Sovereignty
CADA, Data Act, NIS2, DORA: the cloud and your obligations
What your AI phone system provider should know about the four European texts reshaping the cloud, and what is binding today.
CADA: the draft regulation
The Cloud and AI Development Act (CADA) is a draft regulation presented by the European Commission on 3 June 2026, in a “Tech Sovereignty” package. It has not been adopted.
CADA proposes four assurance levels, from a base one (infrastructure and customer data in the EU) to a maximal one (European ownership and control without exception, high-level cyber certification, effective control of the software). The intermediate levels add European certification, measures blocking third-country access, a complete software bill of materials and separation of non-European subsidiaries.
The text would first target the public sector and EU entities, with a mandatory risk analysis for public-order workloads. An extension to NIS2 essential entities is possible through implementing acts.
Timeline
CADA is at the proposal stage. Inter-institutional negotiations are expected over 2027-2028, and application is not estimated before 2028. None of it is binding on the private sector today.
Data Act: switching providers more easily
The Data Act is a European regulation already in application. It aims in particular to make switching cloud service providers and data portability easier.
It has triggered the gradual removal of exit fees: these provider-switching fees must disappear by 12 January 2027. For a buyer, this lowers the cost of reversibility, and therefore lock-in.
Concretely, it makes enforceable what often relied on goodwill: full export, open formats, documented exit lead times. All points to check in an AI phone system contract.
NIS2 and DORA: the subcontracting chain
NIS2 is a cybersecurity directive; DORA is a regulation on the operational resilience of financial players. Both govern the use of third-party cloud providers.
For the entities concerned, the cloud provider and its subcontractors fall within the risk-management scope: inventory of critical providers, contractual requirements, audit capability, continuity plans. An AI phone system that processes calls is part of this chain.
This shifts the requirement towards transparency: a provider must be able to document its own subcontractors and the level of each link, not merely display overall compliance.
NIS2
Cyber risk management extended to providers and the supply chain.
DORA
Operational resilience of financial players, third-party ICT providers included.
Enforceable transparency
Documenting subcontractors and the level of each link becomes contractual.
What is binding today
It is important to distinguish what already applies from what is being prepared, so as not to confuse a trend with an obligation.
Already in application: GDPR, the Data Act, NIS2 (after transposition) and DORA for financial entities. In preparation: CADA, whose application is not estimated before 2028. The Cloud Sovereignty Framework, meanwhile, structures the procurement of European institutions.
For a private buyer, the sensible reading is pragmatic: comply with what is binding, and use the SEAL levels or SecNumCloud as benchmarks to anticipate, without being sold an obligation that does not yet exist.
Frequently asked questions
Is CADA in force today?
What does the Data Act change for my cloud contract?
Is my AI telephony provider affected by NIS2 and DORA?
Primary sources
- European Commission — CADA proposal (Cloud and AI Development Act) 3 Jun 2026
- European Commission — Tech Sovereignty package 3 Jun 2026
- EUR-Lex — Data Act (Regulation 2023/2854) accessed 2 Oct 2026
- EUR-Lex — NIS2 (2022/2555) and DORA (2022/2554) accessed 2 Oct 2026
Align your telephony with your obligations
We review what is binding on you and what is coming, without overselling.