Sovereign AI: running AI on your data without sending it away

Where the model runs, where the data sits, who can read it. We scope your use cases, then deploy what has to stay in-house. Scoping from €2,000.

What is sovereign AI?

Sovereign AI means AI where you control three things: where the model runs, where your data is stored, and the list of people and companies that can reach it. In this context the word is not political. It is a question of architecture and contracts.

It is not the same thing as a national model. A model trained in France but called through an API hosted outside the European Union does not make you sovereign. Conversely, an American open-source model running on your own servers sends no data anywhere. What matters is the path your data takes, not the nationality of the model.

The three options, and what they really cost

There are not four. Each one is the right answer in a specific case.

OptionWhat leaves your networkWhen it is the right choice
Public APIThe content of your prompts, to a third party often outside the EUNon-sensitive data, no personal data, individual use
Enterprise tier in an EU regionYour prompts, to a third party, under a processing agreement and a no-training commitmentMost cases: internal data, no trade secrets, a contract is enough
Self-hosted modelNothingHealth data, client data under a confidentiality agreement, trade secrets, sector obligations

The part suppliers leave out: self-hosting has a running cost. A model on your servers needs GPU, version upgrades, and somebody watching it. That is justified when the data demands it, not as a principle.

What GDPR actually requires

A lot of decisions get made on an approximate reading of the regulation. Here is the short and accurate version.

GDPR does not ban AI

It governs the processing of personal data. Using a language model is not illegal. Sending personal data to a processor with no legal basis, no contract and no notice to the people concerned is, whether the recipient is an AI or an online spreadsheet.

What you need in place

A legal basis for the processing, a data processing agreement with the supplier, data minimisation applied to what you send, and safeguards for transfers outside the European Union. The enterprise tiers of the large suppliers cover the contract, and often the location. They do not cover minimisation: that one stays your job.

Training on your data

This is the clause to read. Consumer tiers often use your conversations to improve the models. Enterprise tiers generally commit not to. The difference is contractual rather than technical, and it cannot be inferred from the price.

We are not lawyers and we do not write your processing register. We work on the technical half: what leaves, what stays, and how to prove it.

When self-hosting is the wrong answer

We would rather say so before quoting anything.

If your data is neither personal nor confidential

An enterprise tier in an EU region does the job for a fraction of the cost. That is the most common case, and it is what we recommend most often.

If nobody on your side can run a server

A self-hosted model becomes a liability. You need either a team or a maintenance contract, and that belongs in the budget from the first estimate.

If what you want is compliance theatre

We are not the right supplier. Self-hosting is justified by a real constraint, not by a sales argument.

What it costs

The answer depends entirely on which option you land on, so there is no grid specific to this topic. Here are the two existing entry points, with their already published rates.

FormatBudgetWhat you get
Express scoping€2,000 to €4,000Half a day on one specific use case. Which data it touches, which option fits, and what each one costs.
Full AI audit€6,000 to €12,000A map of your use cases, ranked by data sensitivity, with the architecture choice for each one.
Deploymentfrom €800 per daySetting it up, integrating it with your tools, and the documentation that lets your team take it over.

Scoping is often enough. In plenty of cases its conclusion is that an enterprise tier in an EU region solves the problem, and the engagement stops there.

Frequently asked questions

What is sovereign AI?

AI where you control where the model runs, where the data is stored, and which third parties can reach it. It is not defined by the nationality of the model but by the path your data takes. An American open-source model running on your servers is more sovereign than a French model called through an API hosted outside the European Union.

Is there a European sovereign AI option?

There are models published in Europe, and European hosts able to run them. The two do not automatically go together: a European model consumed through a foreign API gives you no location guarantee at all. The useful question is not where the model was made but where it executes and under what contract.

Is AI compatible with GDPR?

Yes, with conditions. GDPR does not ban AI, it governs the processing of personal data. You need a legal basis, a processing agreement with the supplier, minimisation of what you send, and safeguards for transfers outside the European Union. Enterprise tiers cover the contract and often the location, but never minimisation, which stays with you.

Can you use ChatGPT and stay GDPR compliant?

On an enterprise tier, yes, in most cases. It is the consumer tiers that cause the problem: they often use conversations to improve the models and offer no processing agreement. The clause to check is the one about training on your data. It is contractual and cannot be inferred from what you pay.

Which AI tool is GDPR compliant?

No tool is compliant by itself. Compliance depends on what you send it, the contract binding you to the supplier, and the notice given to the people concerned. The same tool can be used compliantly on anonymised data and non-compliantly on a customer file. It is the use that is compliant, not the software.

Should you host your own model?

Rarely, and that is what we answer most often. Self-hosting is justified when the data cannot leave: health, trade secrets, confidentiality commitments to your own clients, sector obligations. Otherwise an enterprise tier in an EU region covers the need for far less, and with no recurring running cost.

A confidentiality constraint on an AI project?

Tell us which data is involved. We will tell you which of the three options fits, including when it is not ours.

purple linear waves