Sovereign AI means AI where you control three things: where the model runs, where your data is stored, and the list of people and companies that can reach it. In this context the word is not political. It is a question of architecture and contracts.
It is not the same thing as a national model. A model trained in France but called through an API hosted outside the European Union does not make you sovereign. Conversely, an American open-source model running on your own servers sends no data anywhere. What matters is the path your data takes, not the nationality of the model.
There are not four. Each one is the right answer in a specific case.
| Option | What leaves your network | When it is the right choice |
|---|---|---|
| Public API | The content of your prompts, to a third party often outside the EU | Non-sensitive data, no personal data, individual use |
| Enterprise tier in an EU region | Your prompts, to a third party, under a processing agreement and a no-training commitment | Most cases: internal data, no trade secrets, a contract is enough |
| Self-hosted model | Nothing | Health data, client data under a confidentiality agreement, trade secrets, sector obligations |
The part suppliers leave out: self-hosting has a running cost. A model on your servers needs GPU, version upgrades, and somebody watching it. That is justified when the data demands it, not as a principle.
A lot of decisions get made on an approximate reading of the regulation. Here is the short and accurate version.
It governs the processing of personal data. Using a language model is not illegal. Sending personal data to a processor with no legal basis, no contract and no notice to the people concerned is, whether the recipient is an AI or an online spreadsheet.
A legal basis for the processing, a data processing agreement with the supplier, data minimisation applied to what you send, and safeguards for transfers outside the European Union. The enterprise tiers of the large suppliers cover the contract, and often the location. They do not cover minimisation: that one stays your job.
This is the clause to read. Consumer tiers often use your conversations to improve the models. Enterprise tiers generally commit not to. The difference is contractual rather than technical, and it cannot be inferred from the price.
We are not lawyers and we do not write your processing register. We work on the technical half: what leaves, what stays, and how to prove it.
We would rather say so before quoting anything.
An enterprise tier in an EU region does the job for a fraction of the cost. That is the most common case, and it is what we recommend most often.
A self-hosted model becomes a liability. You need either a team or a maintenance contract, and that belongs in the budget from the first estimate.
We are not the right supplier. Self-hosting is justified by a real constraint, not by a sales argument.
The answer depends entirely on which option you land on, so there is no grid specific to this topic. Here are the two existing entry points, with their already published rates.
| Format | Budget | What you get |
|---|---|---|
| Express scoping | €2,000 to €4,000 | Half a day on one specific use case. Which data it touches, which option fits, and what each one costs. |
| Full AI audit | €6,000 to €12,000 | A map of your use cases, ranked by data sensitivity, with the architecture choice for each one. |
| Deployment | from €800 per day | Setting it up, integrating it with your tools, and the documentation that lets your team take it over. |
Scoping is often enough. In plenty of cases its conclusion is that an enterprise tier in an EU region solves the problem, and the engagement stops there.
AI where you control where the model runs, where the data is stored, and which third parties can reach it. It is not defined by the nationality of the model but by the path your data takes. An American open-source model running on your servers is more sovereign than a French model called through an API hosted outside the European Union.
There are models published in Europe, and European hosts able to run them. The two do not automatically go together: a European model consumed through a foreign API gives you no location guarantee at all. The useful question is not where the model was made but where it executes and under what contract.
Yes, with conditions. GDPR does not ban AI, it governs the processing of personal data. You need a legal basis, a processing agreement with the supplier, minimisation of what you send, and safeguards for transfers outside the European Union. Enterprise tiers cover the contract and often the location, but never minimisation, which stays with you.
On an enterprise tier, yes, in most cases. It is the consumer tiers that cause the problem: they often use conversations to improve the models and offer no processing agreement. The clause to check is the one about training on your data. It is contractual and cannot be inferred from what you pay.
No tool is compliant by itself. Compliance depends on what you send it, the contract binding you to the supplier, and the notice given to the people concerned. The same tool can be used compliantly on anonymised data and non-compliantly on a customer file. It is the use that is compliant, not the software.
Rarely, and that is what we answer most often. Self-hosting is justified when the data cannot leave: health, trade secrets, confidentiality commitments to your own clients, sector obligations. Otherwise an enterprise tier in an EU region covers the need for far less, and with no recurring running cost.
Tell us which data is involved. We will tell you which of the three options fits, including when it is not ours.
