
Jochen Michels, Director Public Affairs, Europe, Kaspersky
The European Commission has proposed the Cloud and AI Development Act (CADA) to strengthen the EU's cloud and AI ecosystem, investment, and infrastructure. The initiative aims to drive innovation, accelerate public sector capacity-building, and establish a single EU-wide assessment framework for digital sovereignty. CADA complements strategies like the Chips Act 2.0 to ensure a more competitive, secure, and resilient European digital economy. The proposed CADA represents an important opportunity to strengthen Europe’s computing infrastructure, expand sustainable computational capacity, and accelerate the adoption of cloud and artificial intelligence solutions across critical sectors. From the perspective of a global cybersecurity company, these objectives can only be achieved if security, reliability, and trustworthiness are embedded in the future framework. At the same time, CADA should preserve an open market for providers that meet common European requirements and contribute to the EU’s strategic autonomy.
Strengthening Security-by-Design, Continuous Monitoring, and Incident Management
Cloud and AI providers should be required to apply threat-model-driven development methodologies. These should include regular static and dynamic code analysis as well as the consistent implementation of zero-trust principles. Preventive safeguards must be complemented by continuous monitoring. Providers should deploy telemetry capable of identifying anomalous behavior and feeding relevant information into Security Information and Event Management systems. These systems should be interoperable with the EU-wide network of Computer Security Incident Response Teams. Incident classification should align with the NIS2 Directive to avoid overlapping or conflicting reporting regimes. CADA should also support effective threat intelligence sharing. An EU-wide platform building on existing CERT-EU structures could facilitate the rapid exchange of indicators of compromise and information on emerging attack techniques. Collective access to relevant threat intelligence would strengthen the resilience of providers and public institutions alike.
Establishing a Continuous Risk Management Lifecycle
Risk management should not be treated as a one-off assessment. CADA would benefit from a structured lifecycle covering risk identification, assessment, mitigation, and verification. Risk identification should draw on up-to-date threat intelligence so that risk registers reflect emerging threats. Risk assessment should combine established vulnerability scoring methods, such as the Common Vulnerability Scoring System, with AI-specific impact factors. Mitigation should include technical measures such as timely patching, container image signing, and model hardening. It should also encompass organizational measures, including secure-by-design training for development teams. Finally, periodic independent audits and red-team exercises should verify whether the implemented controls work effectively in practice.
Creating a Tiered European Certification Framework
A fragmented landscape of national certification schemes would increase compliance costs and create new barriers within the Digital Single Market. CADA should instead introduce a European Cloud Security Certification based on a common, tiered framework. A Basic tier could apply to non-critical Software as a Service and public-facing Infrastructure as a Service offerings. An Advanced tier could cover mission-critical Platform as a Service offerings and AI model hosting services. A Critical tier could apply to services supporting essential sectors such as healthcare, energy, and transport. Each tier should be linked to progressively more stringent security requirements. These could range from an ISO/IEC 27001 baseline and SBOM publication to full alignment with NIS2 and mandatory independent third-party audits. A complementary AI Model Assurance scheme should evaluate the robustness of AI models against adversarial inputs, the explainability of model decisions, and quantitative bias metrics. Adversarial-attack simulations, bias audits, and model-drift detection should be mandatory before the deployment of AI systems falling under the Advanced or Critical tiers. Existing certifications should be recognized where they provide equivalent assurances.
Combining Strategic Autonomy with Market Openness
The objective of strengthening Europe’s strategic autonomy should be pursued through common and verifiable requirements rather than unnecessary market barriers. A single EU-wide sovereignty framework should assess cloud and AI services against criteria such as data residency and supply-chain security. This would provide a clear benchmark for European sovereign offerings while allowing non-EU providers to participate on equal terms if they satisfy the same standards. A common EU-level procurement framework would also enable public administrations to purchase certified cloud and AI services jointly. This could generate economies of scale while ensuring that successful providers meet the security and sovereignty criteria established under CADA. Open-source solutions can make an additional contribution to resilience through transparent and community-audited code. CADA should require the availability of an SBOM and, where feasible, encourage the publication of source code under an OSI-approved license for components forming the security-critical core of a service.
Translating Europe’s Ambition into Practical Security
CADA can provide the foundation for a secure, sustainable, and competitive European cloud and AI ecosystem. To fulfil this potential, the Act should address supply-chain transparency, secure-by-design development, continuous monitoring, data protection, AI robustness, certification, and the effective allocation of responsibility. A common European framework can strengthen strategic autonomy without closing the market to trusted international partners. Providers that meet transparent and demanding requirements should be able to compete on equal terms, regardless of their geographical origin. By embedding these principles in the regulatory text, CADA can support the rapid deployment of cloud and AI solutions while protecting citizens’ rights, strengthening critical infrastructure, and preserving Europe’s digital competitiveness. Kaspersky has put forward key recommendations through the European Commission's feedback process and stands ready to cooperate with the European Commission, national authorities, industry bodies, and academia in refining the technical provisions of CADA and supporting their practical implementation across the European Union.