“CAIDA certifies hyperscalers rather than displacing them; without EUCS addressing CLOUD Act jurisdiction, sovereign-tier status is a legal label, not strategic.”
CAIDA's Sovereignty Tiers: Legal Architecture or Hyperscaler Licence to Stay?

CAIDA's tiered cloud framework lets AWS, Azure, and Google qualify as sovereign providers.
- Supply Chain × Scenario Modelling
- Supply Chain × Long-Memory Filter
- Policy × Scenario Modelling
- Policy × Long-Memory Filter
- Talent × Scenario Modelling
- Talent × Long-Memory Filter
3 of 6 cells applied
What to do next
- 01Audit all public sector cloud contracts now against CAIDA's tier classifications — do not wait for Commission guidance, as compressed timelines will inflate renegotiation costs.
- 02Require vendors to disclose the legal entity holding the master services agreement and the platform controller designation, not just data centre location, and embed this distinction in tender evaluation criteria before CAIDA's procurement rules take effect.
- 03Map member state implementation trajectories across BSI, ANSSI, and NCSC now, as divergent national interpretations of CAIDA's tier definitions will create fragmented compliance obligations that favour large incumbents.
- 04Stress-test any 'sovereign-compliant' vendor claim against US CLOUD Act exposure — an EU-domiciled subsidiary under a US-incorporated parent does not resolve federal compulsion risk regardless of data residency.
- 05Engage directly with EUCS standard-setting processes to push for explicit CLOUD Act jurisdictional criteria before CAIDA's procurement rules take effect, as this is the single highest-leverage intervention point in the current framework.
CAIDA's Sovereignty Tiers: Legal Architecture or Hyperscaler Licence to Stay?
Subject Line: CAIDA creates sovereign-cloud tiers — but US hyperscalers can qualify. Here is what that means for procurement.
Preview Text: The European Commission's new Cloud and AI Development Act does not exclude AWS, Azure, or Google Cloud. It gives them a compliance pathway. That is the problem.
Article
Executive Summary
- The European Commission's Cloud and AI Development Act (CAIDA), proposed 3 June 2026, creates tiered compliance categories for cloud providers — but does not exclude US hyperscalers. AWS, Azure, and Google Cloud can satisfy sovereign-cloud designations through EU-domiciled subsidiaries and technical partitioning.
- Public sector and critical infrastructure buyers face procurement rule changes without clear guidance on which vendors qualify under which tier — creating immediate budget and legal exposure.
- The structural risk is not that the law fails. It is that it succeeds on paper while entrenching the dependency it was designed to reduce.
The Signal
On 3 June 2026, the European Commission formally proposed CAIDA — the Cloud and AI Development Act — as the centrepiece of its broader Tech Sovereignty Package. The regulation attempts to convert "digital sovereignty", a phrase circulating in Brussels policy documents since at least 2020, into hard infrastructure law with enforceable procurement consequences.
The mechanism is a tiered compliance architecture. Providers are classified across sovereignty tiers on criteria including data residency, operational control, and jurisdictional exposure. Public sector buyers and critical infrastructure operators face new procurement rules that, in principle, restrict which tier of provider they may contract with for sensitive workloads.
What CAIDA does not do — and this is the operative fact — is exclude US hyperscalers from the EU cloud market. AWS, Microsoft Azure, and Google Cloud can qualify under the framework by routing compliance through EU-domiciled legal entities or by implementing technical partitioning of data and operations. As Euractiv reported, the Commission's sovereign cloud plan "would not exclude US hyperscalers from the EU cloud market" — raising immediate questions about the depth of sovereignty actually achieved.
The Noise
The mainstream framing presents CAIDA as a decisive step toward European cloud independence. That framing is wrong in a specific and consequential way.
It conflates legal compliance with operational sovereignty. These are not the same thing. A US hyperscaler operating through a German-registered subsidiary, with EU-resident staff managing day-to-day operations, can satisfy CAIDA's tier requirements while the underlying intellectual property, platform architecture, and — critically — jurisdictional exposure to the US CLOUD Act remain entirely unchanged. The EU-domiciled wrapper is real. The sovereignty is not.
EUobserver's analysis puts it precisely: the European tech sovereignty debate "conflates computational capability with genuine strategic autonomy." Technical compliance tiers can mask continued structural dependence on foreign platforms. Raconteur's reading of CAIDA reinforces the point — the practical definitions embedded in the tiers determine whether sovereignty is real or cosmetic, and those definitions currently leave substantial interpretive room.
The risk is not regulatory failure in the conventional sense. The risk is regulatory success that legitimises the status quo.
Forensic Analysis
Silicon. Technology moves faster than the tier definitions.
Hyperscalers have been anticipating a European sovereignty framework for years. AWS's European Sovereign Cloud, Azure's EU Data Boundary programme, and Google Cloud's Sovereign Controls for Europe were not reactive compliance exercises — they were pre-positioned products designed to satisfy exactly this kind of tiered regulatory architecture. By the time CAIDA's compliance criteria are finalised and enforcement begins, the hyperscalers will already hold certified sovereign-tier designations.
European cloud challengers — Scaleway, Hetzner, OVHcloud — lack the capital to compete on price at equivalent scale, and CAIDA's tier structure creates no preferential procurement pathways for European-headquartered providers. The compliance race was won before the regulation was published.
Stone. Geography and jurisdiction are not the same problem.
CAIDA addresses geography — where data sits, where operations run. The harder sovereignty problem is jurisdictional. The US CLOUD Act (2018, current law) grants US federal authorities the ability to compel US-headquartered companies to produce data held abroad, including in EU-domiciled subsidiaries, subject to certain procedural constraints. CAIDA's tier architecture does not resolve this exposure.
A nominally sovereign-compliant deployment on Azure's EU infrastructure remains subject to CLOUD Act reach if Microsoft Corporation — not its EU subsidiary — is the contracting entity or the platform controller. Politico's reporting on European industry concerns identifies this precisely: companies fear the law "codifies market access rather than curtailing it." That is not hyperbole. It is a structural reading of what the tiers actually require.
Strategic Implication
Procurement contracts require immediate legal audit — not a scheduled review.
Any public sector organisation currently operating on hyperscaler infrastructure needs to determine now whether its existing contracts will satisfy the tier requirements applicable to its workload classification under CAIDA. Jones Day's analysis flags significant renegotiation or termination exposure [AUTHOR: cite the specific Jones Day publication, date, and the precise language used — "significant implication" is too vague to stand as a sourced claim]. Agencies that wait for Commission guidance before auditing contracts will face compressed timelines and inflated renegotiation costs.
"Sovereign-compliant" vendor claims must be stress-tested against CLOUD Act exposure — not just data residency.
Procurement teams should require vendors to specify the legal entity holding the master services agreement and the platform controller designation, not merely the data centre location. If the contracting entity is a US-incorporated parent, data residency in Frankfurt does not resolve jurisdictional exposure. This distinction should be written into tender evaluation criteria before CAIDA's procurement rules take effect.
Member state interpretation divergence is the near-term operational risk.
CAIDA's tier definitions leave interpretive space that individual member states will fill differently. Germany's BSI, France's ANSSI, and the Netherlands' NCSC have historically applied EUCS-adjacent criteria with material differences in stringency [AUTHOR: one concrete example of a past divergence between these bodies would anchor this claim — a specific EUCS assessment, a national procurement ruling, or a documented policy disagreement]. Agencies operating across borders should map member state implementation trajectories now. A fragmented sovereign cloud market benefits large incumbents with the compliance resources to satisfy multiple national interpretations simultaneously.
The Long View
CAIDA is the most substantive attempt the Commission has made to translate digital sovereignty from political aspiration into procurement-grade law. That matters. The Deloitte analysis of the Tech Sovereignty Package is correct that compliance complexity will force genuine architectural decisions across the public and private sectors [AUTHOR: cite the specific Deloitte report — title, date, and the relevant passage]. The regulation is not cosmetic in intent.
But intent and effect are different things. The tier architecture, as currently proposed, creates a compliance pathway that US hyperscalers are better positioned to walk than European challengers. Sovereignty washing — rebranding existing EU-region deployments as sovereign-compliant — is not a hypothetical risk. It is the commercially rational response to the framework as written, and the hyperscalers have the legal and technical resources to execute it at speed.
The critical policy intervention is not in the tier definitions themselves. It sits in two adjacent mechanisms: whether CAIDA's enforcement body has the mandate and capacity to audit operational sovereignty rather than just legal structure; and whether the EU Cybersecurity Certification Scheme for Cloud (EUCS) criteria are tightened — before CAIDA's procurement rules take effect — to address CLOUD Act jurisdictional exposure explicitly. Without both, CAIDA will have achieved something precise and insufficient: it will have made hyperscaler dependency legible without making it reducible.
Europe has written the law. It has not yet built the alternative.
Stone Truth: CAIDA does not displace the hyperscalers — it certifies them. Until EUCS criteria address CLOUD Act jurisdiction directly, sovereign-tier compliance is a legal designation, not a guarantee of strategic independence.
Relevant for:
Go deeper: AI Act Compliance Toolkit
The structured governance toolkit: catalogue systems, classify risk, collect vendor evidence, and plan against the phased AI Act timetable.
Get it — From £79Related Intelligence
Europe's Open Source Gambit: The Sovereignty Play Nobody's Talking About
Europe can't out-build Silicon Valley. But it might out-open-source them.
The Collision Course: Trump's Tariffs vs. EU Tech Enforcement
30% tariffs. €35M fines. The Atlantic just got wider.
EU AI Act: What 2 August 2026 Actually Requires (and What Moves to 2027–28)
2 August 2026 moves the transparency line and switches on the penalty regime; the heavy high-risk obligations move to December 2027 and August 2028.