The Conventional Wisdom
Your AI governance program is designed to manage risk. It's built around the EU AI Act's prohibited practices, high-risk classifications, and conformity assessments. Your compliance roadmap views innovation as something that happens after regulatory requirements are satisfied. The EU's regulatory stance has been clear: AI is primarily a risk to be controlled, not an opportunity to be seized.
This approach made sense. The EU AI Act drew from product safety law and fundamental rights protections. It established red lines and created bureaucratic obligations for high-risk systems. Despite proposals for simplification, the underlying philosophy remained unchanged: regulate first, innovate later.
Why We Disagree
The June 2026 Cloud and AI Development Act (CADA) proposal shows this view is incomplete. CADA doesn't just adjust the compliance framework; it introduces obligations on governments to enable AI development, codifies an "AI first" principle into EU law, and creates infrastructure for frontier AI without imposing significant new burdens on companies.
This isn't regulatory whiplash. It's a deliberate two-track system: the EU AI Act manages downside risk while CADA mobilizes upside opportunity. A governance program that only addresses the first track misses half the regulatory signal.
The Evidence
CADA's Titles II and III contain few obligations for companies. Instead, they mandate that Member States establish "Centers for AI" and adopt National AI Strategies within one year of CADA's entry into force. These aren't symbolic gestures. The proposal requires Member States to designate at least one data center acceleration zone with streamlined permitting procedures within six months.
CADA's operational objectives read like a national industrial policy, not a compliance framework. Article 3(2) directs the Commission and Member States to advance EU capabilities in frontier AI, support development of platforms for large-scale deployment of AI agents, and promote physical AI models across strategic sectors. Article 4(4) goes further, requiring actions to accelerate development of a "European physical AI stack" and facilitate access to datasets for physical AI training.
Consider the treatment of "world models" for physical AI. Annex I defines Grand Challenge 4 as co-designing software with underlying hardware architectures and combining frontier AI techniques with world models "supporting physical reasoning for delivering robust manipulation, navigation, and interaction capabilities with minimal human supervision." The regulation mandates government support for this development.
The proposal also establishes a framework for the Commission to designate "Frontier AI priority projects" undertaken by European digital infrastructure consortia. These projects would receive guaranteed computing resources from Member States and the Commission "within the limits of available capacity" per Article 9.
This approach mirrors frameworks outside the EU. America's AI Action Plan promotes data center permitting acceleration and government-led AI adoption. Japan's AI Promotion Act establishes mandatory national planning cycles. All three frameworks place primary obligations on governments, not companies. The EU has joined a global pattern of AI-enabling regulation.
What to Do Instead
Stop treating your AI governance program as purely defensive. CADA creates strategic opportunities that compliance-only frameworks can't capture.
First, map your AI development roadmap to CADA's operational objectives and Grand Challenges in Annex I. If you're working on autonomous systems, physical AI, or multi-agent platforms, you're now aligned with explicit EU policy goals. That alignment changes your conversation with regulators, procurement officers, and national AI centers.
Second, engage with your Member State's emerging National AI Strategy. Article 7(2) requires these strategies to include measures for accelerating AI development and adoption at national, regional, and local levels. Your input during the strategy development phase shapes the infrastructure, compute access, and dataset availability you'll have access to later.
Third, evaluate whether your projects qualify for Frontier AI priority project designation. Article 8 establishes criteria including that projects must be undertaken by European digital infrastructure consortia. If your work meets the threshold, designation unlocks computing resource commitments from Member States and the Commission.
Fourth, reframe your AI governance documentation. Your Technical Documentation (Annex IV) under the EU AI Act should demonstrate not just risk controls but also alignment with CADA's innovation objectives where applicable. Your AI Management System under ISO/IEC 42001 should include processes for capturing strategic opportunities from government AI initiatives, not just managing compliance obligations.
Fifth, monitor data center acceleration zones in your operational territories. CADA's streamlined permitting in these zones affects your infrastructure planning and vendor selection. If your cloud providers or foundation model providers establish presence in acceleration zones, you inherit deployment advantages.
When the Conventional Wisdom Is Right
CADA doesn't replace the EU AI Act. It complements it. If you're deploying high-risk AI systems under Annex III, your conformity assessment obligations haven't changed. If you're providing General-Purpose AI Models, the General-Purpose AI Code of Practice still applies. Prohibited AI Practices remain prohibited.
The compliance-first approach remains correct for managing regulatory floor requirements. You still need robust Technical Documentation, Post-Market Monitoring, and Instructions for Use. Your model validation rigor under SR 11-7 principles (if you're in financial services) or your AI System Impact Assessment under ISO/IEC 42005 don't become less important because CADA encourages innovation.
The conventional wisdom is also right that regulatory complexity remains a barrier. CADA adds a new legislative instrument to navigate alongside the EU AI Act, GDPR, sector-specific rules, and emerging standards. The administrative burden hasn't disappeared.
But here's what changed: the EU now explicitly signals that AI development aligned with strategic objectives receives government support, infrastructure investment, and resource commitments. Your governance program that only manages downside risk while competitors capture upside opportunity isn't comprehensive. It's incomplete.
The question President von der Leyen posed in October 2025 at Italian Tech Week applies to your governance strategy: "How can AI help?" CADA makes that question regulatory policy. Your answer determines whether your program enables strategic advantage or just checks compliance boxes.



