The EU Just Redefined AI Sovereignty Around Data Centres. It Forgot About Your Devices.

By Bart de Witte, Founder, Isaree 24 June 2026


Three weeks ago, the European Commission adopted the Cloud and AI Development Act (CADA); the most ambitious piece of EU digital infrastructure legislation since the AI Act. It proposes to triple European data centre capacity by 2030, creates a four-tier cloud sovereignty framework for public procurement, establishes an EU open source catalogue, and mandates that 25% of public cloud and AI procurement go to innovative SMEs.

It also, in Recital 21, does something remarkable: it explicitly recognizes AI agents and multi-agent orchestration as a strategic technology frontier, calling for "sovereign and secure AI platforms dedicated to the large-scale deployment and orchestration of advanced AI agents" supported by "innovative orchestration frameworks that ensure transparency and accountability in multi-agent interactions."

That sentence is Isaree's product architecture, written by the European Commission. We have spent 14 months building the world first on-device multi-AI agent platform that lets clinicians build, own, and deploy personalized AI agents running entirely on their own devices. No data centre. No cloud dependency. No third-country access vector. The Commission's vision and ours are aligned except for one thing.

CADA defines sovereignty as a data centre problem.

The Blind Spot

CADA's four-tier Union assurance framework (Levels 1 through 4) defines sovereignty through five criteria: EU establishment of the provider, EU location of infrastructure, EU citizenship of personnel, absence of third-country control, and cybersecurity certification. At Level 4 (the highest), every condition tightens: infrastructure must be in the EU, all personnel must be EU citizens, no third country may exercise control over the provider.

There is a historical parallel here that deserves attention, because it tells us how fast this will move and how badly unprepared our regulatory imagination still is.

CADA reads like a policy designed to regulate mainframe computers; IBM System/360, locked in a corporate basement, accessed through a terminal. The regulation in its entirety, from the definitions in Article 2 to the EuroCloud Federation in Article 35 to the procurement mandates in Article 30, assumes that AI is delivered from centralized infrastructure that must be located, staffed, audited, and controlled. It is a mainframe-era sovereignty framework, written with admirable rigour, for a technological architecture that is already being replaced.

Meanwhile, Apple and Microsoft just created the personal computer market. NVIDIA shipped the DGX Spark; a personal AI server that fits on a desk. Google released the Coral dev board; a dedicated edge AI accelerator running Gemma models locally at one to three watts, priced under $150. Nous Research demonstrated autonomous agents running natively on local hardware with auditable security boundaries. We at Isaree are doing this for healthcare. And Apple committed its entire AI strategy to on-device models running on Apple Silicon across phones, desktops, and wearables.

The mainframe is not the future of AI. The personal device is. And Europe is about to regulate the mainframe while the personal computer market takes off without us.

But here is what CADA does not mention anywhere across its 100-plus pages, annexes, and impact assessments: on-device AI. Local inference. Edge processing. Client-side orchestration. The idea that an AI agent could run entirely on a clinician's or patient's own device and achieve stronger sovereignty outcomes than the most stringently audited EU data centre is simply not part of the regulation's conceptual vocabulary.

This is not a minor oversight. It is a structural blind spot that risks excluding the most privacy-preserving, sovereignty-maximizing AI architecture from the very regulatory framework designed to promote European digital sovereignty.

The Sovereignty You Don't Need to Audit

Consider what happens when a clinician uses an on-device AI agent:

Patient data never leaves the device. There is no cloud infrastructure for a third country to access, disrupt, or control. There are no personnel with administrative access to patient records. The clinician owns the hardware. The model runs locally. The orchestration logic executes on-device. When the agent calls a sub-agent for a specialized clinical task, that exchange also happens locally.

This is a simplification, of course. On-device AI does not mean no regulation applies. The EU Cybersecurity Act, the upcoming Cyber Resilience Act, and national frameworks like Germany's BSI technical guidelines for edge AI security (Isaree's Proximity AI) all establish requirements that local AI deployments must meet: secure enclaves, attested boot chains, model integrity verification, vulnerability disclosure. The difference is that these frameworks regulate the device and the software supply chain; things Europe can control; rather than the behaviour of a foreign hyperscaler we cannot. On-device sovereignty does not mean zero compliance. It means compliance over a stack we own.

Every concern that CADA's assurance levels are designed to address is eliminated by architectural design rather than managed through audit. You do not need to verify that infrastructure is in the EU because there is no infrastructure. You do not need to screen personnel for citizenship because no personnel touch the data. You do not need to audit for third-country control because the device is in the clinician's hand, not a provider's rack.

This is not a lower tier of sovereignty. It is a categorically different approach that achieves stronger outcomes by making the questions CADA asks about cloud providers completely irrelevant. And CADA does not know what to make of it.

Why This Matters Now

CADA is entering the ordinary legislative procedure. The European Parliament will appoint rapporteurs. The Council Working Party on Telecommunications will debate amendments. And critically, Article 7 requires every Member State to adopt a national cloud and AI strategy within one year of CADA's entry into force.

This is a one-time window. If on-device AI is not recognized in those national strategies and in the final regulation text, we will have built a European sovereignty framework that inadvertently tilts the playing field toward centralized, capital-intensive cloud models while leaving the most sovereignty-maximizing architecture undefined and unregulated.

That outcome would be ironic, given that CADA itself is framed as a response to Mario Draghi's warning about European competitiveness. The Draghi report argued that Europe's productivity and GDP growth are structurally trailing, and that digital infrastructure dependence is a core driver; what Draghi called "slow agony" if left uncorrected. The answer to that diagnosis is not just building more data centres; it is enabling architectures that do not need them.

The Supply Chain We Already Control

Here is the part that should make European policymakers sit up straight.

For two decades, Europe watched the cloud computing revolution from the sidelines. We have no AWS. No Azure. No Google Cloud. Our digital infrastructure is rented from American hyperscalers, and our data, including health data, flows through their pipes. The productivity gains per capita, the GDP growth, the network effects; all of it flows across the Atlantic along with the data. Europe is not just renting compute. It is exporting its own economic future, one inference call at a time.

The local AI hardware stack resets this equation entirely.

Europe's industrial strengths are not in cloud infrastructure. They are in the exact domains a local AI hardware stack needs: embedded systems, industrial automation, automotive chips, medical devices, and precision manufacturing. And Europe already has the companies that can deliver this entire stack.

ASML builds the lithography machines that make the world's most advanced chips. ARM designs the processor architecture that powers every mobile device on the planet and is now being extended for on-device AI inference. Infineon and STMicroelectronics manufacture the microcontrollers, sensors, and edge AI accelerators that already run inside European cars, factories, and medical devices. Bosch builds the MEMS sensors and embedded AI systems deployed in hundreds of millions of devices globally. These are not startups with a pitch deck. These are industrial giants with fabrication plants, supply chains, and decades of embedded systems expertise; exactly what you need to build a sovereign local AI inference hardware industry.

What is missing is not the capability. It is the policy framework that treats this as a strategic priority. CADA should not be a regulation that audits cloud data centres. It should be an investment act that activates the European hardware supply chain to build the next generation of personal AI devices. The Chips Act 2.0, which the Commission published alongside CADA, is a step in the right direction. But getting silicon fabrication right is only half the equation. The other half is making sure that silicon ends up in devices that run AI locally; on hospital desks, in clinic examination rooms, on the phones in clinicians' pockets; not just in hyperscaler data centres.

Japan understood this dynamic. In the 1980s, when the personal computer market emerged, Japan did not try to regulate IBM mainframes harder. It invested in Toshiba, NEC, and Fujitsu to build laptops, memory chips, and displays. The result was a domestic hardware industry that captured the personal computing era. Europe has the same opportunity today with the local AI stack. What it needs is not mainframe-era regulation. It is personal-computer-era industrial policy.

And the evidence is accelerating faster than most analysts realize. In February 2025, DeepSeek demonstrated that open-weight models could compete with proprietary alternatives; nearly $600 billion was erased from US Big Tech valuations in a month. By April 2026, research confirmed that models under 10 billion parameters running on consumer-grade hardware could match or exceed massive cloud-based models on domain-specific tasks. In May, Apple and Google both committed to local, on-device AI as their primary strategy. By June 2026, the local AI hardware ecosystem had gone from research prototype to shipping product in a single season. The DGX Spark. The Coral dev board. Hermes Agent on local hardware. Every major player in the AI industry is now betting that the future of inference is local.

This is not a trend. This is a phase transition. The market is moving to local AI not because regulators demanded it, but because the engineering case is overwhelming: lower latency, higher privacy, predictable cost, offline resilience, and the ability to build specialized agents that understand local context without shipping sensitive data to a foreign data centre.

CADA needs to catch up to this reality. The regulation was drafted against an implicit assumption that advanced AI requires centralized cloud infrastructure controlled by a handful of companies. That assumption is now obsolete. When a hospital can run validated, certified AI agents on its own hardware; hardware that ships with built-in security primitives, auditable runtimes, and transparent model architectures; the entire cloud sovereignty framework CADA builds becomes a solution to a problem that local AI already solved, and solved better.

There is a deeper regulatory point here. For five years, European AI regulation; GDPR, MDR, the AI Act; has been criticized for creating compliance burdens that disproportionately harm European innovators while leaving US Big Tech relatively unscathed. Local AI hardware changes the calculus on all three. When the model runs on the device, GDPR compliance becomes an architectural feature, not a compliance cost; the data never leaves, so there is no "data transfer" to regulate. When every hospital can run AI on its own hardware, the AI Act's "deployer versus provider" distinction collapses; the hospital is both, the regulatory path becomes clean and auditable and local. Regulation designed for cloud monopolies becomes irrelevant when the monopolies get out-competed by open, local-first ecosystems. That is the regulatory breakthrough Europe has been waiting for since the GDPR was written. CADA should be the vehicle that delivers it, not the barrier that blocks it.

What Isaree Is Doing

We are submitting a position paper to the Commission, to Member State governments developing their national strategies, and to the relevant Parliament committees. Our recommendations are threefold:

  1. A definitional clarification that on-device AI agents processing data exclusively on user hardware fall outside the scope of "cloud computing services" under CADA.
  2. Recognition that architectural elimination of sovereignty risks (no remote infrastructure, no third-country access vector, no data transfer) constitutes an equivalent or superior assurance pathway.
  3. A healthcare-specific sandbox within the Cloud and AI Leadership Initiatives that funds and accelerates on-device clinical AI orchestration.

We are small and in alpha; 50 clinical innovators across 18 countries, with signed cooperations with some of the largest hospital providers, targeting 5,000 users by end of this year. We are a collective of forward-thinkers redefining what's possible. But we are also the only company building what Recital 21 describes: a sovereign agent orchestration platform that happens to run entirely on your own devices.

The local and personalized AI era is entering. CADA is the first major regulatory framework of that era. We have one chance to ensure it recognizes the full spectrum of sovereignty architectures, not just the ones that come with a data centre attached.


Isaree is an on-device AI agent platform enabling clinicians to build, own, and deploy personalized AI agents running entirely on their own devices; desktop or mobile. Founded in 2025, Isaree has signed cooperations with some of the largest hospital providers and works with a closed community of 50 clinical innovators from 18 countries. Contact: bart.dewitte@isaree.ai.

Subscribe to Isaree Newsletter

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe