EU Considers Limits on US Cloud Use for Sensitive Data

The European Commission formally proposed its European Technological Sovereignty Package on June 3, 2026, after delaying it from an originally reported May 27 target (European Commission; CNBC). The centerpiece Cloud and AI Development Act does not ban US cloud providers outright; it creates four "Union assurance levels" of cloud sovereignty, and Silicon Canals reports the US CLOUD Act's extraterritorial reach makes the top levels structurally out of reach for Microsoft, Amazon, and Google as long as they remain subject to US jurisdiction. Commission Executive Vice-President Henna Virkkunen told CNBC, "We want to be sure nobody has a kill switch." The package also bundles Chips Act 2.0 and aims to triple EU data-center capacity within five to seven years, as the EU's share of the cloud market has fallen from about 29% in 2017 to roughly 15% in 2022.
The real bite in the EU's new Cloud and AI Development Act isn't a ban, it's a legal trap: any provider can technically qualify for its four-tier sovereignty framework, but the US CLOUD Act's extraterritorial reach makes the top tiers structurally unreachable for Microsoft, AWS, and Google as long as they remain subject to US jurisdiction. That distinction, sovereignty-by-design rather than a named ban, matters more to practitioners than the earlier headline framing of "EU restricts US cloud."
What happened
The European Commission formally proposed its European Technological Sovereignty Package on June 3, 2026, after the announcement slipped from an originally reported May 27 target (European Commission press release; CNBC). The package bundles four measures: the Cloud and AI Development Act (CADA), Chips Act 2.0, an Open Source Strategy, and a Strategic Roadmap for Digitalisation and AI in Energy. CADA establishes four "Union assurance levels" of cloud sovereignty; any provider serving EU public-sector customers must meet at least the lowest level, while progressively higher levels impose stricter data-residency and foreign-control restrictions for more sensitive workloads (European Commission; digital-strategy.ec.europa.eu). Commission Executive Vice-President Henna Virkkunen told CNBC, "We want to be sure nobody has a kill switch."
Regulatory context
Silicon Canals reports that CADA does not name or ban specific US companies, but the US CLOUD Act, which lets American authorities compel US-headquartered firms to hand over data regardless of where it is physically stored, makes it nearly impossible for Microsoft, AWS, and Google to satisfy the top assurance levels' independence-from-foreign-access requirements without structural changes such as fully independent EU subsidiaries. CADA is still a Commission proposal and requires approval from the European Parliament and Council before it becomes law. Earlier reporting from CNBC (May 7) and Politico had previewed the package before its formal unveiling; Politico quoted Thibaut Kleiner, the Commission's Director for Future Networks, warning Europe risked becoming a "technological colony" without domestic capacity, a sentiment consistent with the package Commission ultimately proposed.
Industry context
The Commission frames the push around a capacity gap: the EU's share of the global cloud market has fallen from about 29% in 2017 to roughly 15% in 2022, according to Commission figures cited in coverage of the proposal. CADA requires member states to designate at least one "data centre acceleration zone" with streamlined permitting, capped at a 12-month permit-granting timeline, as part of a goal to triple the EU's data-center capacity within five to seven years. UK MP Chi Onwurah, who chairs the UK Science, Innovation and Technology Select Committee, separately raised concerns about government reliance on Microsoft, Amazon Web Services, and Palantir (ITSecurityNews), reflecting a wider debate not limited to the EU proposal itself.
For practitioners
Cloud architects and compliance teams serving EU public-sector customers should start mapping current infrastructure against the four assurance levels rather than waiting for final legislative text, since procurement requirements are likely to phase in as CADA moves through the Parliament and Council. Vendors should treat the CLOUD Act conflict as a design constraint, not a hypothetical: any EU-sovereignty claim that doesn't structurally sever US legal reach is unlikely to satisfy the higher assurance tiers.
What to watch
- •CADA's progress through the European Parliament and Council, and whether the assurance-level thresholds change during negotiation.
- •Whether US hyperscalers propose structural workarounds, such as legally independent EU subsidiaries, to reach the top sovereignty tiers.
- •Member states' designation of data-centre acceleration zones and early progress toward the capacity-tripling target.
- •Which specific public-sector data categories (health, financial, judicial) get mapped to which assurance level in implementing guidance.
Key Points
- 1The European Commission formally proposed its Cloud and AI Development Act on June 3, 2026, after delaying it from a planned May 27 date.
- 2The act creates four cloud sovereignty tiers rather than banning US providers, but the US CLOUD Act makes the top tiers structurally unreachable for them.
- 3The package also targets tripling EU data-center capacity within five to seven years as the bloc's cloud market share has fallen sharply since 2017.
Scoring Rationale
Now a confirmed formal Commission proposal (official press release, CADA proposal text, CNBC on-record VP quote), not preliminary reporting: a genuinely major EU regulatory push bundling cloud sovereignty tiers, a data-center capacity target, and Chips Act 2.0, with real operational stakes for hyperscalers and public-sector cloud procurement. Kept below the major-tier ceiling since it is still a legislative proposal requiring Parliament and Council approval, not enacted law.
Sources
Primary source and supporting public references used for this report.
View 7 more sources
- Commission proposes tech sovereignty package to strengthen Europe's digital autonomy and resilienceec.europa.eu
- Proposal for the Cloud and AI Development Act (CADA)digital-strategy.ec.europa.eu
- Europe unveils tech sovereignty package amid growing concerns over reliance on U.S. tech: 'We want to be sure nobody has a kill switch'cnbc.com
- Europe's new tech-sovereignty plan doesn't ban U.S. cloud giants, it sets four levels of sovereignty, and an American law makes the top levels nearly impossible for them to reachsiliconcanals.com
- EU tech sovereignty package curbs US cloud, launches Chips Act 2.0thenextweb.com
- Cloud law will stop Europe becoming tech 'colony,' Commission official sayspolitico.eu
- Europe is moving to block Microsoft, Amazon, and Google from handling government health, financial, and legal datatechspot.com
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems