Sovereignty

CADA, Data Act, NIS2, DORA: the cloud and your obligations

What your AI phone system provider should know about the four European texts reshaping the cloud, and what is binding today.

8 min

CADA: the draft regulation

The Cloud and AI Development Act (CADA) is a draft regulation presented by the European Commission on 3 June 2026, in a “Tech Sovereignty” package. It has not been adopted.

CADA proposes four assurance levels, from a base one (infrastructure and customer data in the EU) to a maximal one (European ownership and control without exception, high-level cyber certification, effective control of the software). The intermediate levels add European certification, measures blocking third-country access, a complete software bill of materials and separation of non-European subsidiaries.

The text would first target the public sector and EU entities, with a mandatory risk analysis for public-order workloads. An extension to NIS2 essential entities is possible through implementing acts.

Timeline

CADA is at the proposal stage. Inter-institutional negotiations are expected over 2027-2028, and application is not estimated before 2028. None of it is binding on the private sector today.

Data Act: switching providers more easily

The Data Act is a European regulation already in application. It aims in particular to make switching cloud service providers and data portability easier.

It has triggered the gradual removal of exit fees: these provider-switching fees must disappear by 12 January 2027. For a buyer, this lowers the cost of reversibility, and therefore lock-in.

Concretely, it makes enforceable what often relied on goodwill: full export, open formats, documented exit lead times. All points to check in an AI phone system contract.

NIS2 and DORA: the subcontracting chain

NIS2 is a cybersecurity directive; DORA is a regulation on the operational resilience of financial players. Both govern the use of third-party cloud providers.

For the entities concerned, the cloud provider and its subcontractors fall within the risk-management scope: inventory of critical providers, contractual requirements, audit capability, continuity plans. An AI phone system that processes calls is part of this chain.

This shifts the requirement towards transparency: a provider must be able to document its own subcontractors and the level of each link, not merely display overall compliance.

NIS2

Cyber risk management extended to providers and the supply chain.

DORA

Operational resilience of financial players, third-party ICT providers included.

Enforceable transparency

Documenting subcontractors and the level of each link becomes contractual.

What is binding today

It is important to distinguish what already applies from what is being prepared, so as not to confuse a trend with an obligation.

Already in application: GDPR, the Data Act, NIS2 (after transposition) and DORA for financial entities. In preparation: CADA, whose application is not estimated before 2028. The Cloud Sovereignty Framework, meanwhile, structures the procurement of European institutions.

For a private buyer, the sensible reading is pragmatic: comply with what is binding, and use the SEAL levels or SecNumCloud as benchmarks to anticipate, without being sold an obligation that does not yet exist.

Frequently asked questions

Is CADA in force today?

No. CADA is a draft regulation presented on 3 June 2026 and not adopted. Inter-institutional negotiations are expected over 2027-2028 and application is not estimated before 2028. None of it is binding on the private sector so far.

What does the Data Act change for my cloud contract?

It eases provider switching and data portability, and gradually removes exit fees, which must disappear by 12 January 2027. Check your contract for full export, open formats and documented exit lead times.

Is my AI telephony provider affected by NIS2 and DORA?

If it processes your calls, it is part of your subcontracting chain. For an entity subject to NIS2 or DORA, that means listing it among providers, requiring suitable clauses and an audit capability, and documenting the level of each link in the voice chain.

Align your telephony with your obligations

We review what is binding on you and what is coming, without overselling.

Request a demo