This IDC Market Perspective examines the European Commission's proposed Cloud and AI Development Act (CADA), published on June 3, 2026, as the centerpiece of the European Union's (EU's) Technological Sovereignty Package. CADA pairs supply-side measures to expand EU compute capacity with demand-side procurement levers and introduces four Union assurance levels that classify cloud services against progressively stricter requirements for infrastructure location, ownership and control, personnel, data localization, cybersecurity certification, and software supply chain transparency, backed by a detailed audit-evidence regime.IDC's view is that CADA is well aligned with how European buyers now think about sovereignty — as IT risk management rather than a political label — and that CADA's greatest contribution is to replace self-declared "sovereign" claims with an audited, evidence-based framework. Drawing on IDC's 2026 Worldwide Digital Sovereignty Survey, the document shows interest rising sharply in Western Europe (73%), while wholesale abandonment of global providers remains marginal (3%), confirming a balanced "glocal" posture rather than a "techxit." The analysis flags three areas that will determine CADA's success: how conservatively member states apply the assurance ladder, whether the market delivers genuinely disconnected, EU-operable control planes, and whether ambitious AI-sovereignty requirements can be verified rather than merely asserted."CADA's real achievement is to turn sovereignty from a contested label into something that can be audited and proven. That is exactly the shift the market needs. But its impact will be decided in implementation. If the strictest tiers are reserved for genuinely critical workloads and verifying sovereignty over marketing claims is rewarded, CADA reinforces the balanced, trusted-ecosystem model our evidence says European buyers actually want," says Rahiel Nasir, research director, Cloud and Datacenter Infrastructure Services, IDC.
This IDC Market Perspective examines the European Commission's proposed Cloud and AI Development Act (CADA), published on June 3, 2026, as the centerpiece of the European Union's (EU's) Technological Sovereignty Package. CADA pairs supply-side measures to expand EU compute capacity with demand-side procurement levers and introduces four Union assurance levels that classify cloud services against progressively stricter requirements for infrastructure location, ownership and control, personnel, data localization, cybersecurity certification, and software supply chain transparency, backed by a detailed audit-evidence regime.
IDC's view is that CADA is well aligned with how European buyers now think about sovereignty — as IT risk management rather than a political label — and that CADA's greatest contribution is to replace self-declared "sovereign" claims with an audited, evidence-based framework. Drawing on IDC's 2026 Worldwide Digital Sovereignty Survey, the document shows interest rising sharply in Western Europe (73%), while wholesale abandonment of global providers remains marginal (3%), confirming a balanced "glocal" posture rather than a "techxit." The analysis flags three areas that will determine CADA's success: how conservatively member states apply the assurance ladder, whether the market delivers genuinely disconnected, EU-operable control planes, and whether ambitious AI-sovereignty requirements can be verified rather than merely asserted.
"CADA's real achievement is to turn sovereignty from a contested label into something that can be audited and proven. That is exactly the shift the market needs. But its impact will be decided in implementation. If the strictest tiers are reserved for genuinely critical workloads and verifying sovereignty over marketing claims is rewarded, CADA reinforces the balanced, trusted-ecosystem model our evidence says European buyers actually want," says Rahiel Nasir, research director, Cloud and Datacenter Infrastructure Services, IDC.
Coverage