October 9, 2026

Europe needs greater digital capacity, not digital isolation

Europe needs more cloud and AI capacity. The Cloud and AI Development Act can help, but only if it strengthens investment, innovation and competitiveness.

Carola Ekblad, digital policy, och Carolina Brånby, jurist och policyansvarig.
Carola Ekblad, expert Digital Policy. Photo: Stefan Tell

Cloud services, data centres and computing capacity are essential for AI and the digital economy. In today’s geopolitical landscape, they are also increasingly important for Europe’s security and resilience.

The Confederation of Swedish Enterprise welcomes the ambition behind CADA. But stronger European capacity must not come at the expense of open markets, competition or access to globally competitive technologies.

Remove barriers to investment

Slow permitting, insufficient grid capacity and limited access to competitive energy make it harder to expand Europe’s digital infrastructure.

CADA should address these practical barriers and create faster and more predictable processes for all qualifying investments, rather than selective fast tracks for a limited number of projects.

Keep assurance requirements risk-based

CADA introduces four assurance levels for cloud computing services. All public procurement of such services would require at least level 1. For public-sector activities with particular public-order relevance, a risk assessment would determine whether level 2, 3 or 4 is required. Cloud providers wishing to serve these needs would have to show that the relevant service meets the required level.

The Commission states that most public services would not need the highest levels. But clear definitions and risk-based thresholds are essential. Otherwise, public authorities may choose a higher level than the activity and data require, restricting competition and making the strictest requirements more widespread than intended.

Higher levels should be reserved for clearly defined, highly critical public-sector use cases. Restrictions on providers should be based on documented risks that cannot be managed through equivalent safeguards, not on origin or ownership alone.

Do not extend obligations through delegated acts

CADA would initially allow private companies in NIS2 sectors to carry out voluntary impact assessments. However, the proposal also gives the Commission delegated powers to make assessments or related measures binding.

This power should be removed. Any future CADA obligations for private companies should be decided through the ordinary legislative procedure, following a full impact assessment and structured consultation with affected businesses.

Requirements aimed at the public sector are likely to spill over to private companies through procurement, contracts and supply chains. This risks turning exceptional assurance requirements into de facto market standards, creating unnecessary costs and limiting competition. These effects must be carefully assessed and minimised when the rules are designed and implemented.

Keep markets open

Public procurement should strengthen security, resilience and innovation while preserving competition and value for money. European added value may be considered, but it must not become an origin-based preference or an indirect Buy European requirement.

Open source and open standards can support innovation and reduce lock-in. But they should remain tools, not mandatory technology choices.

Make CADA part of the solution

CADA can strengthen Europe’s digital capacity and resilience. To succeed, it must attract investment, preserve competition and avoid another layer of overlapping regulation.

In conclusion; Europe will become stronger by building its own capacity while remaining open to global technology, investment and cooperation.

Read the full position of the Confederation of Swedish Enterprise on CADA.

CADA position Confederation of Swedish Enterprise October 2026.pdf