Ask around, and you’ll find that regulation continues to be treated as a constraint on European technology. Something to interpret, navigate, and, oftentimes, complain about.
In cloud computing, this view is growing more outdated by the day. At Scaleway, we believe the next phase of European cloud adoption will not happen despite regulation, but because regulation is starting to create the conditions for trust, investment, and scale.
This is already visible at the national level. This year, Italy continued to formalize its €150 million Cloud & Cybersecurity Voucher scheme, which offers grants to help SMEs and self-employed professionals adopt cloud computing and cybersecurity services. By structuring access through a regulated provider framework, the program aims to lower the cost, complexity, and perceived risk of cloud adoption.
Meanwhile, in France, the SecNumCloud qualification issued by ANSSI has become the clearest expression of what trusted cloud means in practice. By setting a demanding standard for the security, resilience, and legal protection of sensitive workloads, it gives public institutions and highly regulated companies a clearer way to identify providers aligned with their needs.
The same pattern can be seen at the European level. In 2026, the Network and Information Security Directive 2 (NIS2) continued to raise cybersecurity expectations across critical sectors, making trusted cloud solutions a more central part of compliance. In June, the European Commission’s proposal for the Cloud and AI Development Act (CADA), which aims to “at least triple the EU’s data centre capacity within the next 5 to 7 years,” showed that regulation is increasingly understood as an industrial policy tool.
For cloud providers and customers alike, this changes the game. Clearer rules reduce uncertainty, stronger standards make it easier to compare providers, public incentives accelerate adoption, and capacity-focused regulation helps mobilize investment and orchestrate deployment.
Of course, this does not mean that every rule is perfect, or that compliance has somehow become simple. Every new framework still needs to be reviewed, understood, and reconciled with previous (and upcoming) ones — across sectors, internal policies, and technical architectures. If every country defines cloud trust in its own way, Europe may gain clarity inside each market while only creating new complexity across the continent.
That is why cloud regulation, like cloud ambition, must operate at European scale: with shared standards that make trust comparable and actually actionable across markets.
Explore the full VivaTech takeaways
At VivaTech 2026, one question stood out: how can Europe remain competitive by building and scaling more of its technology at home?
Our executive briefing brings together the key insights from four days of discussions on cloud, AI, infrastructure, and digital sovereignty — and explores what they mean for Europe’s technology ecosystem.
Download the Scaleway Briefing: VivaTech 2026 Takeaways.