EU cloud and AI sovereignty could change how organisations assess suppliers, especially those handling sensitive data or supporting public-sector services. The proposed EU Cloud and AI Development Act, alongside potential public-sector cloud sovereignty requirements, isn’t a blanket ban on US cloud providers. But it signals a shift towards stronger scrutiny of data hosting, supplier ownership, legal jurisdiction, cloud dependencies, AI infrastructure and auditability.
Latest update: The EU Cloud and AI Development Act is still a proposal, not a final regulation. The detailed compliance thresholds, procurement rules and definition of “sovereign cloud” still need to be settled. Procurement teams should treat this as an early warning signal, not a reason to make rushed supplier decisions.
EU cloud and AI sovereignty is the idea that European organisations, especially public-sector bodies, should have greater control over the digital infrastructure, cloud services and AI systems they rely on.
In practical terms, this means looking more closely at
For procurement teams, this turns cloud and AI infrastructure into a supplier risk issue, not just an IT issue.
One important complication is that “sovereign cloud” does not yet have one simple definition. It may cover data location, provider ownership, operational control, exposure to foreign legal orders, resilience, interoperability and, in some cases, performance. Procurement teams should avoid reducing the issue to “EU provider good, non-EU provider bad.” The more useful question is whether the supplier can prove how data is protected, who can access it, which laws apply, and how the organisation can retain control if requirements change.
There are two connected developments procurement leaders should watch.
The EU Cloud and AI Development Act, or CADA, is part of the EU’s wider technology sovereignty agenda. According to the European Commission, the proposal aims to strengthen the EU’s cloud and AI ecosystem, investment and infrastructure.
The Commission’s cloud computing policy page also states that CADA aims to at least triple the EU’s data centre capacity within the next five to seven years and meet the needs of EU businesses and public administrations by 2035.
For procurement, the important point isn’t just the legislation itself but the potential trajectory of this regulation. The EU wants cloud and AI infrastructure to become more resilient, more transparent and less dependent on non-EU providers.
The EU is also considering stronger sovereignty requirements for some cloud services handling sensitive public-sector data.
According to Raconteur’s reporting on proposed EU cloud restrictions, this could affect dominant US cloud providers handling sensitive government data, including financial, health and judicial data.
This isn’t a blanket ban on US cloud providers. It’s also not a direct restriction on private-sector cloud use. However, it may affect how public bodies buy cloud services and how suppliers prove that they meet sovereignty, security and resilience expectations. Similarly, procurement leaders in the private sector should still pay attention, especially if they operate in regulated sectors or supply into government.
| Area | Public sector | Private sector |
| Direct impact | More likely to be directly affected, especially where sensitive government data is involved | Not directly covered by the proposed cloud restrictions, based on current reporting |
| Procurement requirements | May need stronger evidence around sovereignty, jurisdiction, hosting and provider control | May adopt similar checks as best practice, especially in regulated sectors |
| Supplier impact | Technology suppliers may need to prove compliance with sovereignty requirements | Suppliers may face more questions from customers, investors and risk teams |
| Risk focus | Sensitive citizen data, public services, national resilience and legal exposure | Commercial risk, customer data, operational resilience and regulatory confidence |
| Practical action | Update tender questions and supplier assessment criteria | Review high-risk suppliers and add proportionate due diligence questions |
Procurement teams should care because cloud and AI risk increasingly sits inside the supplier base.
A supplier may appear low risk from a commercial perspective, but still rely on infrastructure or technology partners that create hidden exposure. For example, a SaaS provider may use a non-EU cloud provider. An AI tool may process data through third-party models. A supplier management platform may rely on subcontractors for hosting, analytics or support.
These dependencies can affect
This means procurement teams need better visibility over the digital supply chain behind each supplier.
Procurement teams should prioritise suppliers that handle sensitive data, support critical services or rely heavily on cloud and AI infrastructure.
High-priority supplier categories include
Platforms used for procurement, supplier management, analytics, finance, HR, legal, or customer data.
Tools that process prompts, documents, supplier data, contracts, bids or internal business information.
Systems where data hosting, jurisdiction and continuity are important.
Suppliers selling into government or public bodies, where future sovereignty expectations may be stricter.
Suppliers used by organisations in sectors such as healthcare, finance, energy, transport or public services.
Rather than asking every supplier the same long questionnaire, procurement teams should apply due diligence based on supplier risk. A low-risk software provider may only need baseline checks, while suppliers handling sensitive data, AI-enabled processes or public-sector workloads should face deeper questions around infrastructure, jurisdiction, auditability and exit planning.
Here’s an example framework.
These questions are suitable for most technology suppliers.
Use these where the supplier handles sensitive data, supports important processes or relies on cloud and AI infrastructure.
Use these for public-sector contracts, regulated industries, business-critical systems or suppliers handling highly sensitive data.
If a supplier uses AI agents, procurement teams should go beyond standard AI usage questions. For example
You don’t need to overhaul every supplier process immediately, but the key is to start preparing.
Exit planning should also cover practical switching rights, data portability, interoperability and any technical or contractual barriers that could make it difficult to move away from a cloud or AI provider later.
Start with suppliers that handle sensitive data, support critical services, use AI or provide cloud-hosted systems.
Add proportionate questions on cloud hosting, data residency, jurisdiction, subcontractors, AI dependencies and exit plans.
Check whether your organisation supplies into public-sector contracts, or whether key suppliers support public-sector services.
Look beyond the direct supplier. Identify cloud providers, AI systems, subcontractors and fourth parties where possible.
Store supplier responses, documentation, certifications and decisions in a structured way so they can be reviewed or audited later.
Structured sourcing and supplier onboarding software can help procurement teams manage cloud and AI sovereignty questions more consistently.
Market Dojo helps teams
This reduces reliance on scattered emails, spreadsheets and one-off checks. It also gives procurement teams a clearer record of how supplier risk was assessed.
As cloud and AI sovereignty becomes more important, procurement teams will need to show not just who they selected, but why that decision was made and what evidence supported it.
EU cloud and AI sovereignty may sound more relevant to IT or legal, but it’s becoming a practical procurement issue.
The proposed rules don’t mean every organisation needs to stop using US cloud providers. Nor do they directly restrict private-sector cloud use. But they do signal a future where technology suppliers face more scrutiny around data, infrastructure, ownership, jurisdiction and resilience.
For procurement leaders, the best response is preparation. Start with your highest-risk technology suppliers, update your due diligence questions, and make sure supplier evidence is easy to collect, compare and audit.
As a SaaS provider of e-sourcing solutions, Market Dojo’s position is that AI should support procurement teams without compromising trust. Our AI-enabled questionnaire features use Google Cloud Platform (GCP), consistent with the wider infrastructure used across our production environment. Customer data isn’t used to train the foundation models, and information passed to the AI service is encrypted in transit and used only to generate the requested output.
Our wider cloud infrastructure is also supported by Google Cloud, with Market Dojo using GCP data centres in Belgium and the UK. Environmental and physical security, including secure areas, equipment management and data centre controls, is managed by Google Cloud. Market Dojo reviews GCP’s security posture at least once a year through its certifications and compliance programmes, with further information available through Google Cloud’s published security and compliance resources.
As with any AI-enabled tool, users should avoid entering unnecessary confidential information. But our policy is designed around a clear principle: AI should reduce manual work and improve sourcing efficiency while protecting customer information, maintaining strong cloud governance and supporting a responsible approach to data security.
Start by reviewing supplier onboarding and risk questionnaires for technology suppliers, AI tools and cloud-hosted platforms. Focus on hosting location, legal jurisdiction, subcontractors, infrastructure partners, access controls, AI usage, audit trails, data portability and exit plans.
This is where e-sourcing, supplier onboarding and supplier management technology can help. Market Dojo helps procurement teams standardise supplier questionnaires, collect evidence, track responses and maintain a clear audit trail. This gives teams a more consistent way to assess supplier risk, (rather than relying on scattered emails, spreadsheets or one-off checks) and spot risk before it becomes a contractual problem.
Digital sovereignty may sound like a policy issue. For procurement, it’s becoming a practical question of supplier control, resilience and evidence. The teams that act early will be better placed to buy technology with confidence, protect sensitive data, prove why supplier decisions were made, and keep pace as regulations develop.
Does EU cloud sovereignty mean US cloud providers will be banned?
No. The current proposals shouldn’t be treated as a blanket ban on US cloud providers. The focus is on stronger sovereignty requirements for certain sensitive public-sector workloads, not a general ban on private-sector cloud use.
Does this apply to private companies?
Private-sector cloud use isn’t directly covered by the proposed cloud restrictions based on current reporting. However, private companies should be prepared for scrutiny, especially if they operate in regulated sectors, supply into the public sector or handle sensitive data.
What is the EU Cloud and AI Development Act?
The EU Cloud and AI Development Act, or CADA, is a proposed EU initiative designed to strengthen Europe’s cloud, AI and data-centre capabilities. It’s part of a wider effort to reduce dependency on non-EU digital infrastructure and increase European technology resilience.
Is the EU Cloud and AI Development Act already law?
No. The EU Cloud and AI Development Act was proposed in June 2026. The details still need to move through the legislative process, including how “sovereign cloud” will be defined and how public-sector procurement requirements will work in practice. However, the proposal is a strong signal that cloud, AI infrastructure and digital supply chain visibility will face closer scrutiny.
Why is this relevant to procurement?
It’s relevant because many suppliers now depend on cloud platforms, AI tools, subcontractors and digital infrastructure. Procurement teams need to understand these dependencies when assessing supplier risk, especially for suppliers handling sensitive or business-critical data.
What should procurement teams ask SaaS suppliers?
Procurement teams should ask where data is hosted, which cloud providers are used, which jurisdictions apply, whether subcontractors are involved, how data is protected, what audit trails are available and how data can be exported or deleted if the contract ends.
Should procurement teams change supplier onboarding now?
Procurement teams should review supplier onboarding questions now, especially for technology suppliers, AI tools, cloud-hosted platforms and suppliers handling sensitive data. The changes can be proportionate and risk-based rather than applied equally to every supplier.
How can Market Dojo support supplier due diligence?
Market Dojo helps procurement teams standardise supplier questionnaires, collect evidence, compare responses and maintain an audit trail. This helps teams assess cloud, AI and digital supply chain risk more consistently.

June 30, 2026