The proposed Cloud and AI Development Act

The proposed Cloud and AI Development Act

The European Commission's proposed Cloud and AI Development Act would introduce four Union assurance levels for certain public-sector cloud procurement. The file remains under negotiation, so its mechanisms are not yet in force.

The current legal position

On 3 June 2026, the European Commission presented COM(2026) 502, its proposal for a Cloud and AI Development Act under procedure 2026/0138(COD). It is a proposal, not enacted law.

The Commission presents the initiative across three connected areas: research and innovation, measures to develop sustainable data-centre capacity, and a cloud-computing sovereignty framework intended to support public-sector adoption. Its cloud assurance and procurement provisions should be read separately from the development and infrastructure measures.

As at 9 September 2026, Parliament described the file as being in its preparatory phase, while a Council working party was still examining the proposed public-procurement provisions. The final text may therefore change. Parliament's legislative record provides the current parliamentary status.

The proposed Union assurance levels

Proposed Article 16 would establish four cumulative Union assurance levels for cloud-computing services supplied to Union entities and public-sector bodies. The detailed requirements sit in Annex II.

The levels would cover more than where a provider is incorporated. Their cumulative criteria include:

  • establishment, infrastructure and data location;
  • third-country control and data-access risks;
  • operational support and continuity arrangements;
  • software-supply-chain transparency; and
  • cybersecurity assurance.

The proposal envisages a different route for level 1 and for levels 2 to 4.

Proposed level Proposed route
Level 1 Conformity self-assessment and an EU statement of conformity
Levels 2 to 4 Independent third-party audit before recognition by a national competent authority

Under proposed Articles 17, 19 and 20, recognised services would be listed in a central repository. This is the Commission's proposed mechanism; it does not mean that a recognition system, auditors or register already operate under the Act. Nor would recognition be a general certification of legal compliance, a GDPR finding or a cybersecurity safe harbour.

From risk assessment to public procurement

The proposal would link assurance levels to identified public-sector activities rather than applying the same requirement to every public body, organisation or workload.

Under proposed Article 29, Member States and Union entities would assess cloud-using public activities connected with public order in sectors listed in NIS2 Annex I or Annex II, as well as specified state functions. They would then identify an appropriate level 2, 3 or 4 for the activities concerned.

Proposed Article 30 would require level 1 for other in-scope public procurement, and levels 2 to 4 for the public-order activities identified through that assessment. The proposal includes specified exceptional derogations. It would not require an immediate migration of every public-sector cloud service.

For innovative cloud services and AI systems, proposed Article 32 would also introduce ancillary, non-decisive non-price criteria. These include contributions to EU technology and supply chains. They would not override the wider technical, legal and procurement assessment.

The position for private NIS2 entities

The private-sector route is more limited. Under proposed Article 31, private entities in NIS2 Annex I sectors could carry out similar impact assessments voluntarily.

The Commission could later use a delegated act to require assessments and mitigation measures for specified high-criticality private entities. That would not create a general current or automatic assessment duty for all private-sector organisations covered by NIS2.

What cloud-dependent suppliers can prepare now

Manufacturers, service providers and security teams do not need to treat the proposal as a current legal obligation. They can, however, use the proposed framework as a useful prompt for due diligence, especially where their customers supply public-sector activities or critical services.

Useful preparation questions include:

  • Which cloud services, data flows and operational dependencies support each product or service?
  • Where are infrastructure, customer data and support functions located?
  • Which subcontractors and third parties contribute to service delivery?
  • What software-supply-chain evidence, including software bills of materials where relevant, is available?
  • What evidence supports cybersecurity assurance and operational continuity?
  • Could a customer's future public-sector risk assessment or procurement requirements affect the cloud service used in the supplier chain?

For example, a product manufacturer whose monitoring platform supports a customer operating an identified public-order activity may need to understand the customer's future procurement exposure. That is a scenario to test, not a present requirement or a conclusion that a particular backend will automatically determine procurement eligibility.

What to monitor during negotiations

The proposed Act would enter into force 20 days after publication in the Official Journal and apply one year later. No publication or application date exists while the proposal remains under negotiation.

Teams should monitor changes to the assurance criteria in Annex II, the proposed recognition and audit route, the scope of Article 29 risk assessments, procurement derogations, and any delegated-act powers affecting private high-criticality entities. They should also follow the data-protection issues raised by the European Data Protection Supervisor, which recommended further clarification and safeguards for the assurance criteria, audits, Article 29 assessments and procurement design.

The direction of travel is clear enough to justify preparation, but the legal and operational requirements will depend on the final adopted text.

Need help implementing cyber regulation?

Talk to Secuvi →