Brussels spent three years telling American cloud providers that Europe did not need to cut them loose. That position changed on June 3, 2026, when the European Commission unveiled a sovereignty framework buried inside the Cloud and AI Development Act, or CADA, that could bar Amazon Web Services, Microsoft Azure and Google Cloud from the continent’s most sensitive government contracts. By early September, the fight had moved from trade press to defence ministries, and the ministries are not happy about it.

A report published September 7, 2026 by Cloud Computing News, followed by parallel coverage from the European Business Magazine and the policy outlet Servola, laid out the core tension: Brussels wants EU cloud sovereignty enforced down to the software supply chain, while the people who run Europe’s actual defence networks say that level of purity would break systems that already depend on Microsoft, AWS and Google. This is not an abstract policy fight. It is a rule that could reroute a market some analysts peg near €2 trillion, and it lands at a moment when at least 18 EU governments run defence workloads on Azure.

What the EU’s Cloud and AI Development Act Actually Requires

CADA is the centerpiece of a broader tech sovereignty package the Commission presented alongside a “Chips Act 2.0” on June 3, 2026. Stripped of Brussels-speak, the law forces EU public bodies, including defence, justice, border management and law enforcement agencies, to grade every cloud service they use against a four-level sovereignty scale before they can sign a contract.

The grading criteria cover five things: where the data centers physically sit, who operates and administers the infrastructure, who owns and finances the provider, how transparent the software supply chain is, and whether the provider is exposed to a foreign law like the US CLOUD Act or China’s National Intelligence Law. Article 30 of the draft ties the assurance level directly to the sensitivity of the workload, so a records system for a rural transit authority faces far lighter scrutiny than a signals-intelligence platform.

Separately, the Commission has drafted procurement rules for what it calls highly critical state tenders. Those rules let contracting authorities exclude bidders based on ownership, financing structure, or exposure to third-country legislation, and for the most sensitive tier they bar US hyperscalers outright unless the vendor restructures its EU operations to eliminate that exposure entirely. A senior EU official described the goal to Reuters as achieving “strategic autonomy in critical infrastructure,” a phrase that has become shorthand for the whole package.

Four Assurance Levels: How Brussels Grades a Cloud Provider

The assurance scale runs from a baseline tier that most commercial cloud contracts already clear to a top tier that almost nothing clears. Level 1 asks for standard data protection and security controls, and foreign providers pass without much friction. Level 2 covers workloads like internal security and law enforcement, and it demands stronger data localization and clearer jurisdictional guarantees. Level 3 applies to high-risk defence and justice systems, and providers can only qualify if they neutralize third-country legal exposure through binding legal and technical ring-fencing, not just marketing language about a “sovereign region.”

Assurance LevelCore RequirementTypical WorkloadsForeign Provider Status
Level 1Baseline EU data protection and security standardsGeneral public administrationAllowed, minimal restriction
Level 2Data localization plus jurisdictional guaranteesInternal security, law enforcementAllowed if guarantees are contractually enforceable
Level 3Legal and technical neutralization of third-country law exposureDefence, justice, border managementAllowed only with full ring-fencing of EU operations
Level 4 (“Stage four”)Complete software transparency, zero third-country influenceRoughly 1% most sensitive national security systemsEffectively excluded

That top tier, Level 4, is where the political fight actually lives, and it is the reason defence contractors are the loudest voice objecting to the law.

Inside Level 4: The One Percent Nobody Can Touch

Servola’s September 5 reporting on the CADA framework put a number on the top tier: it covers roughly 1% of services, the ones judged the most sensitive, and it demands complete software transparency and no third-country influence at all. No ownership stake, no operational control, no residual legal exposure to a non-EU jurisdiction. That standard does not bend for a data center built on German soil if the parent company is incorporated in Delaware or Washington state.

This is the clause that turns AWS’s European Sovereign Cloud, Microsoft’s EU data boundary, and Google’s sovereign controls from a compliance checkbox into a structural problem. Each of those products puts data inside EU borders and adds local operational oversight, but the parent company remains an American entity subject to the CLOUD Act. Under a literal reading of Level 4, that residual exposure disqualifies them regardless of where the servers sit. Industry lawyers reading the draft describe the requirement as close to a de facto ban on US hyperscalers for the narrow slice of workloads it covers, even though the Commission insists the broader package does not ban American cloud providers from operating in Europe at all.

Why Europe’s Defence Ministries Are Pushing Back

The pushback is not coming from people who dislike sovereignty as a goal. It is coming from officials who run networks that already depend on American infrastructure and who worry the law moves faster than their ability to replace it. The European Business Magazine’s September 4 coverage framed it plainly: the proposed framework would require member states to assess how critical individual digital services are, and could restrict foreign technology use in the most sensitive areas, but defence agencies argue the timeline ignores how deeply embedded US cloud tools already are in day-to-day operations.

Three concerns come up repeatedly in the reporting. First, interoperability: NATO militaries share platforms and data pipelines that run partly on US clouds, and forcing EU-only infrastructure onto some allies but not others fragments systems that are supposed to work together in a crisis. Second, capability gaps: several defence officials argue that no EU sovereign cloud provider currently matches the scale, redundancy, or AI tooling that AWS, Azure and Google Cloud offer, so a hard cutover risks trading resilience for compliance. Third, speed: Level 4 compliance would require providers to restructure ownership and control in ways that take years, not months, while procurement deadlines under the draft rules move faster.

Microsoft’s Grip on European Defence Computing

The numbers explain why Microsoft is the company defence ministries worry about losing the most. A Euronews report published April 17, 2026, citing a European think tank study, found Microsoft is the largest cloud provider for European defence agencies, with its systems used by 19 countries. A separate analysis from EU GovLab published in June 2026 put the figure at 18 countries and noted that Google and Oracle hold defence contracts too, though on a smaller scale, with Google’s defence footprint concentrated in four member states: Germany, Italy, Luxembourg and the Netherlands.

That concentration is exactly what worries the officials pushing back on CADA’s strictest tier. Azure is not a peripheral vendor for European defence, it is close to the default. Microsoft has read the same warning signs, which is one reason the company has spent 2025 and 2026 expanding its Azure sovereign cloud footprint across EU regions, including data boundary controls and local operational staffing designed to blunt exactly the objections Level 4 raises.

The €2 Trillion Procurement Market at Stake

Policy analysis site ModelDiplomat, covering the Commission’s procurement draft, described the rules as enabling EU buyers to exclude foreign firms based on ownership, financing, or exposure to US and Chinese data law, calling it a €2 trillion market shift. That figure describes the scale of EU public procurement and strategic tenders the new exclusion criteria could touch, not a single contract value, but it signals how much commercial weight sits behind a fight that started as a niche compliance debate.

Brussels Signal, reporting on the same June 1 draft that Reuters first surfaced, described the practical effect in blunt terms: member states would need to evaluate the jurisdictional risk of every digital contract before signing, and at the most sensitive tier, covering critical government systems, US cloud hyperscalers would be barred outright from competing. That is a meaningfully harder line than the softer risk-assessment language the Commission uses in public messaging, and it is the specific clause defence contractors are lobbying to soften.

How AWS, Microsoft and Google Are Responding

All three hyperscalers moved before the defence backlash even became public, betting that sovereign-by-design products would blunt the political pressure. AWS got there first: it announced general availability of the AWS European Sovereign Cloud on January 15, 2026, from Potsdam, Germany, describing it as an independent cloud entirely located within the EU and physically and logically separate from other AWS regions. Microsoft and Google have both rolled out comparable sovereign configurations that keep data stored and supervised locally, positioning them as EU-compliant alternatives to their standard global regions.

ProviderEU Defence FootprintSovereign ProductStatus as of Sept. 2026
Microsoft Azure18-19 EU member states, largest defence cloud vendorAzure EU data boundary and sovereign controlsLive, expanding
Amazon Web ServicesBroad commercial and government presenceAWS European Sovereign CloudGA since Jan. 15, 2026, Potsdam region
Google Cloud4 member states with defence contracts (Germany, Italy, Luxembourg, Netherlands)Google sovereign controls, local data supervisionLive, narrower defence footprint
OracleDefence contracts alongside Google, smaller scaleLimited sovereign positioning reportedNot detailed in current filings

None of these products solve the Level 4 problem on their own, because ownership and ultimate legal exposure stay with a US parent company. What they do is buy time and goodwill at Levels 1 through 3, which cover the vast majority of public-sector cloud spending. That is likely enough to keep the bulk of hyperscaler revenue intact even if the top 1% of workloads eventually moves to EU-only providers.

A Regulatory Pincer: The DMA Gatekeeper Angle

CADA is not arriving alone. On June 25, 2026, the European Commission told Amazon and Microsoft it had reached a preliminary position that AWS and Azure should be designated gatekeepers under the Digital Markets Act for their cloud computing services. Gatekeeper status brings its own obligations around self-preferencing, data portability and interoperability, layered on top of whatever sovereignty rules eventually pass under CADA.

The combination matters because it means AWS and Microsoft face pressure from two different regulatory tracks at once: a competition-law track questioning their market power inside the EU, and a national-security track questioning whether their ownership structure disqualifies them from the EU’s most sensitive contracts. Companies that clear one hurdle do not automatically clear the other, which is part of why legal teams at both firms have expanded their Brussels policy staff through 2026.

Historical Context: From Schrems II to Gaia-X

Europe has tried this before, with mixed results. The 2020 Schrems II ruling invalidated the EU-US Privacy Shield over concerns that US surveillance law let American intelligence agencies access European personal data, and it forced years of contractual patchwork before the EU-US Data Privacy Framework replaced it. Gaia-X, the pan-European cloud federation project launched in 2019, aimed to build sovereign infrastructure independent of both US and Chinese hyperscalers, but it struggled to gain commercial traction against providers that already had a decade of scale and enterprise trust.

CADA differs from both precedents in one important way: it does not rely on companies volunteering to build sovereign alternatives. It uses public procurement law to force the issue, tying market access directly to compliance with a legally binding assurance scale. That is a harder lever than Gaia-X’s federation model, and it explains why defence ministries, who remember how slowly Gaia-X moved, are treating CADA’s Level 4 deadline as a much more immediate operational risk.

Market Impact for AWS, Microsoft and Google

For all three hyperscalers, the EU public sector is a meaningful but not dominant slice of revenue, so the near-term financial exposure looks manageable. The bigger risk is precedent. If CADA’s Level 4 exclusion survives defence-sector lobbying largely intact, other jurisdictions weighing their own sovereignty rules gain a template for excluding US providers from the most sensitive tenders without triggering a formal trade dispute over a blanket ban.

That is a bigger structural concern for AWS and Microsoft than for Google, since Microsoft’s defence footprint is the largest of the three and AWS built an entire sovereign product line specifically to compete for this category of contract. It also intersects with the broader multicloud strategy US hyperscalers have pursued in 2026: AWS’s push toward direct interconnects with Google Cloud and Oracle, alongside the private link Microsoft and AWS built between Azure and AWS, shows all three providers preparing for a world where customers, including governments, split workloads across multiple clouds rather than committing to one.

Competitive Landscape: Hyperscalers vs EU Sovereign Alternatives

The uncomfortable truth for Brussels is that no purely EU-owned cloud provider currently operates at the scale, AI tooling depth or global redundancy that AWS, Azure and Google Cloud offer. Analysts comparing the three hyperscalers on cost and capability, as seen in ongoing head-to-head pricing comparisons between AWS, Azure and Google Cloud, consistently find that EU-native providers trail on breadth of managed services, especially in AI infrastructure where US firms have a multi-year lead. Regional players position themselves as the compliant option for the smaller slice of workloads that need Level 3 or Level 4 assurance, not as a wholesale replacement for the hyperscalers.

That capability gap is precisely the argument defence officials make when they call the strictest tier of CADA impractical on the current timeline. It is also the argument the Commission rejects, on the theory that sovereignty requirements will force EU providers to close the gap faster if the market access incentive is strong enough. Both sides agree on the diagnosis. They disagree sharply on how much time closing that gap should take.

Timeline: When These Rules Actually Take Effect

CADA remains in the legislative negotiation phase as of September 9, 2026, not yet formally adopted or in force. The Commission presented the package on June 3, 2026, Reuters surfaced draft procurement documents dated June 1 to 2, and the defence-sector pushback described by Servola and Cloud Computing News emerged in early September as member states began working through what compliance would actually cost. Formal adoption typically follows trilogue negotiations between the Commission, Parliament and Council, then a transition period before obligations bite, so implementation realistically stretches into 2027 or later for the most sensitive Level 4 category, even on an aggressive schedule.

Procurement rules could move faster than the full CADA framework, since contracting authorities can start applying jurisdictional risk assessments to new tenders as soon as the rules are finalized, independent of the broader legislative timeline for the assurance-level classification system.

What Comes Next: Five Predictions

First, expect the Commission to soften Level 4’s timeline for existing defence contracts through grandfathering or phased compliance, rather than backing down on the standard itself, since the political cost of appearing to cave to Big Tech lobbying is high heading into 2027 budget negotiations.

Second, Microsoft will keep expanding EU-local operational control over Azure faster than AWS or Google, simply because it has the most defence revenue exposed and the most to lose if Level 3 compliance becomes the practical ceiling for US providers.

Third, EU sovereign cloud providers will see a wave of new defence and public-sector contracts at Levels 3 and 4 specifically, even if they never seriously compete with hyperscalers on general-purpose commercial cloud.

Fourth, the DMA gatekeeper designation for AWS and Azure will move forward on its own track largely independent of the CADA fight, adding a second layer of EU obligations that compounds compliance costs for both companies through 2027.

Fifth, expect at least one non-EU government, likely in a NATO-adjacent state outside the bloc, to reference CADA’s assurance-level model when drafting its own cloud procurement rules within the next 18 months, turning a European compliance framework into an early template other regulators borrow from.

Frequently Asked Questions

What is the EU Cloud and AI Development Act (CADA)?
CADA is EU legislation, presented June 3, 2026 as part of a broader tech sovereignty package, that requires public bodies to classify cloud services against a four-level sovereignty assurance scale before procuring them, with the strictest tier reserved for the most sensitive national security workloads.

Does CADA ban AWS, Microsoft Azure and Google Cloud from Europe?
No. It restricts their use in the smallest, most sensitive slice of government and defence contracts, roughly 1% of workloads under the top assurance level, while leaving the vast majority of public-sector cloud spending open to any provider that meets baseline data protection standards.

Why are European defence ministries opposed to the rules?
Defence officials argue that Microsoft, AWS and Google are already deeply embedded in operational and NATO-interoperable systems, that no EU sovereign provider currently matches their scale or AI tooling, and that the compliance timeline moves faster than a realistic migration could happen without disrupting mission-critical infrastructure.

How many EU countries rely on Microsoft Azure for defence systems?
Reporting from Euronews and EU GovLab in 2026 puts the figure at 18 to 19 EU member states, making Microsoft the largest cloud provider serving European defence agencies, ahead of Google and Oracle, which hold a smaller number of defence contracts.

What is the AWS European Sovereign Cloud?
It is an independent AWS cloud region announced with general availability on January 15, 2026, based in Potsdam, Germany, that is physically and logically separate from AWS’s other global regions and designed to help customers meet EU sovereignty requirements.

How does the Digital Markets Act gatekeeper designation relate to CADA?
They are separate but overlapping tracks. On June 25, 2026 the European Commission signaled a preliminary view that AWS and Azure should be designated gatekeepers under the DMA for their cloud services, adding competition-law obligations on top of whatever sovereignty requirements eventually apply under CADA.

When will CADA’s sovereignty rules take effect?
CADA is still in legislative negotiation as of September 2026 and has not been formally adopted. Full implementation, especially for the strictest Level 4 tier, is unlikely before 2027 given the standard trilogue negotiation and transition-period process EU legislation follows.

How big is the market CADA’s procurement rules could affect?
Policy analysts tracking the Commission’s draft procurement criteria describe the potential shift as touching a market on the order of €2 trillion in EU public procurement and strategic tenders, though that figure represents the scale of contracts potentially subject to review, not a single confirmed contract value.