Noise around the Cloud and AI Development Act (CAIDA) has intensified recently. The United States’ decision to restrict foreign access to advanced AI models led to the immediate suspension of access to Mythos 5 and Fable 5 through Amazon Web Services.
Critics of the European Commission’s current CAIDA proposal say the incident exposes that Europe’s digital sovereignty plans may not go far enough, particularly for businesses running critical infrastructure. And there are now renewed calls to review the scope of the proposed legislation.
But even before this news complicated the debate, political agreement wasn’t targeted until Q4 2027, at the earliest. That means roughly eighteen months of legislative process, then member state transposition, then the practical work of changing how organisations actually build, host and run AI systems. Full implementation is unlikely before 2028, and it could easily slip into 2029.
So when someone in a steering committee next month says, “let’s wait until we see the final text before we commit,” what they are actually proposing is that we pause infrastructure decisions for two to three years.
I do not think that is always fully understood.
The infrastructure problem nobody wants to talk about
A GB200 NVL72 rack weighs roughly 1.4 metric tonnes. Picture that. Then ask yourself, honestly, whether the floors in your existing data halls can take it. Whether your row power can sustain 140kW per rack (GB200 NVL72), or worse, 370kW per rack (VR200 NVL144). Whether you have liquid cooling at all, anywhere, in production.
This is not something you can patch your way around. It is concrete, steel, copper and chilled water, and retrofitting serious AI capacity into an existing building can take two or three years if you are lucky, longer if you are not. A new build can take as long, particularly with the grid connection queues many organisations are facing across Europe.
So if you wait for CAIDA to be agreed before you start, you finish in 2030, maybe 2031.
What should CTOs do now?
First, tier your workloads. Sensitive data, regulated content, and anything with GDPR weight should stay on infrastructure you control. Run inference locally where you can. Smaller models, particularly in the 7-70 billion parameter range, are now extraordinarily capable. You do not need a hyperscaler to embed a vector store and serve a fine-tuned model.
Training is harder. Most organizations do not have the GPU density they need, so renting capacity from a local or sovereign GPUaaS provider, including European neoclouds, may be the pragmatic option. The contract matters, as data residency, documented deletion and portability should all be clear. Build against open standards so that, when you eventually have your own training compute, you can move without rewriting half your pipeline.
The most fragile part is the middle layer, where sensitive data is transformed into something safe to train on without exposing the underlying information. This is where teams are tempted to cut corners. They should not. The anonymization boundary may be the most important piece of engineering they do this year, and it should be built with the audit in mind.
Second, if you have land and power, build modular now. Prefabricated AI-ready facilities from the major vendors (you know the names) can be deployed in a fraction of the time of a conventional build. That does mean committing capital before the final regulatory shape is clear, which is uncomfortable, but the alternative is finishing years too late.
The two things that gate this decision are power and real estate. If you have neither, securing them should be a strategic priority for the next two quarters. Grid connection queues in most European countries are not improving, although the European Grids Package targeted for Q3 2026 may help.
Third, pay attention to what is happening this quarter, rather than waiting for 2027.
Omnibus VII Digital is targeted for political agreement in June 2026. In legislative terms, that is almost immediate. It is the simplification package for AI regulation, and the window to influence it through trade bodies, national associations and direct contacts in DG CONNECT is closing. Organizations with a view should file it now.
The European Parliament has recently given its final approval to the amendment of certain rules within the EU’s Omnibus VII legislative package, which is the digital simplification framework designed to streamline regulations across AI. The vote passed with 423 votes in favour, 57 against and 174 abstentions, so the wheels are in motion and CTOs need to be aware of its implications.
Then there is the AI Gigafactories program. Investment projects are due to launch from Q4 2026 onwards, and if the EU delivers publicly backed sovereign AI compute, it could change the picture for European enterprises. The promise is compliant by default, European-sovereign by design, and potentially available on terms a commercial neocloud cannot match. So CTOs should be cautious about signing multi-year exclusive hyperscaler deals before they understand what the Gigafactories will actually offer.
The energy story is the real story
The most important part of the roadmap may be the energy section.
ETS review is targeted for Q1 2027, Energy Efficiency Framework is targeted for Q4 2027, and Network charges and taxation reform are aiming for Q2 2027. For anyone running compute-intensive AI workloads, these are not secondary policy details. They could determine whether the business case works at all.
If you are writing a ten-year data center business case this quarter, your energy assumptions need to include scenario planning for material changes in carbon pricing and grid charges by 2027. Otherwise, you may be rewriting the business case in eighteen months.
The practical answer is to over-design for efficiency now, from liquid cooling and renewable PPAs and PUE targets that exceed any plausible future mandate. It is far cheaper to build this in from the start than to retrofit it later.
Where the real risk sits
The risk for European CTOs is not CAIDA itself. CAIDA is a known unknown, and organizations can plan around it.
The greater risk is cultural, and using regulatory uncertainty as cover for delay on decisions that are really about engineering, capital and competitive position.
The roadmap is published. The dates are real. The clock is running. The question for CTOs is what they are prepared to do this quarter.
Comments