Sovereign AI: what it actually means for a smaller company
“Sovereign” is not a label. It is shorthand for four separate questions: where your data is hosted, which law your provider answers to, how much control you hold over the model, and how quickly you could leave. A provider can answer one of them well and the other three badly. The right approach is not to hunt for the most sovereign supplier, but to work out which of those four questions matters for your data.
Updated 04 August 2026
This resource provides general information, accurate as of the date shown. It does not constitute legal advice and does not replace analysis by a qualified professional in light of your situation.
“Sovereign”: four questions, not one
The word covers four requirements that are routinely conflated.
Location. Where is the data stored and processed? A geographic answer, verifiable, the easiest to obtain — and the least decisive on its own.
Law. Which jurisdiction does the provider answer to? A matter of head office and shareholding, not of data centre. A server in Frankfurt run by the subsidiary of an American group still sits within the reach of US law.
The model. Are you using a service whose versions and timetable you do not know, or a model you hold a copy of and update when you choose?
The exit. How long would it take to retrieve your data and your configurations, and start again elsewhere?
Ask the four separately. A supplier who answers “yes, we are sovereign” has answered none of them.
Is hosting in Europe enough?
No, not on its own. The US CLOUD Act, passed in 2018, allows American authorities to require a provider subject to their jurisdiction to hand over data it holds or controls — regardless of the country where it is stored.
Two qualifications, because the subject is often caricatured. It takes a US legal process, in a criminal investigation: this is not self-service access. And the provider can try to have the demand set aside — but that route is narrow: it assumes an agreement between the United States and the country whose law would be broken, and the EU has signed none.
As early as 2019, the European Data Protection Board and the European Data Protection Supervisor flagged the sticking point: such an order can place the provider in conflict with the GDPR.
The risk is real, but targeted. Weigh it against what your data contains, not as a matter of principle.
Can we still use an American service?
Yes, as things stand. The EU-US Data Privacy Framework adequacy decision, adopted on 10 July 2023, has not been annulled. It permits personal data to be transferred to an American company listed as certified under the framework. Failing that, the usual safeguards apply: standard contractual clauses and a transfer assessment.
The framework is contested. The EU General Court dismissed a first challenge on 3 September 2025; an appeal is pending before the Court of Justice. And on 31 July 2026, the European Data Protection Board asked the Commission to assess the consequences of a US Supreme Court ruling of 29 June 2026 for the independence of the authority tasked with enforcing those commitments.
The practical conclusion: it is lawful today. Build nothing that would become unmanageable if that changed.
SecNumCloud: does it concern us?
Probably not, and that is fine.
SecNumCloud is a qualification awarded by France’s ANSSI, the national cybersecurity agency. It attests to a high level of security and, above all, to sought-after protection against extraterritorial laws: head office in the Union, non-European shareholders in the minority, and data, administration and technical logs located in the Union.
It is voluntary. No general rule imposes it on a smaller company. It bites in practice through certain public contracts, certain sectors, or a client who writes it into your agreement.
Its real cost is not its price: it is the catalogue. The qualified offering is narrower, and managed AI services are fewer there than elsewhere.
The sensible reflex: check whether your sector or one of your clients requires it. If not, do not impose it on yourself as a precaution.
Open models or an online service?
An “open” model — one whose parameters are published and downloadable — settles one question: you can run it on infrastructure you choose. Run it on your own, and your documents and your questions never leave.
It settles nothing else. You need suitable hardware, someone to look after it, monitoring, updates. Open means neither free nor simple.
An online service offers the reverse: nothing to run, access to the most advanced models, usage-based billing — and data passing through a third party whose versions and timetable you do not control.
The middle route often fits: an open model, hosted by a European provider, operated on your behalf. You keep control of the applicable law without taking on the operations.
Could you actually change provider?
This is the most useful question, and the least often asked.
The EU Data Act, applicable since 12 September 2025, governs switching cloud provider: a notice period capped at two months, then a transition of no more than thirty days — extendable once at your request, and longer where the provider shows the deadline is technically unfeasible. Switching charges disappear on 12 January 2027; standard service fees and early-termination penalties remain payable.
The law opens the door. It does not make your system portable. What holds you back is your integrations, your indexes, your instructions tuned for one particular model, and your teams’ habits.
Two cheap reflexes at the outset: keep a usable copy of your data and your configurations, and avoid a proprietary feature where a standard equivalent exists.
Test the exit once. A reversibility never attempted does not exist.
When sovereignty is not the right fight
Often, honestly.
Internal meeting notes, a draft sales email, rewording a piece of text: the debate has no place. Use the simplest tool, with clear rules about what does not go into it.
It becomes the right fight as soon as one of three situations is yours. Your data falls under its own regime — health, a regulated sector, sensitive public contracts. You have given clients confidentiality undertakings that bind you, whatever your supplier says. Or the leak of a body of documents would cost you a real advantage: methods, pricing, contracts.
The test fits in one sentence. Look at what goes into the tool, not at the tool. The same service can be acceptable for your training material and out of the question for your client files.
Frequently asked questions
- Do we need a French cloud to use AI?
- No, there is no general obligation. The choice depends on the sensitivity of your data, your client commitments and your sector. Another European cloud, or even a certified American service, may well fit.
- Does the CLOUD Act give free access to our data?
- No. It takes a US court process in a criminal case. The provider can try to have the demand set aside, but that route assumes a US agreement with the country concerned — and the EU has none. Judge the risk on your data.
- Is transferring data to the United States lawful today?
- Yes, if the recipient appears on the list of companies certified under the adequacy decision of 10 July 2023, which has not been annulled. Otherwise, standard contractual clauses and a transfer assessment are still required.
- Is SecNumCloud mandatory?
- No. It is a voluntary qualification awarded by France’s ANSSI. It binds you through a contract or a sector — public procurement, sensitive data — never through a general rule applying to every company.
- Are open models less capable?
- For everyday business uses — summarising, extraction, assisted drafting, questions about your documents — they generally do the job. On the most demanding reasoning tasks, the best online services keep the edge.
- Where do we start if the subject worries us?
- With a list: which data goes where, to whom, under which law. Many companies find that most of the issue is settled by usage rules, not by changing host.
Read next
- Getting an AI to answer from your internal documents: what it delivers, what it demandsLetting an AI answer questions from your company’s internal documents: how RAG works in plain terms, what makes it succeed, the pitfalls — and when it is not worth doing.
- Your employees are using ChatGPT with client data: what does the GDPR say?Your teams already use generative AI with client data. What the GDPR actually requires, where the real risks lie, and how to set a framework without banning the tools.
- AI in a small or mid-sized company: where to startYour first AI project does not start with a tool. How to spot a good use case, what to check beforehand, and when it is better to wait a little longer.
- AI built around your problem — not the other way roundBring AI into your company without gimmicks or needless risk: a tool built around your problem, your data protected. Paris, and across France.
Sources
- https://www.cnil.fr/fr/adequation-des-etats-unis-les-premieres-questions-reponses — la CNIL rappelle la décision d’adéquation du 10 juillet 2023 et précise que seuls les organismes figurant sur la liste tenue par le Département du commerce américain peuvent recevoir des données sans garanties supplémentaires ; à défaut, outils de l’article 46 du RGPD (clauses contractuelles types) et évaluation du transfert
- https://eur-lex.europa.eu/eli/C/2025/6610/oj/eng — pourvoi formé le 31 octobre 2025 par Philippe Latombe devant la Cour de justice (affaire C-703/25 P) contre l’arrêt du Tribunal du 3 septembre 2025 (affaire T-553/23), qui avait rejeté le recours en annulation dirigé contre la décision d’adéquation
- https://iapp.org/news/a/edpb-requests-review-of-eu-us-data-privacy-framework-following-trump-v-slaughter — par lettre du 31 juillet 2026, le Comité européen de la protection des données a demandé à la Commission d’évaluer les conséquences de l’arrêt Trump v. Slaughter sur la capacité de la Federal Trade Commission à faire respecter les engagements du cadre
- https://www.hklaw.com/en/insights/publications/2026/07/what-the-trump-v-slaughter-decision-means-for-independent — la Cour suprême des États-Unis a jugé le 29 juin 2026, dans Trump v. Slaughter, que les protections contre la révocation des commissaires de la FTC violaient la séparation des pouvoirs, revenant sur Humphrey’s Executor (1935)
- https://www.edpb.europa.eu/sites/default/files/files/file2/edpb_edps_joint_response_us_cloudact_annex.pdf — évaluation juridique conjointe du CEPD et du Contrôleur européen (10 juillet 2019) : le CLOUD Act, adopté en mars 2018, vise les données en la possession, sous la garde ou sous le contrôle d’un fournisseur soumis à la juridiction américaine, y compris stockées hors des États-Unis ; le recours pour faire annuler une injonction est réservé aux demandes visant des personnes non américaines et au droit d’un État ayant conclu un accord exécutif avec les États-Unis ; l’injonction peut placer le fournisseur en conflit avec le RGPD (articles 6, 48 et 49)
- https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng — règlement (UE) 2023/2854 sur les données, applicable depuis le 12 septembre 2025 : préavis de changement de fournisseur plafonné à deux mois et période transitoire obligatoire de trente jours calendaires au plus, prolongeable par le client ou en cas d’impossibilité technique justifiée (article 25, paragraphe 2) ; plus aucun frais de changement à compter du 12 janvier 2027 (article 29)
- https://cyber.gouv.fr/enjeux-technologiques/cloud/faq-qualification-secnumcloud/ — SecNumCloud est une qualification volontaire délivrée par l’ANSSI (référentiel v3.2) ; elle exige notamment un siège dans l’Union, un actionnariat non européen minoritaire et la localisation dans l’Union des données, de l’administration et des journaux, afin de protéger contre l’ingérence des lois extraterritoriales