Publication
EU Cloud and AI Development Act
What healthcare and life sciences companies need to know
EU Cloud and AI Development Act
01
Publication
What healthcare and life sciences companies need to know
01
In 2023, France’s data protection authority and its courts reached an uncomfortable conclusion: only Microsoft had the operational capability to run the Health Data Hub, the national repository for tens of millions of French citizens’ health data. France has since switched to Scaleway, a subsidiary of Iliad, but the decision is expensive, technically disruptive and not expected to be completed until later this year or early next. It is also, in microcosm, exactly the problem the Cloud and AI Development Act (“CADA”) is designed to prevent happening again.
Proposed on 3 June 2026 as part of the European Commission’s technological sovereignty package, which also includes the Chips Act 2.0, an Open Source Strategy and an energy digitalisation roadmap, CADA is an ambitious statement of industrial policy intent from the Commission.
For the healthcare and life sciences sector, it presents both an immediate commercial and strategic challenge, and a clear indication of the direction of travel for compliance that would be foolish to ignore. Decisions made today, as to cloud vendors, AI product architecture and M&A, will set the scale of the compliance challenge as the Union continues to turn away from globalisation and towards regionalisation and localisation across its economy.
In the EU, the sector is already coming to terms with a raft of digital regulation: the AI Act classifies AI used in clinical decision support, diagnostics and patient management as high-risk, requiring conformity assessment, technical documentation and post-market monitoring. While the Digital Omnibus on AI, formally endorsed by the Council on 29 June 2026, has deferred the high-risk obligations (to December 2027 for standalone clinical AI systems and August 2028 for AI embedded in medical devices), this is much-needed breathing room, rather than a reprieve. The risk-based architecture is in place and the compliance window is finite.
Alongside the AI Act, NIS2 imposes cybersecurity and incident-reporting obligations on healthcare operators as essential entities, the EU health data space is building a framework for secondary use of health data, and GDPR adequacy and international transfer restrictions remain a live topic.
When enacted, CADA does not replace, simplify or short-cut any of this; it adds a layer on top. The intersection of CADA’s sovereignty requirements with existing obligations under the AI Act and NIS2 creates an additional compliance challenge, one for which the practical implications for private-sector healthcare companies are still being worked out. We expect that early movers – those mapping the interactions to inform strategic decision-making now – will be the best placed as this regime crystallises and evolves.
CADA’s most immediate commercial consequence is the pressure it places on existing and planned cloud arrangements. Three U.S. providers, Microsoft, AWS and Google, currently account for more than 70% of the European cloud market. Healthcare and life sciences companies are among the heaviest users of all three, for everything from clinical trial data management and genomics platforms to drug discovery AI and manufacturing execution systems.
CADA’s assurance levels set out what a cloud provider must demonstrate to serve sensitive workloads. Level 2 requires evidence that third country governments cannot access hosted data or disable services (a direct response to the U.S. CLOUD Act, which gives US authorities the power to compel U.S.-domiciled cloud providers to hand over data anywhere in the world). Level 3 requires that the provider itself is not under third country control, a bar that U.S. hyperscalers will structurally struggle to clear. Level 4 requires full supply chain independence.
CADA’s direct procurement obligations apply to public-sector bodies, including public health systems, national health authorities and agencies such as EMA and ECDC. Mandatory compliance for private entities is not in the current proposal; instead, a voluntary framework allows NIS2-regulated private entities to conduct their own sovereignty impact assessments, with power reserved to the Commission to make this mandatory in future.
The practical pressure on the private sector, however, is more immediate. Companies whose products or services sit in public supply chains can expect to face up to the requirements indirectly, as part of public bodies’ procurement requirements. This means that digital health vendors, CROs and health data processors cannot assume they will be safe; this is not “somebody else’s problem”.
The draft does include a derogation, potentially inspired by the French Health Data Hub, permitting public bodies to use non-compliant providers where no adequate alternative exists. For now, that may buy time. The French switch to Scaleway shows the political direction, though, and the commercial cost of waiting too long to plan the transition.
Cloud and digital services contracts signed today will run into the period when CADA is operative, likely 2028 onwards. Renewal cliffs, termination rights, regulatory change provisions and audit rights should now all be assessed against the direction of travel, ideally, before signatures lock-in structures and commitments that will be expensive to unwind.
CADA makes sovereignty a question for the design stage, rather than a bolt-on. For companies building AI-enabled health products (whether in diagnostics, clinical decision support or pharmacovigilance tools), the cloud infrastructure on which the product runs is now part of its regulatory profile. If that product will be deployed through public health systems, the underlying cloud will need to meet the relevant assurance level, and that means architecture and vendor selection decisions will need to consider the regulatory angle explicitly and up-front.
For health data companies and CROs, the challenge is structural. CADA’s higher assurance levels will require EU-based staff handling relevant workloads and exclude geographies and vendors subject to third country laws compelling access. This is a direct challenge to global delivery models where data processing, sponsor oversight and research staff routinely sit outside the EU.
In both cases, the sovereignty question belongs in the earliest conversations about product design and operating model rather than arriving as a regulatory surprise when a public procurement tender requires it.
For sponsors and strategics, CADA should be a live diligence issue for healthcare IT and digital health assets already. A business built on U.S.-controlled infrastructure serving public hospitals in the EU carries a different risk-profile post-CADA than it does today: either it bears the cost of migrating to sovereignty-compliant infrastructure, or it risks losing access to public-sector customer revenues. Neither outcome is priced in by default.
On the flip side, companies that have anticipated CADA and built on sovereign infrastructure, or at least secured the contractual flexibility to migrate, will be better positioned and likely command a premium. The Open Source Strategy embedded in the broader package adds a further dimension, disrupting incumbents relying on proprietary moats and increasingly favouring open-source tools.
Where relevant, acquirers should be thinking about these risks when evaluating assets, asking relevant DDQs and seeking warranty cover where required (noting that generic compliance with laws warranties are unlikely to cover the as-yet uncrystallised requirements of CADA, given the regulatory process and, as discussed above, focus in the current draft on public sector bodies).
01