The Technological Sovereignty Package presented on 3 June marks what the GLOBSEC GeoTech Center sees as a decisive break with Europe’s traditional regulatory posture. Its centrepiece, Cloud and AI Development Act (CAIDA) moves the EU from rule-making towards an active industrial strategy for the digital infrastructure layer.
By introducing a tiered cloud sovereignty framework tied to procurement access, compliance obligations, and risk classification, the EU is effectively creating a market-shaping mechanism that will influence where sensitive workloads are hosted and which providers can scale across public-sector demand.
Combined with new powers to designate strategic projects and accelerate data centre deployment through “Acceleration Zones,” the Act signals an intent to remove structural bottlenecks in compute capacity while steering investment toward EU-aligned infrastructure.
The proposal represents one of the EU’s most ambitious attempts to strengthen digital sovereignty while accelerating the deployment of AI and cloud infrastructure across Europe. At its core is a four-tier cloud sovereignty frameworkthat would classify cloud providers according to progressively stricter requirements related to infrastructure location, ownership, operational control, and personnel. The highest tiers (3 and 4) are designed to ensure that the most sensitive public-sector and strategic workloads remain under a high degree of European control.
The framework would reshape public procurement by requiring authorities to assess security and dependency risks when procuring cloud services. For operators in sensitive sectors, access to certain contracts and critical workloads would increasingly depend on compliance with at least tier 2 sovereignty requirements, creating strong incentives for providers to localise infrastructure and governance arrangements within Europe.
Beyond cloud governance, the Cloud and AI Act signals a broader industrial policy shift. The Commission would gain powers to designate strategic cloud and AI projects eligible for priority funding, regulatory support, and streamlined administrative procedures. The creation of Data Center Acceleration Zones, coupled with accelerated permitting processes, aims to address one of Europe’s longstanding bottlenecks: the slow deployment of digital infrastructure needed to support advanced AI development and high-performance computing.
Taken together, the proposal reflects a growing recognition in Brussels that technological competitiveness, economic security, and digital sovereignty are increasingly intertwined. Rather than relying solely on regulation, the EU is seeking to actively shape the infrastructure layer of the digital economy, strengthening domestic capabilities while reducing strategic dependencies on non-European providers.
The 4 tiers approach under the Cloud and AI Act: implications for EU and non-EU companies:
The four-tier framework reveals that the Commission is not attempting to exclude American cloud providers from Europe. Rather, it is creating a differentiated market where access depends on the sensitivity of the workload.
Most commercial cloud services and a large share of public-sector workloads will remain accessible to US hyperscalers through Tier 1 and potentially Tier 2 offerings. However, as one moves toward strategic government, defence, and critical infrastructure use cases, the framework increasingly favours providers that can demonstrate European ownership, control, and freedom from third-country influence.
The four-tier approach:
Tier 1: EU Location
- Data must be processed and stored in infrastructure physically located within the European Union.
- This is essentially a data residency requirement.
- It settles where data sits, but not who owns the provider or whether it is exposed to extraterritorial law.
Tier 2: EU Location + Independence Measures
- EU-based infrastructure.
- Demonstrated independence from third-country influence.
- Transparency regarding the software supply chain.
- The focus shifts from where the data is to who could potentially influence or access the service.
- This tier directly addresses concerns linked to foreign legislation and broader supply-chain transparency issues.
Tier 3: EU Ownership and Control
- The provider must be owned and controlled from within the EU.
- Additional requirements may include EU personnel and governance criteria.
- The Commission retains discretion to recognise certain third-country providers under specific conditions.
- This is the EU’s attempt to create a category of genuinely European-controlled cloud infrastructure.
- The issue is no longer technical control alone but corporate governance and strategic decision-making authority.
Tier 4: Full Sovereignty
- Full transparency and control over the software supply chain.
- No interference from any third country.
- The highest level of sovereignty assurance.
- This is the EU’s equivalent of a “strategic autonomy” cloud category.
- It is designed for the most sensitive workloads as part of highly sovereign European solutions, including for defence, national security, intelligence, and highly critical government functions and applications.
- To meet Tier 4 requirements, providers would likely need European ownership, European operational control, European-controlled software supply chains, and legal insulation from foreign governmental authority.
