The European Commission has recently rolled out its ambitious proposal for the Cloud and AI Development Act (CADA), aiming to revolutionize the local cloud and AI industry. The goal? To reshape infrastructure, invigorate the European cloud market, and redefine how public sector bodies will operate in the years to come. This act stands on three strong pillars: investment in research, development, and innovation, a significant push to triple the European data center market in the next five to seven years, and a comprehensive autonomy framework that introduces four levels of sovereignty and security along with new obligations for EU member states. But hold on, not everyone is on board with this plan, and the feedback has been mixed at best.
Industry associations, like CCIA Europe, have come forward, claiming the proposal is discriminatory. Why? Because CADA wants EU member states to determine which use cases need specific sovereignty levels, and non-EU vendors might not be able to meet these by default. Polish tech lawyer Mikolaj Barcenciewicz has also weighed in, insisting that CADA should adopt a risk-based approach instead of a categorical one. He emphasizes that each member state should be able to maintain its individual approach rather than being generalized under one umbrella.
Then we have Swedish MEP Jörgen Warborn, who took to LinkedIn to express his concerns. He argues that while European digital sovereignty goals are crucial, they need to be paired with more simplified processes and better business conditions. In his view, the EU should foster an environment that strengthens the prospect of return on investment. He also pointed out that while it makes sense to tighten sovereignty goals related to national security, less sensitive sectors should not shy away from foreign direct investments. After all, a vast majority of global wealth is outside the EU, and we ought to be attracting those investments rather than pushing them away.
On the flip side, Finnish MEP Aura Salla is pushing for a more centralized approach, advocating for thoroughly testing tech dependencies and assessing risks at the member state level. Meanwhile, some players in the game, like German software provider Nextcloud, are not satisfied with the current proposal. They argue that it lacks ambition and should extend its reach to the private sector as well.
Now, let’s break down Title III of CADA, which sets up two main mechanisms to quickly ramp up EU data center capacity: Data Centre Acceleration Zones and Data Centre Strategic Projects. Each member state has six months to designate at least one acceleration zone that aligns with local urban and district planning while considering grid availability and network capacity. There’s a clear emphasis on using brownfield sites for these developments. Whether a project falls into these pre-approved zones or gets an individual strategic project designation, it enjoys benefits like a “green corridor”—a 12-month maximum for substantial cybersecurity certification, ensuring that customer data won’t be used for third-country AI training. Levels of security are clearly defined, with Level 3 indicating high sovereignty and national security, banning third-country corporate control by default, while Level 4 completely prohibits it.
So, how will EU member states put this new CADA framework into action? The first step is appointing national competent authorities to enforce the rules, audit suppliers, and handle applications for cloud provider recognition. Within a year, member states must conduct risk assessments every two years to pinpoint which public-sector activities depend on cloud services and establish the appropriate security assurance level. This proposal is set to shake up the status quo in public procurement for cloud services. Instead of choosing cloud service providers based solely on price and service quality, member states will now need to factor in non-price criteria, like how much a provider contributes to the European digital ecosystem.
In the end, we are left to wonder about the future of cloud services in Europe. Will this act successfully foster growth and innovation, or will it create barriers that hamper progress? Only time will tell, and we’ll be following these developments closely…
Kaynak: Orijinal Haber
