CADA tracker · source extraction
The Union is committed to become a global leader in artificial intelligence (AI). By enabling faster innovation, greater efficiency and smarter decision-making, AI contributes to substantial economic, environmental and societal gains and is a fundamental driver of competitiveness. In order to fully harness the benefits of AI …
The Union has already laid strong foundations to position Europe as a continent that leads AI development and uptake, in particular through the AI continent action plan communication (3) and Apply AI Strategy (4). With Regulation (EU) 2023/2854 (5) of the European Parliament and of the Council on harmonised rules on fair access to and …
The European Parliament, the Council, the Commission and the Member States have committed themselves to cooperate on delivering the Union’s technological sovereignty in an open manner, in particular by secure and accessible digital and data infrastructures that enable other technological developsments, supporting the competitiveness a…
The Union has become increasingly dependent on a limited number of cloud computing service providers from third countries. Reinforcing the Union’s capacity to develop and deploy cloud and AI technologies within its territory has become a strategic priority for the Union’s competitiveness, security of supply and technological sovereign…
Those dependencies translate not only into limited market shares for the European cloud computing service providers, but also into significant risks for the Union’s operational autonomy, resilience and security. The Council has called for a Cloud and AI Development Act to include common criteria for sovereign cloud computing services,…
A framework for increasing the Union’s resilience and security in the field of cloud and AI technologies should be established, reinforcing the Union’s cloud and AI ecosystem by reducing dependencies, enhancing technological sovereignty, stimulating investment and strengthening the capabilities, security, adaptability and resilience o…
The framework pursues separate objectives, relying on two distinct legal bases.
First, it is necessary to strengthen the competitiveness, capacity and resilience of the cloud and AI technological and industrial base of the Union in accordance with Article 173(3) of the Treaty on the Functioning of the European Union (TFEU). Such measures should not entail the harmonisation of national laws or regulations. To that …
Second, the available compute capacity and resilience of the cloud and AI ecosystem can best be addressed through Union harmonisation measures on the basis of Article 114 TFEU. A single coherent regulatory framework harmonising certain conditions for service providers and deployers of cloud computing services, including capacity b…
The definition of ‘cloud computing service’ in this Regulation should be the same as that in Article 6, point (30), of Directive (EU) 2022/2555 of the European Parliament and of the Council (12), which defines a ‘cloud computing service’ as a digital service that enables on-demand administration and broad remote access to a scalable and …
The Cloud and AI Leadership Initiatives should reinforce the competitiveness and resilience of the cloud and AI technological and industrial base of the Union, while strengthening the innovation capacity of its cloud and AI ecosystem and achieving the deployment of large-scale digital infrastructures, in line with the objectives set out in …
In order to pursue the achievement of those general objectives, the Cloud and AI Leadership Initiatives should support complementary operational objectives designed as actionable initiatives to be implemented at Union level.
To enable data centres to act as key enablers of a sustainable digital transition, the Cloud and AI Leadership Initiatives should support research and innovation capacities for the development of data centre technologies incorporating principles of energy and resource efficiency by design and throughout operations, with a view to achieving …
The Cloud and AI Leadership Initiatives should also support research, development activities and the uptake of cloud stack technologies with a view to closing the capacity gap and strengthening the technological autonomy of the Union. In particular, the Cloud and AI Leadership Initiatives should foster the development of cloud com…
The Cloud and AI Leadership Initiatives should also promote the development of technologies relying on open standards, open specifications and open source and foster the development of innovative, competitive and resilient cloud and AI technologies. It should foster the work on open standards and specifications and the creation of open- …
Frontier AI technologies are advancing rapidly and are expected to have a profound impact on the Union’s economy and society. As those technologies have become critical strategic assets, strengthening the Union’s capacity to develop and govern them is essential to ensure that the AI transition is aligned with Union values, safety 14 …
The emergence of physical AI, which refers to AI systems and models capable of perceiving the physical environment and executing complex actions within that environment, represents a promising frontier where advanced digital intelligence is integrated into tangible systems, such as robotics, autonomous drones and self-driving vehi…
The digital transformation of the Union’s key industries is a central pillar of the apply AI strategy. Accelerating the uptake of AI across those strategic sectors is essential to maintaining global competitiveness and increasing societal benefits. The Cloud and AI Leadership Initiatives should accelerate the development and uptake of industr…
In healthcare, those advancements should improve the accuracy of clinical decisions and transform the pharmaceutical sector. In the automotive sector, they should support the development, testing and deployment of innovative software platforms contributing to the Union industrial leadership in software defined vehicles and autonom…
The Union should also foster the availability of highly secured computing infrastructures for the training, testing and deployment of defence-related AI models and systems.
As AI agents have become increasingly capable and AI applications have become more deeply embedded in real-world business scenarios, industry is rapidly evolving towards a new paradigm that equips such systems with autonomous execution capabilities. This transition to a new paradigm requires a robust technical framework to ensure …
The Cloud and AI Leadership Initiatives should increase the development and adoption of AI models and systems across the Union’s public sector. In particular, AI models and systems should be used to support better decision-making, simplify administrative procedures and reduce unnecessary burdens, in particular for critical public …
The Cloud and AI Leadership Initiative should help accelerate the adoption of AI and cloud computing on a large scale, including at regional and local level. Broad adoption of AI in private and public sectors should be promoted through the network of Centres for AI. Harnessing this network, complementary support measures should be …
The Cloud and AI Leadership Initiatives should also ensure the uptake of cloud computing services provided by European cloud computing service providers across the public and private sectors to ensure that cloud adoption is consistent with the objective of strengthening the Union’s technological autonomy, particularly in sectors s…
Member States should establish Experience and acceleration centres for AI (‘Centres for AI’) with a view to ensuring an appropriate coverage of their territory. Centres for AI need to act as regional and local accelerators for the uptake and deployment of AI, cloud computing and other advanced technologies across the Union, supporting SMEs, …
The implementation of the Cloud and AI Leadership Initiatives should be entrusted to the Commission and Member States. The implementation of the Cloud and AI 16 Decision (EU) 2022/2481 of the European Parliament and of the Council of 14 December 2022 establishing the Digital Decade Policy Programme 2030, (OJ L 323, 19.12.2022, p. 4, ELI…
The Cloud and AI Leadership Initiatives’ operational objectives should, in particular, be implemented by setting ambitious, forward-looking objectives that aim to go beyond the current state of the art in infrastructure development, cloud computing and AI. The Cloud and AI Leadership Initiatives should therefore support major strategic …
The Cloud and AI Leadership Initiatives may be supported by funding from Union programmes and other instruments, in particular from Horizon Europe and the digital Europe programme, as well as the InvestEU programme, in accordance with Regulation (EU) 2021/694 (20), Regulation (EU) 2021/695 (21) and Regulation (EU) 2021/523 (22).Un…
In addition to receiving funding under Union programmes, the Cloud and AI Leadership Initiatives may be supported by Member States through research, development an innovation measures, in line with the applicable State aid rules, ensuring that national policies and Union policy are mutually consistent, as well as through private-s…
The Commission should receive advice from stakeholders with appropriate expertise on the implementation of the Cloud and AI Leadership Initiatives. The Commission should, in particular, foster cooperation with existing expert and advisory forums, such as the Alliance for Industrial Data, Edge and Cloud, the Apply AI Alliance and the …
The Cloud and AI Leadership Initiatives should enhance synergies with actions currently supported by the Union and Member States, including under Horizon Europe and the Digital Europe programme, as well as Council Regulation (EU) 2021/1173 and Regulation (EU) 2026/XXX [Chips Act 2.0] on a framework of measures for strengthening Eu…
In order to ensure that the policies of the Union and the Member States are mutually consistent, Member States should adopt national strategies to help achieve the Union’s objectives on the development of cloud and AI, in line with the AI continent action plan and the Apply AI Strategy. The national strategies should notably include the ‘AI …
Where a Member State has already adopted a national strategy that adequately covers the objectives set out in this Regulation, it should not be required to adopt another strategy. However, if a Member State identifies gaps in its existing strategy in light of those objectives, it should update it accordingly. The European Artificial Intellige…
Given the unprecedented scale of resources required for frontier AI development, it is necessary to set criteria for the designation of a project as a frontier AI priority project. Such projects should support the development and scaling-up of frontier AI technologies, notably in the sector of cybersecurity. In view of their technical …
The allocation of sufficient AI computing resources to frontier AI priority projects should be of strategic importance to the Union and the Member States. The Union should match, on a proportional basis and within the limits of available European high-performance computing (‘EuroHPC’) capacity, the AI computing resources contribut…
To achieve the Union’s AI ambitions, it is necessary to strengthen and invest in digital infrastructures, including cloud and edge capacity enabling training, fine-tuning, deployment and real-time operation. The deployment of data centres across the Union is lagging and remains concentrated in a limited number of established hubs, creating …
Data centres are critical infrastructure for the Union, and can create substantial economic value, including valuable investments and jobs, and may support innovation ecosystems – especially if they are integrated with local needs and follow best practices. If properly managed, the expansion of data centre capacity in the Union can …
Where capacity is being deployed on the territory of Member States, acceleration zones should be designated where the development, expansion and modernisation of data centres may be facilitated . The designation of such zones should help address the Union capacity gap and increase the Union’s competitiveness, autonomy and technolo…
When setting sustainability requirements for data centres deployed in data centre acceleration zones, Member States should ensure that the key performance indicators as defined in Commission Delegated Regulation (EU) 2024/1364 (24) in accordance with Directive (EU) 2023/1791 of the European Parliament and of the Council (25) are u…
To facilitate and accelerate the deployment of data centre projects in acceleration zones, Member States should designate single information points or where possible, upgrade or integrate with those designated pursuant to Regulation (EU) 2024/1309 of the European Parliament and of the Council (26).
Regulation (EU) 202X/XXX [on speeding-up environmental assessments] (27) establishes a common acceleration framework for environmental assessments to boost the Union’s roll-out of key technologies, reduce dependencies and increase competitiveness. Procedures linked to environmental assessments should be accelerated and streamlined…
It should be possible for the Commission to designate as strategic projects data centre projects that significantly contribute to the Union’s digital and energy sectors and that meet clear criteria. Considering the importance of the data centre strategic projects, Member States may, without prejudice to Articles 107 and 108 TFEU, apply suppor…
Data centre strategic projects should be granted support from Union programmes, funds and financial instruments, in accordance with the objectives set out in the regulation establishing those funds and programmes and without prejudice to the next (2028-2034) multiannual financial framework. In particular, those strategic projects …
To foster the strategic deployment of data centre capacity across the Union, the Commission should monitor the available compute capacity and the volume of demand for data centre capacity and identify the size of the capacity gap across the Union. Such monitoring may be used by the Commission to inform its possible recommendations…
This Regulation should apply to Union institutions, bodies, offices and agencies (‘Union entities’) when carrying out procedures for the procurement of cloud computing services and AI systems falling within the scope of this Regulation.
The Union still remains critically dependent on a limited number of cloud computing service providers subject to the control of third countries or legal entities established in third-countries. This exposes the Union to critical strategic dependencies and concentration risks, including vulnerabilities arising from the extraterritorial …
Existing Union law addresses cybersecurity, data protection, interoperability and data portability requirements which cloud computing services are subject to. However, there is no cross-cutting Union regulatory framework establishing a harmonised understanding of what constitutes a trusted cloud computing service for mitigating su…
Cloud computing service providers have launched tailored versions of their service offerings in response to the Union’s growing concerns over sovereignty. However, those versions do not address the core sovereignty issues allowing for the extraterritorial reach of third-country laws and the possible degradation or disruption of th…
Against this background, the significant increase in public order concerns – including, for example, economic security risks – requires effective and coherent implementation of safeguards for activities supported by the Union budget. In the context of Union entities, Article 136 of Regulation (EU, Euratom) 2024/2509 (29), sets out the scope, …
To protect public order, it is therefore necessary to specify the conditions that Union and Member States’ contracting authorities should use in public procurement procedures of cloud computing services. The consideration of possible exposure to risk is fundamental when selecting appropriate mitigation measures to preserve the pub…
To address those risks and provide for the appropriate mitigation measures, it is necessary to establish a Union cloud computing sovereignty framework determining criteria for trusted cloud computing services. To cater for the nuanced and layered nature of sovereignty, the framework should provide for four different levels of trusted …
The Union assurance levels should provide for a proportionate framework to ensure that public order is preserved by maintaining control and agency by public-sector bodies. Most public services would not require the highest levels of assurance. In some specific cases Union assurance levels 3 or 4 may be considered necessary and pro…
It is important that national competent authorities of establishment of the cloud computing service provider can assess whether cloud computing service providers aiming to provide their cloud computing services to Union entities and public sector bodies offer the appropriate assurance level. A mechanism for recognition of cloud 29 …
In order to demonstrate compliance with Union assurance level 1, cloud computing service providers should have sole responsibility for carrying out conformity self- assessments by applying the relevant criteria for that Union assurance level. Such self- assessments should be based on documented evidence, internal control procedures and …
Independent audits are an important tool for monitoring the compliance of cloud compuring services provided by cloud computing service. Given the need to ensure that the applicable criteria for Union assurance levels 2, 3 or 4 are verified by third- party independent experts, cloud computing service providers should be accountable, …
The audit report should be substantiated to give a meaningful account of the activities undertaken and the conclusions reached during the audit. It should help provide information for, and where appropriate suggest improvements to, the measures taken by the cloud computing service providers to comply with the applicable criteria and …
The establishment of a central repository of recognised Union-assured cloud computing services is necessary to facilitate the secure and efficient storage, access and exchange of relevant information between public sector customers of services offering Union assurance levels, auditing organisations, competent authorities and the C…
To ensure the continued accuracy and reliability of the status of cloud computing services as offering Union assurance levels pursuant to the cloud sovereignty framework, providers should be required to promptly report any relevant information or material changes in circumstances to the auditing organisation and the competent auth…
To ensure effective and consistent application of the cloud sovereignty framework, Member States should designate one or more competent authorities responsible for recognising the auditing procedure and framework and the supervision of recognised cloud computing service providers. Those authorities should be granted the necessary …
The provision of mutual assistance between competent authorities is essential to ensure the effective supervision and enforcement of this Regulation across the Union borders, including through the timely exchange of information, coordination of investigative measures and support in the execution of tasks within the Union. Furtherm…
The Union’s objective of strengthening its autonomy should be pursued in a manner that remains open, cooperative and consistent with the Union’s international commitments and partnerships. The policy objectives pursued through Union assurance levels 1, 2, and 3 should therefore be understood as the Union’s capacity to act autonomo…
To ensure a coherent and risk-based approach to the autonomy of the Union, Member States and the Union entities should carry out one or more risk assessments to determine public-sector activities that concerns public order. The risk assessment should determine which Union assurance level is appropriate for the activities, due to t…
In their risk assessments, Union entities and Member State shall assess the sensitivity, criticality and magnitude of personal and non-personal data processed in cloud environment. Such processing may include ordinary business information, commercially sensitive information, operationally critical data, personal data within the me…
The free flow of data within the Union is an essential condition for the proper functioning of the internal market. To promote the free flow of data within the Union and to support the functioning of the internal market, it is appropriate that Member States ensure that data is not confined to the territory of a single Member State and …
To enhance resilience and limit dependency on a single cloud computing service provider, Union entities and Member States should, as part of their public procurement procedures, consider whether a multi-vendor or multi-cloud strategy may be appropriate. The decision to adopt and implement a multi-cloud architecture should be based…
Public procurement frequently serves as a primary signal of market direction. Requirements imposed by or on public authorities to adopt specific assurance levels offered by cloud computing services tend to be mirrored by private-sector entities operating in regulated industries, with subsequent spillover effects contributing to br…
In public procurement procedures for cloud computing services and AI systems, contracting authorities should include clear European added value as part of the quality evaluation of the tender. Such added value should consist in helping reinforce the digital supply chain in the Union; integrating Union technologies; conducting the …
Innovation procurement in cloud computing services and AI systems is essential to foster technological development, strengthen digital resilience and competitiveness and enable public authorities to benefit from secure, efficient and trustworthy digital solutions that evolve with rapidly changing technological and societal needs. Member …
In the joint declarations ‘Building the next-generation cloud for businesses and the public sector in the EU’ of 15 October 2020 (30) and the Berlin Declaration on Digital Society and Value-Based Digital Government of 8 December 2020 (31), Member States expressed great interest in determining a common approach to federating cloud …
The members of the EuroCloud Federation should comply with specific requirements to avoid any distortion of competition in relation to private economic operators by placing a private provider of services in a position of advantage over its competitors. 30 Joint declaration, ‘Building the next generation cloud for businesses and the publ…
Participation within the EuroCloud Federation should be limited to public entities, without direct participation of a private party. In this regard, direct private participation should be excluded where the sharing entity, either directly or indirectly through an intermediate legal entity, owns the hardware, as defined in Article 3, point …
To ensure effective, secure and resilient provision of services, the sharing entity should put in place appropriate technical, operational and organisational measures. This should include, in particular, policies on risk analysis and information system security, including access control policies, policies on incident handling and business …
Finally, the sharing of data centre services and cloud computing services within the EuroCloud Federation should be anchored in a public-sector cooperation. Such cooperation should be governed solely by considerations of public interest, and should not entail any form of consideration in exchange for another. In particular, the sharing …
Contracting authorities of Member States frequently encounter significant difficulties in procuring digital solutions such as data centre services, cloud computing services, software and AI systems. Limited financial resources, reduced purchasing power, insufficient technical or procurement expertise prevent public-sector bodies from …
In order to increase flexibility and administrative efficiency, it is appropriate to provide, in a derogation from the Regulation (EU, Euratom) 2024/2509, for the possibility of adding participating entities during the lifespan of a dynamic purchasing system. Under that derogation, participating entities that have acceded to the a…
The Commission should present to the Member States a draft agreement setting out the practical arrangements governing the procurement activities. Given the potentially large number of participating entities involved, that draft agreement should be negotiated and initially concluded between the Commission and the Member States will…
Where participating entities enter into an agreement for the provision of central purchasing activities, including ancillary purchasing activities, they should not apply the public procurement procedures provided for in applicable Union law, in accordance with Directive 2014/24/EU and Regulation (EU, Euratom) 2024/2509. Any contra…
The agreement should establish a steering committee composed of the Commission and representatives of Member States. The committee is responsible for strategic oversight of the procurement activities, including the strategic guidance of the agenda of public procurement activities and of each procurement procedure. The steering com…
The rules governing responsibility and the applicable public procurement framework between the Commission, acting as a central purchasing body, and the participating entities procuring through it should be clarified in the agreement. Where a participating entity conducts certain parts of the procurement procedure autonomously, it …
In order to ensure that the necessary resources remain available, the participating entities will contribute to the costs incurred in the procurement procedures and any ancillary activity. To this end, the Commission should be entitled to charge fees to the participating entities. Those fees should be set at a level sufficient in principle to…
Open source plays an important role in ensuring transparency, security and efficiency in the use of digital technologies by the public sector. Access to the source code enables auditability, fosters collaboration and reuse and reduces dependency on a single vendor, thereby limiting the risk of vendor lock-in. Promoting the use of open …
To ensure the efficient, transparent and interoperable use of digital technologies across the Union’s public sector, it is necessary for public administrations to promote open standards and components released under an open source licence when building their cloud and AI ecosystem or stack.
An increasing number of Union entities and public-sector bodies are sharing software developed by or for them and making it available for reuse under an open-source licence. This may be considered to be in the public interest and may maximise the value of public expenditure, reduce duplication costs and foster innovation across the …
In order to ensure effective and consistent implementation across the Union of the obligations to conduct an open-source assessment and to make software available for reuse, it is necessary to set up a network of open-source programme offices (‘the OSPO network’) bringing together the relevant structures within Union entities and …
In order to take account of technological development and maintain an efficient framework of measures for strengthening the cloud and AI ecosystem at Union level, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of: amending Annex I to reflect relevant market and technolo…
When adopting delegated acts under this Regulation, it is of particular importance that the Commission carries out appropriate consultations during its preparatory work, including at expert level, and that those consultations are conducted in accordance with the principles set out in the Interinstitutional Agreement of 13 April 2016 on …
In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission. Those powers should 35 Regulation (EU) 2024/903 of the European Parliament and of the Council of 13 March 2024 laying down measures for a high level of public sector interoperability across the Unio…
Due to the relevance of this Regulation on the protection of personal data, the European Data Protection Supervisor should be consulted, where necessary, in accordance with Article 42(1) of Regulation (EU) 2018/1725 (38).
If any of the measures provided for by this Regulation constitute State aid, the provisions concerning such measures are without prejudice to the application of Articles 107 and 108 TFEU.
This Regulation should be without prejudice to the application of Articles 101 and 102 TFEU, and to the enforcement powers of competition authorities.
Since the objectives of this Regulation cannot be sufficiently achieved by the Member States, but can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the TEU. In accordance with the principle of…