Skip to content
You can now search across every topic, entity and event.What's new
Russia-Ukraine War 2026
3AUG

CAIDA leak: US clouds barred from EU public data

3 min read
10:16UTC

CNBC reported on Thursday 7 May 2026, and gHacks confirmed on Tuesday 12 May, that CAIDA's leaked scope bars Microsoft, AWS and Google Cloud from processing financial, judicial and health data on behalf of EU public-sector clients. Private-sector procurement is excluded entirely.

ConflictDeveloping
Key takeaway

CAIDA as leaked is a public-sector procurement rule; the enterprise cloud market it covers represents the smaller share.

CNBC reported on Thursday 7 May 2026, and Germany's gHacks confirmed on Tuesday 12 May, that the Cloud and AI Development Act's leaked scope will bar US cloud providers from processing financial, judicial and health data on behalf of European Union public-sector clients 1. CNBC's reporting names three targeted hyperscalers: Microsoft, Amazon Web Services (AWS) and Google Cloud. The leaked outline excludes private-sector procurement entirely.

The public-sector-only scope means roughly 70 per cent of EU cloud revenue, the enterprise market the three hyperscalers dominate, sits outside the restriction. Ministries, regulators and other public-sector buyers face the procurement floor; enterprises remain free to keep AWS, Azure and Google Cloud. The shape of CAIDA as leaked is therefore a contracting rule for the slice of the market Brussels directly controls, not a competition rule that reshapes the European cloud market at large.

The leaked outline does not address the status of S3NS, the Thales-Google joint venture rated at the second tier on the Commission's Sovereignty European Assurance Level scale (SEAL-2), which sits inside the Commission's existing €180m sovereign-cloud framework . S3NS's continued eligibility under CAIDA is the file's most-watched detail at adoption. CISPE (the Cloud Infrastructure Services Providers in Europe trade body) shipped a rival pass-fail badge in April ; whether CAIDA inherits the multi-tier SEAL approach, adopts the CISPE binary, or introduces a third framework will signal whether Brussels is repeating its own April compromise or correcting for it. Neither the CAIDA text nor a leaked draft has been published; the scope is sourced from Commission officials speaking to CNBC, not from a circulated document.

Deep Analysis

In plain English

Imagine the EU government saying: 'US companies can no longer store our courts' records, hospitals' patient data, or tax information on their servers.' That is roughly what CAIDA does, but only for government agencies, not private companies. For context, about 70 per cent of cloud services used in Europe are supplied by three US companies; Microsoft, Amazon, and Google. CAIDA affects only the government slice of that market. European cloud providers like Scaleway and OVHcloud stand to win public-sector contracts when governments switch suppliers.

Deep Analysis
Root Causes

The public-sector-only scope reflects a structural constraint in EU trade law: the EU-US Trade and Technology Council framework, reaffirmed in 2025, contains a mutual commitment against 'unjustified' digital trade barriers. A restriction on private enterprise cloud services would fall directly within the USTR Section 301 criteria that triggered a parallel investigation into French digital services taxes in 2020, and Commission legal advisers would have flagged that risk as deal-breaking.

A secondary driver is the GAIA-X governance failure: the GAIA-X project, designed to provide a European multi-cloud framework applicable to both public and private sectors, produced a certification hierarchy without a private-sector mandate attached. CAIDA fills the public-sector gap that GAIA-X's voluntary model could not close.

What could happen next?
  • Consequence

    CAIDA adoption forces EU member states to develop European cloud procurement criteria for financial, judicial, and health data contracts; the first affected renewals are likely to arise in 2027-2028.

    Short term · 0.75
  • Risk

    The USTR Section 301 final determination, due 24 July 2026 (ID:3073), may classify CAIDA's public-sector cloud restriction as a digital trade barrier warranting retaliatory tariffs on EU goods, creating a Brussels-Washington standoff in the same week as the DMA Google decision.

    Immediate · 0.55
  • Precedent

    The S3NS SEAL-2 carve-out question — whether a Google-joint-venture product qualifies under CAIDA's public-sector ban — will establish whether sovereignty certifications can be used to launder US CLOUD Act exposure.

    Short term · 0.7
First Reported In

Update #5 · Brussels' 27 May package, two days before G7

gHacks· 17 May 2026
Read original
Causes and effects
This Event
CAIDA leak: US clouds barred from EU public data
The leak sets a procurement floor on US hyperscalers rather than a market transformation; roughly 70 per cent of EU cloud revenue sits outside the restriction.
Different Perspectives
Belarus
Belarus
Minsk announced completion of its own 37th Separate Airborne Assault Brigade near Gomel, under plans dating to August 2025 rather than a response to any single frontline event this window, keeping its hedge of hosting the war without formally joining Russia's mobilisation drive.
European Union / Operation IRINI states
European Union / Operation IRINI states
Italy, Greece and Poland boarded the sanctioned tanker Toa Payoh off Pantelleria under a standing EU mandate rather than a national decision, extending enforcement from the Channel and Baltic and the Black Sea and Azov into the Mediterranean. Italian Defence Minister Guido Crosetto praised the crew; the captain's refusal to produce documentation left detention unconfirmed.
Poland and the NATO eastern flank
Poland and the NATO eastern flank
Warsaw's Coordination Team said explicitly its forces tracked the 30 July missile incursion and were ready to shoot it down, then flew air cover for an EU tanker interdiction three days later. Poland is simultaneously the war's nearest spillover victim and a contributor to enforcing sanctions against the state causing that spillover.
Ukraine (government, defence establishment and civilians)
Ukraine (government, defence establishment and civilians)
Kyiv runs its manpower crisis through acting Defence Minister Yevhen Khmara, whose formal appointment waits for parliament's 18 August return, and a fortnight-old Commander-in-Chief, Mykhailo Drapatyi. Reported attacks on enlistment officers rose from 5 cases in 2022 to 341 in 2025, reaching Odesa's Territorial Recruitment Centre staff directly on 2 August.
Kremlin and Russian domestic economic voices
Kremlin and Russian domestic economic voices
Moscow has not addressed July's advance-rate collapse or Sberbank's OFZ warning; Novak's diary ran to OPEC+ quota diplomacy with no diesel item logged since 15 July. Economist Nikolai Korzhenevsky calls the Central Bank's RUB 2.3tn in bank lending effectively deficit monetisation, a framing Sberbank's Skvortsov, with his own institutional interest, has not disputed.
IAEA (Rafael Grossi)
IAEA (Rafael Grossi)
IAEA inspectors logged Zaporizhzhia's 22nd loss of off-site power, ten of them in the last three months, after a thunderstorm knocked out the plant's sole surviving backup line. Grossi reads the accelerating frequency, not any single outage, as the safety signal now that the plant's redundancy is exhausted.