Three months after the European Commission tabled the law meant to break Europe's dependence on American cloud computing, the loudest objections are not coming from Washington or from Amazon's lobbyists. They are coming from European defense ministries.
Officials and contractors across several member states are pressing Brussels to soften the sovereignty provisions of the Cloud and AI Development Act, or CADA, arguing that pushing armed forces off US-supplied cloud, software and data services before credible European substitutes exist would degrade capability rather than protect it, according to Financial Times reporting confirmed by European defense trade press. The fears are operational: less capable tooling, new cyber exposure created by migration itself, and friction with NATO systems European militaries plug into daily. Opposition is reported strongest among eastern and Nordic states, whose immediate task is reinforcing NATO's north-eastern flank. The officials making the argument have not been named publicly; the reporting rests on anonymous sourcing.
The clearest illustration is the F-35, whose operators exchange mission, logistics and maintenance data through a support ecosystem tightly coupled to US technology. Swapping a provider inside that architecture is not re-tendering an office software contract.
What the act would actually require
CADA was presented on June 3, 2026 as the centerpiece of the Commission's European Technological Sovereignty Package, alongside a revised Chips Act. Its explanatory memorandum states plainly that "the current landscape of cloud and AI is characterized by a pronounced dependence on a limited pool of third-country providers."
Article 16 would require public authorities — particularly those handling public order, national security, border management, defense, justice and law enforcement — to run sovereignty risk assessments against four ascending assurance levels. Level 1 requires data hosted on EU-located infrastructure by an EU entity, including EU subsidiaries of US firms, plus a guarantee the provider is not compelled to report unpatched software vulnerabilities to a third-country government. Level 2 adds proof that no third country can access hosted data or trigger a service cut-off. Level 3 bars control by a third country or a third-country legal entity. Level 4 — the defense tier — additionally demands that components be free of third-country control and carry the highest European cybersecurity certification.
Crucially, the strictest rules apply to very little. The Commission estimates roughly 70 percent of public contracts fall under Level 1, about 20 percent under Level 2, under 10 percent at Level 3, and roughly 1 percent — mainly defense-related — at Level 4, matching the Financial Times' sizing of the defense tier at about 1 percent of the public procurement market. Two derogations soften the edges: Article 30 lets authorities go outside the framework where "no adequate or reasonable alternative or comparable cloud computing service exists," and Article 18 opens a path for providers from "associated third countries" holding a GDPR adequacy decision.
The act pairs this with an infrastructure push: at least tripling EU data-center capacity within five to seven years, on an estimated €200 billion in mostly private investment.
The argument underneath the argument
Two distinct cases for sovereignty are being run in parallel, and CADA blurs them.
The security case is concrete. The US CLOUD Act permits unilateral American access to European-held data for law enforcement. The February 2025 US sanctions on International Criminal Court officials showed American firms can be compelled to sever services to Europeans — the episode that converted an abstract worry into what Brussels now calls the kill switch. Executive Vice-President for Technological Sovereignty Henna Virkkunen was explicit about the design intent: "We want to make sure that nobody has a so-called kill switch possibility there." Commission President Ursula von der Leyen framed it similarly: "We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure." The Netherlands blocked a US acquisition of its national ID system operator in June, citing the CLOUD Act.
The industrial case is separate and less often stated. European cloud providers hold roughly 15 percent of their own regional market, down from 29 percent in 2017, while Amazon, Microsoft and Google together take about 70 percent of a market Synergy Research Group sized at €61 billion in 2024. OVHcloud has estimated it needs roughly 15 percent of continental public procurement ring-fenced to reach competitive scale. Whether Levels 3 and 4 are a security floor or a subsidy in procurement clothing is the question the Council will actually be arguing about.
The capacity question is hardest. "As US cloud providers continue to invest some €10 billion every quarter in European capex programs, that presents an impossible hill to climb for any companies who wish to seriously challenge their market leadership," Synergy chief analyst John Dinsdale said in 2025. Gaia-X, launched to solve this problem, coincided with European share falling, not rising. CADA's defenders note the difference: Gaia-X was a voluntary federation; CADA is a binding regulation with procurement leverage behind it.
It also lands in an odd relationship with the EU AI Act, which excludes systems used exclusively for military, defense and national security purposes. Defense AI escaped the bloc's flagship AI law and is now being regulated through the back door of cloud procurement.
Industry has already pushed back. Technology associations from the US, Canada, Japan and Australia wrote to member state governments before the June 8 Telecom Council urging revision "in a manner that remains consistent with the principles of non-discrimination, proportionality, and openness to key trade partners."
What to watch
The file now sits with Parliament and Council, adoption targeted for the fourth quarter of 2027. Three variables matter: whether the Level 3 recognition clause for third-country providers survives intact, which is where the hyperscaler lobby is concentrated; whether defense ministries win staged timelines or NATO-interoperability carve-outs rather than a rewrite of the levels; and whether member states back European suppliers with actual contracts. The Bundeswehr's April decision to reject Palantir for its military cloud and AI project suggests some already will. Sovereignty written into a regulation is cheap; sovereignty bought with procurement budgets is not.
“We want to make sure that nobody has a so-called kill switch possibility there.”— Henna Virkkunen, EVP for Technological Sovereignty, European Commission