20 submissions from 18 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 468 submissions on this file. Shown here: the 20 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
NextFeedback on adopted proposal open: Cloud and AI Development Act — closes 24 Oct 2026
Deliberations in Council working party · 7 Jul 2026
Deliberations in Council working party · 16 Jun 2026
Adoption of legislative proposal by the Commission · 3 Jun 2026
Call for evidence closed: Cloud and AI Development Act — 193 responses · 3 Jul 2025
Public consultation closed: Cloud and AI Development Act — 244 responses · 3 Jul 2025
Who showed up
15 submissions from industry — companies and their trade associations — against 3 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5 industry submissions for every one from civil society.
Industry 15Civil society 3Public authorities, academia, other 2
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
The file, right now
The consultation is open — 55 days leftto submit. It closes on 24 Oct 2026.
Responding? PolicySpeak drafts consultation responses grounded in your organization’s own positions. Request access.
FINULIO SIA supports the proposed Union cloud sovereignty framework and, in particular, the use of defined assurance levels, independent audit evidence and software supply-chain transparency. We suggest strengthening one aspect of the framework: the lifecycle of assurance after recognition. Cloud services and their software supply chains are continuously changing.
Tyche Institute is an independent non-profit research institute in Tallinn, Estonia, working on verifiable evidence for automated action. We build open reference implementations and publish the underlying data. We have no commercial interest in any cloud, compute or trust-service provider. OUR CLAIM.
OpenMined is a non-profit building open-source infrastructure that lets organisations make sensitive data available for AI development and evaluation without transferring it. We welcome the proposed Act, but its sovereignty framework measures everything except control: the Annex II assurance criteria rest on establishment, location, and ownership tests, with no route for verifiable technical controlconfidential…
Please find here below INDICAM's observations on the Commission's proposal for a Regulation establishing a framework of measures for strengthening Europe's cloud and AI ecosystem (the "Cloud and AI Development Act"), prepared in the interest of our associates — brand owners and rights holders active in anti-counterfeiting and IP enforcement who increasingly rely on cloud infrastructure and AI tools for online brand…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Sovereignty without inspectability is a slogan. The package concedes every premise dependency is dangerous, open source is the remedy, hardware matters and then stops short of the conclusion. Draw it: Your data, your access code. Any product storing user data must ship a complete, royalty-free format specification with a reference implementation.
Warsaw, August 4th, 2026 Position of Digital Association Lewiatan on Cloud and AI Development Act The Cloud and AI Development Act (CADA) initiative seeks to address critical challenges related to expanding the EU’s data center capacity, particularly in view of the growing demand generated by AI development.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Warsaw, July 30, 2026 r. Position of Polish Confederation Lewiatan on Cloud and AI Development Act I. General comments The objectives of the technological sovereignty package—building European capacity in critical technologies and accelerating investment in artificial intelligence (AI)—are fully justified, and its focus on interoperability is welcome.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
[Please refer to the full position paper attached]. The CADA can reduce the EUs structural dependence on non-European digital providers. But it will strengthen European digital sovereignty only if cloud, AI and data centre infrastructure is planned within Europes energy and climate transition.
Kaspersky welcomes the European Commissions initiative to strengthen Europes computing infrastructure through the proposed Cloud and AI Development Act (CADA). As a global cybersecurity company operating across Europe and internationally, we support the European Commissions objective to expand sustainable computational capacity, strengthen Europes competitiveness in artificial intelligence, and improve the…
Airbus Amber Position on CADA 1. Airbus strongly supports the European Commission’s proposal for a Cloud and AI Development Act (CADA). 2. Airbus particularly values: ● The establishment of a certification framework for sovereign cloud services (‘Cloud computing sovereignty framework’) including four assurance levels, with the strongest one providing protection against risks of unauthorized access to data or…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Transparent Edge welcomes CADA’s objective to strengthen Europe’s cloud and AI ecosystem. As a European owned and operated scale-up, we provide edge computing, content delivery and network security services to more than 20.000 websites and we are a digital infrastructure entity in Annex I of NIS2. From this operational perspective, we put forward three recommendations to strengthen the proposal: 1.
Filed in Spanish · English published by the European Commission
Public Consultation on the proposed Regulation of the European Parliament and of the Council establishing a framework of measures to strengthen the European cloud and artificial intelligence ecosystem. Madrid, July 20, 2026. From: AOTEC (Association of Telecommunications Operators).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Europeans for Safe Connections opposes this proposal, because it promotes acceleration. By its very nature, an acceleration-focused legislative framework reduces the time and opportunity to generate, evaluate and incorporate long-term scientific evidence on impacts on public health and the environment. Acceleration and the precautionary principle pursue different objectives.
This submission draws the Commission's attention to an open-source protocol GFSIP/1.0 (ANTARES) whose architectural properties directly address structural tensions in three WRC-27 agenda items. GFSIP/1.0 is a fully encrypted, multi-channel federation protocol over QUIC (ALPN: gfsip/1) with deterministic CBOR encoding.
This submission draws the Commission's attention to an open-source protocol GFSIP/1.0 (ANTARES) whose architectural properties directly address structural tensions in three WRC-27 agenda items. GFSIP/1.0 is a fully encrypted, multi-channel federation protocol over QUIC (ALPN: gfsip/1) with deterministic CBOR encoding.
The European Commission (EC) presented on June 3 the Tech Sovereignty Package, which includes two legislative proposals (the Chips Act 2.0 and the Cloud and AI Development Act), the EU Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy.
Tripling the EU's data center capacity by 2030 and establishing the Union Cloud Computing Sovereignty Framework (Levels 1 to 4) is a geopolitical move, but its architecture contains a fatal flaw in the annex: "Software within the meaning of Regulation (EU) 2024/2847, Article 3, point (4) falls within the scope of this Annex...
Executive Summary: DI broadly supports CADAs ambition to strengthen Europes cloud and AI capacity through investment, innovation and improved framework conditions. At the same time, digital sovereignty should be built on enhanced competitiveness, flexibility, strategic choice and robust security requirements not on protectionism or geographically based restrictions.
See my warehouse for reference:https://github.com/nohn3043-arch/second-perspective Current LLMs possess a systemic vulnerability: the mathematical inability to eliminate the final 1% of hallucinations and prompt injections. In high-risk sectors, a 99% safety rate equals 0% security.
Europes cloud and AI strategy should address not only infrastructure capacity and provider-level sovereignty, but also the operational and technical assurance layer required for AI agent deployment. CADA defines sovereignty assurance at the cloud and provider level.
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.