The EU Data Act Forces a Cloud Switching Reckoning

The EU Data Act has been in force since September 12, 2025, and the first wave of compliance obligations is already active. Cloud switching provisions apply to new contracts today. But the bigger deadlines are still ahead: September 2026 brings "data by design" requirements and enhanced cloud interoperability rules, and January 2027 bans switching fees entirely. EU companies still running on US cloud providers are running out of runway.
What Has Already Changed
Three major provisions are now active under the Data Act:
- Articles 4-5: Data access and sharing. Users of connected products and digital services can demand access to data those products generate, in real time where technically feasible. They can also direct that data to third parties. This covers both personal and non-personal data.
- Cloud switching for new contracts. Providers of data processing services must include switching provisions in new customer contracts, allowing data transfer to another provider within 30 days.
- Mandatory contract terms. Cloud contracts must allow termination on short notice. Fixed-term commitments are effectively overridden once a customer requests to switch.
These rules apply across all three layers of cloud computing:
| Service Type | Examples | Switching Requirement |
|---|---|---|
| IaaS | Storage, compute, rented servers | Full data export within 30 days |
| PaaS | Managed databases, deployment platforms | Structured data and config transfer |
| SaaS | Hosted applications, AI API services | Complete data portability support |
What Is Coming: The 2026-2027 Deadlines
The September 2025 obligations were the first wave. Three more compliance deadlines are approaching fast, and each one raises the bar.
| Deadline | Requirement | Impact |
|---|---|---|
| September 12, 2026 | "Data by design" obligations | Connected products placed on the EU market after this date must be designed so users can access their data easily and free of charge, with direct access required where technically feasible |
| September 12, 2026 | Enhanced cloud interoperability | Cloud services must meet higher interoperability standards, making it technically simpler to switch between providers |
| January 12, 2027 | Complete ban on switching charges | Providers may no longer charge any fees for switching between data processing services |
| September 12, 2027 | Full data portability standards | Standardized portability requirements take effect; unfair contract terms rules extend to pre-2025 contracts |
The January 2027 ban on switching charges is particularly significant. Today, providers can still charge "reasonable" fees for facilitating a switch. After January 12, 2027, even that exception disappears. Combined with the enhanced interoperability requirements arriving in September 2026, the technical and financial barriers to switching are being systematically dismantled.
The September 2027 deadline also pulls pre-existing contracts into scope. Companies that thought their long-term agreements were grandfathered will find that unfair terms become unenforceable, and switching rights apply retroactively.
Why US Providers Are a Growing Liability
US-headquartered cloud and AI providers face a compounding set of risks that have only intensified since the Data Act took effect:
Jurisdictional conflict. The US CLOUD Act allows US authorities to compel US-based providers to disclose data stored anywhere in the world, including EU data centers. This directly conflicts with GDPR Article 48, which restricts transfers of personal data to third-country authorities unless covered by an international agreement. When a US provider receives a US government data request covering EU customer data, there is no clean legal resolution.
Schrems II remains unresolved. The Schrems II ruling (C-311/18) invalidated the Privacy Shield framework. Its successor, the EU-US Data Privacy Framework, faces ongoing legal challenges. EU companies relying on US providers for data processing remain exposed to future invalidation.
Switching friction. The Data Act demands that providers actively assist customers in switching, including supporting exit strategies and providing comprehensive data exports. US providers built on proprietary APIs and tightly integrated ecosystems have a structural incentive to make switching difficult, which the Data Act penalizes. The enhanced interoperability requirements arriving in September 2026 will make non-compliance with switching assistance even more consequential.
Subprocessor transparency. The Data Act, like the GDPR before it, requires clear disclosure of who processes data and where. US providers with complex, opaque subprocessor chains, including subprocessors subject to US government access, create compliance gaps that EU regulators are scrutinizing with increasing intensity.
The AI Inference Angle
AI API services fall squarely within the Data Act's definition of "data processing services." Every prompt sent to an AI model, every completion returned, and every log of that interaction constitutes data covered by the regulation.
For EU companies using AI APIs from US providers, the risks are concrete:
- Prompts may contain proprietary business data, customer data, or trade secrets
- Completions may be logged in US data centers, subject to US government access
- Switching between AI providers is technically difficult due to proprietary model APIs and prompt formats
- The Data Act's 30-day switching requirement means EU companies must maintain the ability to change AI providers quickly
The OpenAI-compatible API standard offers a practical solution here. If a provider supports the OpenAI chat completions format, switching requires changing a base URL and API key rather than rewriting application code. This is precisely the architecture that makes rapid switching technically feasible as the Data Act demands, and it positions providers using this standard well for the enhanced interoperability requirements arriving in September 2026.
Enforcement and Penalty Exposure
Each EU Member State appoints a national authority to enforce the Data Act, with the power to investigate, fine, and order corrective actions. Where personal data is involved, existing data protection authorities take the lead.
Penalties are substantial. Germany can impose fines up to EUR 5 million or 4% of global annual turnover, whichever is higher. France can reach 5% for repeat violations. If personal data is implicated, GDPR penalties stack on top. Civil litigation, including collective lawsuits similar to US class actions, is explicitly enabled under the Data Act.
Enforcement is expected to ramp up through 2026 as national authorities complete their setup and begin proactive investigations. Companies that treated the September 2025 deadline as a soft launch should expect regulators to take a harder line as the 2026 and 2027 deadlines approach.
What EU Companies Should Do Now
The first compliance deadline has passed. Companies still on US providers need to move from planning to execution.
Audit current contracts. Identify every cloud and data processing service used in the EU. Map which contracts contain lock-in clauses, minimum terms, or excessive exit fees. These terms are already voidable under the Data Act for new contracts, and will be for all contracts by September 2027.
Evaluate switching readiness. For each provider, assess how long it would take to export all data and transition to an alternative. If the answer exceeds 30 days, the current setup does not comply.
Prioritize EU-jurisdiction providers. Providers incorporated in the EU, operating EU data centers, and subject to EU law eliminate the jurisdictional conflicts that complicate both the Data Act and the GDPR. This is not about performance or cost. It is about avoiding the structural legal tension of relying on a provider whose home government claims extraterritorial access rights.
Demand Zero Data Retention. For AI inference specifically, verify that prompts and completions are not stored by any provider or subprocessor. If a provider retains inference data, that data becomes subject to Data Act access rights, GDPR obligations, and potential US government access simultaneously.
Moving to EU-Native Infrastructure
For AI inference, the combination of the Data Act, GDPR, and the lingering uncertainty around US data transfer frameworks makes a strong case for EU-native providers. An EU-only inference gateway ensures that every subprocessor is vetted for EU incorporation, EU data center operations, and EU legal jurisdiction, which addresses the core jurisdictional conflict at the root of both the Data Act and GDPR compliance risk.
ozeye provides exactly this: EU-only inference with Zero Data Retention, an OpenAI-compatible API that enables the 30-day switching the Data Act demands, and a published subprocessor list that satisfies the transparency requirements both regulations require.
The Data Act does not ban US providers outright. But with each passing deadline, the compliance cost of staying on a US provider grows while the switching cost shrinks. Companies that move now avoid the squeeze.