The European Commission’s newly released cloud and AI infrastructure study puts numbers and causes behind a problem that European IT buyers have been living with for years: capacity is scarce, unevenly distributed, and increasingly controlled by companies headquartered outside the EU. As reported by INSIGHT EU MONITORING, the Technopolis-led research now underpins the impact assessment for the proposed Cloud and AI Development Act, or CADA, which the Commission presented on June 3, 2026.

For Windows administrators, Microsoft 365 and Azure customers, and enterprises running hybrid environments across Europe, the immediate change is not a new compliance deadline. CADA remains a Commission proposal that still requires negotiation and adoption by the European Parliament and EU member states. The practical signal is more consequential than the study’s release might suggest: the EU is building a formal policy case for treating cloud location, provider control, support-chain exposure, and foreign legal reach as operational risks rather than procurement footnotes.

The study examines capacity, grid connections, water availability, cross-border barriers, data-centre permits, AI-stack lock-in, investment conditions, and the effects of third-country laws with extraterritorial reach. Its central conclusion is straightforward: computing capacity in the EU is limited and concentrated in a small number of national markets, while the region remains dependent on non-European cloud and AI providers.

That is a diagnosis, not yet a mandate. But it is the evidence base Brussels is using to change how public-sector and critical-service cloud purchasing could work.

Futuristic European energy grid linking renewable power, cloud data centers, cybersecurity, and digital infrastructure.The shortage is about where capacity exists, not simply whether Europe has data centres​

The Commission’s impact assessment, drawing on the Technopolis study, says EU computing capacity is concentrated in a handful of hubs. Dublin, Frankfurt, Amsterdam and Paris are the established centres, with further growth in Spain, Italy, Belgium, Poland and the Nordic countries. This pattern favors the places with strong connectivity, large enterprise demand, tax advantages, and established power infrastructure; it also leaves much of the bloc with fewer nearby options for low-latency cloud workloads.

The distinction matters for enterprise planning. A cloud region inside the EU is not the same thing as capacity that is available near a workload, within a country’s preferred legal and procurement framework, or connected to an electricity grid capable of supporting new AI infrastructure. A company may have Azure, AWS, or Google Cloud regions available in the broader European Economic Area while still facing delays for GPU allocations, higher colocation prices, or few realistic alternatives when a specific region reaches power or space constraints.

The Commission’s assessment estimates that the EU accounted for 20% of global installed data-centre capacity in 2025, compared with 42% for the United States. It also says that EU capacity per capita remains heavily skewed toward countries including Ireland, the Netherlands, Denmark, Sweden, Finland and Luxembourg. Those figures should be read carefully: they measure installed data-centre capacity rather than every private enterprise server room or dedicated high-performance computing installation. They nevertheless describe the commercial infrastructure on which most scalable cloud and AI services depend.

The more immediate procurement issue is competition for the capacity that does exist. The impact assessment says European colocation asking prices for 100 kW leases rose 51% from 2022, while vacancy rates in major European data-centre markets fell to 7.4%. It also notes that hyperscalers including Microsoft, Amazon Web Services and Google reserve substantial new capacity. This does not make hyperscalers the cause of every regional shortage; they are responding to the same surge in demand. It does mean that smaller providers and enterprise buyers can find themselves competing for physical infrastructure long before they begin comparing virtual-machine prices.

CADA turns “sovereignty” into a purchasing and audit issue​

The Commission’s June proposal aims to triple European data-centre capacity over five to seven years. Its mechanisms include streamlining deployment conditions for data centres, supporting more sustainable infrastructure, and creating a Union-wide framework for assessing cloud and AI sovereignty.

This is where the study’s attention to foreign dependencies becomes concrete. The Commission’s impact assessment identifies risks involving data control and operational autonomy when cloud or AI computing services are supplied by non-European providers. The CADA proposal responds with four assurance levels for cloud-computing sovereignty, intended for services supplied to EU institutions and public-sector bodies. The proposal also contemplates a coordinated approach to sensitive uses, common audits, public procurement, and the federation of public-sector cloud and AI resources.

The policy is aimed at avoiding what the Commission calls sovereignty-washing: a service presented as European because its data centre is located in the EU, while key control points remain subject to a parent company, support operation, supply chain, or foreign jurisdiction outside it. Physical data residency is important, but it does not settle who can administer a platform, push updates, access telemetry, manage encryption systems, provide emergency support, or be compelled by a non-EU authority.

For Microsoft customers, that scrutiny will not be confined to the location selector used when creating an Azure resource. A serious sovereignty assessment reaches into tenant administration, identity architecture, privileged support access, encryption-key custody, backup and disaster-recovery locations, software dependencies, subcontractors, and contract terms governing law-enforcement or government-access requests.

Microsoft has invested heavily in European cloud regions and in sovereignty-oriented offerings. The Commission proposal does not, at this stage, prohibit non-European suppliers from the EU market. The Commission itself says it intends to keep most of the market open to like-minded partners. But the proposal would create a more formal basis for public buyers to distinguish services by their legal and operational attributes, rather than accepting a broad “EU hosted” claim as sufficient.

The study exposes the constraint that legislation cannot fast-track away​

CADA’s most tangible near-term objective is faster data-centre deployment. The study covers permitting delays, financial incentives, grid limitations and water constraints because those are the factors that determine whether announced capacity becomes live infrastructure. A favorable regulation can shorten administrative processes; it cannot create substations, transmission capacity, water resilience, trained operators, construction labor, or high-end AI accelerators on its own.

The Commission acknowledges this tension. Its broader technology-sovereignty package couples CADA with Chips Act 2.0, an open-source strategy, and a roadmap for digitalisation and AI in the energy sector. That combination is an admission that cloud capacity is no longer an isolated IT-market question. AI infrastructure draws on power systems, semiconductor supply, network build-outs, land-use rules and software dependencies at the same time.

The study’s energy and water emphasis should also temper assumptions that every member state can simply race to attract hyperscale facilities. Grid queues and permitting constraints vary by region, and increased capacity can increase resource use even where new facilities are more efficient than older sites. The Commission argues that CADA would encourage sustainable technology and better planning, but the proposal will be judged against local delivery: whether it improves grid coordination and access to capacity rather than merely accelerating competition for the same constrained sites.

There is also a policy trade-off for enterprises. More harmonised rules and one EU-wide sovereignty audit could reduce duplicated compliance work for providers serving multiple countries. Yet a new classification regime could require customers to do more detailed due diligence before placing sensitive systems in cloud services. Public bodies and operators in NIS2 sectors should expect the latter discussion to become more pressing as the proposal moves through the legislative process.

What European Windows and cloud teams should do before rules change​

No organization needs to migrate workloads because of this study. CADA is not in force, and the final legal text could change substantially during negotiations. Waiting for a final regulation, however, is an expensive way to discover that the organization cannot explain where its critical workloads run or who can control them.

IT teams with European public-sector customers, regulated operations, or NIS2 exposure should use the study as a prompt for an infrastructure inventory that goes beyond regional residency. The useful question is not whether a service is “in Europe,” but whether the organization can evidence how its data, identity plane, management plane, support path, keys, logs and recovery environment are governed.

A practical review should include the following:

  • Identify production workloads whose loss of availability, confidentiality or administrative control would disrupt a critical service.
  • Record the selected Azure, Microsoft 365, AWS, Google Cloud, or private-cloud region for each workload, along with backup, failover and log-retention locations.
  • Document which identities retain tenant-wide or subscription-wide privileges, including managed service providers and break-glass accounts.
  • Review encryption-key ownership, customer-managed key use, hardware security module location, and the operational consequences of a key-access outage.
  • Separate claims about EU data residency from evidence about corporate control, administrator access, contractual commitments and foreign-jurisdiction exposure.
  • Test whether disaster recovery can operate without depending on a single congested region or a support process outside the organization’s intended sovereignty boundary.

The Commission’s study does not settle the European cloud market’s future, and it does not establish that every foreign provider is unsuitable for sensitive work. It does establish the policy record for a more demanding standard: capacity, jurisdiction and control will increasingly be assessed together. For organizations with European public-sector or critical-infrastructure responsibilities, that assessment is likely to arrive in procurement reviews before it arrives as a binding rule.