Sovereign AI for business: the four layers that decide who controls your data
By the E-Solutions Web editorial team. Published , updated . How we write
The short answer
For a company, sovereign AI means keeping control over four things: where data is processed, which country’s laws can reach it, which model runs and who can change it, and who operates the system. Hosting in Europe covers only the first. A provider can store data in Frankfurt and still be bound by a foreign law. Each of the four needs an answer you can check in a contract.
Sovereign AI: two meanings of one word
“Sovereign AI” means one thing for a country and another for a company, and most confusion comes from mixing the two. In the national sense, it describes a state’s capacity to build and run AI on its own terms. The chip maker NVIDIA, for instance, describes models “trained and fine-tuned with local data, hosted and run on local infrastructure, subject only to local laws.” That is an industrial policy goal, measured in data centers, research budgets and skills.
A company’s question is narrower and more practical: can we put sensitive work into an AI system without losing control of it? Control here has several dimensions. Where are prompts, documents and answers processed? Which authorities, in which country, can legally demand them? Which model runs, and can someone else change it overnight? Who holds administrator access? And if the provider raises prices or changes its terms, can we leave?
This guide uses the company meaning. It does not grade providers and it does not promise that any setup is “fully sovereign.” It gives you the questions that separate a marketing label from a verifiable arrangement.
The four layers to check
A sovereign setup is one where you have an acceptable answer at every layer, and the weakest layer sets the level of the whole. The European Commission reasons the same way in its own Cloud Sovereignty Framework, first presented in October 2025 for a cloud tender for EU institutions. It breaks sovereignty into eight objectives, from strategic and legal to supply chain and technology, rates each on a scale from SEAL-0 to SEAL-4, and takes the lowest rating across objectives as the overall level. For an AI project, four layers cover most of what matters.
| Layer | The question | What counts as evidence |
|---|---|---|
| Hosting | Where are data, prompts, answers and logs processed and stored? | Named regions and data centers in the contract, including backups and support tools |
| Jurisdiction | Which country’s laws can compel the provider, and its parent company, to hand data over? | Registered office and ownership of the provider and every subcontractor that can reach the data |
| Model | Who decides which model runs, which version, and on what terms? | Open weights you can host, or a contract that fixes versions and forbids training on your data |
| Operations | Who administers, supports and monitors the system, from where? | Named operators, access logs you can read, an exit plan with data and configuration returned |
Each layer can be strong while another is weak. A model you host yourself, operated by a team you trust, still leaks sovereignty if its logs are shipped to a monitoring service governed by another country’s law. Mapping all four is the actual work, and the table above is a starting grid.
European hosting and foreign law: two separate questions
Where the servers sit and which law governs the provider are two separate questions, and a European data center answers only the first. The US CLOUD Act, enacted in March 2018, added a sentence to federal law, now 18 U.S.C. § 2713, that requires providers of electronic communication or remote computing services to disclose data “within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.”
European law pushes the other way. Article 48 of the GDPR provides that a judgment of a foreign court, or a decision of a foreign administrative authority, requiring a company to transfer or disclose personal data can be recognized or enforced only if it is based on an international agreement, such as a mutual legal assistance treaty, in force between that country and the EU or a member state. A provider subject to both laws can therefore face contradictory obligations. Sovereignty requirements exist to remove that tension.
For routine transfers of personal data to the United States, the current legal basis is the EU-US Data Privacy Framework, an adequacy decision adopted by the Commission on July 10, 2023. On September 3, 2025, the EU General Court dismissed an action seeking its annulment. An appeal against that judgment was lodged on October 31, 2025 and published in the Official Journal on December 22, 2025 as Case C-703/25 P. The previous two EU-US frameworks were both invalidated by the Court of Justice, so the case is worth following. Transfers are only one of the duties the GDPR sets for a company that uses AI; our guide to GDPR and AI covers the others.
Models: open weights, APIs, and who holds the switch
The model layer is about control over change: who can alter, withdraw or reprice the model your processes depend on. With a model reached through a vendor’s API, the vendor decides when versions change and on what terms. That can be perfectly acceptable for low-sensitivity tasks, provided the contract fixes how your data may be used.
With an open-weight model, you download the weights and run them where you choose. The version stays fixed until you decide to change it, and nothing leaves your perimeter unless you send it. Mistral AI states in its documentation that it “develops, or makes available, open-weight and commercial large language models,” and lists several of them under the Apache 2.0 license. Other open-weight families exist, with different license terms, and a license is always checked for the intended use before a model is chosen.
Open weights are not a quality guarantee, and they do not tell you what data the model was trained on. The only reliable way to choose is to test candidate models on your own tasks and keep the smallest one that does the job well. Our private LLM service works that way: models are compared on your cases, then deployed on your servers or in an EU cloud you choose.
What formal yardsticks exist
No single legal definition of “sovereign AI” applies to companies, but a few public yardsticks turn the idea into checkable criteria. Two are worth knowing, even if you are not a public body.
France’s national cybersecurity agency, ANSSI, runs the SecNumCloud qualification for cloud providers. Version 3.2 of its requirements, dated March 8, 2022, mainly added criteria for protection against non-European law. It requires the provider’s registered office and main establishment to be in an EU member state, caps ownership by entities based outside the EU at 24% individually and 39% collectively, and requires that non-EU subcontractors have no technical ability to obtain the data processed through the service. A French order of August 12, 2026, published in the Journal officiel on August 14, 2026, approves this reference framework for commercial cloud providers that process particularly sensitive data of French state administrations, state operators and public interest groupings.
The Commission’s Cloud Sovereignty Framework is the second yardstick. In its April 2026 announcement, the Commission explains that providers had to reach SEAL-2, the level it calls data sovereignty, to be eligible for its tender. Its eight objectives make a useful checklist for any buyer, even outside public procurement.
Neither is an AI-specific standard. Both are ways to ask the jurisdiction and operations questions with precision.
What “sovereign” does not mean
A sovereign setup reduces legal and dependency risks; it says nothing on its own about security, quality or compliance. Four misunderstandings come up often.
- Security is a separate job. A system can be entirely European and poorly secured. Access control, encryption, logging and incident response still have to be designed and tested.
- AI Act compliance is a separate question. The EU AI Act applies to the use you make of AI wherever the model runs. Our guide to EU AI Act compliance covers what a company that deploys AI must do.
- Full independence is rarely the goal. It would mean European control of every component, from chips to operating systems. The Commission’s scale reserves its top level, SEAL-4, for “technology and operations under complete EU control,” which shows how demanding that is.
- The arrangement can change. Ownership changes, subcontractors change, laws change. Contracts should require the provider to tell you when something that affects your requirements changes, as SecNumCloud does with a one-month notice.
Reversibility deserves a separate line. Being able to leave is part of control. The EU Data Act, which has applied since September 12, 2025, provides that from January 12, 2027 providers of data processing services may no longer charge customers for switching. Check that your exit plan covers the AI layer too: prompts, configurations, evaluation sets and the document index, as well as the raw files.
How to decide the level you need
Set the requirement by the data the AI will touch, whatever the vendor calls its offer. Most companies do not need maximum sovereignty for everything, and paying for it everywhere delays the projects that matter.
Start by sorting the data the AI will touch into three groups. Public or low-sensitivity content, such as published product information, can often use a mainstream API under a contract that excludes training on your data. Internal content, such as procedures, tickets or sales records, usually calls for EU hosting and a provider whose jurisdiction you have examined. Sensitive content, such as HR files, unpublished financials, source code or data covered by sector rules, points to a model you host, in your data center or in a qualified European cloud, operated by people you can name.
Then write the requirement down, layer by layer, and ask each supplier to answer in writing with evidence. If the use case is an assistant over internal documents, our guide on how RAG works explains where the data flows, and you can see such an assistant answer with its sources in the live demo. If you are unsure where to begin, an AI readiness assessment maps your use cases against these data groups before any build starts.
Keep your data under your control from the first project
For the internal and sensitive groups, the most direct route is a model you host yourself. A private LLM runs open-weight models in an EU cloud you choose or on your own servers, so prompts, documents and logs stay where you decide, in Europe or in your own data center, and the version only changes when you say so. Our guide to EU AI Act compliance then covers the duties that apply whatever the hosting.
Bring your list of data and use cases to a free 30-minute assessment. We tell you which layer needs attention first and what level of control each project really calls for, then fix the scope and price in writing before any work starts. Book your free 30-minute assessment: we reply within one business day.
Frequently asked questions
What is sovereign AI?
The term has two uses. For governments, it means a country’s ability to build and run AI with its own infrastructure, data and skills. For a company, it means control over its AI systems: where data is processed, which jurisdictions can demand access, which models run, who operates them, and whether it can leave a provider without losing its work.
Who controls sovereign AI?
Whoever controls each layer. The host controls the machines, the provider’s home jurisdiction determines which authorities can compel disclosure, the model publisher controls versions and license terms, and the operator holds the administrator access. A system is only as sovereign as its least controlled layer, which is also how the European Commission scores cloud offers in its own sovereignty framework.
Is data hosted in the EU protected from US law?
Not automatically. Since 2018, US law requires covered providers to disclose data in their possession, custody or control regardless of whether it is located inside or outside the United States. What matters is who controls the data, wherever it sits. The GDPR, for its part, restricts disclosures ordered by foreign authorities without an international agreement.
Is an open-weight model automatically sovereign?
No, but it helps. Open weights let you run the model on infrastructure you choose, keep a fixed version and stop depending on a vendor’s API terms. Sovereignty still depends on where you host it, who operates it and whether the license fits your use. Check the license of each model, since open-weight families do not all use the same terms.
What is a sovereign AI agent?
An AI agent whose model, data, tools and logs all stay under the control you require: hosted where you decide, operated by people and companies under a jurisdiction you accept, with a model version you choose. Because an agent acts in your systems, the question of who can reach its credentials and logs matters as much as where the model runs.
Sources
- How Nations Are Deploying AI for Strategic Priorities, NVIDIA Blog, published 2026-07-06, accessed 2026-09-30.
- Cloud Sovereignty Framework: Implementation guidance, European Commission, accessed 2026-09-30.
- Commission advances cloud sovereignty through strategic procurement, European Commission, published 2026-04-17, accessed 2026-09-30.
- 18 U.S. Code § 2713, Required preservation and disclosure of communications and records, Legal Information Institute, Cornell Law School, accessed 2026-09-30.
- Promoting Public Safety, Privacy, and the Rule of Law Around the World: The Purpose and Impact of the CLOUD Act, U.S. Department of Justice, April 2019, accessed 2026-09-30.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 48, EUR-Lex, Publications Office of the European Union, published 2016-05-04, accessed 2026-09-30.
- Press release No 106/25: the General Court dismisses an action for annulment of the new framework for the transfer of personal data between the European Union and the United States, Court of Justice of the European Union, published 2025-09-03, accessed 2026-09-30.
- Appeal brought on 31 October 2025 against the judgment of the General Court in Case T-553/23 (Case C-703/25 P), Official Journal of the European Union, C/2025/6610, published 2025-12-22, accessed 2026-09-30.
- Prestataires de services d’informatique en nuage (SecNumCloud), référentiel d’exigences, version 3.2, ANSSI (French National Cybersecurity Agency), version of 2022-03-08, accessed 2026-09-30.
- Arrêté du 12 août 2026 portant approbation du référentiel d’exigences relatif aux prestataires de services d’informatique en nuage, Légifrance, Journal officiel de la République française n° 0189, published 2026-08-14, accessed 2026-09-30.
- Models, Mistral AI documentation, accessed 2026-10-01.
- Regulation (EU) 2023/2854 (Data Act), EUR-Lex, Publications Office of the European Union, published 2023-12-22, accessed 2026-09-30.