EU Proposes 4-Level Cloud Sovereignty Law as Defense Officials Warn of NATO Friction
Updated
Updated · InfoWorld · Sep 22
EU Proposes 4-Level Cloud Sovereignty Law as Defense Officials Warn of NATO Friction
3 articles · Updated · InfoWorld · Sep 22
Summary
The proposed Cloud and AI Development Act would create a four-tier sovereignty regime for EU institutions and public bodies, steering defense, justice and law-enforcement workloads toward higher-assurance cloud services.
Roughly 70% of Europe’s cloud infrastructure market is controlled by AWS, Microsoft and Google, a concentration Brussels says leaves public-sector data exposed to overseas—mainly US—laws.
Defense officials from eastern and Nordic member states are resisting the plan, arguing tighter sovereignty rules could limit access to US hyperscalers’ cloud and AI tools and weaken interoperability with NATO systems.
CADA includes exceptions where compliant services do not exist, but the debate highlights a broader trade-off: stronger jurisdictional control versus slower deployment, higher costs and thinner service ecosystems in European sovereign clouds.