Enterprise AI
Sovereign AI: keeping your company's AI inside the EU
Why data residency is not data sovereignty, what the US CLOUD Act actually says, and how EU-hosted open-weight models make sovereign AI practical — with a live demo you can test.
Ask a cloud vendor where your data lives and you will get a reassuring answer: an EU region, an EU data centre, maybe even one in Luxembourg. Ask a different question — who can be legally compelled to hand that data over, and under which country's law? — and the answer gets more complicated. That difference is the difference between data residency and data sovereignty, and for companies deploying AI in Luxembourg it is worth understanding precisely.
Residency is geography. Sovereignty is jurisdiction.
Data residency means your data is physically stored in a given place — say, Frankfurt or Luxembourg. Data sovereignty means your data is subject only to the laws you expect it to be subject to, and controlled by entities within that legal order.
An AI system can have perfect EU residency and still fall under non-EU jurisdiction. If the provider operating your AI stack is subject to another country's law, where the servers sit is not the whole story. For AI specifically, the question extends beyond storage: prompts, retrieved documents, embeddings and model outputs all flow through whoever operates the model endpoint.
The CLOUD Act, stated factually
The US Clarifying Lawful Overseas Use of Data (CLOUD) Act, enacted in March 2018, allows US authorities — with appropriate legal process, such as a warrant — to require providers subject to US jurisdiction to disclose data in their possession, custody or control regardless of where that data is stored. Storing data in an EU region of a US-headquartered provider does not, by itself, place it outside the reach of this mechanism.
Two things should be said with equal clarity. First, this is not a claim that US providers routinely hand over European corporate data — such disclosures follow legal process, providers do challenge requests, and the EU–US Data Privacy Framework (adopted by the European Commission in 2023) currently provides a lawful transfer basis, though its predecessors (Safe Harbor, Privacy Shield) were both struck down by the Court of Justice of the EU, most recently in the 2020 Schrems II judgment. Second, none of this is hypothetical for a compliance officer: your DPO has to reason about these scenarios in a DPIA whether they are likely or not.
A sovereign design changes the nature of that analysis. When your models run on EU infrastructure operated by EU entities — or on your own hardware — there is no transatlantic transfer to justify and no foreign compulsion scenario to model. The question does not get a better answer; it disappears.
What has changed: EU-grade models are now genuinely good
For years the honest objection to sovereign AI was capability: the best models were only available as US-operated APIs. That has changed on two fronts.
- European model developers. Mistral AI, headquartered in Paris, publishes models — including open-weight releases under permissive licences — that are competitive for the large majority of enterprise tasks: document understanding, retrieval-augmented generation, extraction, multilingual chat. Other open-weight model families can likewise be operated entirely under your control.
- EU hosting options. Open-weight models can run on European cloud providers subject to EU jurisdiction, on EU regions with contractual and technical safeguards, or on-premise. The deployment spectrum runs from fully self-hosted (maximum sovereignty, more operational work) to EU-operated managed inference (less work, still no US-jurisdiction endpoint in the data path).
The practical consequence: for most Luxembourg use cases — internal assistants, document Q&A, structured extraction, customer-facing chat in multiple languages — you no longer trade meaningful capability for sovereignty. The exceptions exist at the frontier of model capability, and an honest assessment names them rather than pretending the trade-off is always zero.
Not a theory: our live, public proof
We would rather show this than assert it. The Legilux demo in our playground is a sovereign AI system you can try right now, free, on yet.lu:
- Luxembourg open data. It queries the Legilux SPARQL endpoint — Luxembourg's Journal officiel as open data on data.public.lu — in real time. It is a registered open-data reuse.
- An EU-hosted model. The answers are generated by an EU-hosted model — no US-jurisdiction API in the loop.
- Grounded, cited answers. Ask a question about Luxembourg legislation in any language and it finds the matching acts, reads them, and answers with numbered citations pointing back to the official texts. The official text always prevails.
Every layer — data source, model, hosting — sits inside the EU. That is the architecture pattern we deploy for clients, demonstrated on public data where anyone can test it. You can see it alongside our other delivered systems on our work page.
How to think about it for your company
A short, honest decision frame:
- Classify your data first. Public marketing copy does not need sovereign treatment. Client files, HR data, anything under professional secrecy obligations, and regulated-sector data deserve the strict path. Most companies need a two-tier policy, not a blanket one.
- Trace the full AI data path. Not just storage: which endpoint receives your prompts? Who operates it, and under which jurisdiction? What do the provider's terms say about using your data for training?
- Match the deployment model to the tier. EU-operated or self-hosted open-weight models for the sensitive tier; more flexibility where the data genuinely is not sensitive.
- Write it down. A sovereignty decision that lives in an architecture diagram and a DPIA is defensible in front of a regulator, a board, or a large client's procurement team. One that lives in a vendor's marketing page is not.
Sovereignty is not an ideology, and it is not free — self-hosting has real operational cost, and EU-operated inference should be chosen on merit, not flag. But for Luxembourg companies whose business rests on confidentiality — and that describes much of the financial centre — it has become an achievable default rather than a sacrifice. The capability excuse is gone. What remains is an architecture decision, and architecture decisions are made deliberately or by accident. Deliberately is better.
Topics
- Sovereign AI
- Data sovereignty
- EU hosting
- Open-weight models
- CLOUD Act
