Back to Research

Four fixes for the Cloud and AI Development Act

September 2026ByDavid Janků
a row of four repeated arch structures in an industrial setting, inspired by the reference shape, concrete and steel, calm engineered photography, no text
AI InfrastructureAI Resilience R&DStatecraft

The Cloud and AI Development Act is one of the main pieces of the Tech Sovereignty Package adopted by the Commission on 3 June. It aims to at least triple EU data centre capacity, and strengthen Europe’s sovereignty and competitiveness in the cloud and AI ecosystem. It creates fast-track Acceleration Zones for building datacentres, introduces a sovereignty framework governing how the public sector buys cloud and AI, and sets objectives for future EU funding through its Leadership Initiatives, focusing on public compute procurement.

In our June commentary on the package, we argued the Act gets the strategic direction right but leaves gaps: acceleration zones don’t address energy access, the sovereignty framework ignores model capability, and the investment objectives fund what private capital would build anyway. This piece, submitted to the Commission's public consultation, offers the fixes.

We make four recommendations:

  1. Make Acceleration Zones deliver fast power in addition to fast permits. Power access is the most crucial bottleneck cited by datacentre developers and the current proposal doesn't touch on that. Several interventions might be useful, ranging from extending the baseline zone-level permit to cover grid-connection infrastructure, to making the Grids Package queue principles and flexible connection agreements the default within zones, to including on-site energy generation and storage in the fast track regime. Finally, shortening permitting cap to 6 months and establishing default approval when deadline lapses would make zones more attractive and competitive for investors.
  2. Weigh model capability in the sovereignty framework. The sovereignty framework might push public institutions to choose providers of less capable AI models even in situations when capability directly influences competitiveness. We suggest that capability should be added as a criterion in the risk assessments, as well as an exception from the assurance levels for mission-critical activities when choosing providers.
  3. Recognise sovereignty audits once, for the whole Union. The currently proposed system might lead to long waiting time until the higher-tier providers are evaluated and approved. We suggest giving the home member state the option to delegate audit evaluation to a dedicated Commission unit whose decision would carry Union-wide validity, removing the 26-state review round and saving administrative capacities of member states.
  4. Make open source resilience a Leadership Initiative objective. Commission’s preference for open-source solutions might lead to increased vulnerabilities in public systems. We suggest the commission should proactively invest in creation of methods and tools that make openly available AI models safe to deploy as an explicit funding objective in Leadership Initiative.

1. Make Acceleration Zones deliver fast power in addition to fast permits

Quick data centre development needs two things: fast permits and fast power. On the permitting side, we think the Acceleration regime is well designed overall, but to make it more attractive for investors, we’d recommend shortening the permitting cap in Art. 13(5) from 12 to 6 months, and improve the regulatory predictability by establishing default approval where the deadline lapses.

On the energy side, however, the current proposal could use several upgrades. These range from accelerating the permitting process for grid connections, through better management of connection queues, to greater support for power sources independent of the grid (‘behind-the-meter’).

First, the zones pre-clear planning and environmental permitting, but grid connection is not included in the regime and does not have a deadline (recital 41). Member states must already weigh available and future grid capacity when designating the zones (Article 10(1), point (b)), so the regime directs demand towards existing capacity instead of pushing data centres up the queue in congested hubs with plenty of housing. However, connections routinely take several years, up to a decade in the busiest hubs, so a developer can clear permitting in twelve months and still wait years for power. We recommend addressing the grid connection issue on both levels - on the level of the zone, and on the level of individual projects. On the zone level, the aggregated baseline permit could be expanded to also cover permits required for the grid connection infrastructure serving the zone, such as connection lines, cable corridors and substations as well as on-site energy generation and storage. On the individual project level, the permitting cap should also cover permits for construction and operation of the grid connection infrastructure serving the acceleration zone.

Second, a deadline on grid connection only compresses the procedural part of the wait. However, grid connection delays are also driven by queue design and by physical capacity limits.

On the former, queue design: most member states still process connection requests in order of receipt, so mature data centre projects sit behind speculative applications that reserve capacity and never build — in Slovakia, an estimated half of all reserved capacity. The Commission's own Grids Package guidance recommends the fix: maturity-based processing ("first-ready, first-served"), milestone-linked capacity reservations and regular queue cleaning and reservation fees that deter speculative applications. However, as the package does not have a binding mandate, member states are adopting it unevenly: Germany's transmission operators switched to a maturity-based procedure for large loads, including data centres, in April 2026, and the Netherlands and Ireland apply readiness and milestone rules, but the Commission’s Notice itself concedes that the vast majority of member states still allocate connections on the first-come, first-served basis.

On the latter, physical constraints: where the grid is full, no deadline can conjure capacity. In such cases, the flexible connection agreements might be an effective instrument already provided for in Article 6a of the Electricity Directive: the data centre agrees in advance that its supply may be curtailed under defined grid conditions, and in exchange connects years earlier using headroom that firm customers cannot touch. The IEA estimates that a commitment of roughly 30 hours of flexibility per year could more than double the grid capacity available to European data centres; the US regulator is moving the same way, with curtailable large loads eligible for interconnection studies completed in as little as 60 days. Article 6a obliges member states to create a framework under which system operators may offer such agreements, but no operator has to offer one in any given case.

Neither change requires rewriting EU energy law. The energy framework already permits both practices and the Commission recommends them. We recommend explicitly adding these practices into the Data Centre Acceleration Zones proposal such that they apply within these zones by default.

Third, where even a flexible connection cannot deliver power in time, the developers might seek an alternative route: generating energy on site. Such generation doesn’t congest the grid and while it is generally supported at a high level elsewhere in Commission’s proposal (e.g. Article 10(1)(b) or Article 14(1)(c)), it’s not included in the fast track permitting regime.

We suggest two regimes of such energy generation: permanent (which should be clean), and temporary, permitted only for the gap between the project launch and grid connection (or permanent clean energy installation). Such temporary installation expires at the connection date, and stays subject to environmental law. We recommend that such on-site and co-located energy generation and storage should be included in the fast track permitting regime designed in Article 13(5).

2. Weigh model capability in the sovereignty framework

CADA introduces a sovereignty framework for the public sector's use of cloud and AI. In a nutshell, member states sort their procured cloud and AI activities by sensitivity and assign each one of four assurance levels, which determine how much insulation from non-EU control the services used for that activity must have. The higher assurance levels demand control over the service, its supply chain, infrastructure and personnel, together with insulation from third-country legal reach. Providers of leading proprietary AI models - all US-based - do not offer that level of control even when serving from European datacentres, since jurisdiction follows the company rather than the location of the servers. In practice, these assurance levels will therefore be easier to reach with self-hosted open-weight models, whose capabilities trail the frontier by several months. For many use cases, like summarising documents, drafting routine correspondence or translating administrative text, that gap does not matter. However, for competitive and high-stakes use-cases like R&D and defence, frontier capabilities will be necessary to ensure European competitiveness. Too stringent sovereignty requirements risk foreclosing those capabilities altogether, locking entire public sectors out of the best tools for the uses where they matter. Capability should thus belong in the risk assessment as a matter of sound method: an assessment that counts the risk of foreign access but ignores the cost of working with weaker tools is incomplete. Therefore, we recommend making a few narrow adjustments to the Framework that would bring the performance and capabilities into consideration: adding the gap in technical capability as one of the criteria in Article 29(2) risk assessment, as well as one of the criteria in Article 30(4), creating an exception for when public sector activity is identified as mission-critical and no cloud computing service or AI model recognised at the Union assurance level required provides the technical capability that the activity requires.

3. Recognise sovereignty audits once, for the whole Union

In the current proposal, a provider submits its audit to its home member state, which evaluates it and sends its draft decision to the other 26 member states for a review period in which any of them can object. Such a process is lengthy and might delay the arrival of higher-tier providers for months. We recommend giving the home member state a second option at the evaluation step: delegating the assessment to a dedicated Commission unit whose decision carries Union-wide validity by default, which makes the review round unnecessary and cuts months from the process.

Such design still leaves the decision in member states' hands, and thus does not run into problems with subsidiarity. The provider still applies to its member state of establishment, and it is that member state that decides whether to evaluate through its own authority or pass the file to the Commission, so no member state can be forced onto the Union track. The member states lose their review window whenever a file goes to the Commission, but they lose it to the body that already has the last word. Moreover, this would also alleviate pressure on administrations with limited resources who would no longer need to build audit bureaucracies, either to evaluate their own providers or to review everyone else's.

4. Make open source resilience a Leadership Initiative objective

The Leadership Initiatives are CADA's investment arm. They move no money themselves, but they set some of the objectives for the dedicated cloud and AI funding that the European Competitiveness Fund and FP10 will implement. Other funding channels for cloud and AI exist, but this is the one CADA controls. Its objectives face two challenges.

First, they support co-financing of data centre build-outs, where public money adds little: the commercial case for building new datacentres is already evident from the five largest hyperscalers alone planning around $660–690 billion of capital spending just this year and the scale of the Commission's multi-year support in the low billions at most is very small in comparison.

Second, they ignore a gap the Act itself creates. The sovereignty framework will steer public institutions towards open-weight models (as argued above in Section 2), because those are the models an administration can host and control itself. But open-weight models are also easier to exploit: anyone can access them, and their guardrails can be removed. Making them safe to rely on takes two kinds of experimental work: attempting to invent improvements to the models themselves, so that safety training cannot simply be stripped out or retrained away, and developing safeguards around them in daily use, such as filters that catch dangerous requests and monitoring that spots misuse once models are deployed. For now, neither is funded in the Act. It should sit in CADA rather than elsewhere, because CADA creates the exposure in the first place. This is also aligned with the open source strategy that accompanied CADA and its Open Source Maintenance Instrument

We thus recommend making advancement of methods and tools that make openly available AI models safe to deploy, including secure deployment environments and monitoring tools, an explicit objective in Leadership’s Initiative’ Article 4(2).

What happens next

The proposal is now in the ordinary legislative procedure. In Parliament, the file is split between the industry committee (ITRE), and the internal market committee (IMCO). Shadow rapporteurs from the other political groups are still being appointed. In Council, the file sits with the technical working party under the Irish presidency, with Lithuania taking over in January. The European Economic and Social Committee is drafting its opinion. The stated ambition in Parliament is a vote by mid-2027, with negotiations between the institutions concluding towards the end of that year, so the defining work happens over the coming months..

If you find recommendations above convincing, there are several ways to move them:

  • Back them with more evidence and advocate for them yourself. The arguments here are free to reuse; what they need is more voices. A submission to the consultation, a note to a rapporteur's office, or a public piece drawing on your own data all widen the coalition beyond one think tank.
  • Advocate for similar measures at member state level. Council positions are written in national capitals, and some of these fixes don't need to wait for CADA at all: maturity-based queues and flexible connection agreements are already permitted under EU energy law and can be adopted nationally today.
  • Tell us where we are wrong. These proposals will improve through contact with objections.