§ 01 Procurement · Overview
What a contracting authority can lawfully require of an AI compute supplier today, what changes if the Cloud and AI Development Act passes, and where we honestly stand as a bidder.
§ 02 Answer · Direct
Before the instruments, the thing most tender documents get wrong.
You almost certainly cannot require that a supplier be European. For procurement covered by the WTO Government Procurement Agreement, equal treatment cuts against nationality preferences, and a tender that says “EU suppliers only” is the kind of thing that gets challenged and lost.
What you can do is require the things you actually care about, which are not nationality at all. Where the data sits. Which law reaches the operator. Who the sub-processors are. Whether you can export your weights and your logs when the contract ends. Every one of those is a technical or security requirement, every one is scoreable, and together they get you most of what “sovereign” was shorthand for.
This distinction is about to get institutional support. The Commission's proposed Cloud and AI Development Act would put a four-level sovereignty assurance framework behind exactly these questions, so that a contracting authority can point at a level instead of drafting the criteria from scratch.
This page is a reading of published instruments and proposals, not legal advice. Your own counsel and your national transposition govern.
§ 03 Rulebook · In force
Five instruments, and what each one actually gives a buyer of AI compute.
| Instrument | Reference | Bearing on the tender |
|---|---|---|
| Public Procurement Directive | Directive 2014/24/EU | Sets the procedures and the equal-treatment duty. Technical specifications may not name a make or origin without an “or equivalent” escape, so a sovereignty goal has to be written as a requirement, never as a brand or a nationality. |
| EU AI Act | Regulation (EU) 2024/1689, Art. 27 | A body governed by public law deploying an Annex III high-risk system must complete a fundamental rights impact assessment before first use, notify the market surveillance authority, and register it. This is a duty on you as deployer, not on your supplier. |
| GDPR | Regulation (EU) 2016/679, Art. 28, 44–49 | The processor terms and the transfer basis are contract clauses you set. If the tender does not require a named sub-processor list, you will not get one. |
| NIS2 | Directive (EU) 2022/2555, Art. 21(2)(d) | Public administration entities in scope must manage supply-chain security, which is the lawful hook for asking about a supplier's own dependencies rather than its passport. |
| Data Act | Regulation (EU) 2023/2854 | Switching and egress rights for cloud services. Worth restating as a contract term so exit is priced at procurement rather than at renewal. |
Note the direction of travel on the AI Act. Article 27 is a duty on you as the deployer, not something a supplier can discharge on your behalf, and it is separate from the provider's conformity assessment under Article 43. A bidder offering to “handle your AI Act compliance” is describing something that is not theirs to handle.
§ 04 CADA · Proposed
From the impact assessment accompanying the Cloud and AI Development Act. A proposal in the ordinary legislative procedure — not law, and the detail can still move.
| Level | How it is verified | Expected share of public use cases | What it means |
|---|---|---|---|
| Level 1 | Provider self-assessment | ≈70% | The baseline tier. SMEs are not required to pass national competent authority validation at this level. |
| Level 2 | Third-party audit, verified by a national competent authority | ≈20% | Broadly the tier France's SecNumCloud providers would land in on the impact assessment's own comparison. |
| Level 3 | Third-party audit, verified by a national competent authority | ≈9% | Can only be served by a provider owned and controlled by an EU entity. |
| Level 4 | Third-party audit, verified by a national competent authority | ≈1% | Ten cumulative criteria, including EU establishment of provider and subcontractors, EU-national personnel, no third-country data reuse, demonstrable control of the software stack, and EUCS certification at level “high”. |
Two details matter more than the tiering itself. First, the shares: on the Commission's own working estimate, roughly seven in ten public use cases would sit at level 1 and only one in a hundred at level 4. If your tender demands the top tier for a helpdesk summariser, you are shrinking your bidder pool for no risk reduction.
Second, level 4 requires EUCS certification at level “high” — and EUCS does not exist. ENISA has been developing it since 2019, the sovereignty requirement was stripped out of the March 2024 draft, and the scheme is still unadopted. The proposal resolves that by moving sovereignty into CADA and leaving EUCS as a technical cybersecurity certification, with the revised Cybersecurity Act as the vehicle to finish it. Until both land, the top tier is unreachable by anyone.
Source: SWD(2026) 502 final, 3 June 2026, accompanying COM(2026) 502 final.
§ 05 Criteria · Wording
Four requirements you can score today, and one you should not write.
| Requirement | Why it holds, or does not |
|---|---|
| Where will the data physically sit, and under whose law does the operator fall? | A performance and security requirement. Lawful, and answerable with evidence. |
| Name every sub-processor and every jurisdiction in the request path. | A GDPR Art. 28 disclosure requirement. Lawful, and it is where most bids get uncomfortable. |
| Demonstrate that no third-country authority can compel disclosure without notice. | A risk question about applicable law. Lawful. Note it is a question about legal exposure, not about the supplier's flag. |
| Produce the audit trail and export the weights and logs on demand. | An operability and exit requirement, reinforced by the Data Act. Lawful and easy to score. |
| Only EU-headquartered suppliers may bid. | Not lawful as a general rule for GPA-covered procurement. Express the underlying concern as a security requirement instead, which is exactly what the CADA levels are designed to standardise. |
If CADA passes in its more assertive form, contracting authorities buying services where the EU has been assessed as dependent would have to apply a set of non-price award criteria rewarding EU supply-chain contribution, uptake of EU-funded research, innovation performed in the Union, and hardware designed or manufactured in the Union. That last one is a hardware-origin criterion arriving in procurement law, which is worth watching if your compute strategy assumes the current vendor landscape is permanent.
§ 06 Standing · As a bidder
A procurement page that does not disclose the supplier's own gaps is a brochure. Here are ours.
| Item | Status | Detail |
|---|---|---|
| Public-sector contract awarded | None | We hold no public contract in any Member State and are not listed on any framework agreement or dynamic purchasing system. |
| EUCS certification | Not held — and not holdable | The scheme has been in development at ENISA since 2019 and is still not adopted. Nobody holds an EUCS certificate today, so no bidder can truthfully claim one. |
| CADA sovereignty level | Not assessed | CADA is a Commission proposal. No competent authority has been designated and no audit route exists, so no provider has a level. |
| Cyprus campus capacity | Pre-construction | Vasilikos is not built. Nothing can be delivered from it against a contract signed today. |
| Copperway gateway | Live software | An OpenAI-compatible EU gateway with a PII vault in the request path. This is the only thing on this page you could actually put into a pilot this quarter. |
| Reserved future capacity | Pre-construction instrument | An SRA reservation is a letter of intent against capacity that does not exist yet. It is a procurement of an option, and should be evaluated as one. |
The useful conclusion for a buyer is narrow and we would rather say it plainly: there is nothing here to award a capacity contract to yet. What there is, is a live gateway you can pilot, a reservation instrument if you are planning past construction, and a reading of the rules that we think is more accurate than most of what the market is currently telling you.
§ 07 Questions · FAQ
The questions contracting authorities actually ask us.
§ 08 Start · Talk to us
If you are drafting sovereignty criteria for an AI compute tender, we will read your draft and tell you which requirements we could evidence and which we could not. The second list is usually the useful one.