EU works on new rules for cloud and AI. Polish digital industry calls for “open technological sovereignty”
The Digital Poland Association has submitted its position on the proposed EU Cloud and AI Development Act (CADA) to the Polish Ministry of Digital Affairs, calling for its recommendations to be reflected in Poland’s position on the forthcoming regulation. The Association supports the objectives of the EU’s technology sovereignty package, but warns that CADA, in its current form, could restrict competition, limit access to cutting-edge technologies and weaken security by excluding trusted non-EU providers from the market.
The European Commission is currently working on the Cloud and AI Development Act (CADA), one of the key elements of the EU’s technology sovereignty package. The regulation is intended to create conditions for the development of European cloud and AI infrastructure and to establish rules governing the use of cloud services by public administrations and strategic sectors. Member States, including Poland, are currently preparing their positions on the proposal, which will feed into the next stages of the legislative process. According to the Digital Poland Association, while the objectives of the regulation are justified, some of the proposed measures require significant changes.
As the industry association’s experts emphasise, Europe should strengthen its own technological capabilities and invest in the development of digital infrastructure. However, the Digital Poland Association points out that building technological sovereignty should not mean closing the European market or restricting cooperation with trusted partners from outside the European Union.
– Sovereignty cannot be equated with the nationality of a provider. It should be built on genuine control over data, infrastructure resilience, operational security and the ability to use the best technologies available on the market. Only such an approach will allow Europe to strengthen its security while maintaining the competitiveness of its economy – says Michał Kanownik, President of the Digital Poland Association.
Security should matter more than a provider’s origin
The Association’s main concerns relate to the proposed Union Assurance Levels (UAL). These are intended to determine which providers will be allowed to deliver services to the most sensitive areas of the public sector. Under the proposed rules, at the highest assurance levels, market access would primarily be available to EU companies, while non-EU providers would effectively be excluded or allowed to operate only in exceptional circumstances, subject to approval by the European Commission.
– The paradox is that the most restrictive requirements would apply precisely to the sectors that need the most advanced artificial intelligence and cybersecurity tools the most. Europe should not restrict its own access to technologies that are essential today for both security and economic competitiveness – Michał Kanownik emphasises.
According to the Association, the current proposal confuses sovereignty with the origin of capital. From the perspective of digital service users, what matters most is whether they retain full control over their data, whether they can switch services to another provider, whether the infrastructure guarantees business continuity, and whether it meets rigorous security standards. Industry experts argue that these are the requirements that should determine whether a provider is granted access to the market.
Regulation without a comprehensive impact assessment
In its position submitted to the Ministry of Digital Affairs, the Digital Poland Association also points out that the CADA proposal has not been accompanied by a comprehensive assessment of the impact of the proposed measures. Among other things, there has been no full analysis of how the new rules could affect costs for public administrations, the pace of AI adoption, the competitiveness of the European economy, or the ability to attract EUR 200 billion in private investment in digital infrastructure.
According to the Association, limiting the number of providers could lead to higher costs, weaker competition and slower modernisation of public administration and strategic sectors. This is particularly relevant for areas relying on advanced artificial intelligence and modern cybersecurity solutions, whose development requires investment on a global scale and access to geographically distributed technological infrastructure.
– Europe will not win the global technology race if it starts restricting competition in its own market. We need regulations that attract investment, develop European capabilities and, at the same time, preserve the possibility of cooperating with trusted partners from around the world. This is what we mean by open technological sovereignty – Michał Kanownik emphasises.
In its position submitted to the Ministry of Digital Affairs, the Digital Poland Association recommends that Poland support solutions based on objective criteria relating to security, infrastructure resilience and control over data, rather than on a provider’s country of origin.
The Association also calls for the most restrictive assurance levels to be eased and for the possibility of cooperation with trusted non-EU partners to be maintained. It also highlights the need to limit the European Commission’s powers to interfere with decisions taken by Member States.
According to the Association, a comprehensive impact assessment should also be carried out before the legislative process is concluded, including an assessment of the regulation’s impact on competition, investment, public-sector costs and the pace of cloud and AI adoption across Europe.
