Informa helps businesses and professionals in hundreds of ways.

Our international portfolio of live events, world-leading research publications, and innovative digital services provide specialists with the knowledge and connections they need to thrive.

Data Center World Europe
13-14 October 2026
VIECON – Vienna Congress & Convention CenterVienna, Austria
What EU Regulation Requires of Your Sovereign AI Data Centre Infrastructure

The conversation about sovereign AI data centre infrastructure in Europe has reached an inflection point. We know how to build it, we have the capital structures to finance it, and we understand the delivery timelines and the physical capacity requirements.

But what needs to happen once that infrastructure is live, how does the EU regulatory environment require from operators to demonstrate, and what will their enterprise customers come asking for?

This October at Data Center World Europe in Vienna, we’ll be addressing this question on the panel What EU regulation requires of sovereign AI infrastructure.

Rajiv Dalal, moderator for the panel on this topic, is a researcher, speaker, author and advisor specialising in AI governability in critical systems and the frameworks governing them in regulated industries.

When Rajiv and I spoke, he outlined the three key developments which are shaping the decisions of every enterprise deploying AI workloads on European infrastructure, and the questions these enterprises are bringing to their infrastructure providers.


NIS2: Cybersecurity Rules Already in Force, Directly Applicable

The Network and Information Security Directive 2 (NIS2) explicitly names data centre operators as essential entities. Adopted at the EU level in 2023, NIS2 is a directive rather than a regulation, meaning it requires individual nations to pass their own local laws to enforce it. While the official EU implementation deadline has passed, the rollout timeline varies across Europe due to regional legislative delays. Once active in a country, these national legal frameworks mandate four operational dimensions for data centres that go well beyond documentation:

  • Risk management that is demonstrably operational and tested under real conditions
  • Cybersecurity incident reporting within 24 hours (early warning) and 72 hours (full notification) to national competent authorities
  • Supply chain security assessments covering every vendor, software provider, and infrastructure component in the stack
  • Personal liability for board members and senior executives

That last point is the most significant new element introduced by NIS2. The question has shifted from "does our organisation comply?" to "can a named executive demonstrate, under regulatory scrutiny, that they personally understood and approved the security posture of the systems they authorised?"


The EU AI Act: High-Risk Provisions Applicable from August 2026

The EU AI Act's obligations for providers of what’s classified as “high-risk AI” become fully applicable in August 2026, two months before Data Center World Europe convenes in Vienna. While the Act primarily targets deployers of AI systems, it creates direct supply chain obligations for infrastructure providers.

Enterprise customers deploying high-risk AI workloads will be required to demonstrate conformity assessments, human oversight mechanisms, and technical documentation. Organizations will come to their AI infrastructure providers asking: Can you support our compliance obligations? Can you adequately demonstrate the resilience, security, and auditability of the infrastructure on which our regulated AI systems run?

Operators who can answer those questions credibly will win and keep enterprise contracts. Those who cannot will find themselves excluded from the most valuable AI workloads in the European market.


Data Sovereignty Implications: CLOUD Act and GDPR

Many of the neoclouds and sovereign AI infrastructure providers building European capacity are US-incorporated entities. This creates significant implications for data sovereignty in Europe: the US CLOUD Act compels US companies to produce data stored anywhere in the world, including EU data centres, at the request of US law enforcement. GDPR prohibits the transfer of EU personal data to jurisdictions without adequate protections.

The EU Cloud and AI Development Act is designed to address these sovereignty concerns directly, establishing frameworks for European cloud infrastructure to operate under European jurisdiction.

US-incorporated operators running European data centres are navigating these implications right now and their enterprise customers, particularly those in healthcare, financial services, and public administration, are asking questions about the sovereignty of their European infrastructure.


Why This Matters Now

The EU AI Act's high-risk provisions take full effect in August 2026. NIS2 is already in force and enforcement is beginning across member states. The EU Cloud and AI Development Act will establish the frameworks that define what European cloud sovereignty means in practice. The enterprise customers of Data Center World Europe's audience are coming to their infrastructure providers with compliance questions that the industry has not yet collectively addressed.

Our conference session gives data centre operators and builders the regulatory clarity, peer experience, and practical framework they need to be a governance asset for their enterprise customers and not a governance liability. For enterprise data centre operators, it will provide clear questions they need to be prepared to answer about their AI workloads. All of that is a competitive differentiator in the European AI infrastructure market.

Join us in Vienna October 13-14 to discuss this and many other practical operations topics with peers in the data centre, power, and regulatory ecosystem.