The EU Cloud Sovereignty Framework (SEAL) Explained for AI Buyers
SEAL-0 to SEAL-4 explained: how the EU's Cloud Sovereignty Framework scores providers, who won Cloud III, and what it means for AI buyers.
Key takeaways
- ✓SEAL (Sovereignty Effectiveness Assurance Level) is the European Commission's official scoring system for cloud sovereignty, running from SEAL-0 (no sovereignty) to SEAL-4 (full EU supply chain control).
- ✓In April 2026 the Commission awarded €180 million in Cloud III contracts to four providers: Post Telecom/OVHcloud/CleverCloud, STACKIT, Scaleway (all SEAL-3), and Proximus/S3NS/Clarence/Mistral (SEAL-2).
- ✓SEAL-2 — Data Sovereignty — was the minimum eligibility bar: EU law applies without extra technical workarounds, but material dependencies on non-EU technology remain.
- ✓The framework is Union-entity procurement guidance, not law binding every private buyer — but it is rapidly becoming the reference vocabulary regulated European organizations use to evaluate any cloud or AI vendor, including non-EU-institution buyers.
What SEAL Actually Measures
The European Commission's Cloud Sovereignty Framework — first published in October 2025 as part of the Cloud III Dynamic Purchasing System tender — translates "digital sovereignty" into a measurable procurement scorecard. It scores providers on 48 specific criteria across eight objectives: strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability.
Two outputs come out of that scoring:
- A Global Sovereignty Score — the aggregate across all 48 criteria.
- A Sovereignty Effectiveness Assurance Level (SEAL) — a threshold rating from SEAL-0 to SEAL-4 that summarizes how much control non-EU third parties retain over the service.
The Five SEAL Levels
| Level | Name | What it means |
|---|---|---|
| SEAL-0 | No Sovereignty | Service, technology, or operations under exclusive control of non-EU third parties, governed entirely by non-EU jurisdictions. |
| SEAL-1 | Jurisdictional Sovereignty | EU law formally applies, but enforceability is limited; the service remains under exclusive non-EU control. |
| SEAL-2 | Data Sovereignty | EU jurisdiction applies and material dependencies on non-EU technology remain; the service is under indirect non-EU control. This is the minimum bar for Cloud III eligibility. |
| SEAL-3 | Technological Sovereignty | EU actors exercise meaningful — but not full — influence; non-EU control is marginal, not structural. |
| SEAL-4 | Full Digital Sovereignty | Technology and operations under complete EU control, subject only to EU jurisdiction, with no critical non-EU dependencies — full supply chain, from chips to software. |
Who Was Awarded, and at What Level
The Commission's first Cloud III award (April 2026, €180 million over six years, for EU institutions' own cloud procurement) went to four providers:
- Post Telecom, with partners CleverCloud and OVHcloud — SEAL-3
- STACKIT (Schwarz Group, Germany) — SEAL-3
- Scaleway (Iliad Group, France) — SEAL-3
- Proximus, with S3NS (a Thales/Google Cloud joint venture), Clarence, and Mistral — SEAL-2
The Proximus/S3NS result is the instructive one: even with EU corporate structuring, a technology stack built on a non-EU hyperscaler's underlying platform caps out at SEAL-2, not SEAL-3 or SEAL-4. Ownership of the corporate entity is necessary but not sufficient — the technology stack itself has to be free of critical non-EU dependencies to score higher.
What SEAL Means If You Are Not an EU Institution
The Cloud III tender only governs procurement for EU institutions themselves. It does not directly bind a Dutch municipality, a German hospital, or a private bank. But three things make SEAL relevant well beyond that tender:
- It is now the reference vocabulary. Procurement teams, security reviewers, and consultancies increasingly ask vendors "what SEAL level would you score?" as shorthand for a question that used to take a paragraph to ask.
- National frameworks are converging on the same logic. The Dutch BIO2, France's SecNumCloud, and Germany's C5 all evaluate variations of the same question — legal jurisdiction, technical control, supply-chain dependency — that SEAL formalizes at the EU level.
- It exposes the "sovereign-washing" gap. A provider can hold ISO 27001 certification, run an EU-region data center, and still score SEAL-1 or SEAL-2 if the parent entity and underlying technology stack remain non-EU controlled. SEAL gives buyers precise language to ask the follow-up question hyperscaler sales teams would rather skip.
Applying SEAL to an AI Vendor Evaluation
When evaluating an AI platform against SEAL-style criteria, ask for evidence — not assurances — on:
- Legal jurisdiction: Where is the operating entity incorporated, and which government's law enforcement can compel data access?
- Technology stack ownership: Does the platform run on the vendor's own infrastructure, or is it a wrapper over a non-EU hyperscaler (as with S3NS/Google Cloud)?
- Data and AI control: Does training, fine-tuning, and inference data stay under your tenant's control, or does it transit a non-EU-controlled model API?
- Supply chain transparency: Can the vendor name its subprocessors, hardware suppliers, and model providers — and are those EU-domiciled?
- Operational resilience: Could the service continue operating if political or legal pressure on a non-EU parent company forced a shutdown or access request?
NeuroCluster is a European-owned, European-operated entity running its own infrastructure stack — the SEAL-4 end of the spectrum in practice, not just on paper. See how that maps to a specific deployment on the sovereign AI cloud in Europe pillar guide, or compare named providers directly on the European sovereign cloud providers comparison.
Frequently asked questions
Is SEAL a legal requirement for private companies?+
No. SEAL is part of the Cloud Sovereignty Framework the European Commission built to procure cloud services for its own institutions under the Cloud III Dynamic Purchasing System. Private companies and non-EU-institution public bodies are not legally bound by it — but it is fast becoming the shared vocabulary procurement and security teams use to evaluate any vendor's sovereignty claims.
What SEAL level did the Cloud III awardees achieve?+
Post Telecom (with OVHcloud and CleverCloud), STACKIT, and Scaleway each achieved SEAL-3 (Technological Sovereignty). Proximus, partnered with S3NS (a Thales/Google Cloud joint venture), Clarence, and Mistral, achieved SEAL-2 (Data Sovereignty) — the minimum eligibility threshold.
Can a provider with a Google or US technology dependency still score well on SEAL?+
It can reach SEAL-2, the Data Sovereignty threshold, if EU law applies without requiring extra technical workarounds. But SEAL-3 and SEAL-4 require EU actors to exercise meaningful-to-full control over the technology stack — a dependency on a non-EU hyperscaler's underlying platform structurally caps the achievable level, as the Proximus/S3NS result shows.
How does SEAL relate to the Dutch BIO2 or Germany's C5?+
They are complementary, not identical. BIO2 and C5 are national security-control baselines; SEAL is an EU-level sovereignty scorecard focused on jurisdiction, ownership, and supply-chain control. In practice, a vendor targeting regulated European buyers needs to satisfy both: the national security baseline and the sovereignty question SEAL formalizes.
Stay ahead of European AI regulation
See how EU AI Act readiness — logging, human oversight, and audit evidence — is built into the NeuroCluster platform.
Explore EU AI Act readiness