European defense officials are resisting certain aspects of the EU’s proposed Cloud and AI Development Act that would impose stricter sovereignty requirements on cloud services used by military and other sensitive public-sector systems, as reported by the Financial Times.
According to the report, officials from various EU countries, including those in Eastern and Nordic regions, are worried that these provisions could limit the use of US cloud providers for high-security workloads.
The European Commission introduced the Cloud and AI Development Act (CADA) in June, covering aspects such as data center capacity, public-sector cloud procurement, and dependencies on non-European cloud and AI providers.
CADA establishes a four-level framework to evaluate the sovereignty of cloud services utilized by EU institutions and public-sector organizations. The criteria encompass infrastructure location, operational control, ownership, software supply chains, and exposure to third-country jurisdictions, with stricter requirements at higher assurance levels.
Under Article 29, member states and EU entities would conduct risk assessments to identify public-sector activities using cloud services that contribute to maintaining public order. Activities in areas like national security, defense, internal security, border management, justice, and law enforcement would be required to use cloud services meeting assurance Levels 2, 3, or 4 as per Article 30.
While the proposal does not outright ban US cloud providers, exceptions are permitted when compliant services are not available, procurement processes fail to yield suitable offers, or other conditions specified in the regulation apply.
The NATO Alliance Digital Strategy for January 2026 advocates for a federated, multi-classification, scalable, and hybrid cloud model integrated with tactical edge computing. It emphasizes interoperability for countries joining federated networks used in NATO-led operations and infrastructure objectives aligned with international standards and NATO-agreed reference architectures.
The Financial Times highlighted concerns from defense officials regarding the potential limitations on access to cloud and AI capabilities from major providers like Amazon, Microsoft, and Google due to stricter sovereignty requirements. Interoperability with NATO systems was also raised as a concern.
The European Defense Fund’s 2026 program outlines specific technical requirements for military cloud infrastructure, allocating funds for military multi-domain operations cloud services across various operational domains.
The program mandates military cloud infrastructure and associated networks to possess self-forming, self-healing, and redundant capabilities, ensuring data consistency and failover provisions during communication disruptions. Interoperability with NATO standards is also a key component of the program.
Overall, the article emphasizes the evolving landscape of cloud infrastructure in Europe, with a focus on sovereignty requirements, interoperability, and the role of major cloud providers in meeting these demands. The unique content seamlessly integrates with a WordPress platform, maintaining the original structure and key points of the article.



