secureskies
Cyber Security/Evaluate/EU Cloud & AI Act Readiness

Three acts,
one decision.

Three European instruments reach into your cloud and AI landscape at the same time: the Data Act, with switching and portability rights applicable since 12 September 2025; the AI Act, with deployer duties (high-risk from 2 August 2026, Annex III systems by 2 December 2027); and the draft Cloud and AI Development Act of 3 June 2026, with four Union Assurance Levels for sovereign cloud services. We assess where your contracts, architectures and AI systems stand today — and which of it is an obligation, which a procurement criterion of your customers, and which an option.

FormatAssessmentcontracts + architecture + AI inventory
InstrumentsData Act · AI ActCADA draft COM(2026) 502
Deadline12 Jan 2027switching charges end
OutcomeReadiness matrixplus action plan per instrument
01 · Service

What is included.

Cloud switching rights, sovereignty tiers and AI duties in one picture.

Data Act: switching and exit

Cloud contracts against Chapter VI: notice period of two months at most, switch within 30 days, data categories, exit assistance; charges cost-covering only until 12 January 2027, zero thereafter. Technical exit test per service.

CADA: sovereignty tier

Your cloud services placed against the draft’s four Union Assurance Levels — establishment, data localisation, third-country control, certification. Relevant if you supply public bodies or NIS2 sectors.

AI Act: deployer role

Inventory of your AI systems, classification, provider-versus-deployer clarification, duties under Art. 4, 12, 14, 26 and 50 — tied to the cloud services they run on.

Readiness matrix

One picture per cloud service and AI system: obligation today, obligation with a date, procurement criterion, option. The action plan with owners follows from it.

The Cloud and AI Development Act is a Commission proposal in the ordinary legislative procedure; the Annex II criteria may still change. “EU Cloud Act” is not an official title and should not be confused with the US CLOUD Act. Secureskies does not provide legal advice; this assessment is a technical reading for your legal function.

02 · Process

Five steps,
one deliverable.

01

Inventory

Record cloud contracts, services, regions, AI systems and their purpose.

02

Contract review

Data Act clauses and provider addenda against Chapter VI; mark the findings.

03

Architecture review

Data residency, key custody and exit capability per service; map to assurance levels.

04

AI review

Classification and duty mapping under the AI Act, linked to the Ring-1 requirements (private model instance).

05

Report

Readiness matrix and action plan, presented to management and the legal department.

03 · Who it fits

When this service
applies.

Companies supplying public authorities or NIS2 entities
Deployers of AI systems on hyperscaler infrastructure
Procurement and legal teams facing cloud renewals in 2026/27
More services · Evaluate

Will you renew your cloud contracts
before or after 12 January 2027?