CADA: EU's Bid for Tech Sovereignty Faces Criticism Amid US, China Tensions
July 22, 2026
CADA, framed as Europe’s Technological Sovereignty Package, aims to boost innovation, expand EU data center capacity, and establish an EU sovereignty framework for cloud and AI services.
The act signals Europe’s move to reduce dependence on US and Chinese tech by building European-owned infrastructure and standards, reflecting a proactive regulatory stance.
At its core, CADA would impose EU-centric data processing requirements and higher assurance levels, potentially excluding a portion of non-EU cloud contracts depending on implementation, while balancing risk protection with competitiveness.
Proportionality concerns warn that a sovereignty framework based on ownership could limit market access, fragment procurement, raise costs, and create entry barriers for smaller providers, especially in public and regulated sectors.
Critics argue that an origin-based sovereignty approach may distort incentives, reduce competition, raise costs, fragment procurement, and harm innovation and openness if not matched with risk-based controls.
Additional worries highlight potential negative impacts like reduced competition, fragmented procurement, higher costs, and barriers to entry if sovereignty is treated as ownership-based exclusion.
In the short term, Parliament is scrutinizing Article 31 and US hyperscalers are lobbying against Level 3 and Level 4 requirements that could function as origin-based restrictions.
Comparative analysis shows the US, Singapore, Australia, and UK rely on risk-based security certifications (e.g., FedRAMP, MTCS, IRAP, NCSC principles) rather than country-of-origin rules, suggesting governance and safeguards can achieve sovereignty.
Global frameworks emphasize risk-based security assessments over provider nationality, illustrating that sovereignty can be pursued through governance and technical controls.
The piece contrasts global approaches to show sovereignty objectives can be met without excluding providers by origin, through robust risk management and security standards.
Public procurement alone is unlikely to make Europe a global cloud leader; private decisions and national fragmentation could dilute effects, with member states often continuing to buy non-European or best-in-class providers.
Summary based on 15 sources



