Our approach to sovereign AI
Understand ATG's approach to sovereign AI: a French company, European infrastructure, an on-premise option, and the choice between full sovereignty and model performance.
Our definition of sovereign AI
For ATG, sovereign AI is not just about using a European model. Sovereignty depends on control over three complementary elements:
- The law that applies to the company providing the service
- The infrastructure that hosts the platform and the data
- The AI models that process requests and their context
This distinction matters. A platform can be hosted in Europe while calling an AI provider subject to a non-European jurisdiction. Conversely, a European model is not enough to make a solution sovereign if its infrastructure or operator falls outside the European perimeter.
This page describes our own implementation. For the general definition, the assessment criteria and the questions to ask any vendor, see our sovereign AI page. To go deeper into dependency and digital sovereignty issues, see our articles on sovereignty.
1. A French company under European law
Ask This Guy is a French company. Our contractual commitments and decisions about data processing sit within French and European law, including the GDPR.
This first level of sovereignty gives you a counterpart established in France and a European legal framework. It is not enough on its own: infrastructure location and AI provider choices matter just as much.
2. European infrastructure, with an on-premise path
The ATG platform is hosted in the European Union by companies under European law. Our main infrastructure relies in particular on dedicated OVHcloud servers in Gravelines, France, with redundancy in Frankfurt, Germany.
The essential components stay within that perimeter:
- ATG frontend and backend;
- PostgreSQL and PGVector databases;
- document and media storage;
- backups and replication.
The ATG backend is the control point for calls to external services. It accesses storage, applies access rules, and only sends the information required to the AI providers authorized by your policy.
Our own GPU infrastructure in Europe
ATG does not only consume external inference APIs. We also build our own GPU infrastructure with Verda, a Finnish provider running its data centers in Finland and Iceland. There, we deploy and operate some models ourselves, on GPUs dedicated to ATG.
This layer complements the use of external providers and brings:
- AI hosted in Europe all the way to the inference layer, with no context leaving our perimeter;
- control over the model served: version, configuration, update cycle;
- an operator under European law, since Finland is in the European Union and Iceland is in the European Economic Area, and therefore covered by the GDPR.
Depending on the use case, ATG combines its own GPUs with selected third-party inference providers, within the limits of the AI policy your organization has chosen.
Going further with on-premise
For some organizations, sovereignty requires the platform to run in their own environment. We want on-premise to remain a possible option to go further in controlling infrastructure, network, and data location.
Depending on context, scope, and security requirements, a dedicated deployment can be reviewed with your teams. The goal is to bring ATG closer to your trusted infrastructure, without giving up search, knowledge management, and AI assistance capabilities.
3. AI models: full sovereignty or better performance
The AI market is moving fast. At this stage, there is still, depending on tasks and models compared, a performance gap between some US and European providers. That gap combines in particular:
- inference speed;
- reasoning and generation quality;
- multimodal capabilities and native attachment support.
We therefore prefer to be transparent about this trade-off rather than present theoretical sovereignty as a universal answer. ATG lets you choose the level that fits your organization.
Two AI policies based on your requirements
EU-only: maximum sovereignty
The EU-only policy limits AI processing to providers under European law that run their services in Europe, plus the models we operate ourselves on our GPUs at Verda. This is the preferred choice when control of jurisdiction and European residency of processing are priorities.
This policy fits an AI hosted in Europe approach and AI aligned with GDPR compliance requirements. It may, however, reduce model choice, speed, or capabilities for some use cases.
Worldwide: an exception limited to the AI layer
The Worldwide policy allows, in addition to European providers, selected international providers. It lets you benefit from the most capable or fastest models when that brings concrete value to your users.
This exception concerns the AI layer. ATG's core infrastructure, storage, and databases remain hosted in Europe. Even with this policy, ATG:
- only sends what is needed to process the request;
- generally transmits the question and relevant excerpts, rather than full documents;
- uses providers through governed APIs;
- does not allow the LLMs used via ATG to train their models on your data.
Choosing worldwide therefore does not remove our minimization and control requirements. It lets you explicitly trade off maximum sovereignty against operational performance.
You stay in control at all times
The AI policy can be changed at any time from the AI Policy menu in the admin console:
You can start with a worldwide policy to evaluate performance, then switch to EU-only when your compliance requirements or use case require it. The reverse is also possible if your priorities change.
For the exact available providers and their guarantees, see AI providers management. For data flow details, see Your Data Management.
Our roadmap: letting you choose your AI
Our longer-term goal is to offer a Bring Your Own AI mode. It will let organizations that want to connect their own models, providers, or inference endpoints keep more autonomy over the last link in the chain.
This capability is on our roadmap. In the meantime, the EU-only and Worldwide policies already let you adapt the sovereignty level to each organization's risk, regulatory constraints, and performance goals.
In summary
Our approach to sovereign AI rests on three commitments:
- A French company under French and European law
- European infrastructure, including our own GPUs at Verda in Finland and Iceland, with an on-premise option for the most demanding needs
- An explicit choice for AI, between European providers only and access to worldwide providers for better performance
Sovereignty is not a slogan or a single switch. It is a documented trade-off that you can evolve as your constraints and model performance change.
Frequently asked questions about sovereign AI
Sovereign AI is a solution where an organization controls the applicable legal framework, the infrastructure hosting its data, and the AI providers processing its requests. Using a European model alone is not enough if the operator or infrastructure falls outside that perimeter.
No. European hosting is important, but it does not guarantee sovereignty on its own. You must also examine the law governing the operator and the AI providers processing requests. A solution may store its data in Europe while depending on a provider subject to a non-European jurisdiction.
Ask This Guy is a French company subject to French and European law. French AI is not the right description: we primarily provide a French platform for using AI.
The EU-only policy limits AI processing to providers under European law that run their services in Europe. The Worldwide policy also allows selected international providers, while ATG's core infrastructure, storage, and databases remain in Europe. You can therefore choose between maximum sovereignty and access to a broader range of models.
Yes. On top of external AI providers, ATG builds its own GPU infrastructure with Verda, a Finnish provider whose data centers are located in Finland and Iceland. We deploy and operate some models there ourselves, which keeps inference within a European, GDPR-covered perimeter, alongside the platform hosted at OVHcloud.
On-premise is an option considered for organizations that need more control over their infrastructure, network, and data location. Depending on the context, scope, and security requirements, a dedicated deployment can be reviewed with your teams.