Cloud and AI regulation must be built on capability

Netnod was invited by the Ministry of Finance (Finansdepartementet) to comment on the European Commission’s proposed Cloud and AI Development Act (COM(2026) 502 final).

Netnod operates Sweden’s largest Internet exchange points and critical DNS infrastructure — including one of the world’s thirteen root name servers (i-root) — and is responsible for time and frequency distribution across Sweden and parts of northern Europe. This is the infrastructure layer on which cloud services depend for reachability, accurate timestamping and synchronisation.

Netnod welcomes the Commission’s ambition to strengthen Europe’s resilience and competitiveness in cloud and AI, and specifically welcomes the SBOM requirements in Annex II and the open-source provisions in Articles 43–44. However, Netnod’s principal objection is that the proposal’s Union assurance levels — which classify suppliers by where they are established and who controls them — focus on supplier characteristics rather than on what organisations actually need to maintain their critical functions. The EU already has capability- and risk-based instruments for exactly this purpose in the NIS2 Directive (2022/2555) and the CER Directive (2022/2557). The regulation should build on their functional logic rather than layering a parallel, origin-based regime on top — risking overlap, double regulation and conflict.

Resilience is achieved through redundancy, diversification and verified recovery capability — not through the properties of any single supplier. Routing all critical public procurement through a single Union assurance framework creates a new monoculture with a shared attack surface. Non-European suppliers must therefore remain available as part of a genuinely diversified approach: a monoculture of Union-certified providers is not a resilience goal. Netnod also calls for risk assessments under Article 29 to be grounded in function and dependencies — identifying critical functions, consequences of disruption, RTO/RPO parameters and alternative solutions — rather than simply producing a Union assurance level selection. Requirements should apply to the critical function rather than automatically to the whole of an operator’s organisation, and should flow down the supply chain through contractual obligations.

Finally, Netnod calls for the regulation to require verified — not merely documented — continuity capability, tested through practical failure drills rather than paper-based audits. The legitimate industrial policy goal of strengthening European suppliers’ competitiveness is best pursued through innovation procurement, with requirements focused on function, interoperability and portability rather than on the supplier’s origin. Subsidised demonstration projects that cannot sustain themselves once public funding runs out are not a reliable path to lasting European capacity. The collective purchasing power of European public bodies, properly channelled through innovation procurement, is a more effective and durable tool.