Editor’s Note: The Cloud and AI Development Act, a draft European regulation, asks a question many vendor questionnaires may not reach: who actually decides. Its audit annex would tell an auditor to collect the shareholders up to the ultimate owners, the cap table, the bodies that take strategic decisions, the majorities those decisions need, everyone holding 5 percent or more of capital or votes, and any influence running through commercial or financial links. That examination would attach at assurance level 2 and above, not at level 1.

The act is a proposal, not adopted law. The Commission published it on June 3, 2026, and no adoption date is set. European Central Bank research supplies context for why the ownership question may matter: a total fund size of approximately 930 billion euros for venture funds located in the U.S. against roughly 150 billion euros for funds located in the EU, a gap that widens at later stages. Neither institution connects its work to the other; the article says the connection is its own.

Buyers need not wait for adoption to borrow the annex’s questions. The audit criteria can function as a questionnaire now. Watch whether buyers do.


Content Assessment: Europe's draft cloud rule would put vendor ownership in the audit file

Information - 92%
Insight - 92%
Relevance - 88%
Objectivity - 90%
Authority - 88%

90%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Europe's draft cloud rule would put vendor ownership in the audit file."


News Analysis – Data Privacy and Protection Beat

Europe’s draft cloud rule would put vendor ownership in the audit file

ComplexDiscovery OÜ Staff

A draft European regulation would ask who controls a cloud provider, and the annex explaining how control is assessed would tell an auditor to ask for the cap table. Among the public buyers it covers, what triggers it is the work rather than the sector label: a public sector activity identified as contributing to the preservation of public order. That moves ownership out of due diligence and into an audit file. Where data sits is a fact about infrastructure. Who decides is a fact about shareholders, boards and voting thresholds, and procurement may not hear when it changes.



What the draft rule would require

The Cloud and AI Development Act is a proposal, not adopted law. The Commission published it on June 3, 2026. It is moving under the ordinary legislative procedure, and Parliament’s file shows it in a preparatory phase, with committees still awaiting referral decisions and no adoption date set. It is worth reading now anyway, because it writes down questions a buyer can ask long before anyone is obliged to answer them.

The annexes are more specific than the Commission’s public summary suggests. Assurance level 1, the lowest of four tiers, is not a data-residency clause under a new name. It carries seven cumulative criteria. Three go to establishment and location: the provider established in the Union, infrastructure and assets located there, and customer data including metadata and telemetry staying there, the last two subject to an exception where the public sector body explicitly requires otherwise. Three of the other four cover outsourced technical support, cybersecurity standards, and subcontractor transparency and oversight. The fourth is stranger: where the provider is controlled from a third country, a guarantee demonstrated by independent sources that no laws or practices there require it to report software vulnerabilities to that country’s authorities before those vulnerabilities are known to have been exploited.

Level 3 goes further, asking that the provider and the subcontractors involved in the audited service be established in the Union and barring control from a third country. That bar has a way around it, and it does not open provider by provider. The Commission can identify a third country by implementing act, on six cumulative criteria. Only then can a provider controlled from there be audited at level 3. Even then, the provider and its subcontractors must demonstrate further safeguards: that the control does not constrain them, does not give that country access to customer data or the power to disrupt the service, and does not oblige them to apply that country’s sanctions or embargoes, unless those measures are legitimate under Member State or Union law.

Then comes the part a governance team should read twice, and the examination it describes would attach at assurance level 2 and above, not at level 1. The audit annex asks for all direct and indirect shareholders up to the ultimate owners, the cap table documenting the ownership structure, and the bodies empowered to take strategic decisions. It also wants the rules for appointing them, the majorities their decisions require, everyone holding 5 percent or more of capital or votes, and influence running through commercial or financial links. Ownership is evidence there rather than the answer, because the regulation is asking who actually decides.

The answer to who would face this is a fork rather than a floor. Member States and Union entities run the risk assessments, which decide whether a public sector activity contributes to the preservation of public order. The scope is drawn to the sectors covered by NIS2, the EU’s network and information security directive, plus national security, internal security, external border management, defense, justice and law enforcement. Sitting in one of those sectors is not the test; the finding is. For an activity so identified, a buyer could procure only level 2, 3 or 4, and the ownership examination would come with it. For one that is not, level 1 applies. Neither is absolute: a contracting authority may depart from either requirement on an exceptional basis and where duly justified, including where no recognized service can supply what the tender needs. Entities listed in Annex I of the NIS2 Directive that are not public sector bodies may voluntarily carry out similar assessments of their own.

What the funding gap has to do with it

A rule that asks who controls a vendor matters most when the answer can change. Investors meeting in Haapsalu on Aug. 27 were arguing about something adjacent: where European companies have to go for growth capital. At the Baltic VCA Summit, Sten Tamkivi, a partner at Plural, and Rainer Sternfeld, a general partner at NordicNinja, spoke on a panel titled “A Fragmenting World: Capital, Security & the End of Globalization.” Moderating was Taavi Veskimägi, a former Estonian minister whom the Estonian Private Equity and Venture Capital Association calls a partner at Sentris Capital and 2C Ventures, though Sentris’s own imprint gives him a different title. What follows comes from the association’s press release on the session, which presents no opposing view.

Tamkivi’s measure of a mature market is blunt: “[H]ow far does a founder have to travel to raise the capital they need?” A startup raising 50 million euros can probably still find a lead investor in Europe, he said, while a company seeking 200 million euros will most likely have to turn to U.S. investors. One route has closed. “Ten years ago, we would also have called Chinese investors, but because of geopolitics, that is no longer the case,” he said.

The European Central Bank published the same shape with figures attached. Venture funds located in the United States have a total fund size of approximately 930 billion euros, “around six times as much” as the roughly 150 billion euros of funds located in the EU, according to a research box in the bank’s Economic Bulletin, Issue 5/2026, citing work by Banu and colleagues. Its authors found the gap widens specifically at later-stage rounds, and named Estonia among the small but highly developed venture capital markets that “remain heavily dominated by US investors.”

“Heavy reliance on non-EU investors, especially at later stages, may create strategic vulnerabilities, particularly where local scale-up financing is weak,” the bank’s authors wrote. Separately, they wrote that “US and other foreign VC investors may increase the likelihood of successful European start-ups relocating headquarters, management functions, talent, intellectual property or future listing activity outside the EU.” They named an upside as well: “An internationally diversified investor base can provide capital, expertise, networks and access to global markets.”

Read that relocation list from a governance chair. In U.S. federal civil litigation, Rule 34 reaches designated documents, electronically stored information and tangible things within Rule 26(b)’s scope that are in a party’s possession, custody or control, and the rule does not define control. The draft regulation is more specific about what an auditor looks at. Joining the bank’s warning to the Commission’s criteria is this article’s reading, not a claim either source makes. Capital may move where a company is run from, and this draft asks who runs it. Some of that capital is aimed at sectors that may contain activities a risk assessment would identify as contributing to the preservation of public order.

Where the strategic sectors come in

Sternfeld took the argument toward sovereign capability, saying Europe has to build its own capacity in the sectors it treats as strategic, among them defense, energy and space. He and Veskimägi were arguing for a category their firms invest in: NordicNinja backs “critical technologies across deep tech, decarbonization, and digital society,” while Sentris Capital calls itself “a pan-European investment manager focused on resilience, defense, and dual-use capabilities.” That does not make them wrong and does make the disclosure necessary.

Defense is named outright in the scope those risk assessments cover, and a finding there is what would push a buyer past level 1 and into the ownership examination. “National industrial policies and protectionism are fragmenting the single market,” Veskimägi said, “while in sectors such as defense, a truly single market has effectively never existed.” None of that changes what a contract says today.

Where governance teams should start

But buyers need not wait for adoption to borrow the annex’s questions. Ask vendors not only where data resides but who holds 5 percent or more of the equity or votes, who sits on the body taking strategic decisions, and what majorities those decisions need. Build a change-of-control trigger into data processing terms so a transfer assessment gets rerun rather than assumed. The audit annex can function as a questionnaire now, and nothing about using it that way depends on whether the regulation passes.

The investors in Haapsalu were arguing about how big Europe should build. The narrower question belongs to whoever owns the vendor file. Brussels has drafted the questions an auditor would put to a cloud provider, and a cap table is not a difficult document to request. So request it, and then ask the harder one: when a European supplier’s control changes hands in the middle of a contract term, does anything in your agreement require anyone to tell you?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).