Showing posts with label planning permission. Show all posts
Showing posts with label planning permission. Show all posts

Friday, 31 July 2026

The effectiveness of the Cloud and AI Development Act regarding data centres


 


Annelieke Mooij, Assistant Professor, Tilburg Law School

Photo: Facebook Clonee (Ireland) data centre

Photo credit: Thomas Nugent, via Wikimedia commons

 

1.    Introduction

The debate about sovereignty and specifically digital sovereignty is fierce. Member States, struggle to achieve digital sovereignty which impacts the continuity and safety of the digital services. To speed up the realization of the sovereign cloud the Commission has proposed a new act the Cloud and AI Development Act (CADA). The act covers three important facets: AI, Cloud and Data centres. This contribution is limited to the proposed rules regarding data centres and analyze their effectiveness. The proposed Regulation should not be considered a stand-alone Regulation but rather forms part of the European Union’s broader strategy to strengthen digital sovereignty. The EU aims to reduce dependence on foreign digital service providers and expand Europe’s cloud and data centre capacity. At its core, the proposed Regulation seeks to create the conditions necessary for a sovereign European cloud ecosystem. A system that can support economic growth, innovation, and public-sector resilience.

The pursuit of cloud sovereignty, however, depends on more than software, governance frameworks, or industrial policy. Cloud services, AI and other digital services ultimately rely on physical infrastructure. Data centres provide storage, computing power, and connectivity upon which cloud services and AI applications depend. Without sufficient data centre capacity, ambitions for European technological autonomy cannot be achieved. The Commission aims to stimulate the increase of the data centre capacity through the CADA. The CADA therefore introduces a regulatory framework aimed at accelerating the development of data centres.  The Commission aims for the EU capacity to have tripled by 2030, and by 2035, all critical infrastructure will be hosted in EU data centres. These objectives are ambitious but there are good reasons for the Commission to emphasize digital sovereignty.

2. Why Digital Sovereignty Is Necessary & Difficult

Before delving into the CADA, it is important to understand why digital sovereignty is important to the EU. Cloud computing provides its users with remote access to data storage, software, and computing resources hosted on external servers. By outsourcing storage and computing functions to the cloud, organizations can reduce the need to maintain their own IT infrastructure. Whilst benefiting from greater scalability and operational flexibility. Public authorities increasingly rely on cloud services for precisely these reasons.

At present, however, the European cloud market is heavily concentrated. American providers dominate the sector, with Amazon Web Services and Microsoft accounting for approximately 75% of the European market. The largest European provider holds only a marginal 2% share. This concentration creates a structural dependency on foreign companies for critical digital infrastructure. One of the principal objectives of CADA is therefore to reduce this dependency and strengthen Europe’s technological autonomy.

The strategic rationale for reducing dependence on non-European providers extends beyond concerns about market concentration. Control over cloud infrastructure increasingly translates into geopolitical influence. A recent example is that of the latest AI-model created by Anthropic. The US government prohibited Anthropic from releasing its newest and most powerful model to its European customers. The official reason was due to considered possibilities of jailbreaks. The possibility of this happening was strongly denied by Anthropic. The EU Commission, however, stressed the possible negative impact on EU cybersecurity and cyberdefense.  It has been illustrative of how the US can cut-off new technologies to the EU, without serious repercussions. These incidents have not remained limited to simply limiting foreign accessibility but also to demonstrate power to individuals and institutions. Illustrative of this is the disruption of e-mail communications involving the International Criminal Court. The ICC’s email was cut-off after President Trump disagreed with actions from its main prosecutor. The case illustrated how political pressure exerted through private technology providers, without court permission, may affect the continuity of essential digital services. This dependence can be dangerous for Europe as it includes technology that is necessary for military purposes.

To achieve the desired increased EU cloud and AI capacity, physical infrastructure (or hardware) is necessary. Cloud and AI systems require data centres to operate on. The CADA therefore introduces a framework to create the necessary infrastructure.

3. The CADA’s rules on achieving data centre capacity.  

3.1. Specific Objectives

The CADA seeks to establish what the Commission describes as a coordinated and integrated ecosystem approach to cloud computing and artificial intelligence. According to the Commission, divergent national approaches to data centre permitting barriers to the efficient functioning of the internal market and hinder the development of a competitive European cloud ecosystem.

Against this background, the Regulation aims to create the conditions necessary for the large-scale deployment of cloud and AI infrastructure throughout the Union. In addition to reducing regulatory fragmentation, the proposal seeks to strengthen technological sovereignty, improve operational resilience, and support public-order objectives. The Commission further presents the Regulation as an instrument for promoting innovation and sustainability in Europe's digital infrastructure.

Regarding data centres specifically, the proposal seeks to address perceived shortages in computing and storage capacity through a combination of harmonisation measures and accelerated deployment procedures. This should lead to a specific result namely; triple the data centre capacity by 2030 and have sufficient EU data centre capacity for critical infrastructure by 2035.

3.2 Role of the Commission

The responsibility for achieving the operational objectives established by the CADA rests primarily with the European Commission. To achieve its goals, the proposal relies heavily on existing and future funding programmes intended to stimulate the development of cloud and AI technologies. These programmes seek, among other things, to improve the efficiency with which computing resources are used.

Particular emphasis is placed on technological innovation. High Performance Computing (HPC), for example, may increase the amount of computing output generated from a given level of infrastructure. More efficient use of computing resources can reduce the relative amount of storage and processing capacity required to achieve a particular outcome. Nevertheless, such efficiency gains do not eliminate the need for physical infrastructure. High-performance computing still depends on data centres and therefore remains subject to the same underlying constraints relating to energy, water, and spatial planning.

The effectiveness of this strategy consequently depends largely on the success of research and innovation projects supported through European funding programmes. There is ample reason to believe these strategies can be successful, economic literature has long recognised that research subsidies can stimulate innovation by reducing investment costs and encouraging experimentation. The chance of success, however, depends on the knowledge of the subsidy provider. In the past EU subsidies have proven a successful strategy. It is to be expected that the aim of development through subsidies will be successful again.

3.3. Data centre Acceleration Zones

To facilitate the expansion of data centre capacity, the CADA introduces so-called Data Centre Acceleration Areas (article 10). Each Member State is required to designate at least one such area for the accelerated development of data centre infrastructure, within six months of the Regulation entering into force.

When identifying acceleration areas, Member States must consider existing and future infrastructure capacity, energy availability, and broader sustainability considerations. The proposal further requires national authorities responsible for spatial planning to consider future data centre development and the necessary supporting infrastructure in those zones.

A developer wishing to develop a data centre in such an acceleration zone, will have the right to be assisted by a single point of information (article 11). This single point of information can assist the developer by sharing and coordinating the necessary permits and environmental and habitat assessments. The latter will be a sped-up procedure in accordance with Regulation 2026/XXXX on speeding-up environmental assessments. This Regulation was proposed in December 2025 with the aim to simplify environmental assessments. These rules aim to ensure that new projects have completed the permitting procedures within a year. The latter is the maximum that permitting procedures are allowed to last.

Taken together, these measures are intended to reduce administrative burdens and increase legal certainty for developers. The underlying assumption is that lengthy and fragmented permitting procedures constitute a significant obstacle to data centre deployment. To the extent that regulatory complexity delays investment, the proposed measures may indeed facilitate development. It is, however, questionable whether regulatory procedures are the primary challenge. The extent to which these objectives can be achieved in practice is, however, less clear. The realization of data centres come with significant challenges. When in operation, data centres become increasingly hot. With temperatures rising to 70 degrees in an hour. To continue their operations data centres need to cool. The cooling process requires high amounts of energy and clean water. E.g. data centres in the Netherlands constituted for approximately 5% of electricity demand in 2024. Recently a data centre by Microsoft made headlines that it uses 1% of the total national energy in the Netherlands. This whilst on the other hand there are significant shortages in energy supply for new housing and net congestion is increasing. Thereby creating serious debates on whether power should be diverted to data centres. On an EU level the targets for energy consumption are not yet met. The reduction target is approximately 18% away from its 2030 target. In 2024 the EU was 17% from renewable energy targets for 2030. In 2024 data centres consumed roughly 3% of the EU’s energy. Tripling this number and increasing it further till there is sufficient capacity for digital sovereignty creates a significant challenge.

These concerns are not limited to energy, the Netherlands is estimated to have a drinking water shortage by 2030. This whilst the data centres require approximately 3.7 million tonnes of drinking water per year, roughly 0.3% of Dutch tap water consumption, in the EU it is estimated to total 5.747.764.000 (nearly 6 billion liters). The CADA does not provide solutions to these underlying constraints. Instead, it requires Member States to create data centre acceleration zones and take infrastructure into account when designating these zones. Within these zones permitting procedures must be conducted within 12 months. While this may improve planning and coordination, it does not generate additional electricity capacity, alleviate network congestion, or increase the availability of water resources. The permits may become a hollow factor. A good example of the potential irony is that of the data centre in the Netherlands. The data centre had the required planning permits but were put on a waiting list for their energy connection.

The requirements created by the CADA may seem with a large margin of discretion as it uses language such as “take into consideration”. This language does not exert pressure on Member States. The CADA, however, also includes the earlier mentioned hard objective to triple the data centre capacity by 2030. Here lies another difficulty with the proposed framework. The CADA does not introduce a division key for how much capacity must be realized by each individual Member State. There are, however, big gaps between Member States in the current capacity.

Hungary for example only has 7.3MW of total capacity whereas Germany has 2.6GW of IT power. Arguably the capacity can be divided equally over all Member States, using the GDP as percentage divider. GDP is an indication of how much IT power is consumed in the economy. Generally, the higher the GDP the higher the IT consumption is. There is, however, little data on the demand for critical infrastructure in the EU. This is likely to change as article 15 of the CADA charges the EU Commission with obtaining that data. From an environmental perspective it is, however, ineffective to simply divide along GDP. Countries with cold climates and large coastal areas can build new more efficient data centres as the can use ocean water or outside air to cool. A submerged data centre on the coast is more sustainable than a data centre in a desert. In theory, the incentive to build data centre capacity by these countries is profit. Countries with favorable circumstances can build capacity cheaper than others and sell the capacity for profit. This theory of absolute advantage seems undermined by the next section of the CADA; the introduction of the European Cloud Federation.

 

4. The European Cloud Federation

In addition to measures aimed at expanding data centre capacity, in articles 34 and 35 the CADA introduces the proposed EuroCloud Federation. Participation in the Federation is voluntary and open to EU institutions and public-sector bodies. The purpose of the Federation is to facilitate the sharing of public cloud and data centre resources among participating members.

The underlying rationale is straightforward. Public authorities do not always utilize their available computing resources at full capacity. By enabling participating organisations to share infrastructure, the Federation seeks to improve the utilisation of existing resources and reduce unnecessary duplication of investments. In principle, such an approach may contribute to a more efficient use of public infrastructure.

To facilitate this objective, the proposal establishes a framework governing access to and sharing of infrastructure within the Federation. A notable feature of this framework is the limitation placed on financial compensation. Under Article 35(5), members providing infrastructure may recover their costs but are not permitted to generate profit from sharing their capacity with other participants.

From the perspective of short-term efficiency, this approach is understandable. Allowing access at cost price reduces barriers for participating entities and may encourage greater use of available infrastructure. The arrangement may therefore improve the allocation of existing capacity within the public sector.

The longer-term effects are less clear. The development of additional infrastructure requires significant investment and involves financial and operational risks. Where providers are unable to obtain any return beyond cost recovery, but cost recovery is not guaranteed, the incentive to create surplus capacity that can later be shared within the Federation may be reduced. Public entities may conclude that it is more attractive to rely on the capacity of other participants than to invest in additional infrastructure themselves.

 

5. Conclusion: a failed attempt?

The aim of the CADA is to increase the total EU data centre capacity. The CADA, however, does not create a division key. This is a fundamental gap within the regulation, it is too easy to state that all Member States should triple their data centre capacity equally. At present there are high differences in capacity between the different Member States.

The proposed Cloud and AI Development Act represents an ambitious attempt to strengthen European digital sovereignty through the expansion of cloud and AI infrastructure. Central to this ambition is the objective of significantly increasing data centre capacity across the European Union. To facilitate this development, the Regulation requires Member States to designate acceleration areas, develop national cloud and AI strategies, and participate in a broader framework intended to support the growth of sovereign digital infrastructure.

The proposal therefore sends a clear political signal. Data centres are no longer regarded as purely commercial infrastructure but as strategic assets that are essential for economic competitiveness, public administration, and technological autonomy. In that respect, the CADA forms part of a broader shift in European policy towards reducing strategic dependencies in critical digital technologies. Nevertheless, the CADA does not solve issues regarding natural resources. The introduction of the EU Cloud Federation furthermore has the potential to undermine a sustainable and economically efficient capacity division.