The Cloud and AI Development Act and FIDA: What CADA Article 18 Means for FDSS and FISP Cloud Infrastructure
- Julius Šakalys
- Jul 17
- 4 min read
The Cloud and AI Development Act (CADA, COM(2026) 502) was adopted by the European Commission on June 3, 2026. It establishes four Union assurance levels for cloud infrastructure used to process sensitive EU data. For FIDA infrastructure builders — specifically FDSS operators and FISPs — CADA Article 18 introduces cloud sovereignty obligations that run in parallel with FIDA's data-sharing requirements. This article explains what CADA is, what Article 18 requires, and how it intersects with FIDA compliance infrastructure design.
What Is the Cloud and AI Development Act (CADA)?
CADA is a European Commission proposal (COM(2026) 502) adopted June 3, 2026. It is currently at an early interinstitutional legislative stage — no EP rapporteur assigned as of July 2026, no Council working party pickup confirmed. Estimated legislative timeline: 18–24 months from adoption, placing entry into force in approximately late 2027 to mid-2028.
CADA's core mechanism is a four-tier Union assurance framework for cloud providers processing sensitive data:
Level 1: All public sector cloud processing — basic baseline requirements
Level 2: Elevated risk public sector data — security certifications required
Level 3: High-sensitivity data in NIS2-critical sectors — legal and technical separation from non-EU entities required
Level 4: Most sensitive data (defence, critical infrastructure) — highest sovereignty requirements, source code audits, SBOM requirements
The regulation is designed to reduce EU dependency on non-EU cloud providers for sensitive state and regulated sector data. US hyperscalers (AWS, Azure, GCP) face the most significant obligations under Levels 3/4.
What Is CADA Article 18?
Article 18 covers the technical and legal sovereignty requirements that cloud providers must meet to process data classified at Level 3 or Level 4. Key requirements at Level 3/4 include:
Legal separation: EU-based entities of non-EU cloud providers must be legally separated from their parent companies with respect to data access
Technical separation: Data processing infrastructure must be operated independently, without remote access from non-EU parent entities
Source code audits: Independent audits of cloud infrastructure code for Level 4
Software Bill of Materials (SBOM): Full component disclosure for critical workloads
Certifiable under EUCS Level High (or equivalent)
The crucial question for FIDA infrastructure teams is: which assurance level applies to FDSS and FISP cloud infrastructure?
Where Does FIDA Intersect with CADA?
FIDA requires Data Holders (banks, insurers, investment firms, pension funds) to share customer financial data via Financial Data Sharing Schemes (FDSS). FISPs (Financial Information Service Providers) access this data via certified APIs. Both FDSS operators and FISPs process sensitive, personal financial data at scale.
Financial services entities are already classified as critical or important entities under DORA and NIS2. If CADA adopts a risk-based classification that maps to DORA/NIS2 criticality designations, FDSS and FISP infrastructure could trigger Level 2–3 requirements. Data processed by FDSS operators includes:
Payment account data (PSD3/PSR scope)
Investment and insurance portfolio data (FIDA scope)
Pension fund data (FIDA scope)
Customer consent and permission records
The sensitivity profile of this data — personal financial data of EU consumers processed in real-time at scale — places FDSS/FISP infrastructure in a risk category that may attract Level 3 obligations under CADA's eventual classification framework.
The practical implication: if FDSS operators and FISPs are required to meet CADA Level 3, this constrains cloud vendor choice. US hyperscalers at Level 3 must demonstrate legal and technical separation from their US parent entities — a requirement that, in practice, many cannot currently meet without significant structural changes. EU-sovereign cloud providers (OVHcloud, Deutsche Telekom T-Systems, IONOS, Hetzner) or sovereign cloud offerings from US hyperscalers (Microsoft Azure Sovereign, etc.) become the compliant baseline.
Timeline: When Do CADA and FIDA Converge?
CADA was adopted by the European Commission on June 3, 2026, with no EP rapporteur assigned and an estimated 18–24 month legislative timeline — placing entry into force at approximately late 2027 to mid-2028. FIDA is currently in trilogue under the Irish Presidency (H2 2026); if agreement is reached in H2 2026, data holder obligations would apply from approximately H2 2028.
CADA and FIDA obligations converge in the 2028–2029 window. Infrastructure builders designing FIDA-compliant FDSS and FISP architecture today should account for CADA Level requirements in their cloud vendor selection and infrastructure design — not as a future retrofit, but as an architectural input now.
What Should FDSS Operators and FISPs Do Now?
Map your cloud infrastructure against CADA's assurance level framework — even though CADA is not yet in force, the classification logic is already visible in the proposal text. Identify where your FDSS/FISP processing would sit.
Audit vendor contracts for sovereignty compliance gaps — review MSA terms with current cloud vendors for data access provisions, cross-border transfer clauses, and parent company access rights.
Design FIDA compliance infrastructure with cloud sovereignty as a constraint, not an afterthought — organisations that retrofit cloud sovereignty requirements onto existing FIDA infrastructure will pay significantly more than those that build for both from the outset.
Monitor CADA's legislative progress — EP rapporteur assignment and first Council working party sessions will clarify which sectors face which assurance levels. This is the critical legislative intelligence signal.
CADA is not yet law. FIDA is not yet agreed. But both arrive in the same infrastructure window — and they share the same organisations as their compliance subjects. FDSS operators and FISPs that design their cloud infrastructure for CADA Level 3 compliance now will not be facing a double rebuild in 2028.
The regulation can take 18 months to pass. The infrastructure decisions are being made today.