Token-OPEX: Inference Controls, Not the Seat Budget
Angelika Beierlein
9 Min. read time Token costs aren’t a line item in SaaS contracts. They’re variable OPEX per workflow-and ...
On June 3, 2026, the European Commission proposed the Cloud and AI Development Act, shifting a question from strategy slides into procurement law. Going forward, public contracting authorities will be required to treat Union added value as a non-price criterion. Sovereignty is moving from a talking point to a mandatory requirement. For board members, this boils down to one very concrete question: Will your existing hyperscaler contract withstand a four-tier sovereignty classification, or does the company need an exit strategy?
Key Takeaways
Related:Cloud sovereignty becomes a board-level issue / Sovereignty beats price: the new procurement signal
For a long time, digital sovereignty was merely a political pledge. With the Cloud and AI Development Act, it becomes law. The proposal introduces a standardized, EU-wide assessment grid for the sovereignty of cloud and AI services, linking it to a mechanism that steers public procurement toward compliant providers. The novelty lies not in the concept itself, but in its binding nature.
What is Union added value? Union added value is an evaluation criterion that measures how strongly a provider contributes to the European technology supply chain: through technologies developed in the EU, through innovation within the EU, or through hardware components designed or manufactured in the EU. Public contracting authorities will be required to weight this contribution as a non-price criterion going forward.
For providers, this shifts the competitive logic. The cheapest provider no longer wins automatically if a competitor scores significantly higher in the sovereignty assessment. This changes public sector tenders and radiates outward into regulated industries.
The operational consequences begin in the contract, not in the vision. If a provider’s sovereignty classification plays a role in awarding contracts, it becomes a risk factor for anyone relying on that provider. A company serving public contracts or customers in regulated industries would effectively inherit the classification risk of its cloud providers.
The sober question for leadership is therefore: In which category does my current hyperscaler fall, and what happens to my competitiveness if it stays there? Those who cannot provide a reliable answer continue steering their cloud strategy based on price and features, while the evaluation landscape shifts beneath them.
Regulation only becomes an advantage when acted upon early. Three steps are meaningful regardless of the final legal text because they inherently increase resilience.
First, an inventory: Which critical workloads are hosted with which provider, and how would this provider be classified in a four-tier framework? Second, exit capability: Can these workloads be relocated with reasonable effort, or is there a factual lock-in? Third, contract negotiations: Sovereignty and portability commitments should be part of the next negotiation round, not the contingency plan.
None of these steps require the law to already be in effect. They provide lead time if it comes, and cost little if it is delayed.
The CADA is a law proposed by the European Commission on June 3, 2026, introducing an EU-wide sovereignty assessment framework for cloud and AI services and linking public procurement to this framework. It aims to transform digital sovereignty from a declaration of intent into binding procurement and infrastructure law.
Union added value is a non-price criterion that evaluates a provider’s contribution to the European technology supply chain, such as through technology developed in the EU, innovation within the EU, or hardware manufactured in the EU. Public procurers must now weigh this alongside price.
The procurement obligation directly applies to the public sector. Indirectly, it affects any company that serves public contracts or has customers in regulated sectors, because the sovereignty classification of cloud providers impacts the entire supply chain.
CADA introduces a four-tier sovereignty assessment framework that places cloud and AI services on a unified scale. It replaces fragmented national programs and sector-specific guidelines with a common EU evaluation.
Three steps without waiting for the final text: capture critical workloads and their providers, assess their portability and lock-in risks, and include sovereignty and portability commitments in the next contract round. These steps increase resilience regardless of legislative speed.
Read more on Digital Chiefs
Digital ChiefsDigitalization Without a Big Bang: A Step-by-Step TransformationDigital ChiefsLearning on the Job: What the Board of Directors Needs to Demand when 89% of the AI Strategy isDigital ChiefsAI as a Digitalization Engine: What is Really Driving the German Economy NowMore from the MBF Media Network
cloudmagazinVMware Cloud Foundation 9.1: AI Workloads Sovereign in the Data Center mybusinessfutureOut of the US Cloud: What the Mid-Sized Business Must Check securitytodayNIS2 Meets CLOUD Act: Who is Liable for the Third Country GapTitle image: AI-generated (June 2026)