European Union Proposed Cloud and AI Sovereignty Law
The proposed 2026 legislation aims to reduce reliance on U.S. cloud providers for sensitive public sector operations.
Updated on Oct. 2, 2026 in Data Centers

Live Poll
Should nations restrict foreign companies from sensitive public cloud contracts to ensure technological sovereignty?
On June 3, 2026, the European Union tabled the Cloud and AI Development Act to establish digital sovereignty by restricting U.S. provider access to public contracts. This proposed legislation sets a framework for infrastructure control, targeting a tripling of regional data-center capacity within five to seven years.
Why it matters
The proposal seeks to mitigate hybrid threats and end critical dependencies on foreign technology providers that currently dominate the market. By establishing mandatory assurance levels for public data, the EU aims to shift its long-term digital infrastructure strategy.
The act establishes four distinct assurance levels for cloud contracts, with Level 1 required for all public sector work. Levels 2 through 4—which mandate strict participation in EU joint ventures—are reserved for sectors including defense, justice, and internal security.
The players
European Union
A political and economic union of 27 member states that regulates regional digital standards and market access.
Amazon
A major global provider of cloud infrastructure and e-commerce services that holds a portion of the 70% U.S. market share in the EU.
Microsoft
A global technology firm providing enterprise software and cloud hosting services to European public and private sectors.
A multinational technology company with significant infrastructure operations and a major stake in the European public cloud market.
The details
The act utilizes a hierarchical assurance structure to restrict foreign influence over government digital assets. Under Article 29 and Article 30, member states must conduct risk assessments and enforce specific security tiers based on the sensitivity of the public function. To access high-assurance infrastructure contracts, vendors must meet provisions outlined in Article 18 or maintain direct participation in regional EU joint ventures.
Timeline
June 3, 2026: The Cloud and AI Development Act was formally tabled.
5 to 7 years: The projected window to triple total European Union data-center capacity.
The Tech Race
The Cloud and AI Development Act extends security requirements already initiated by the European Union's NIS2 directive for critical sectors. By formalizing these data sovereignty rules, the EU is attempting to build a regional ecosystem that competes directly with the three major U.S. providers.
The legislation will likely force a transition in how public sector IT departments procure and host sensitive data over the next several years. Organizations relying on existing U.S.-based cloud contracts may face mandatory migration or compliance updates as the new assurance levels are phased in.
The takeaway
This act represents a significant shift toward local digital protectionism that could reshape the European cloud landscape. Industry watchers should monitor the specific requirements for Article 18 compliance, which will determine the operational viability of non-EU firms in defense and security sectors.
Further reading
For broader trends regarding infrastructure capacity and regional hosting, see Data Centers.
Source note: This article includes information reported by Decode39.
Live Poll
Should nations restrict foreign companies from sensitive public cloud contracts to ensure technological sovereignty?







