Bull's position on the Cloud and AI Development Act and the EU Open Source Strategy
Europe spends an estimated €264 billion a year on digital products and services bought from outside the EU, while its three million open source contributors generate value that too often ends up captured elsewhere. Those two figures explain why technological sovereignty has moved back to the top of Brussels' agenda, through the European Tech Sovereignty Package.
The Communication behind the package defines sovereignty clearly: the ability to develop, control and scale critical technologies at every step of the supply chain, building towards a full European technology stack, grounded in openness and fair competition rather than protectionism. Within this package, two instruments matter most for AI: the Cloud and AI Development Act (CADA) and the EU Open Source Strategy.
CADA does three things. It funds research and development for next-generation cloud and AI technologies. It aims to remove the barriers standing in the way of tripling Europe's data centre capacity. And, most notably, it introduces four Union Assurance Levels, which is a graded and criteria-based way of measuring how exposed a provider is to foreign control or coercion, judged on control rather than nationality. That's a genuine advance: it lets sovereignty be assessed rather than being claimed.
The Open Source Strategy approaches the problem from a different angle, aiming to boost adoption of open source, build a stronger European ecosystem, support public administrations, and promote European open source internationally. Its diagnosis is that European contributors do the work, and non-European companies too often capture the commercial value.
Both instruments embed the right principles. However, as a European AI-infrastructure operator working across hardware, systems, cloud, platforms and models, our view is that both currently apply those principles at the wrong point in the AI value chain.
How AI is actually built
Our position rests on a simple observation from our experience delivering AI infrastructure: an organisation doesn't buy "AI" from a cloud provider. It assembles a stack, layer by layer. That stack runs, bottom to top, through AI hardware, AI systems, cloud or on-premises infrastructure, data and AI platforms, AI models, and finally the use-case solutions people actually adopt.
Most of the real dependency on foreign suppliers, and most of the intellectual property that matters, sits above and below the cloud layer. The cloud is rather the delivery pipe and not where most of the risk or opportunity lives.
Extend CADA's assurance across the whole stack
CADA's assurance levels are well designed, control-based rather than origin-based. The problem is what they are applied to. As drafted, CADA binds its levels to cloud computing service providers alone. The AI system and the model running on it are explicitly excluded. AI hardware sits outside scope entirely, even at the highest assurance level. Not one CADA performance indicator tracks dependency reduction at the hardware, software or model layers. In practice, CADA reads more as a cloud sovereignty framework.
The consequence is that a cloud operator can be fully recognised while running on foreign servers and third-party models. This shows up in two separate ways. The first is about scope: the layers where AI capability and dependency actually concentrate, hardware, systems, platforms, models, simply sit outside the framework. A cloud provider can be fully certified while running on foreign servers and foreign models, because the framework never asks the question. The second is about the unit of assessment: certification covers the whole cloud package rather than its individual parts. So even within the layer that CADA covers, the companies that often own the most valuable intellectual property, a hardware or model vendor, can't be certified on their own. They can only piggyback on a cloud provider's certificate, which puts them in a weaker commercial position than the companies whose business is simply hosting.
We propose extending the reach of the existing levels rather than rewriting them:
-
Apply the assurance levels to hardware, systems, cloud, on-premises deployments, platforms and models alike. Most of the existing criteria transfer across with little change. A handful of cloud-specific ones need adapting to each layer.
-
Let individual vendors, whether they build chips, models or platforms, be assessed and certified in their own right, rather than only ever appearing inside a cloud provider's certificate.
-
Score sovereignty cumulatively. Rather than an all-or-nothing bundle grade, assess each component and add the results up, weighted by how critical each one is. That way, a company that has made real progress on some layers but not others gets credit for it, instead of being treated the same as a company that has made none.
-
Add hardware, software and model dependency reduction to CADA's official success indicators, alongside the existing cloud capacity numbers, so the framework can actually tell whether Europe is becoming less dependent where it matters most.
Treat AI software as its own category in the Open Source Strategy
The Open Source Strategy's diagnosis is correct. European developers do much of the open source work, but non-European companies often capture the commercial value it creates. Where it falls short for AI specifically is that it tends to reward the open licence rather than the outcome. Funding an unbacked open source project, or expecting a public body to build and maintain a fast-moving AI stack in-house, rarely makes Europe more sovereign in practice. There is often a risk to hand the commercial opportunity to whichever company, usually non-European, to turn that open work into a usable product.
Our proposal here is narrower than for CADA: procurement rules for AI software should ask for "open-core" solutions, an accountable vendor building on open, compulsory foundations with real anti-lock-in guarantees, rather than an open licence alone. These should be treated on a par with pure open source, and European-controlled ones should qualify for CADA's highest assurance levels.
Why this matters now
The package includes substantial public investment in AI Gigafactories, rightly framed as a sovereignty asset. But without extending assurance to hardware, platforms and models, that investment risks entrenching dependency at exactly the layers where non-European vendors hold the greatest share of value, even as the compute itself becomes European.
As Europe is about to spend heavily on AI sovereignty through funding and through procurement rules, that spending will land somewhere in the stack whether the assurance framework tracks it or not.
The only question is whether it lands where the dependency actually is. Extending CADA and the Open Source Strategy to the whole stack is what will decide whether this investment builds European capability, or quietly pays for someone else's.