Andrii Paziuk (National Aviation University) has posted Procuring Sovereignty: Public Authority under the EU Cloud and AI Act on SSRN. Here is the abstract:
The European Commission’s June 2026 proposal for a Cloud and AI Development Act (CADA) is the Union’s most ambitious attempt to translate digital sovereignty into operative law. This article argues that the proposal is significant but structurally incomplete. CADA builds a sophisticated supply-side framework: cloud providers are classified against graduated Union assurance levels; higher levels depend on third-party assessment; contracting authorities must procure at the level indicated by risk assessment; and the proposal expressly addresses extraterritorial access, service disruption and vendor dependency. Yet the responsible public institution is constituted principally as a purchaser of qualified services, not as an administrator that must remain capable of discharging public-law duties through those services. The article develops this distinction between supplier assurance and retained operational control. It examines the proposal’s cumulative legal basis under Articles 114 and 173(3) TFEU, its accommodation of Article 4(2) TEU, and its reliance on private assurance and adequacy mechanisms. It then shows why Articles 41 and 47 of the Charter expose a demand-side gap concerning reasons, evidence, correction, intervention, continuity and exit. The proposed complement is not a new constitutional settlement, but procurement and governance duties preserving non-delegable public responsibility throughout the lifecycle of digitally mediated public functions.
Recommended!
To receive new posts from Legal Theory Blog by email, get a free subscription to Legal Theory Stack.
Lawrence Solum
