EU Cloud and AI Development Act Could Shut US Cloud Providers Out of Sensitive Public Contracts
Amazon, Microsoft and Google run most of Europe’s cloud computing. A law now moving through Brussels could decide whether they may keep hosting its most sensitive public data. On 8 September 2026 EU governments went through the key part of the proposed Cloud and AI Development Act, articles 29 to 44, article by article. Those articles set who qualifies to host public-sector data at each level of sensitivity, and they turn on conditions the United States may not meet.
The Commission proposed the Act on 3 June 2026. Its headline aim is industrial: to triple the EU’s data-centre capacity within five to seven years. Each member state would have to designate at least one acceleration zone for data centres, with permit decisions within twelve months. The sharper edge is in how public bodies buy cloud.
Four levels of sovereignty
The proposal sets four “Union assurance levels” for public-sector cloud. At level one, infrastructure and data must be in the EU. Level two adds EU-based staff and certification under the EU cloud security scheme. Level three requires the provider to be EU-owned and controlled, with one exception: providers from a third country can qualify if that country has an EU data adequacy decision, can’t force the provider to disrupt services, and keeps its own market open to EU cloud firms. Level four allows no third-country control at all and requires a high-level cybersecurity certificate.
In procurement, the proposal adds a “Union added value” criterion. The recitals suggest it could count for up to 15 of 120 points in a tender.
The level three exception is where the transatlantic argument sits. US providers could qualify only if the United States meets all three conditions. The first, an adequacy decision, depends on the EU–US Data Privacy Framework, which is itself under appeal.
The court case behind it
The Data Privacy Framework, adopted in 2023, survived its first challenge in September 2025, when the EU General Court rejected a case by the French MP Philippe Latombe. He appealed to the Court of Justice in October 2025. In June 2026 the Court allowed Microsoft to intervene. No hearing date has been announced.
If the Court of Justice strikes the framework down, as it did with two earlier versions, the US would lose its adequacy decision and with it, under the Act as proposed, the route to level three.
Who’s for and against
The tech industry lobby CCIA Europe called the proposal a recipe for fragmented discrimination and asked the Commission to withdraw it. The software industry group BSA objected to market access based on ownership and to data localisation. On the other side, the European Economic and Social Committee backed the Act in September by 212 votes to none, said its funding wasn’t secured and asked for the Union added value weighting to rise from 15 to 40 points out of 120.
In the Parliament, the industry and internal market committees share the lead, with rapporteurs Diego Solier and Reinier van Lanschot, appointed in June. The Council presidency, held by Ireland, has said it wants a constructive discussion rather than a rushed one. Ireland hosts the European operations of most big US tech firms.
How it compares
The US approach to government cloud, through FedRAMP, certifies security and doesn’t ask much about ownership, because most providers are American. France already has a sovereignty test in its SecNumCloud qualification, and Germany has its C5 standard. The EU-wide certification scheme, EUCS, has been stuck since 2024 on exactly the ownership question this Act now tries to answer in law.
The Act moves that argument from a technical certification body to the EU legislature. That makes it more political, and probably more durable. It also makes it a trade issue with Washington, which has already threatened to retaliate against Europe’s procurement preferences.