The Cloud and AI Development Act (CADA) represents everything that’s wrong with Europe’s approach to digital sovereignty

The EU’s Tech Sovereignty Package is supposed to jump-start Europe’s “sovereign AI” ambitions. But due to fundamental misunderstandings about the technology behind ‘AI’ and the blind trust in Big Tech’s AI doomer and boomer narratives, it is more likely to instead hurt digital rights and the environment instead, and waste valuable public resources that should have been invested in actually increasing Europe’s digital resilience. The Cloud and AI Development (CADA) Act, a part of the Tech Sovereignty Package, adds up to an aggressive policy push to impose “European AI”.

By EDRi · October 8, 2026

EU’s Tech Sovereignty Package signals a shift in strategy but is riddled with internal contradictions

Published on 3 June, the European Commission’s Tech Sovereignty Package—comprising the Chips Act 2.0, the Cloud and AI Development Act (CADA), the EU Open Source Strategy, and a Strategic Roadmap for Energy Digitalisation—is portrayed as a significant shift in the EU’s digital governance strategy. It signals that the EU is no longer content to rely on regulatory frameworks like the General Data Protection Regulation (GDPR), Digital Services Act (DSA), Digital Markets Act (DMA) and the Artificial Intelligence (AI) Act. The EU now seeks to artificially inflate both the supply of and demand for AI data centres, as well as to expand the material infrastructures underpinning them.

Yet, as the rhetoric of “strategic autonomy” echoes through the policymaking corridors of Brussels, the Package is fractured by internal contradictions. It conflates the fraught competitiveness agenda with the goal of genuine digital self-determination, mistakes building AI data centres on EU soil for structural tech independence, and engages in what can only be described as “sovereignty-washing”—repackaging the deregulation of fundamental rights and environmental protection as an industrial win. This aggressive industrial policy also embraces the EU’s securitisation and militarisation agenda, as Europe’s loss of competitiveness is perceived as a security threat.

An aggressive industrial policy to impose “European AI”

The Commission’s AI policy is almost entirely based on the highly speculative assumption that ‘AI’ is the inevitable future of tech and everybody needs it now or they will lose out on global markets. It claims—without evidence—that “the Union’s limited data centre capacity poses a significant threat to its ability to benefit from the digital transformation” towards AI.

The CADA proposal specifically aims at “regaining and retaining control over data and cloud computing services” and “expanding domestic computational capacity” in order to push for broad AI adoption.

In order to achieve that, the Regulation proposes the massive funding of “research and innovation” projects through public funds and private investment. These projects—called “Cloud and AI Leadership Initiatives”—are supposed to develop, test and deploy “advanced AI technologies,” including autonomous cars, drones and robots (“physical AI”) and AI models for specific industrial sectors (“industrial AI”), notably in healthcare, defence, and in the public sector. CADA is thus supposed to provide the material conditions to implement the EU’s Apply AI strategy principle of “AI first,” forcing the use of more ‘AI’ on public administrations across the continent.

Moreover, CADA would require Member States to establish national “experience and acceleration centres for AI” meant to secure the widespread adoption of AI in private and public sectors. EU countries are also expected to adopt national strategies, mandating the application of the “AI first” principle by all private and public organisations.

On the infrastructure side, Member States would be required to designate so-called “Data Centres Acceleration Zones” on their territory, in which permit-granting procedures are sped up, energy supply is guaranteed, and environmental assessments are fast-tracked, an approach that can put some Member States in a tight spot and risks increasing popular discontent with such imposed infrastructural build-out in their communities.

Whose “digital sovereignty”?

The inherent flaw of the EU’s “digital sovereignty” policy, illustrated by CADA, is to focus its effort on territorial control over data, infrastructure, and supply chains, instead of the ability to control vendor dependencies and the technology itself. “Building tech in Europe” becomes a goal in itself, one that shifts public resources and attention towards an unproven technology that is currently developed in wildly overvalued markets full of highly indebted companies that may fail at any moment. But it buries a much more important question: What kind of tech should we be building? Who owns it, and whom does it serve?

There is no reason to believe that large, EU-based AI and data centre corporations are going to treat people’s personal data any better, respect the environment more, or not undermine democracy, than their US counterparts. Digital sovereignty is not about the sovereignty of nations, it is about the sovereignty of people to be in control of the technology they depend on.

What is more, this package cannot be read in isolation from the Commission’s broader deregulation agenda, notably the so-called “Digital Omnibus”. While CADA proposes to redirect significant amounts of public funding to private enterprises, the Omnibus strips away hard-won rights protections by weakening the AI Act and GDPR.

When our fundamental rights are stripped away in the name of European tech sovereignty, we need to ask the question: Whose digital sovereignty is this policy supposed to serve? True digital self-determination is not a goal desired only by Europeans, but by people around the world. By misunderstanding digital sovereignty for self-sufficiency and by attempting to build an insular, defensive digital Fortress Europe, the EU misses a crucial opportunity to support other countries as a leader for sovereign digital ecosystems that do not depend on Big Tech.

Militarisation undertones

Data centres are not neutral infrastructure. They can serve and support specific political goals such as military operations. For example, until a year ago, Israeli military intelligence relied until a year ago on Microsoft’s Azure cloud platform in the Netherlands to store its mass surveillance data. Google and Amazon Web Services also entered into a $1.2 billion contract with Israel’s armed forces, called “Project Nimbus”, which included the construction of multiple data centres in Israel to provide cloud computing services. OpenAI’s and Anthropic’s AI models have been used by the US government for military planning and analysis, and the latter has infamously almost led to a military confrontation with China. Hence, the EU’s industrial push for ‘AI’ and compute cannot be divorced from its own broader militarisation agenda, the main objective of which is to unlock EU and Member States’ defence spending, including military AI.

CADA contributes to this agenda by vowing to fund “highly secured” computing infrastructures for the training, testing and deployment of defence-related AI models. Its “sovereignty framework” to assess “cloud and AI independence” will also influence national public procurement policies for the defence sector.

Green-washing ahead

The Commission’s objective to force the massive build-out of new AI data centres comes at a time where Europeans are already acutely experiencing the dangerous effects of the climate crisis. The EU is already overshooting its internationally agreed emissions budget and with CADA as it is proposed, this could get much worse.

The CADA proposal aims to “triple EU capacity (…) and reach the needed capacity by 2035.” Estimates put the current European data centre market at a total energy consumption of about 13 Gigawatt (GW) by the end of 2026. Tripling that capacity would require 39 GW of electricity to be produced and transported to those AI data centres. For perspective: a typical nuclear reactor has a capacity of about 1 GW. 39 GW is the annually averaged power consumption of over 70 million people.

While the Commission promises the promotion of “clean energy” and “sustainable” data centres in “Data Acceleration Zones,” studies show this will not be sufficient to prevent a dramatic rise in overall greenhouse gas emissions. The direction accelerated by CADA will certainly not address the wider environmental and social problems generated by data centres, such as carbon emissions, excessive water demands, extraction of raw materials and e-waste, displacement of people and wildlife, and public health issues.

The Commission seems to be well aware of those risks and the public opposition against Europe’s data centre boom, as local communities increasingly mobilise to safeguard their living conditions and protest rising electricity prices, water and land use, as well as the unchecked power of Big Tech. As part of CADA, it therefore proposes that Member States create “single information points” to inform the public, “with the aim of increasing public acceptance of the data centre project.”

Breaking free from US Big Tech?

One of the Commission’s justifications for CADA is that without it European AI companies depend on foreign (read: US)-based “hyperscaler” infrastructure, which can pose a threat to people’s fundamental rights and to data protection due to “third-country jurisdictions” with “laws mandating data access and transfer.” Yet this is a wholly unconvincing argument from an institution that enacts, maintains, and expands exactly those data transfers via agreements like the 2022 “EU-US Data Privacy Framework”, and the new biometric data-sharing arrangement negotiated with the Trump administration.

In reality, with CADA, current and future data centres in the EU will continue to rely on US investors and tech companies, who will capture most of the wealth and entrench their power on European critical infrastructures while outsourcing the negative external effects on people and the environment onto communities in the EU.

Towards digital self-determination

First, the EU must acknowledge that fundamental rights are not an obstacle to the EU’s technological independence; they are a precondition. Europe’s rights-based order is what makes the continent attractive and helps working towards a world in which the economy works for everyone.

Second, instead of losing its head in the ‘AI’ cloud, the EU should focus on the key properties of any technology that fosters digital self-determination:

  • Does it avoid problematic dependencies and vendor lock-in?
  • Does it protect data security and user privacy?
  • Does it prevent market concentration and contribute to fair competition in the EU?
  • Is the technology interoperable with open standards and is the code open for inspection and re-use (open source)? Can it contribute to the digital commons?
  • Are the technology’s governance and business models compatible with democracy and human rights?

The jurisdiction and geographic location of any given vendor may play a part in this calculation—for instance to avoid service providers that are subject to authoritarian rule or pressure by hostile foreign governments—but it is not a sufficient sovereignty metric. CADA’s assumption that there is an absolute necessity for Europe to invest in its own polluting ‘AI’ data centres in order to become digitally sovereign, seems therefore fraught with contradictions at best, and plain wrong at worst.

Interestingly, the European Commission has already spelled out some of the things Europe should do to increase people’s digital self-determination in the accompanying EU Open Source Strategy:

  • Strengthen and promote a vibrant open source ecosystem, with a particular focus on public interest, non-profit digital infrastructure and their governing bodies;
  • Promote and support open and interoperable digital ecosystems for public administrations, including EU institutions, and become a real anchor customer for them;
  • In particular, strengthen the open source social media space by supporting open and decentralised social media solutions and platforms;
  • Build out the EU’s Open Source Programme Office (OSPO); and
  • Reinforce digital standards and international outreach.

While this list is by no means complete, it is a better start than CADA to start this conversation. Such an approach to a decentralised, open source, public interest-oriented tech ecosystem would provide Europe and its people with better digital resilience and a renewed sense of digital self-determination, rather than trying to win an imaginary “AI race” against the US and China, with little to no consideration for the environmental, societal, and financial risks it creates.

This blog post will be followed by a deeper policy analysis and EDRi is committed to constructively engaging with lawmakers.