Sovereign AI and sovereign cloud

What is sovereign AI and sovereign cloud?

Sovereign AI and sovereign cloud are two names for one demand: that the models you use, the data they read and the machines they run on sit under European jurisdiction and European control. For a company it comes down to a plain question. If a foreign court orders your provider to produce something, or a government orders it to stop serving you, what happens next?

The term only becomes usable once you split it in three, because vendors answer these separately and rarely say which one they are answering.

Residency is where the bytes sit. A region in Frankfurt or Brussels settles it, and it is the easiest of the three to buy.

Sovereignty is whose law reaches the data and whose staff can reach the system. That follows the legal entity on your contract and the passports of the people with production access, not the location of the disk.

Control is who can switch it off or change the terms. A supplier that can be ordered to stop serving you, or that can retire the model your process was built on, holds that lever whatever the contract says about location.

A European region operated by a non-European company answers the first question cleanly and the other two only in part. Data residency and data sovereignty have their own entries here, so this one stays on the AI and cloud stack and on the buying question that comes with it.

The layers where sovereignty gets claimed

Every sovereignty claim is about a layer, and almost no vendor claims all four.

  • The datacentre and its operators. Where the building stands, who owns it, and which country the staff with physical access live in. Everybody has an answer for this one.

  • The control plane and administrative access. The systems that deploy, patch and monitor your environment, and the engineers who can reach production from a laptop elsewhere. Picking a region does nothing here, so this layer needs a commitment of its own.

  • The model weights and who trained them. Whether you can download the model and keep it, or only call somebody's endpoint. An open-weight model on your own hardware is the only version of this layer you fully own, and the strongest models are not available that way.

  • Support and the edges. Tickets with screenshots in them, telemetry, billing, identity, incident logs. These travel further than the workload does, and they are usually the first thing an auditor asks to see.

A claim that data stays in Europe covers the first layer. A claim that only EU residents approve remote access covers the second. Neither says anything about the third.

Residency versus sovereignty: who can be compelled to hand it over

The two get used as synonyms and they answer different questions. Set them next to each other on the dimension that decides things, compulsion, and the difference stops being semantic.

Residency asks where the data is. You settle it by picking a region and prove it with a configuration screen. It is a fact about geography.

Sovereignty asks who can be ordered to produce the data. You settle it by reading the legal entity on your contract and asking which courts can give that entity an order it has to obey. It is a fact about company law.

The US CLOUD Act of 2018 is the clearest case: it confirms that a US provider can be required through lawful process to produce data in its possession, custody or control, wherever that data is stored. Custody follows the company, not the disk. A US-parented provider running a datacentre in Belgium gives you European residency and stays reachable by a US order, while a Belgian host with no US parent is not reachable that way and is of course reachable by a Belgian one. The test takes a minute: read the entity name on your contract, look up where it is incorporated and who owns it, then do the same for its sub-processors.

What has actually shipped in Europe

AWS European Sovereign Cloud. Generally available since 15 January 2026, with a first region in Brandenburg that is physically and logically separate from other AWS regions. Around it sits a parent company and three subsidiaries incorporated in Germany as GmbH, led by EU citizens. Only EU residents located in the EU control day to day operations, including access to the datacentres, and AWS says the cloud has no critical dependencies on non-EU infrastructure and could keep running if communication with the rest of the world were cut. What none of that changes is who ultimately owns the group. The catalogue is also narrower than a mature region, because AWS opens a region with core services and expands from there.

Microsoft Sovereign Public Cloud. Sovereignty features layered on the existing Azure and Microsoft 365 regions rather than a separate cloud. Data Guardian means remote access by Microsoft staff to systems in the EU and EFTA is approved and monitored only by authorised Microsoft personnel resident in Europe, with a human approval step per request and every session written to a tamper-evident ledger. External key management keeps the encryption keys in your own hardware security module. The Sovereign Landing Zone is policy as code, so location and encryption rules are enforced by configuration rather than by intent. Alongside it Microsoft sells Sovereign Private Cloud on Azure Local, where the control plane runs on your own hardware, and works with national partner clouds such as Bleu in France and Delos Cloud in Germany.

European providers. OVHcloud is incorporated in France and sells SecNumCloud-qualified offerings, the French state qualification for trusted cloud, on the argument that a European company cannot be reached by an extraterritorial order at all. That is the strongest form of the claim and it comes with the smallest service list.

European models. Mistral AI is French, publishes several models under an open licence and documents self-deployment on runtimes such as vLLM, which puts the weights layer in your hands. Publicly funded work exists too. EuroLLM, co-funded by the EU, covers the 24 official EU languages under Apache 2.0. Teuken-7B from the German OpenGPT-X project covers the same 24 languages and ships in two instruction-tuned variants under different licences, a commercial one under Apache 2.0 and a research one that is non-commercial, which is the reminder that downloadable does not automatically mean usable at work. Neither model is at the frontier, so treat them as a real option for classification and extraction rather than a swap for the strongest hosted model.

The legal conflict a contract cannot settle

Underneath all of it is a conflict of laws that no clause resolves. EU law limits what may be handed to a foreign authority; foreign law with extraterritorial reach can order a company subject to it to hand something over. When both bind the same company, one of them gets broken.

So read what the contracts actually promise. The AWS European Sovereign Cloud Addendum commits AWS to redirect the requesting party to you, to notify you promptly where it is legally permitted, to seek a waiver where it is not, to challenge a request that conflicts with EU or member state law or is overbroad, and, if it still has to disclose, to disclose only the minimum needed. Those are procedural protections, and none of them is a promise never to disclose. Microsoft made a parallel commitment in April 2025: if ordered by any government to suspend or cease cloud operations in Europe it will promptly and vigorously contest the measure through all legal avenues including litigation, made binding through its contracts with European national governments and the European Commission. Those commitments are made in contracts with governments and the Commission, not in the contract an individual customer signs.

The limit was put plainly in June 2025, when the legal director of Microsoft France was asked at a French Senate hearing whether he could guarantee under oath that data of French citizens would never be passed to US authorities without the agreement of the French authorities. He answered that he could not guarantee it, and added that it had not happened. Any provider in the same legal position would answer the same way, which is why a sovereignty assessment ends in a documented risk decision rather than a certificate.

Answering a tender question about where your AI runs

A Flemish software company of forty people bids for work with a public body. One line in the questionnaire reads: describe where personal data is processed, by which legal entities, and whether any AI component processes data outside the EU. Three years ago that line was not there, and it is spreading down the supply chain, because a supplier who has answered it starts asking its own suppliers the same thing.

Their answer is built layer by layer and it stays short.

  1. Name the entity, not the brand. Their model calls go through a cloud provider, so the processor on their contract is that provider's European entity and the model vendor sits underneath as a sub-processor. Naming the model tells the buyer nothing about exposure. The entity does.

  2. Say where processing happens and what enforces it. A deployment type that keeps processing inside a named European zone is a stronger answer than a parameter somebody set once, so they name the mechanism as well as the value.

  3. State retention. Whether prompts and outputs are stored, for how long, and whether they are used for training. This is the point a buyer checks against the vendor's own documentation.

  4. Say what you cannot claim. The weights are not theirs and the vendor can retire the version they built on. They write that down, name the person who reads deprecation notices, and describe what they would move to.

They win or lose on the fourth point more often than on the first three. A questionnaire that answers everything perfectly reads as marketing.

What it costs, and where most companies land

The trade goes both ways, so it deserves stating without a thumb on the scale. A sovereign option usually costs more and usually lags: new sovereign regions open with core services and fill in over years, pinning inference to a geography can carry a surcharge, and the open European models you can host yourself sit behind the strongest hosted ones. Against that, some data may not leave and some terms may not be signable, and for that slice the comparison is not price against price. It is a workload you can run against one you cannot.

Check what the vendor actually sells before you promise a buyer anything. Anthropic's own API is a fair illustration: as of September 2026 the geography you can pin inference to is either the United States or global, there is no EU-only value, and the pinned option is priced at 1.1 times the standard rate.

For almost every company the answer is a split rather than a side. Classify first: which datasets actually carry the obligation, and which are ordinary business text that has quietly been treated like a state secret. Put the sensitive slice under the stricter arrangement, whether that is a sovereign region, a European provider or an open-weight model on your own hardware. Leave the rest where the capability is, with a processing agreement, a European region and a written retention position. Two things make that split hold: somebody owns the classification and reviews it when the business changes, and the split runs on a technical boundary rather than a line in a policy document. Separate keys, separate endpoints, separate accounts. A rule nobody can enforce is a rule your people will route around the first time the strict path is slower.

One thing to watch. The Commission proposed a Cloud and AI Development Act on 3 June 2026 that would put a single EU framework with four assurance levels behind all of this: EU infrastructure at level 1, independence from third countries and software supply chain transparency at level 2, EU ownership and control plus citizenship criteria for personnel at level 3, and full supply chain control with no third-country interference at level 4. Public bodies would assess each use case and buy at the matching level. It is a proposal in negotiation and not law, the levels are the part most likely to shift, and the vocabulary is already showing up in tenders.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
sovereign ai sovereign cloud data sovereignty data residency cloud act gdpr eu data act open-weight model local llm managed llm service eu regulation compliance