Who is bound by the EU's cloud and AI proposal
The EU's cloud and AI development proposal contains no general duty for private users. The obligation in Article 29 falls on Member States and Union entities, and for a supplier the requirements arrive instead through the customer's procurement and through the recognition the supplier applies for itself.

Key insights
- The Commission adopted the proposal on 3 June 2026. It is neither adopted nor in force, and the Swedish consultation closes on 2 October 2026.
- Article 29 requires Member States and Union entities to carry out risk assessments. Level 1 is a floor for every contracting authority, and the assessment lifts an activity off that floor to level 2, 3 or 4.
- The Commission's memorandum says Article 31 allows private sector entities within the meaning of the NIS2 Directive to run their own impact assessments. Allows, not requires.
- The Annex II levels are cumulative and level 3 requires Union citizenship for relevant personnel. A supplier that applies for recognition also becomes directly regulated, not only bound through the contract.
- Tripling data centre capacity is an ambition on the Commission's policy page. The enacting text carries no such figure; Article 15(1) tasks the Commission with mapping the capacity gap.
The question usually arrives as a worry: will the EU's new cloud and AI rules force us to move something. For the great majority of private organisations using cloud services or AI infrastructure the answer is no. The enacting text of the proposal contains no general, direct obligation on users. That is the honest answer and it belongs first.
It is not the whole picture, though, and the second part is the one that matters: the line does not run by who you are but by who you sell to.
It is a proposal, and it is not the US CLOUD Act
On 3 June 2026 the Commission adopted a proposal for a regulation on cloud and AI development, COM(2026) 502. A proposal is not a regulation. The text is neither adopted nor in force, and it will be negotiated.
Two things separate this from the question it is most often confused with. The US CLOUD Act concerns what a provider can be compelled to disclose, and it follows the provider's control over the data; that question and its criteria are set out in our analysis of who decides where data may sit. This proposal is about something else: what requirements the Union itself will place on cloud services, and who will apply them.
The national process in Sweden is under way and it has a date. The Ministry of Finance published the consultation on 10 July 2026 under reference Fi2026/01676, stating in Swedish that "Sista dag att svara på remissen är den 2 oktober 2026", the last day to respond being 2 October 2026. The government's preliminary position is set out in explanatory memorandum 2025/26:FPM99 of 8 July 2026, which states that the government is positive to the ambition of strengthening the EU's capacity, competitiveness and digital sovereignty in the cloud and AI field.
The same memorandum says what the government intends to push for: that rules and processes be designed so that the consequences are proportionate and impose no greater restrictions or costs than necessary. And one sentence sets the tone of the whole Swedish position, including the balance it carries in its own second half: Sweden is to have control over its data and systems and be able to act independently and in line with European values and interests, while the benefits of global cooperation with international partners are preserved.
A note on the sources belongs here. No Swedish language version of the proposal could be read, nor the full English wording of the provisions: the published versions break off inside the recitals, before the articles discussed here. What appears in quotation marks below therefore comes from the Commission's own explanatory memorandum to the proposal and from Annex II. The content of the provisions is otherwise given without quotation marks.
What binds a public body
Article 29 is the provision that actually creates an obligation, and the addressees are spelled out. The Commission's memorandum puts it this way: "Article 29 sets out the obligations for Member States and Union entities to conduct risk assessments to determine the required level of conformity against the Union assurance levels 2-4 for different public sector activities." The deadline is one year from entry into force, and every two years thereafter or whenever necessary.
The assessment is to identify which public activities use or will use cloud services in the sectors named, and to determine an appropriate sovereignty level: 2, 3 or 4. Under Article 29(2) it must consider at least the sensitivity, criticality and volume of the data, together with the risk of unlawful access by a third country or third-country entity and the risk of service disruption.
A risk assessment that has to land on a level is a decision about suppliers, not a description of the situation.
The procurement rule follows from the levels, and it is built as a floor with an exception rather than as two boxes. The Commission's memorandum describes Article 30 as follows: "Article 30 sets out obligations for contracting authorities that procure cloud computing services to procure, as a minimum requirement, Union assurance level 1. Where a risk assessment determines that the activities of such contracting authorities have public order relevance, they must only procure and use services that have been recognised as offering Union assurance levels 2, 3, or 4."
Level 1 is therefore a floor for every contracting authority buying cloud services, not a level assigned to the less sensitive ones. It is the risk assessment that lifts an activity off the floor, and then to 2, 3 or 4.
The scope of Article 29 is precise and easy to get wrong. It covers Member States and Union entities. It does not cover private actors delivering public services. The assessment duty reaches them only through Article 31, and only on the conditional terms described there. The procurement rule in Article 30 is a different matter: it follows from who is buying, not from who is supplying.
Two ways in to a private supplier
This is the part that decides whether the proposal concerns you, and it is invisible if you only read for obligations aimed at yourself.
The sovereignty framework sits in Article 16, described by the Commission's memorandum as follows: "Article 16 sets out a Union cloud computing sovereignty framework consisting of four assurance levels and introduces the requirements established in Annex II to the Regulation for cloud computing services to be considered as providing Union assurance across level 1 to level 4." The requirements are therefore requirements on providers, and they bite when the service is to be delivered to Union entities and public sector bodies. The per-level requirements are in Annex II and they are cumulative.
Level 1 requires the provider to be established in the Union, its infrastructure and assets to sit there, and customer data to remain within the Union unless the public sector body explicitly requires otherwise. Level 2 adds that relevant subcontractors must also be established in the Union, that personnel must be located there, that support must be initiated and performed exclusively within the Union, and certification at least at assurance level "substantial" where a relevant scheme exists. Level 3 tightens on personnel: they must be Union citizens, and as a rule neither the provider nor the relevant subcontractors may be under third-country control. Level 4 requires certification at least at "high", sensitive customer data to remain within the Union at all times, and closes the derogation route from third-country control that level 3 leaves open.
Two requirements are routinely placed one level too high. The requirement that infrastructure sit in the Union is already at level 1, and the requirement for national security clearance where classified information is handled appears word for word at both level 3 and level 4.
Level 3's requirement of Union citizenship for personnel is the single most concrete consequence in the whole proposal for a company selling to the public sector.
The requirement reaches you as a procurement criterion at the customer, but it does not stop there. A provider that wants to be recognised at a level applies for it itself under Article 17, and the Commission's own memorandum describes the arrangement as requiring the provider to submit an application for recognition to the national competent authority of establishment. Article 23 then carries transparency obligations for recognised providers, who are to report material changes that may affect their recognition, and Article 24 sets penalties for infringements by providers. The demand arrives through the contract; the obligation becomes your own as soon as you apply for a level.
What the proposal does not say
Two things are often attributed to the text and are not in it.
The first is a capacity figure. The Commission's own policy page for the proposal states the ambition of "at least tripling the EU's data centre capacity within the next 5-7 years". The enacting text contains no such figure. Article 15(1) requires the Commission to identify and monitor, among other things, the compute capacity available in the Union, the volume of demand for data centre capacity and the size of the capacity gap. Mapping a gap is a different thing from promising to close it, and the difference between a political ambition and a proposed provision is what decides what a company can plan on.
The second is a private obligation. The Commission's memorandum describes Article 31 as follows: "Article 31 allows for private sector entities within the meaning of the NIS2 Directive to conduct impact assessments with a similar purpose to the ones conducted by Union entities and public sector bodies." The verb is allows, not requires. Article 31(3) is the door: a binding duty for non-public entities in sectors of high criticality can be introduced later by delegated act. The memorandum mentions no such duty, and it would in any case be a possible future arrangement rather than a current one.
The acceleration zones are also described as more compulsory than they are. Article 10(1) requires a Member State to designate at least one zone within six months, but the obligation is conditional on data centre capacity being deployed on its territory.
The objection that carries weight
There is a countervailing case for doing nothing at all, and it should be put plainly.
The proposal is a proposal. It will be negotiated between the Council and the Parliament, and what is finally adopted routinely differs from what was tabled. Article 48 sets the entry into force and the dates of application, and both are tied to a publication that has not happened. Neither clock has started. A reader may therefore fairly ask why anything should be done now, and for anyone who is neither a public body nor selling to one the answer is that nothing needs to be done.
What gets negotiated away is almost never the structure of the framework, but where the thresholds land.
Three things nonetheless argue against postponing the question for those it does concern. The Swedish consultation closes on 2 October 2026, before the national position is fixed, and that is the only occasion on which an individual supplier can influence the outcome rather than adapt to it. The Union citizenship requirement for personnel at level 3 is the kind of thing that takes longer to arrange than a procurement cycle, because it concerns staffing and subcontracting chains rather than configuration. And the government is pushing, on its own memorandum, for requirements to be proportionate, which is an argument that improves when a supplier can show what a requirement actually costs.
The two questions that decide whether this is your problem
The first question is who your customer is. If you are a public body, Article 29 binds you and you have to land on a level. If you sell to the public sector, the Annex II level requirements become procurement criteria at your customer, and they reach you through the contract. If you then apply for recognition at a level, the regulation binds you directly as well. If you are a private entity in a NIS2 sector, nothing binds you today, and Article 31(3) is the only door. If you are none of these, the proposal's obligations do not reach you.
The second question is which level your customer would land on, and it decides how large the work is. The difference between level 2 and level 3 is not incremental. Level 2 is about where things sit and who owns them, that is establishment, location and certification. Level 3 is about who works on them. A supplier can move an operating region within a quarter. Changing who has access to a system, across the whole subcontracting chain, is a different kind of work.
There is a third question that is not about the proposal but about your own list: do you know which of your systems run with which provider, and which subcontractors those providers use in turn. Without that list neither of the first two questions can be answered. How it is built and who owns it afterwards is set out under AI governance and compliance. The calendar for the AI Act, which is a separate and already adopted rulebook, is on our EU AI Act page.
Common questions
A proposed EU regulation on cloud and AI development, COM(2026) 502, adopted by the Commission on 3 June 2026. It establishes a Union cloud sovereignty framework with four levels, requires Member States and Union entities to run risk assessments of their cloud use, and ties procurement requirements to the levels. It is a proposal, so it is neither adopted nor in force. In Sweden, the national consultation closes on 2 October 2026.
No, and they answer different questions. The US CLOUD Act governs what a provider can be compelled to hand over to US authorities and follows the provider's control over the data rather than where the server sits. The EU proposal governs what requirements the Union itself will place on cloud services sold to the public sector, and who applies them. One is a disclosure question, the other a procurement question.
Level 1 is a floor. The Commission's memorandum describes Article 30 as requiring contracting authorities that procure cloud computing services to procure, as a minimum requirement, Union assurance level 1, and says that where a risk assessment determines that their activities have public order relevance they must only procure and use services recognised at level 2, 3 or 4. Which level applies is therefore decided by the risk assessment under Article 29, not by the size or sector of the organisation as such.
It is translated into measurable requirements in Annex II, and they are cumulative. Level 1 requires the provider to be established in the Union and its infrastructure, assets and customer data to sit there unless the public sector body explicitly requires otherwise. Level 2 adds that relevant subcontractors must also be established in the Union, that personnel must be located there, that support must be performed exclusively within the Union, and certification at least at assurance level substantial. Level 3 requires personnel to be Union citizens and, as a rule, that neither provider nor relevant subcontractors are under third-country control. Level 4 requires certification at least at high and sensitive customer data to remain within the Union at all times.
The ambition to triple the Union's data centre capacity within five to seven years appears on the Commission's policy page, not in the enacting text. What the proposal actually requires of the Commission, under Article 15(1), is to identify and monitor the compute capacity available in the Union, the volume of demand for data centre capacity, and the size of the capacity gap. Mapping a gap is a different thing from promising to close it.
No. The Commission's memorandum describes Article 31 as allowing private sector entities within the meaning of the NIS2 Directive to conduct impact assessments with a similar purpose to those conducted by Union entities and public sector bodies. Allows, not requires. Article 31(3) opens the door for a binding duty to be introduced later for non-public entities in sectors of high criticality, by delegated act. That is a possible future arrangement, not a current obligation.
Both, in that order. The demand arises at the customer, because the level requirements become procurement criteria under Article 30. The obligation becomes the provider's own as soon as it seeks recognition: on the Commission's memorandum to Article 17 the provider must submit an application for recognition to the national competent authority of establishment, Article 23 carries transparency obligations for recognised providers, and Article 24 sets penalties for infringements by providers.
Article 48 sets the entry into force and the dates of application, and both are tied to a publication in the Official Journal that has not happened. Since the proposal is neither adopted nor published, neither clock has started. The risk assessments under Article 29 are to be carried out within a year of entry into force and every two years thereafter, or whenever necessary.
On 2 October 2026. The Swedish Ministry of Finance published the consultation on 10 July 2026 under reference Fi2026/01676. The government's preliminary position is set out in explanatory memorandum 2025/26:FPM99 of 8 July 2026, where it states that it is positive to the ambition of strengthening the Union's capacity and digital sovereignty but intends to work for requirements that are proportionate.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.