AI Playbook: Innovate - Improve efficiency, decision quality and enterprise value with AI Download Now
How EU Cloud and AI Sovereignty is changing supplier due diligence

How EU Cloud and AI Sovereignty is changing supplier due diligence

Why does EU cloud and AI sovereignty matter to procurement?

EU cloud and AI sovereignty could change how organisations assess suppliers, especially those handling sensitive data or supporting public-sector services. The proposed EU Cloud and AI Development Act, alongside potential public-sector cloud sovereignty requirements, isn’t a blanket ban on US cloud providers. But it signals a shift towards stronger scrutiny of data hosting, supplier ownership, legal jurisdiction, cloud dependencies, AI infrastructure and auditability.

Latest update: The EU Cloud and AI Development Act is still a proposal, not a final regulation. The detailed compliance thresholds, procurement rules and definition of “sovereign cloud” still need to be settled. Procurement teams should treat this as an early warning signal, not a reason to make rushed supplier decisions.

Summary

  • The EU is exploring stronger cloud and AI sovereignty rules.
  • The proposed Cloud and AI Development Act aims to strengthen Europe’s cloud and AI ecosystem, investment and infrastructure.
  • The immediate focus of proposed cloud restrictions is sensitive public-sector data.
  • Private-sector cloud use isn’t directly restricted by the proposals, based on current reporting. But procurement teams may still be affected indirectly through supplier due diligence, risk checks and public-sector tender requirements.
  • Technology suppliers may need to provide clearer evidence on data residency, infrastructure ownership, subcontractors, cloud dependencies and exit plans.
  • Procurement teams should review supplier questionnaires now, especially for SaaS, AI tools and suppliers handling sensitive data.

 

What is EU cloud and AI sovereignty?

EU cloud and AI sovereignty is the idea that European organisations, especially public-sector bodies, should have greater control over the digital infrastructure, cloud services and AI systems they rely on.

In practical terms, this means looking more closely at

  • where data is hosted and processed
  • who owns and controls the infrastructure
  • which legal jurisdictions apply
  • whether non-EU authorities could access data
  • which subcontractors and technology partners are involved
  • how easily an organisation can exit or switch provider
  • whether supplier decisions can be audited later

For procurement teams, this turns cloud and AI infrastructure into a supplier risk issue, not just an IT issue.

One important complication is that “sovereign cloud” does not yet have one simple definition. It may cover data location, provider ownership, operational control, exposure to foreign legal orders, resilience, interoperability and, in some cases, performance. Procurement teams should avoid reducing the issue to “EU provider good, non-EU provider bad.” The more useful question is whether the supplier can prove how data is protected, who can access it, which laws apply, and how the organisation can retain control if requirements change.

What new EU cloud and AI rules are being considered?

There are two connected developments procurement leaders should watch.

1. The proposed EU Cloud and AI Development Act

The EU Cloud and AI Development Act, or CADA, is part of the EU’s wider technology sovereignty agenda. According to the European Commission, the proposal aims to strengthen the EU’s cloud and AI ecosystem, investment and infrastructure.

The Commission’s cloud computing policy page also states that CADA aims to at least triple the EU’s data centre capacity within the next five to seven years and meet the needs of EU businesses and public administrations by 2035.

For procurement, the important point isn’t just the legislation itself but the potential trajectory of this regulation. The EU wants cloud and AI infrastructure to become more resilient, more transparent and less dependent on non-EU providers.

2. Potential cloud restrictions for sensitive public-sector data

The EU is also considering stronger sovereignty requirements for some cloud services handling sensitive public-sector data. 

According to Raconteur’s reporting on proposed EU cloud restrictions, this could affect dominant US cloud providers handling sensitive government data, including financial, health and judicial data.

This isn’t a blanket ban on US cloud providers. It’s also not a direct restriction on private-sector cloud use. However, it may affect how public bodies buy cloud services and how suppliers prove that they meet sovereignty, security and resilience expectations. Similarly, procurement leaders in the private sector should still pay attention, especially if they operate in regulated sectors or supply into government.

Get a demo of Market Dojo Supplier Onboarding

Public sector vs private sector: what’s the difference?

AreaPublic sectorPrivate sector
Direct impactMore likely to be directly affected, especially where sensitive government data is involvedNot directly covered by the proposed cloud restrictions, based on current reporting
Procurement requirementsMay need stronger evidence around sovereignty, jurisdiction, hosting and provider controlMay adopt similar checks as best practice, especially in regulated sectors
Supplier impactTechnology suppliers may need to prove compliance with sovereignty requirementsSuppliers may face more questions from customers, investors and risk teams
Risk focusSensitive citizen data, public services, national resilience and legal exposureCommercial risk, customer data, operational resilience and regulatory confidence
Practical actionUpdate tender questions and supplier assessment criteriaReview high-risk suppliers and add proportionate due diligence questions

Why should procurement teams care?

Procurement teams should care because cloud and AI risk increasingly sits inside the supplier base.

A supplier may appear low risk from a commercial perspective, but still rely on infrastructure or technology partners that create hidden exposure. For example, a SaaS provider may use a non-EU cloud provider. An AI tool may process data through third-party models. A supplier management platform may rely on subcontractors for hosting, analytics or support.

These dependencies can affect

  • data protection
  • cyber security
  • regulatory compliance
  • service continuity
  • public-sector tender eligibility
  • contractual risk
  • exit planning
  • supplier resilience

This means procurement teams need better visibility over the digital supply chain behind each supplier.

What types of suppliers should procurement teams review first?

Procurement teams should prioritise suppliers that handle sensitive data, support critical services or rely heavily on cloud and AI infrastructure.

High-priority supplier categories include

1. SaaS providers

Platforms used for procurement, supplier management, analytics, finance, HR, legal, or customer data.

2. AI tools

Tools that process prompts, documents, supplier data, contracts, bids or internal business information.

3. Cloud-hosted business systems

Systems where data hosting, jurisdiction and continuity are important.

4. Public-sector suppliers

Suppliers selling into government or public bodies, where future sovereignty expectations may be stricter.

5. Regulated-sector suppliers

Suppliers used by organisations in sectors such as healthcare, finance, energy, transport or public services.

What questions should procurement ask suppliers?

Rather than asking every supplier the same long questionnaire, procurement teams should apply due diligence based on supplier risk. A low-risk software provider may only need baseline checks, while suppliers handling sensitive data, AI-enabled processes or public-sector workloads should face deeper questions around infrastructure, jurisdiction, auditability and exit planning. 

Here’s an example framework.

Level 1: Baseline questions for SaaS and data-processing suppliers

These questions are suitable for most technology suppliers.

  • Where is our data hosted and processed?
  • Do you use subcontractors or fourth parties to deliver the service?
  • What controls exist around access, encryption and data segregation?
  • How quickly can data be exported or deleted?

Level 2: Enhanced questions for higher-risk suppliers

Use these where the supplier handles sensitive data, supports important processes or relies on cloud and AI infrastructure.

  • Which cloud providers, AI models or infrastructure partners do you rely on?
  • Which legal jurisdictions apply to the provider and its subcontractors?
  • Do any non-EU third parties have access to systems, support or data?
  • What audit trails are available?

Level 3: Strategic questions for critical or regulated suppliers

Use these for public-sector contracts, regulated industries, business-critical systems or suppliers handling highly sensitive data.

  • Who owns and operates the underlying infrastructure?
  • What is the exit plan if regulatory requirements change?

Additional questions for agentic AI tools

If a supplier uses AI agents, procurement teams should go beyond standard AI usage questions. For example

  • What systems can the agent access?
  • What actions is the agent allowed to take?
  • Can the agent update records, trigger workflows, approve actions or influence decisions?
  • What human approval is required before important actions are completed?
  • Is the agent treated as a separate identity with its own permissions?
  • Can every action be traced back to the data, policy and user instruction behind it?
  • What happens if the agent makes an incorrect or unauthorised decision?

What should procurement teams do now?

You don’t need to overhaul every supplier process immediately, but the key is to start preparing.

Exit planning should also cover practical switching rights, data portability, interoperability and any technical or contractual barriers that could make it difficult to move away from a cloud or AI provider later.

Step 1: Identify high-risk suppliers

Start with suppliers that handle sensitive data, support critical services, use AI or provide cloud-hosted systems.

Step 2: Update supplier questionnaires

Add proportionate questions on cloud hosting, data residency, jurisdiction, subcontractors, AI dependencies and exit plans.

Step 3: Review public-sector exposure

Check whether your organisation supplies into public-sector contracts, or whether key suppliers support public-sector services.

Step 4: Map hidden technology dependencies

Look beyond the direct supplier. Identify cloud providers, AI systems, subcontractors and fourth parties where possible.

Step 5: Keep evidence in one place

Store supplier responses, documentation, certifications and decisions in a structured way so they can be reviewed or audited later.

How eSourcing and supplier management software can help

Structured sourcing and supplier onboarding software can help procurement teams manage cloud and AI sovereignty questions more consistently.

Market Dojo helps teams

  • build standard supplier questionnaires
  • tailor questions by risk level or category
  • collect supplier evidence
  • compare responses consistently
  • keep an audit trail of supplier decisions
  • review supplier data over time

This reduces reliance on scattered emails, spreadsheets and one-off checks. It also gives procurement teams a clearer record of how supplier risk was assessed.

As cloud and AI sovereignty becomes more important, procurement teams will need to show not just who they selected, but why that decision was made and what evidence supported it.

Final takeaway

EU cloud and AI sovereignty may sound more relevant to IT or legal, but it’s becoming a practical procurement issue.

The proposed rules don’t mean every organisation needs to stop using US cloud providers. Nor do they directly restrict private-sector cloud use. But they do signal a future where technology suppliers face more scrutiny around data, infrastructure, ownership, jurisdiction and resilience.

For procurement leaders, the best response is preparation. Start with your highest-risk technology suppliers, update your due diligence questions, and make sure supplier evidence is easy to collect, compare and audit.

Market Dojo’s approach to responsible AI and cloud governance

As a SaaS provider of e-sourcing solutions, Market Dojo’s position is that AI should support procurement teams without compromising trust. Our AI-enabled questionnaire features use Google Cloud Platform (GCP), consistent with the wider infrastructure used across our production environment. Customer data isn’t used to train the foundation models, and information passed to the AI service is encrypted in transit and used only to generate the requested output.

Our wider cloud infrastructure is also supported by Google Cloud, with Market Dojo using GCP data centres in Belgium and the UK. Environmental and physical security, including secure areas, equipment management and data centre controls, is managed by Google Cloud. Market Dojo reviews GCP’s security posture at least once a year through its certifications and compliance programmes, with further information available through Google Cloud’s published security and compliance resources.

As with any AI-enabled tool, users should avoid entering unnecessary confidential information. But our policy is designed around a clear principle: AI should reduce manual work and improve sourcing efficiency while protecting customer information, maintaining strong cloud governance and supporting a responsible approach to data security.


 

Next steps

Start by reviewing supplier onboarding and risk questionnaires for technology suppliers, AI tools and cloud-hosted platforms. Focus on hosting location, legal jurisdiction, subcontractors, infrastructure partners, access controls, AI usage, audit trails, data portability and exit plans.

This is where e-sourcing, supplier onboarding and supplier management technology can help. Market Dojo helps procurement teams standardise supplier questionnaires, collect evidence, track responses and maintain a clear audit trail. This gives teams a more consistent way to assess supplier risk, (rather than relying on scattered emails, spreadsheets or one-off checks) and spot risk before it becomes a contractual problem.

Digital sovereignty may sound like a policy issue. For procurement, it’s becoming a practical question of supplier control, resilience and evidence. The teams that act early will be better placed to buy technology with confidence, protect sensitive data, prove why supplier decisions were made, and keep pace as regulations develop.

Get a demo of Market Dojo Supplier Onboarding

Get a demo of Market Dojo Sourcing

 

Frequently Asked Questions

Does EU cloud sovereignty mean US cloud providers will be banned?
No. The current proposals shouldn’t be treated as a blanket ban on US cloud providers. The focus is on stronger sovereignty requirements for certain sensitive public-sector workloads, not a general ban on private-sector cloud use.

Does this apply to private companies?
Private-sector cloud use isn’t directly covered by the proposed cloud restrictions based on current reporting. However, private companies should be prepared for scrutiny, especially if they operate in regulated sectors, supply into the public sector or handle sensitive data.

What is the EU Cloud and AI Development Act?
The EU Cloud and AI Development Act, or CADA, is a proposed EU initiative designed to strengthen Europe’s cloud, AI and data-centre capabilities. It’s part of a wider effort to reduce dependency on non-EU digital infrastructure and increase European technology resilience.

Is the EU Cloud and AI Development Act already law?
No. The EU Cloud and AI Development Act was proposed in June 2026. The details still need to move through the legislative process, including how “sovereign cloud” will be defined and how public-sector procurement requirements will work in practice. However, the proposal is a strong signal that cloud, AI infrastructure and digital supply chain visibility will face closer scrutiny.

Why is this relevant to procurement?
It’s relevant because many suppliers now depend on cloud platforms, AI tools, subcontractors and digital infrastructure. Procurement teams need to understand these dependencies when assessing supplier risk, especially for suppliers handling sensitive or business-critical data.

What should procurement teams ask SaaS suppliers?
Procurement teams should ask where data is hosted, which cloud providers are used, which jurisdictions apply, whether subcontractors are involved, how data is protected, what audit trails are available and how data can be exported or deleted if the contract ends.

Should procurement teams change supplier onboarding now?
Procurement teams should review supplier onboarding questions now, especially for technology suppliers, AI tools, cloud-hosted platforms and suppliers handling sensitive data. The changes can be proportionate and risk-based rather than applied equally to every supplier.

How can Market Dojo support supplier due diligence?
Market Dojo helps procurement teams standardise supplier questionnaires, collect evidence, compare responses and maintain an audit trail. This helps teams assess cloud, AI and digital supply chain risk more consistently.

 


 

More resourcesDownload the Digitise Procurement Playbook

June 30, 2026
Get A Demo Today