The Cloud and AI Development Act, CADA, proposed in June, would require European public bodies in the categories it singles out to buy cloud at a recognised assurance level set by a risk assessment. How that assessment should be done is not in the proposal. It is left to follow-up rules that do not exist yet.
The Cloud Sovereignty Framework the Commission published in October 2025 leaves the same gap. It runs to six pages, defines eight sovereignty objectives, and grades a tenderer’s cloud services on each using Sovereignty Effectiveness Assurance Levels, from SEAL-0 (“No Sovereignty”) to SEAL-4 (“Full Digital Sovereignty”). The buyer sets a minimum level for each objective. Miss one, and the tender does not qualify. The framework never says how a buyer is to arrive at the minimums. It is already in use: in April 2026 the Commission awarded the first contracts assessed under it, grading three bidders building their own technology at SEAL-3 and a fourth, whose service runs on Google Cloud technology, at SEAL-2.

In those six pages, exactly one sentence concerns which of the buyer’s own systems can go where. It says the results “may also be used”, by the buyer’s own technical services during the contracts that come out of the same tender, “to determine the nature of systems that can be deployed at a specific provider, different risk profiles requiring different assurance levels”. That is the whole of it, and it presupposes the risk profiles already exist.
Meanwhile the labelling goes on. Across Europe, organisations are sorting their applications into “sovereign” and “standard”, one row at a time, and filing the result. The file records what each application is, never what it stands on.
What the file misses shows up the first time a boundary closes.
Continue reading “Sovereignty Is Decided on the Edges”