Editor’s Note: The Cloud and AI Development Act, a draft European regulation, asks a question many vendor questionnaires may not reach: who actually decides. Its audit annex would tell an auditor to collect the shareholders up to the ultimate owners, the cap table, the bodies that take strategic decisions, the majorities those decisions need, everyone holding 5 percent or more of capital or votes, and any influence running through commercial or financial links. That examination would attach at assurance level 2 and above, not at level 1.
The act is a proposal, not adopted law. The Commission published it on June 3, 2026, and no adoption date is set. European Central Bank research supplies context for why the ownership question may matter: a total fund size of approximately 930 billion euros for venture funds located in the U.S. against roughly 150 billion euros for funds located in the EU, a gap that widens at later stages. Neither institution connects its work to the other; the article says the connection is its own.
Buyers need not wait for adoption to borrow the annex’s questions. The audit criteria can function as a questionnaire now. Watch whether buyers do.
Content Assessment: Europe's draft cloud rule would put vendor ownership in the audit file
Information - 92%
Insight - 92%
Relevance - 88%
Objectivity - 90%
Authority - 88%
90%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Europe's draft cloud rule would put vendor ownership in the audit file."
News Analysis – Data Privacy and Protection Beat
Europe’s draft cloud rule would put vendor ownership in the audit file
ComplexDiscovery OÜ Staff
A draft European regulation would ask who controls a cloud provider, and the annex explaining how control is assessed would tell an auditor to ask for the cap table. Among the public buyers it covers, what triggers it is the work rather than the sector label: a public sector activity identified as contributing to the preservation of public order. That moves ownership out of due diligence and into an audit file. Where data sits is a fact about infrastructure. Who decides is a fact about shareholders, boards and voting thresholds, and procurement may not hear when it changes.
What the draft rule would require
The Cloud and AI Development Act is a proposal, not adopted law. The Commission published it on June 3, 2026. It is moving under the ordinary legislative procedure, and Parliament’s file shows it in a preparatory phase, with committees still awaiting referral decisions and no adoption date set. It is worth reading now anyway, because it writes down questions a buyer can ask long before anyone is obliged to answer them.
The annexes are more specific than the Commission’s public summary suggests. Assurance level 1, the lowest of four tiers, is not a data-residency clause under a new name. It carries seven cumulative criteria. Three go to establishment and location: the provider established in the Union, infrastructure and assets located there, and customer data including metadata and telemetry staying there, the last two subject to an exception where the public sector body explicitly requires otherwise. Three of the other four cover outsourced technical support, cybersecurity standards, and subcontractor transparency and oversight. The fourth is stranger: where the provider is controlled from a third country, a guarantee demonstrated by independent sources that no laws or practices there require it to report software vulnerabilities to that country’s authorities before those vulnerabilities are known to have been exploited.
Level 3 goes further, asking that the provider and the subcontractors involved in the audited service be established in the Union and barring control from a third country. That bar has a way around it, and it does not open provider by provider. The Commission can identify a third country by implementing act, on six cumulative criteria. Only then can a provider controlled from there be audited at level 3. Even then, the provider and its subcontractors must demonstrate further safeguards: that the control does not constrain them, does not give that country access to customer data or the power to disrupt the service, and does not oblige them to apply that country’s sanctions or embargoes, unless those measures are legitimate under Member State or Union law.
Then comes the part a governance team should read twice, and the examination it describes would attach at assurance level 2 and above, not at level 1. The audit annex asks for all direct and indirect shareholders up to the ultimate owners, the cap table documenting the ownership structure, and the bodies empowered to take strategic decisions. It also wants the rules for appointing them, the majorities their decisions require, everyone holding 5 percent or more of capital or votes, and influence running through commercial or financial links. Ownership is evidence there rather than the answer, because the regulation is asking who actually decides.
The answer to who would face this is a fork rather than a floor. Member States and Union entities run the risk assessments, which decide whether a public sector activity contributes to the preservation of public order. The scope is drawn to the sectors covered by NIS2, the EU’s network and information security directive, plus national security, internal security, external border management, defense, justice and law enforcement. Sitting in one of those sectors is not the test; the finding is. For an activity so identified, a buyer could procure only level 2, 3 or 4, and the ownership examination would come with it. For one that is not, level 1 applies. Neither is absolute: a contracting authority may depart from either requirement on an exceptional basis and where duly justified, including where no recognized service can supply what the tender needs. Entities listed in Annex I of the NIS2 Directive that are not public sector bodies may voluntarily carry out similar assessments of their own.
What the funding gap has to do with it
A rule that asks who controls a vendor matters most when the answer can change. Investors meeting in Haapsalu on Aug. 27 were arguing about something adjacent: where European companies have to go for growth capital. At the Baltic VCA Summit, Sten Tamkivi, a partner at Plural, and Rainer Sternfeld, a general partner at NordicNinja, spoke on a panel titled “A Fragmenting World: Capital, Security & the End of Globalization.” Moderating was Taavi Veskimägi, a former Estonian minister whom the Estonian Private Equity and Venture Capital Association calls a partner at Sentris Capital and 2C Ventures, though Sentris’s own imprint gives him a different title. What follows comes from the association’s press release on the session, which presents no opposing view.
Tamkivi’s measure of a mature market is blunt: “[H]ow far does a founder have to travel to raise the capital they need?” A startup raising 50 million euros can probably still find a lead investor in Europe, he said, while a company seeking 200 million euros will most likely have to turn to U.S. investors. One route has closed. “Ten years ago, we would also have called Chinese investors, but because of geopolitics, that is no longer the case,” he said.
The European Central Bank published the same shape with figures attached. Venture funds located in the United States have a total fund size of approximately 930 billion euros, “around six times as much” as the roughly 150 billion euros of funds located in the EU, according to a research box in the bank’s Economic Bulletin, Issue 5/2026, citing work by Banu and colleagues. Its authors found the gap widens specifically at later-stage rounds, and named Estonia among the small but highly developed venture capital markets that “remain heavily dominated by US investors.”
“Heavy reliance on non-EU investors, especially at later stages, may create strategic vulnerabilities, particularly where local scale-up financing is weak,” the bank’s authors wrote. Separately, they wrote that “US and other foreign VC investors may increase the likelihood of successful European start-ups relocating headquarters, management functions, talent, intellectual property or future listing activity outside the EU.” They named an upside as well: “An internationally diversified investor base can provide capital, expertise, networks and access to global markets.”
Read that relocation list from a governance chair. In U.S. federal civil litigation, Rule 34 reaches designated documents, electronically stored information and tangible things within Rule 26(b)’s scope that are in a party’s possession, custody or control, and the rule does not define control. The draft regulation is more specific about what an auditor looks at. Joining the bank’s warning to the Commission’s criteria is this article’s reading, not a claim either source makes. Capital may move where a company is run from, and this draft asks who runs it. Some of that capital is aimed at sectors that may contain activities a risk assessment would identify as contributing to the preservation of public order.
Where the strategic sectors come in
Sternfeld took the argument toward sovereign capability, saying Europe has to build its own capacity in the sectors it treats as strategic, among them defense, energy and space. He and Veskimägi were arguing for a category their firms invest in: NordicNinja backs “critical technologies across deep tech, decarbonization, and digital society,” while Sentris Capital calls itself “a pan-European investment manager focused on resilience, defense, and dual-use capabilities.” That does not make them wrong and does make the disclosure necessary.
Defense is named outright in the scope those risk assessments cover, and a finding there is what would push a buyer past level 1 and into the ownership examination. “National industrial policies and protectionism are fragmenting the single market,” Veskimägi said, “while in sectors such as defense, a truly single market has effectively never existed.” None of that changes what a contract says today.
Where governance teams should start
But buyers need not wait for adoption to borrow the annex’s questions. Ask vendors not only where data resides but who holds 5 percent or more of the equity or votes, who sits on the body taking strategic decisions, and what majorities those decisions need. Build a change-of-control trigger into data processing terms so a transfer assessment gets rerun rather than assumed. The audit annex can function as a questionnaire now, and nothing about using it that way depends on whether the regulation passes.
The investors in Haapsalu were arguing about how big Europe should build. The narrower question belongs to whoever owns the vendor file. Brussels has drafted the questions an auditor would put to a cloud provider, and a cap table is not a difficult document to request. So request it, and then ask the harder one: when a European supplier’s control changes hands in the middle of a contract term, does anything in your agreement require anyone to tell you?

News sources
- Europe’s venture capital gap and the financing of high-growth firms (European Central Bank)
- Cloud and AI Development Act (European Commission)
- Programme, Baltic VCA Summit 2026Â (Baltic VCA Summit)
- Kuursaalis kohtuvad Balti investorid (Lääne Elu)
- Team (Plural)
- Rainer Sternfeld (NordicNinja VC)
- Empowering Europe’s Sovereign Resilience (Sentris Capital)
- Investors: Europe Cannot Afford to Think Small. Undated press release on the summit’s opening panel, provided to ComplexDiscovery by the association. Not posted on the association’s news index, whose most recent entry as of Sept. 3, 2026 was dated Aug. 30. (Estonian Private Equity and Venture Capital Association)
- News index (Estonian Private Equity and Venture Capital Association)
- Proposal for a Cloud and AI Development Act, COM(2026) 502 final, full text with annexes (EUR-Lex, CELEX 52026PC0502)
- Procedure file 2026/0138(COD)Â (European Parliament)
- Rule 34, Federal Rules of Civil Procedure (Legal Information Institute, Cornell Law School)
Assisted by GAI and LLM Technologies
Additional reading
- The eight-hour clock starts today: EU e-evidence orders now land on covered U.S. providers’ EU addressees
- California’s AI Transparency Act arrives alongside Europe’s Article 50
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.


























