CADA: An (E)U-turn on AI regulation
The new EU Cloud and AI Development Act (CADA) proposal marks a genuine shift in the way the bloc regulates AI, as it codifies the “AI first” principle and it is as much an “AI promotion and enabling”-type of legislation as it is a cloud sovereignty one.
The European Commission published the CADA proposal at the beginning of June 2026, as part of a broader EU Tech Sovereignty package. The legislative proposal has two general objectives: to increase the competitiveness and innovation capacity of the EU in the cloud and AI ecosystems; and to increase the resilience and strategic autonomy in cloud and AI technologies of the EU.1 This analysis focuses primarily on how CADA implements the first objective related to competitiveness and innovation. So far, this part of the proposal has received significantly less attention than the way CADA deals with the second objective on strategic autonomy through laying out cloud assurance levels for public procurement, which is set to affect the complex integrations of technology stacks. This, despite the fact that the “AI promotion” part of CADA marks a fundamental shift in the way the EU regulates AI and related technologies. The analysis also looks at where the two objectives intersect: key areas where sovereignty is imbued in the proposal’s AI promotion part.
The CADA proposal is arguably the first piece of comprehensive tech regulation introduced by the EU that provides for positive obligations to enable innovation and competitiveness, including facilitating the development and widespread adoption of AI. In doing so, it attempts to mobilize data for AI training, compute power, infrastructure, including data centers and federated cloud, EU funds, national programmatic action and all-of-government approaches to AI adoption.
In fact, reading Titles II (“Research, Development and Deployment Activities for the Cloud and AI Ecosystem”) and III (“Data Centre Capacities”) of CADA, one can draw comparisons to, and find similarities with “America’s AI Action Plan” published by the White House in 2025 and Japan’s “AI Promotion Act”. Remarkably, neither of Titles II and III of CADA virtually includes any obligation for companies among their provisions. The scarcity of obligations for companies in the AI supply chain and the onus on governments to act are foundational policies connecting the three frameworks.
CADA aims to achieve its competitiveness and innovation capacity objectives through setting up “Cloud and AI Leadership Initiatives”, with obligations for Member States and the Commission, including the creation of “Centers for AI” in each Member State and adoption of National AI Strategies. Among other measures, it pledges compute support for frontier AI priority projects, it creates a framework for the “accelerated deployment of data centers”, including a streamlined local authorization process for designated data center “acceleration zones”, and pushes to make vast amounts of data available for AI training, building up on the loosened provisions proposed in the Digital Omnibus. The proposal also aims to codify verbatim the “AI first” principle that was launched as European policy in a public speech by the President of the Commission, Ursula von der Leyen, in early October 2025, before being included in the Apply AI Strategy of the Commission.
On one hand, all of this seems at odds with the significant first iteration of AI regulation proposed by the EU – the EU AI Act – which regulates AI primarily as a risk, drawing from product safety and fundamental rights legal protections, includes “red lines” for specific uses of AI, and rules for high-risk AI systems and for general purpose AI models. Following the publication of the Draghi report, the AI Act has been criticized for being over-bureaucratic and a potential barrier to AI development, with the Commission itself proposing simplification measures through an AI Omnibus. On the other hand, these AI-enabling measures included in the CADA proposal could be effective and more easily accepted throughout the EU precisely because they are not proposed in a vacuum of AI safety rules.
Below, this blog details (1) what are the markers of an AI-enabling legislation present in the CADA proposal, lays out (2) how it aims to embed the “AI first” principle into EU law, before (3) exploring how the proposal elevates making data available for AI training as a strategic goal at EU level. It then (4) analyzes how sovereignty is imbued in the “AI promotion” part of CADA, before reaching (5) conclusions.
1.Markers of AI-enabling Legislation: AI Leadership Initiatives, Centers for AI, and Streamlined Permitting for Data Centers
The CADA Proposal introduces “Cloud and AI Leadership Initiatives” as one of its main tenets, whose implementation is placed primarily on the European Commission and the Member States2. While the proposal does not define what the nature of these initiatives is, it establishes detailed operational objectives to be reached by them, from advancing the EU’s capabilities in frontier AI, to supporting the development of advanced platforms for the large-scale deployment of AI agents (see Table 1 below for the full list). It is notable that CADA also proposes legal definitions for both “frontier AI” and “AI agents”, filling thus a gap of the EU AI Act, which omits these two concepts. 3

Table 1. Operational objectives of the Cloud and AI Leadership Initiatives, Article 3(2) CADA
These eight operational objectives are each further dissected into multiple actions under Article 4, and each of them maps to one of the “Grand Challenges” listed in Annex I of the CADA proposal, to a large extent. These “Grand Challenges” are “the most strategic technological and industrial challenges” the Commission estimates that the EU is facing, and the CADA proposal wants to address them through large-scale, cross-sectoral initiatives.4 This is why it is important to read each of the operational objectives listed under Article 3(2) CADA together with the detailed actions under Article 4 and, further, their corresponding “grand challenge” in Annex I.
Take “physical AI models” for example. Annex I establishes that, in order to tackle Grand Challenge 4 – Physical AI, “the focus will be on co-designing software and its underlying hardware architectures and on combining frontier AI techniques with world models (our emphasis – n.) supporting physical reasoning for delivering robust manipulation, navigation, and interaction capabilities with minimal human supervision”. The Annex further notes that potential applications could include autonomous robots, industrial systems and drones operating in dynamic real-world environments. At the same time, Article 3(2)(d) CADA proposal designates “advancing Union’s capabilities in physical AI models and systems and fostering their deployment across the Union’s strategic sectors” as one of the operational objectives of the Cloud and AI Leadership Initiatives. To top it off, Article 4(4) CADA proposal further identifies specific actions to promote physical AI:
- accelerate the development of a “European physical AI stack”, supporting model training and system development and deployment;
- facilitate access to, and the collection and preparation of specific datasets for physical AI;
- support the development, testing and validation in real-world environments of physical AI models and systems.
Thus, “world models” make their way into EU regulation, without being defined and with a focus on accelerating their development, including through making data available for training.
Frontier AI and Agentic AI are both targeted by CADA measures as well, with obligations for Member States and the Commission to “support the development of advanced, resilient and secure platforms for the development, deployment and orchestration of advanced AI agents at scale”, while creating a framework for the Commission to designate “Frontier AI priority projects”, if certain criteria are met – including that the project must be undertaken by a “European digital infrastructure consortium” (Article 8 CADA). Such designation would be important, given that Frontier priority projects would benefit from an obligation of the Member States and the Commission “to ensure” that sufficient computing resources are available for them within the limits of available capacity, per Article 9 CADA proposal.
The “Cloud and AI leadership initiatives” are complemented by more concrete AI-enabling obligations directed at Member States. Significantly, Member States would be under an obligation “to establish national cloud and AI strategies” within a year after the entry into force of CADA, which must include a prescriptive list of provisions. Among them, the national strategies must lay out measures to accelerate the development and adoption of cloud and AI at national, regional and local levels, measures to invest in high intensity computing infrastructure such as quantum computers, and measures to support the deployment of data center capacity, per Article 7(2) of the CADA proposal.
Additionally, Member States would be under an obligation to establish “Centers for AI”, whose objectives are to support the scaling-up of AI use cases in strategic and public sectors, accelerate a broad adoption of AI technologies at regional and local levels, and to leverage relevant infrastructure to accelerate the development and fine-tuning of AI models and systems (Article 5(1) CADA proposal).
The whole Title III of the CADA proposal focuses on data center capacities and has at its core an obligation for Member States to “designate at least one data center acceleration zone within its territory”, with a deadline of six months after the entry into force of CADA. Among other benefits, such acceleration zones would enjoy streamlined permitting procedures.
All of these characteristics squarely place CADA’s Titles II and III5 alongside AI promotion and enabling frameworks, such as Japan’s AI Promotion Act of 2025, or America’s AI Action Plan of 2025. First of all, the three frameworks – even if different in nature, varying between executive policy and adopted laws – virtually lack any significant obligations placed on companies in the AI supply chain and direct specific obligations to governments and public authorities. For instance, both the AI Action Plan and the CADA Proposal promote data center permitting acceleration6, the government as lead AI adopter7, facilitating compute access for start-ups and researchers8, or making data available for AI training9. The CADA Proposal is also similar to Japan’s AI Promotion Act through multiple elements, including the mandatory national planning and strategic cycle10.
2. Codifying the “AI First Principle”
The “AI first principle” is not yet clearly defined, even as it is making its way into EU law. The notion was brought into EU policy parlance by the President of the European Commission, Ursula von der Leyen, in a speech in October 2025 at the Italian Tech Week, where she said that the future “Apply AI” Strategy of the EU is based “on a simple, yet transformative principle: AI first”. She explained that “AI first” means that whenever a company or a public office is facing a new challenge, “the first question must always be: how can AI help?”. Von der Leyen specifically pointed out the transformative role of AI in healthcare, recalling that she is a medical doctor, and marveled at the promise of AI to save lives. She added that the Commission will “promote the same AI first approach across our strategic industries, from robotics to energy”.
Indeed, when the Apply AI Strategy was published weeks later, the document made specific reference to an “AI first policy”, stating that: “the Strategy promotes a shift in how companies and public sector organizations approach problem-solving. By adopting an AI first policy, they are encouraged to integrate AI building on European solutions.” The principle, thus, was also given a sovereignty flavor.
The Strategy went on to include subsections that “outline flagship initiatives to address the main sectoral challenges and support the AI first policy approach”, each dedicated to sectors like healthcare, defense and space, or mobility, among others. At the same time, the webpage of the European Commission which hosts the Strategy describes the document as encouraging “an ‘AI first policy’ where AI is considered as a potential solution whenever organisations make strategic or policy decisions, taking into careful consideration the benefits and the risks of the technology”.
The CADA proposal includes direct references to the “AI first principle” in its provisions, paving the way for it to be codified in EU law. One of the three objectives of the AI Centers that each Member State must establish is to “accelerate the broad adoption of cloud and AI technologies at regional and local levels, notably for SMEs (small and medium enterprises – n.), SMCs (small midcaps – n.) and public sector bodies, in line with the ‘AI first’ principle”, per Article 5(2)(b) of the CADA proposal, indicating thus that the principle is applicable both to the private and public sectors.
Additionally, the national strategies for cloud and AI that each Member State must adopt under Article 7 CADA have to include “key objectives and priorities for cloud and AI adoption, in line with the ‘AI first’ principle”. Recital 32 explains that this provision is about the “AI first principle” as “defined in the Apply AI Strategy, urging organizations to reflect on their business processes, considering the needs of and opportunities offered by AI, while taking into the consideration the potential risks”.
However, as shown above, the Apply AI Strategy refers to an AI first “policy”, not “principle”, which in any case it does not clearly define. Despite this, the animus behind it is clear enough, in the sense of enthusiasm for AI development, adoption and use. The legislative process for the CADA proposal will have opportunities for further clarification. This principle seems to also be the key explaining the push of the European Commission to make more data, including personal data, available for AI development.
3. Making data available for AI training becomes a strategic policy goal at the EU level
Among the many measures pushed by the CADA proposal to promote and enable AI, one stands out as intersectional: making data available for AI training. Recital 2 of the proposal explains the logic behind it by referring to how the EU “single market for data”, as promoted by the Data Act and the Data Union Strategy, “underpins the development of AI”. The CADA proposal has specific provisions that refer to either “personal” or “non-personal data”, which means that when it refers to “data” only, this term includes both categories.
Perhaps the biggest sign that making data available for AI training becomes a strategic policy goal in the EU is the obligation for Member States to include in their compulsory national cloud and AI strategies “measures to ensure the accessibility of high quality data for AI development, notably by preventing data bottlenecks encountered by organisations” (Article 7(2)(h) of the CADA proposal).
Two of the Grand Challenges in Annex I double down on data accessibility for AI training. While Grand Challenge 8, “Public Sector AI”, focuses on “enabling data sharing and frontier model development across national public services”, Grand Challenge 6, “Cooperative European Industrial Models”, focuses on enabling collaboration at European industrial scale to develop industrial AI models by pooling data in a “confidentiality-preserving” way. Both Challenges refer to specific privacy enhancing technologies as enablers of making data available for AI, such as “federated and distributed training approaches”, “secure execution environments”, “encryption-based processing”, “access compartmentalisation”, “anonymisation and pseudonymisation techniques”, “federated learning” or “high-fidelity synthetic data generation”.
Beyond the strategic desiderata, the CADA proposal also includes specific provisions for the operational objectives of the various “cloud and AI Leadership Initiatives” that push for making data available for AI development. As such, the relevant initiative in each case shall:
- “boost data availability for AI via open-source middleware platforms underpinning common European data spaces” to support the development of EU cloud computing stacks (Article 4(2)(c) CADA proposal);
- “facilitate access to, and the collection and preparation of, specific datasets for physical AI”, to advance physical AI models and systems in the EU (Article 4(4)(b) CADA proposal);
- “enable secure large-scale data pooling for collaborative AI training through technologies enhancing privacy and preserving confidentiality”, to accelerate the development and uptake of industrial AI, and to implement Grand Challenge 6 (Article 4(5)(c) CADA proposal);
- “promote the sharing and reusing of training data and AI models across the Union’s public services” to increase the development and adoption of AI models and systems across the EU’s public sectors (Article 4(7)(c) CADA proposal); and
- “facilitate secure, privacy-enhancing health data reuse for AI models and tools in healthcare”, also with the purpose of increasing AI development and adoption in the public sector (Article 4(7)(d) CADA proposal).
This multi-layered push to make data available for AI training seems to be built upon the measures included in the Digital Omnibus proposed in November 2025 by the European Commission, which, among other things, targets the amendment of the General Data Protection Regulation (GDPR) to loosen the rules for lawfully processing personal data, including sensitive data, for the purpose of AI training and operation. In this sense, the Digital Omnibus proposed an amendment establishing a new lawful ground for processing of personal data on the basis of legitimate interests “in the context of the development and operation of an AI system”, unless national law requires consent. Additionally, a new exception that allows the processing of sensitive data would be added to Article 9(2) GDPR in the context of both the development and operation of an AI system (going thus beyond training). The Digital Omnibus is still in the middle of a lengthy legislative process, with some Member States in the EU Council pushing against exactly these amendments.
4. Sovereignty is the common thread between the AI promotion and the cloud public procurement parts of the CADA proposal
The CADA proposal is the flagship initiative of the EU “Tech Sovereignty package”, making it not surprising that sovereignty is the common thread between the AI-promotion and the cloud public procurement parts of the legislative initiative. This is nonetheless worth mentioning, because as much as the EU is pushing for development and use of AI, the focus is certainly on “European AI”.
For instance, among the operational objectives of the Cloud and AI Leadership Initiatives some are explicitly focused on promoting local AI: “advancing Union’s capabilities in frontier AI” and “advancing Union’s capabilities in physical AI models and systems” (Article 3(2)(c) and (d) CADA proposal). Perhaps the clearest indicator that the measures CADA puts in place are meant to promote European AI are the criteria for designating frontier AI priority projects, which hinge on the projects being undertaken by “a European digital infrastructure consortium […] or another legal entity eligible for funding under Union law and it involves the participation of at least three Member States” (Article 8(b) CADA proposal). Such priority projects would enjoy “sufficient AI computing resources” to be made available by the EU and Member States, pursuant to obligations under Article 9 of the CADA proposal.
Promotion of European AI development is not only emphasized by the provisions above, but also through conditions placed on cloud service providers to reach assurance levels 2 to 4 that prohibit them to use the data generated by using their service “to train or fine-tune any AI system operated by a third country or a legal entity established in a third country”.11
Finally, open source solutions are specifically promoted through a duty of means for Member States and the EU more broadly to “encourage” public sector bodies to use open standards and components released under an open source license when building their cloud and AI stack (Article 41 CADA proposal and following, part of Title IV).
5. Conclusion
The CADA proposal with its AI promotion part was published around the same time the AI Omnibus meant to amend the AI Act was reaching its final stages of legislative approval. Once adopted, the AI Omnibus delayed compliance with its core obligations for high-risk AI systems to December 2027, at the earliest, and even into 2028 for some AI components of devices and machinery (high-risk AI systems that are safety components of products under Annex I of the AI Act).
The CADA proposal and the AI Act Omnibus seem to converge towards relaxing the AI regulatory landscape in Europe, relying on different tools: on one hand, creating an “enabling” framework, as described above, and on the other hand postponing the enforceability of the more stringent obligations for high-risk AI systems under the AI Act. Nonetheless, the risk management and AI safety philosophy of the AI Act remain relevant, even if delayed. It is conceivable the AI-promotion provisions of the CADA proposal will be easier to implement in the EU precisely because they build on an AI safety framework.
The shift in how the European Union aims to regulate AI is visible, though, and it is more akin to industrial and economic policy. Surprisingly, it seems to draw inspiration from American and Japanese AI innovation frameworks, with the difference that the EU proposes an AI-promotion framework on top of an AI safety law.
Access to data for AI development is a key layer of this new approach to AI regulation, as is the strong sovereignty impetus percolating throughout the proposal. The interplay between sovereignty requirements and data governance frameworks is a space FPF will be watching closely.
- Article 1(2) and (3) of CADA. ↩︎
- Per Article 6(1) CADA, which also states that, where necessary, “joint undertakings” or other structures capable of achieving the listed objectives can also play a role. ↩︎
- Article 2(4) CADA loosely defines “frontier AI” as “AI models or AI systems built upon such models that can perform a wide variety of tasks and that approach, reach or exceed the current state of the art”. In contrast, “AI agent” is defined with more precise terminology in Article 2(5) CADA as meaning “an AI system or a coordinated set of AI systems that can perceive and act upon their environment, with a degree of autonomy, using tools as needed to achieve specific goals and adapt to changing inputs and contexts”. ↩︎
- See p. 2 of the Proposal and Article 6(2) CADA. ↩︎
- And, partly, even title IV, through the Chapter dedicated to the promotion of open source technology. ↩︎
- CADA proposal: Articles 10-14 CADA; America’s AI Action Plan: Pillar II, “Create Streamlined Permitting…”, p. 14 – 15. ↩︎
- CADA proposal: Articles 7(2)(a) – (c); 4(7) – (8); 34; America’s AI Action Plan: Pillar I, p. 10 – 11. ↩︎
- CADA proposal: Articles 7(2)(e); 8 – 9; America’s AI Action Plan: Pillar I, “Encourage Open-Source and Open-Weight AI”, p. 4 – 5.
↩︎ - CADA proposal: Articles 7(2)(h); 4(2)(c), 4(4)(b), 4(7)(d); America’s AI Action Plan: Pillar I, p. 8 – 9.
↩︎ - CADA proposal: Article 7; Japan’s AI Promotion Act: Article 18. ↩︎
- Annex II, paragraphs 2.1(f); 3.1(f); and 4.1(f), CADA proposal. ↩︎