Germany's Deutsche Kreditwirtschaft backs EU Cloud and AI Development Act but warns against duplicating DORA rules for banks
Germany's Deutsche Kreditwirtschaft (DK) backs EU cloud/AI sovereignty but warns the planned Cloud and AI Development Act must stay technology-neutral, not duplicate banks' existing DORA rules. CADA would set a 4-tier sovereignty framework for cloud providers.
Germany's banking industry association, the Deutsche Kreditwirtschaft (DK), published a position statement Monday on the European Commission's proposed Cloud and AI Development Act (CADA), which aims to reduce Europe's dependence on non-EU cloud and AI infrastructure providers. DK says it supports the underlying goal of strengthening EU digital sovereignty, but insists the law must be designed to be technology-neutral and risk-based, and must not create new, parallel regulatory obligations for banks on top of what already exists. Specifically, DK wants the EU's existing Digital Operational Resilience Act (DORA), which governs how financial institutions manage IT and third-party risk, to remain the primary framework for banks rather than layering CADA requirements on top of it. CADA itself, adopted by the European Commission in June, would be the EU's first binding infrastructure law built around digital sovereignty rather than just policy aspiration. It proposes a four-tier assurance framework that conditions access to public-sector cloud contracts on criteria such as EU-based data processing, independence from non-EU corporate control, supply-chain transparency and EU ownership, alongside measures to expand the bloc's own data center capacity. For banks specifically, the stakes are about avoiding a second layer of compliance on top of DORA at a time when European lenders are already navigating tightening capital markets and cybersecurity rules while depending heavily on US hyperscalers for cloud infrastructure.