All articles
AI Insights

EU Cloud and AI Development Act (CADA): What Swiss SMEs Need to Know About Infrastructure Sovereignty

Chris Jon Graf · AI Strategist & CEOPublished on 20 July 2026
EU Cloud and AI Development Act (CADA): What Swiss SMEs Need to Know About Infrastructure Sovereignty

In short

The EU Cloud and AI Development Act (CADA) introduces four sovereignty levels that will de facto become procurement guidelines for Swiss companies with EU business. Level 1 requires EU infrastructure, Level 2 additionally demands independence from third-country laws such as the US CLOUD Act, Level 3 requires EU ownership and control. Around 80 per cent of professional cloud spending in the EU currently goes to US providers – CADA addresses this strategic vulnerability through harmonised compliance assessment from 2028/2029, yet many procurement bodies already demand the criteria today.

Why CADA matters for Swiss companies despite non-EU status

On 3 June 2026, the European Commission published the draft Cloud and AI Development Act (CADA) as the centrepiece of its Tech Sovereignty Package. The declared goal: to triple datacenter capacity in the EU within five to seven years and reduce strategic dependencies. Switzerland formally stands outside the EU legal order, yet Swiss SMEs with EU customers, EU subsidiaries or subcontracting agreements for public clients will need to meet CADA requirements de facto. Instruments such as the JEFTA agreement demand equivalence, and procurement bodies in France, Germany and the Netherlands are already incorporating the four sovereignty levels into tenders – long before CADA is adopted following the trilogue process at the earliest in 2027 and enters into force 12 to 24 months later.

For you as CFO or CTO, this means: infrastructure decisions you make today determine compliance risks and contractual capability tomorrow. Switching between cloud or AI providers is technically complex and contractually expensive – those who wait until the customer demands Level 2 or 3 face time pressure and lose negotiating power.

The four sovereignty levels (Union Assurance Levels) at a glance

Level 1 – EU Location: Data stays in the Union

Level 1 requires that data is exclusively processed and stored in EU infrastructure. Additionally, the provider must not be subject to any jurisdiction that obliges it to report software vulnerabilities to third countries before an exploit is closed. This level covers around 70 per cent of all public cloud contracts and is fundamentally achievable for EU subsidiaries of AWS, Microsoft Azure or Google Cloud with pure data residency.

Level 2 – EU Location + Independence: Independence from third-country laws

Level 2 significantly tightens requirements: the provider must demonstrate that it operates independently of third-country influence, makes the software supply chain transparent and has no «kill switch» through foreign sanctions laws. Here arises the conflict with the US CLOUD Act, which obliges US companies to hand over data on order – even if stored in the EU. Around 20 per cent of contracts fall into this category. Geopolitical dependencies on US AI are no theoretical risk – CADA Level 2 addresses precisely this vulnerability.

Level 3 – EU Ownership & Control: Ownership and governance

Level 3 demands EU ownership and EU control of the provider as well as personnel and governance requirements – such as EU citizenship for critical employees. The Commission may recognise third-country providers in individual cases, but the hurdle is high. This level targets sensitive workloads in financial services, healthcare or critical infrastructure.

Level 4 – Full Sovereignty: Complete transparency for highest-criticality systems

Level 4 demands complete transparency and control over the software supply chain; no influence by third countries may be possible. This level is reserved for defence, intelligence services and highest-criticality infrastructure. Together with Level 3, these two levels account for around 10 to 11 per cent of contracts – yet they set the standard for long-term market development.

The Compliance Cascade: CADA stacks on AI Act, NIS2, DORA and Data Act

CADA is not an isolated rulebook. The Cloud Security Alliance speaks of the «Compliance Cascade»: CADA stacks on AI Act, NIS2, DORA and Data Act – each framework demands its own assessments, with overlapping evidence requirements. Swiss companies that must already meet EU AI Act Omnibus requirements for AI agents and high-risk AI now face a second assessment layer: infrastructure sovereignty. Those who plan their cloud and AI infrastructure strategically today can cover both frameworks with an integrated governance model.

Window is closing

Many EU procurement bodies already demand CADA criteria in tenders today, even though the Act will only be binding from 2028/2029 at the earliest. Those who wait lose contracts.

US providers control 80 per cent of EU cloud spending – what now?

The European Commission sees the structural dependency as a strategic vulnerability: US providers control around 80 per cent of professional cloud spending in the EU. Lawfare Media commented on 3 June 2026: «CADA represents a significant change in tone for the Commission, which has maintained its 'open market' credentials long after the U.S. and China abandoned them.» Industry associations such as ITIF, CCIA Europe and the Business Software Alliance criticised CADA as protectionist and discriminatory – yet the political dynamic is clear.

For Swiss decision-makers this means: vendor diversification for cloud and AI infrastructure becomes a compliance necessity rather than a nice-to-have. Those who rely exclusively on AWS, Azure or Google Cloud today must either demonstrate an exit plan for Level-2 projects or build a hybrid stack with EU providers such as OVHcloud, Scaleway, Mistral or Aleph Alpha.

Concrete decision questions for CFO and CTO

  • Which of your customers or projects fall under public procurement or critical infrastructure in the EU?
  • Can you transparently document today where your data is processed and who has access?
  • Do you have a contractual exit plan in case your cloud or AI provider no longer meets Level-2 requirements due to sanctions, acquisition or jurisdiction change?
  • How high are your migration costs and how long does a provider switch realistically take?
  • Do you have internal or external expertise to assess EU providers technically and contractually?

These questions are not theoretical. Token billing escalation and lack of infrastructure control already drive unplanned costs today, and CADA intensifies pressure to regain strategic control.

Swiss open-source and confidential computing alternatives

Switzerland is not a passive observer. ETH Zurich is developing Apertus LLM, an open-source alternative with confidential computing that can meet Level-3 and Level-4 requirements. For Swiss SMEs this means: a hybrid strategy of EU-compliant cloud providers, Swiss open-source models and selective use of US hyperscalers for non-critical workloads is technically feasible and economically sensible.

Start pilot projects early

Test EU providers and Swiss open-source stacks in non-critical projects before the customer demands Level 2 or 3. This way you gain negotiating power and avoid emergency migrations.

Action recommendations: What you can do now

  1. Inventory your cloud and AI infrastructure: where does data reside, who has access, which jurisdiction applies?
  2. Assess existing contracts: are there exit clauses, data portability, transparent subprocessor lists?
  3. Conduct a vendor health check: does your provider meet Level 1, 2 or 3 – and if not, what alternatives exist?
  4. Define internal guidelines: which workloads may run on US infrastructure, which require EU or Swiss sovereignty?
  5. Build expertise: train your team or bring in external support for EU compliance and multi-cloud architecture.

80%

of EU cloud spending goes to US providers – CADA aims to halve this strategic dependency by 2033

Conclusion: Infrastructure sovereignty is now a leadership task

CADA is still a draft, yet market dynamics are real. Swiss SMEs that assess neocloud alternatives and hybrid architectures today secure room for manoeuvre tomorrow. The four sovereignty levels are not merely a compliance requirement – they are a decision framework for strategic independence, cost control and risk mitigation. Those who wait until the customer demands Level 2 face time pressure. Those who act now actively shape their own infrastructure sovereignty.

Frequently asked questions

What is the EU Cloud and AI Development Act (CADA)?
CADA is an EU legislative draft that defines four sovereignty levels for cloud and AI infrastructure. The goal is to reduce strategic dependencies on third countries and triple EU datacenter capacity by 2033. CADA will be adopted at the earliest in 2027, with first binding application from 2028/2029.
Does CADA affect Swiss companies even though Switzerland is not in the EU?
Yes. Swiss SMEs with EU customers, EU subsidiaries or subcontracting agreements for public clients must meet CADA requirements de facto. Many EU procurement bodies already demand the sovereignty levels in tenders today, even before entry into force.
What is the difference between CADA Level 1 and Level 2?
Level 1 requires EU infrastructure and no obligation to report vulnerabilities to third countries. Level 2 additionally demands independence from third-country laws such as the US CLOUD Act, transparent software supply chain and proof that no «kill switch» exists through foreign sanctions.
Can US providers like AWS, Azure or Google Cloud meet CADA Level 2?
Difficult. The US CLOUD Act obliges US companies to hand over data on order – even if stored in the EU. This contradicts Level-2 requirements. EU subsidiaries can meet Level 1, but Level 2 requires independence from the US parent company, which is contractually hardly representable.
What alternatives exist to US hyperscalers for Level-2 and Level-3 projects?
EU providers such as OVHcloud, Scaleway, Mistral or Aleph Alpha meet Level 2 and partially Level 3. Swiss open-source models such as ETH Zurich's Apertus LLM with confidential computing can address Level 3 and 4. A hybrid strategy combines these providers with selective use of US clouds for non-critical workloads.
When must I as a Swiss company expect CADA requirements?
Many EU procurement bodies already demand CADA criteria today. CADA becomes binding at the earliest in 2028/2029, but those who wait lose contracts and face time pressure with customer requirements. Infrastructure decisions today determine compliance risks tomorrow.

Sources

Would you like to explore this topic for your company?

Check Availability

More articles