What CADA means for digital sovereignty in Europe | NTT DATA

Mon, 20 July 2026

What CADA really means for digital sovereignty in Europe

If you’ve spent any time reading the headlines since the European Union announced its intention to introduce the Cloud and AI Development Act (CADA), you’d be forgiven for thinking one of two things: Either Europe has finally solved all of its sovereignty challenges, or the sky is falling and global cloud providers are about to disappear from the European landscape.

The reality, as is often the case, sits somewhere in the middle.

In my conversations with clients across Europe, I see both reactions. Some worry that CADA will create more complexity without solving their real problems. Others fear it signals the end of hyperscalers in Europe. Neither interpretation is accurate.

My view is simple: CADA is neither the end of the world nor the answer to everything. It is an important step forward because it provides a framework for managing sovereignty risks more deliberately, but it does not eliminate those risks altogether. And that distinction is important.

Digital sovereignty is really about business risk

When we talk about digital sovereignty, the discussion often becomes highly technical very quickly. But at its core, sovereignty is a business issue. In fact, I would argue that sovereignty is fundamentally about managing risk‚ which matters even more in the era of AI.

Organizations already assess a range of risks every day — from cybersecurity and operations to supply chains and even natural disasters. Digital sovereignty belongs in the same category.

Unlike traditional applications, AI systems don’t simply store data. They use it, transform it, learn from it and generate insights and decisions from it. That extends sovereignty beyond where data is stored to include where intelligence is created, how it’s governed and whether decisions can be understood, explained and verified.

Digital sovereignty focuses on three specific dimensions:

  • Data sovereignty
  • Operational sovereignty
  • Technical sovereignty

In practical terms, these risks relate to questions such as:

  • Could a foreign government gain access to sensitive data?
  • Could geopolitical tensions disrupt ongoing access to critical technology?
  • Could a provider’s jurisdiction create legal exposure for the business?

These are boardroom conversations, which is why CADA should be seen as a strategic framework rather than a purely technical regulation.

CADA is about stronger sovereignty, not full sovereignty

One of the biggest misconceptions about CADA is that it somehow bans hyperscalers or forces organizations into highly isolated environments. It does neither.

CADA is expected to establish clearer expectations for sovereignty controls while still allowing organizations to benefit from global cloud ecosystems.

The market has already begun moving in this direction. Sovereignty is becoming a core part of hyperscalers’ cloud strategies. They’re investing in sovereign cloud regions, local operating models, restricted-access environments, customer-controlled encryption, disconnected or air-gapped options, and partner-led delivery models designed for highly regulated European workloads. This means the CADA conversation should not be framed as a choice between hyperscalers and Europe. Rather, it should focus on how global cloud capabilities, European regulatory expectations and sovereign operating models can be combined responsibly.

For many organizations, the choice will therefore not be between public cloud and private infrastructure. It will be about selecting the right mix: sovereign cloud services where they meet regulatory and operational requirements, combined with private environments where the risk profile requires it.

The blended, risk-based approach in practice

Banking provides a useful example because the industry has long applied this logic. Core banking systems and highly sensitive customer data are tightly controlled, while many banks have moved surrounding workloads, such as analytics, customer engagement, developer platforms or value-added digital services, into public cloud where the benefits outweigh the risks.

CADA provides a clearer regulatory and assurance framework for this risk-based approach and broadens the range of commercially viable options between standard public cloud and bespoke private infrastructure. For banks, the question becomes more precise: Which workloads can remain on standard cloud services, which require sovereign cloud controls and which need private environments?

The result is a more explicit, evidence-based and procurement-ready version of what regulated organizations have been doing for years.

The goal is appropriate control, not absolute isolation

Another common misconception is that Europe can achieve complete technological independence from non-European technology providers. Today, that simply isn’t realistic. There is currently no fully European, end-to-end technology stack capable of replacing every component that organizations rely on.

Some organizations aspire to remove every foreign technology component from their environments. While understandable, this approach often confuses possibility with probability, and the trade-offs are often underestimated.

Yes, there are hypothetical scenarios in which geopolitical tensions could create technology restrictions. But organizations should make decisions based on realistic risk assessments rather than worst-case assumptions. Ultimately, the goal is appropriate control, not absolute isolation.

How fair are common criticisms of CADA?

Many of the criticisms of CADA fall into familiar categories. Let’s examine some of them.

“CADA is protectionist and could slow Europe down.”

I understand the concern. However, I don’t believe organizations need to choose between innovation and sovereignty. Successful strategies will combine hyperscalers where appropriate, sovereign environments where necessary and hybrid architectures where they make sense. This is about creating options.

“CADA will increase costs and complexity.”

The question is: Compared to what?

When evaluated against a pure public-cloud approach, some sovereign controls may indeed introduce additional costs. But if an organization were building and operating their own private infrastructure, there are sovereign solutions that might actually represent a more efficient path.

More importantly, CADA encourages organizations to classify workloads according to risk and criticality. Not every workload requires the highest level of sovereignty. A pharmaceutical company conducting sensitive R&D may apply stringent controls to research data while using more flexible environments for routine business applications.

Such a targeted approach can prevent unnecessary spending.

“Europe does not have enough domestic capacity.”

There is some truth to this concern. Europe’s sovereign cloud and AI ecosystem is still evolving, with capacity gaps in some areas.

However, progress doesn’t require perfection. Organizations can adopt phased approaches that use existing cloud services where appropriate while gradually building sovereign capabilities around their most critical assets.

Since 2019, the EU and Japan — where NTT Group, of which NTT DATA is a core subsidiary, is based — have operated under a mutual adequacy arrangement that recognizes each other’s data-protection frameworks as providing equivalent safeguards for personal data transfers. In 2023, both sides completed the first review of the arrangement and confirmed its continued effectiveness. As a result, organizations can move personal data between the EU and Japan without many of the additional transfer mechanisms required for other non-EU jurisdictions, paving the way for streamlined strategic partnerships.

This matters because sovereignty is not only about locality; it’s also about trusted jurisdictions, governance and long-term partnerships.

“The definitions are too vague.”

This criticism is fair. Many regulatory frameworks intentionally leave room for interpretation because technology evolves faster than legislation. The challenge for organizations is translating policy language into practical architecture, governance models and operating procedures.

This is where experience matters. The question is not whether a definition is perfectly precise but how it applies to your business, your data and your risk profile.

Which industries will feel the impact first?

While CADA will eventually influence almost every industry, some are likely to experience its effects sooner than others.

Energy and utilities stand out immediately because they operate critical national infrastructure while facing significant modernization pressures.

Banking, pharmaceutical research, defense and public sector organizations will also face heightened scrutiny.

Why this is a valuable opportunity for Europe

CADA should push organizations not into panic or paralysis but into better decisions. The answer is not to try to make everything sovereign at once. You first need to understand your risk exposure, classify your workloads, choose the right control model and build a practical roadmap that includes public cloud, private cloud, sovereign cloud and AI infrastructure.

At NTT DATA, we help you find that balance between autonomy and openness, between protection and innovation, and between local control and global opportunity.

Our approach combines sovereignty assessment, workload classification, phased architecture and managed execution — helping you use existing cloud where appropriate while building private or sovereign capacity where it matters most.

WHAT TO DO NEXT

Read more about NTT DATA’s Private and Sovereign AI services and contact us to see how we can help you orchestrate AI control at scale for autonomy, resilience and advantage.


Related Insights

How can we help you

Get in touch