereignty ladder itself: a graded set of criteria that turns the vague word sovereign into something a procurement team can score. The text does not name winners or ban suppliers; it defines rungs and lets buyers demand them.

What are the four tiers of the sovereignty ladder?

As proposed, each tier adds a harder requirement:

  • Tier one: data processing located in the EU.
  • Tier two: demonstrated independence from third-country control, plus transparency over the software supply chain.
  • Tier three: EU ownership and control of the provider itself.
  • Tier four: a Strategic Autonomy Cloud tier for the most sensitive workloads, demanding full transparency and control over the software supply chain with no third-country interference.

The ordering is the argument. Location can be bought anywhere; ownership, jurisdiction and supply-chain control cannot be patched in software, which is why they sit at the top.

Why does EU data residency not reach the higher rungs?

Because legal reach follows the provider, not the building. Under the US CLOUD Act, US authorities can compel providers subject to US jurisdiction to produce data in their possession or control regardless of where in the world it is stored. An EU region operated by the subsidiary of a US parent can therefore satisfy tier one while failing the question tier two asks: is the operator demonstrably independent of third-country control. The ladder exists precisely because geography stopped answering the sovereignty question years ago.

When would the Act take effect?

No honest date can be given. As of July 2026 the proposal sits in the EU legislative process, where the European Parliament and the Council can amend it substantially. If adopted on the current text, the sovereignty tiers would phase in over the coming years rather than arrive at once. Any supplier claiming to comply with the Act today should be read carefully: there is no final text to comply with yet.

What should procurement and security teams do now?

Four things cost nothing and pay off under any final text:

  • Map current cloud and AI suppliers against the four tiers as drafted, as an internal scoring exercise.
  • Ask each supplier in writing where its ultimate ownership, control and software supply chain sit.
  • Identify which workloads would plausibly count as most sensitive, since those attract the highest rung.
  • Prefer architectures that clear the higher rungs by construction, because control remains valuable however the legislation lands.

Where does operator-owned infrastructure sit on the ladder?

Above it. The ladder grades third-party providers by how much control the customer really retains. An organisation that runs AI on hardware it owns, inside its own walls, has no provider to assess: no third-country parent, no opaque control plane, no supply chain it cannot inspect. That is how we build Mickai, a Sovereign Intelligence Operating System that runs offline on operator-owned hardware behind a zero-egress perimeter, with every action sealed to a post-quantum signed audit ledger that verifies offline. There is no rung to climb when there is no provider standing between the operator and the machine.

The sovereignty ladder writes into procurement criteria what operator-owned infrastructure already delivers by construction.

How an operator-owned deployment reaches the properties the top tier describes is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Is the EU Cloud and AI Development Act already in force?

No. It is a Commission proposal adopted on 3 June 2026 and now moving through the EU legislative process, where the Parliament and the Council can amend it. There is no final text and no in-force date. Suppliers claiming compliance today are anticipating a law, not complying with one.

Does hosting my data in an EU region satisfy the sovereignty ladder?

It addresses tier one only, the location of processing. The higher tiers ask who ultimately controls the provider, whether it is demonstrably independent of third-country control, and, at the top, whether the entire software supply chain is transparent and free of third-country interference. Location is the easiest rung, which is exactly why it is the lowest.

How is this different from the EU AI Act?

The AI Act regulates AI systems and models: its prohibitions and AI-literacy duties have applied since 2 February 2025, general-purpose model obligations since August 2025, and its high-risk Annex III obligations were deferred by the Digital Omnibus from 2 August 2026 to 2 December 2027. The Cloud and AI Development Act proposal addresses infrastructure: where compute lives and who controls it. A single deployment can sit under both.

Can a hyperscaler subsidiary reach the top of the ladder?

On the draft criteria it looks structurally hard. A European subsidiary of a non-EU parent can localise data, staff and contracts, but ultimate ownership, control and exposure to third-country law sit at group level, and those are the exact properties the upper tiers measure. The final answer depends on the adopted text, which is still being negotiated.

Does the sovereignty ladder apply to private companies?

As proposed it is aimed at procurement by public authorities and critical sectors, but criteria of this kind rarely stay confined. Regulated private buyers already borrow public procurement language for their own supplier assessments, and a published ladder gives every board a shared vocabulary for asking who really controls its cloud.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/what-is-the-eu-cloud-and-ai-development-act. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles