The European Commission wants the Cloud and AI Development Act (CADA) to expand Europe's cloud and AI infrastructure while introducing binding sovereignty tiers for sensitive procurement. Resistance is now emerging from the defence sector itself. According to the Financial Times, several European defence officials warn against replacing US providers too quickly with formally more sovereign alternatives if those alternatives cannot match performance, security capabilities or NATO interoperability.
What CADA actually proposes
The Commission presented the CADA proposal on June 3, 2026. It aims to expand European data-centre and AI capacity, create a common cloud-sovereignty framework and introduce new public-procurement rules. The proposal is still moving through the legislative process; it is not yet final law.
The draft defines several assurance or sovereignty levels. Sensitive areas including defence and security would be expected to use higher Union Assurance Levels in procurement. The text also provides derogations for justified cases. That distinction matters: CADA is not simply a blanket ban on US cloud providers.
Defence is a bad place for symbolic policy
According to the Financial Times report from September 4, officials particularly in northern and eastern European countries are concerned about operational disadvantages. Hyperscalers now provide much more than virtual machines: global networking, identity services, security analytics, highly available data platforms and mature interfaces to multinational partners.
For armed forces, provider jurisdiction is therefore only one dimension. Systems also need to interoperate under pressure, keep keys and identities under appropriate control, process classified data correctly, remain resilient during outages and integrate in practice with NATO partners.
Sovereignty is multidimensional
A serious technical assessment must distinguish at least four dimensions: legal control, operational control, technical dependency and exit capability. A European corporate logo does not answer all four.
A service can be operated in Europe while remaining dependent on proprietary US components, foreign update chains or non-portable APIs. Conversely, a US vendor's product may reduce some risks through local key control, isolated operating models, European personnel and contractual exit rights without becoming fully sovereign.
The real trade-off: dependency risk versus replacement risk
The EU has a legitimate strategic reason to reduce dependencies. Critical digital infrastructure that cannot be controlled creates supply, legal and availability risks during political crises. Those risks do not disappear if procurement rules force an operationally weaker service.
In defence, lack of interoperability can itself become a security problem. A formally sovereign stack that exchanges data less effectively in multinational operations, offers weaker detection or scales more slowly can reduce operational resilience. The right objective is therefore not “as little US technology as possible” but maximum controllable freedom of action under realistic crisis conditions.
Media check: 'EU versus US cloud' is too simple
The debate is easy to frame as an industrial fight between Brussels and American hyperscalers. That misses the technically more important issue. CADA uses graduated requirements and includes exceptions, while defence-sector objections are not automatically lobbying for US companies. Interoperability, functional maturity and migration risk are real engineering criteria.
FACT: The Commission wants sovereignty requirements integrated into cloud procurement. FACT: The proposal is not yet final law. FACT: Defence officials are pushing back against overly rigid requirements. INTERPRETATION: A sovereignty quota without measurable requirements for exit, key control, operational resilience and interoperability could weaken the very security it is supposed to improve.
Pandorex View
Europe has too often confused digital sovereignty with the physical location of a data centre. The next mistake would be to confuse it with the nationality of the provider.
CADA becomes useful when higher assurance tiers enforce technically verifiable properties: controllable keys, transparent supply chains, tested migration, credible exit paths, auditable administration and real crisis-operating capability. If it merely filters vendors by category, strategic autonomy can turn into strategic self-limitation.
Relevance: 8/10 · Regulatory significance: 9/10 · Security-policy significance: 9/10 · Confidence in final implementation: 5/10