SDAV Global

Europe moves to triple its data centre capacity.

On 3 June 2026 the Commission proposed the Cloud and AI Development Act, pairing a capacity target measured in gigawatts with a procurement rule measured in assurance levels. Neither is law yet. Both are already specified precisely enough to plan against.

Insights bi îngilîzî tên weşandin.

On 3 June 2026 the European Commission adopted COM(2026) 502, a proposal for a regulation to strengthen Europe’s cloud and AI ecosystem — the Cloud and AI Development Act. It was tabled with the European technological sovereignty package and remains a proposal: Parliament and Council must both agree before it binds anyone.

Two quantities define it: a capacity target in gigawatts, and a procurement rule in assurance levels. The second reaches companies that will never build a data centre.

The shortage the Commission is trying to fix is administrative before it is physical

The Commission’s impact assessment asked operators directly. Eighty per cent intended to expand capacity inside the EU, and the obstacles they named were neither demand nor technology. Eighty-seven per cent cited complex and lengthy permitting procedures and 83 per cent limited access to energy. Fifty-seven per cent needed three to five years on average to bring a data centre into operation, a further 13 per cent five to seven.

The longest single queue is the electricity grid. Connecting a data centre takes three to ten years depending on the member state — three to five in emerging markets such as Italy or Spain, seven to ten in established hubs like Frankfurt, Amsterdam, Paris and Dublin — and up to thirteen where the grid is congested. Price compounds it: industrial electricity in the EU-27 stood at €0.190 per kWh in 2025 against €0.090 in the United States, and energy is 40 to 50 per cent of a data centre’s operating costs.

Tripling capacity is a gigawatt target, and the shortfall is measured in the same unit

Installed EU-27 capacity was expected to reach 12.4 GW in 2025, some 3 GW short of demand, and concentrated: Germany, France, the Netherlands and Ireland held 65 per cent of the market. Left to existing trends, supply grows about 12 per cent a year and demand 13 per cent, leaving a structural gap of 19 GW by 2036.

Against that baseline the Commission sets two objectives: at least tripling current EU capacity by 2030, with capacity meeting the Union’s needs by 2035; and, by 2030, every permit needed to build and run a data centre obtainable in under 18 months anywhere in the EU.

The instrument is the data centre acceleration zone. Article 10 requires each member state deploying capacity to designate at least one within six months of entry into force, weighing grid capacity, connectivity, waste heat reuse and a preference for brownfield sites. Article 13 requires an aggregated baseline permit covering the authorisations ordinarily needed inside the zone, leaving individual projects to obtain only installation-specific consents, and caps permit-granting there at 12 months. Article 12 adds a single information point, with an SME channel.

Sovereignty becomes a specification with four rungs, and the first buyer is the state

The explanatory memorandum states the dependence plainly: the share of EU providers in their own cloud market fell from 29 per cent in 2017 to 15 per cent in 2022 and has been flat since, while three non-EU hyperscalers hold over 70 per cent of it.

The answer is a single sovereignty framework of four assurance levels, set out in Annex II. Level 1 requires establishment in the Union and customer data — metadata and telemetry included — kept in the Union, and is self-assessed. Levels 2 to 4 are cumulative and require an independent audit at the provider’s expense. Level 2 asks a good deal: a European cybersecurity certificate of at least “substantial” assurance, support performed exclusively in the Union, a complete software bill of materials, a bar on using service data to train third-country AI systems, and separation from any third-country subsidiary. Level 3 tightens the tests on people and ownership: personnel must be Union citizens, and the provider must not be under third-country control. Level 4 raises the certificate to “high”, requires demonstrable control over the software components themselves, and admits no exception to the ownership test.

Demand gives the ladder its force. Under Article 29, member states and Union entities must run risk assessments within one year of entry into force and every two years after, migrating within 12 months where an assessment requires it. Article 30 makes level 1 the floor for public bodies whose activities are not public-order relevant, and confines those that are — NIS2 sectors, plus defence, justice, law enforcement and border management — to levels 2, 3 or 4.

Three provisions reach suppliers that are not cloud providers. Article 32 obliges contracting authorities buying innovative cloud services and AI systems to apply non-price criteria measuring a tenderer’s contribution to the European cloud and AI ecosystem, expressly ancillary and not decisive. Article 33 sets an objective that at least 25 per cent of such procurement go to innovative SMEs. Article 31 lets private entities in the NIS2 high-criticality sectors run similar assessments voluntarily, and lets the Commission require them by delegated act.

For a Swiss company the question is which side of the third-country line it falls on

The proposal is marked “Text with EEA relevance”; Switzerland is not in the EEA and will not inherit the regime through that channel. Article 18 nonetheless opens a door: the Commission may identify, by implementing act, third countries whose providers may be audited against level 3 despite being under third-country control. The criteria are cumulative: among them an adequacy decision under Article 45 of the GDPR, no state power to compel data access in conflict with the Data Act or to degrade a provider’s service, and equivalent access to that country’s public procurement.

Switzerland satisfies several of these: the Federal Data Protection and Information Commissioner records the Commission’s confirmation of Swiss data protection adequacy on 15 January 2024, and Switzerland has been a party to the revised WTO Government Procurement Agreement since 1 January 2021. What does not exist is a designation, which needs an implementing act that cannot precede the regulation. Two limits are structural: Annex II requires establishment in the Union at every level, so the derogation concerns control rather than presence, and level 4 admits no exception. A Swiss-controlled provider’s ceiling would be level 3, and only once designated.

Switzerland is answering the same question with its own instrument: the Swiss Government Cloud, a hybrid multi-cloud for the federal administration with a dedicated Swiss public-cloud tier, carrying a commitment credit of CHF 246.9 million and running to 2032. A study published in May 2026 for EnergieSchweiz, a programme of the Federal Office of Energy, found Swiss data centres consuming just under 2.1 TWh in 2024, about 3.6 per cent of national electricity, and expects 2.5 to 3.2 TWh by 2030. The driver is not domestic AI training, which the study notes barely happens in Switzerland, but the migration of workloads out of in-house server rooms into colocation and cloud — that is, into the capacity this proposal is about.

Four things a company can settle before the text is settled

  • Locate the regulated revenue. Identify which contracts touch a public body or a NIS2 sector in the EU, and which assurance level those activities would require after a risk assessment.
  • Document the stack against Annex II’s questions. Where the provider is established, where data and metadata sit, where support staff sit, which subcontractors are involved. Gathering the evidence takes longer than answering.
  • Price an exit. Article 29 of the Data Act removes switching charges for data processing services from 12 January 2027, turning a migration cost into a planning variable.
  • Read Articles 32 and 33 as a market signal. Non-price award criteria and a 25 per cent SME objective show where European public demand is being steered.

The dates already written into the proposal

Most deadlines run from entry into force rather than adoption. The regulation would apply one year after that date; acceleration zones would be designated within six months, national cloud and AI strategies and the first risk assessments within one year, and those assessments every two years thereafter. The assurance-level criteria are themselves reviewed at least every 18 months.

The file is at the preparatory stage in Parliament, in the internal market committee, and its reception has divided those who find the sovereignty criteria discriminatory from those who find them insufficiently ambitious. Much of the drafting will change. The direction is less likely to: in European public procurement, where a workload runs and who controls the entity running it are becoming audited specifications rather than assumptions.

Bulten

Ji çalakiyên me agahdar bimînin.

Çalakî, weşan û nûçeyên komeleyê — çend caran di salê de, bi zimanê ku hûn hilbijêrin.