What CADA actually promises
On 27 May 2026 the European Commission tabled the Cloud and AI Development Act, the centrepiece of its Tech Sovereignty package. One number does all the press work: at least triple the EU's data-centre capacity within 5 to 7 years, with the larger goal of covering the cloud and compute needs of EU business and public administration by 2035. It is Brussels' structural reply to the United States' $500B Stargate buildout. The difference from every sovereignty pledge before it is the legal base: CADA is drafted on Article 114 TFEU, the internal-market article, so if it passes it is a binding regulation with direct effect — not a recommendation a member state can quietly ignore.
That distinction matters because the EU has tried this and lost. GAIA-X became a governance forum that shipped little; the French CloudWatt and Numergy ventures were wound down years ago. CADA's defenders say it is different because it writes the rules into law instead of parking them in a certification scheme that has been deadlocked since 2019. Whether that holds is the entire question.
Is the "triple capacity" target realistic?
The ambition is sound, the timeline sits at the optimistic end of plausible, and "triple" is a target the regulation sets in motion, not an outcome it guarantees. Tripling EU capacity would push the bloc toward roughly half of today's global footprint, and analysts put the bill at €150–200 billion of public and private investment over four years to get there. The Act creates conditions — fast-track permitting, grid access, capital support for new entrants — but it does not write the cheques.
The gap it is trying to close is real, and the numbers are unkind to Europe:
| Metric | United States | Europe / EU |
|---|---|---|
| Share of global data-centre capacity | ~44% (53.7 GW) | EU ~11.9 GW |
| Share of hyperscale facilities | ~54% | ~15% |
| Hyperscalers' share of the European cloud market | ~70% (AWS, Azure, Google) | — |
| European providers' share of their own market | — | ~15%, flat since 2020 |
So the US holds two to three times Europe's data-centre share by capacity, and inside Europe's own borders the three American hyperscalers run about 70% of the cloud market. The most damning figure is the stable one. European providers' share fell by nearly half between 2017 and 2020, then froze at around 15%. The rhetoric has been loud for a decade. The market share never moved.
What's binding versus what's a press release
This is where a reader should weigh substance over the headline. As of mid-2026 CADA is a Commission proposal. It has not been negotiated with Parliament and Council, the indicative adoption window is Q4 2027, and that window is a roadmap target rather than a legal deadline. The "2035" capacity goal is an aspiration the law sets running, not a clause that fines anyone if Europe comes up short. The live picture:
- Tabled and real: the proposal text, the Article 114 legal base, the eligibility framework for "highly secure EU-based" cloud capacity, and a single EU-wide procurement policy for public administrations.
- Proposed, not law: every binding obligation. Nothing in CADA constrains a provider or buyer until the regulation is adopted and in force — realistically 2028 or later, and only if the sovereignty-versus-openness fight that broke the EUCS certification scheme doesn't replay inside CADA.
- Aspirational: the tripling, the 2035 self-sufficiency goal, the
€150–200B. These ride on private capital and grid build-out the Act can encourage but cannot command.
The Act itself already slipped: pencilled in for Q1 2026, it arrived at the end of May. Not a scandal, but a useful tell. Big EU industrial legislation moves on a timescale of years, and the "5 to 7 years" clock started late.
Capacity is not the same as sovereignty
Here is the part the headline buries. Tripling data-centre capacity in Europe does not, on its own, give Europe control of European data. If the new gigawatts are built and run by the same US-parent hyperscalers — the likeliest outcome on current market share, unless the eligibility rules bite hard — you get more concrete and steel in Falkenstein and Frankfurt, owned by entities still reachable under the CLOUD Act and FISA 702. A German subsidiary of a US parent can be compelled to surrender data its parent controls, wherever the server physically sits. Capacity in the EU and jurisdiction over the data are two different problems, and CADA mostly attacks the first.
More racks in Europe is an infrastructure win. It is not, by itself, a sovereignty win. Who can be compelled to read the data is decided by corporate jurisdiction, not by the postcode of the disk.
This is why the architecture you pick still outranks the policy that hosts it. If the operator can read your files, the strongest sovereignty law on Earth only changes which government gets to knock on the door. If the operator cannot read your files — because the data is encrypted on your device before it ever leaves it — then a compulsion order, wherever it lands, retrieves ciphertext.
That is the bet we made building beebeeb. Files are encrypted with AES-256-GCM on your machine; the keys are derived with Argon2id and never reach us; we store blobs we cannot decrypt, on every tier including the free one. Our servers sit in Falkenstein, Germany, under a Netherlands-incorporated company, so we already hold the EU-jurisdiction posture CADA wants to scale. But the load-bearing protection is the math, not the map — you can read exactly how the zero-knowledge model and key handling work rather than take the claim on faith, because the product clients are open source. CADA succeeding would make EU-hosted infrastructure cheaper and more plentiful. It would not change the one fact underneath all of this: the only data a provider can't be forced to surrender is data it was never able to read.
What this means if you're buying cloud in 2026
Don't restructure a procurement decision around a regulation that isn't law yet. CADA is a directional signal — Brussels is serious about EU compute, and the next few years should bring more EU-hosted options and capital flowing toward non-hyperscaler entrants. Good. But "more EU data centres by the early 2030s" is a forecast, and a forecast riding on a 2026 Commission proposal is the weakest kind of commitment.
What you can act on today is the thing CADA cannot legislate into your stack: where your provider is incorporated, who can compel it, and whether it can technically read your data at all. Those are checkable now — on the contract and in the source. We keep our roadmap public for the same reason: we'd rather you check what ships than trust what's promised. If a sovereign-cloud future lands on schedule, it strengthens the EU-hosted, can't-read-your-files model. If it slips again — as GAIA-X did, as the May date did — the encryption is what's left standing.