Digital sovereignty
Our commitment to sovereign AI
Trump declared the trade war in early 2025. He can cut off access to anyone, and his administration has visibility into all the data you hand over to it. Are you ready?
Definition
What is sovereign AI?
Sovereign AI is an artificial intelligence solution where the organisation using it controls three layers: the legal framework that applies to the company providing the service, the location and governing law of the infrastructure hosting its data, and the identity of the models processing its requests. European hosting is a necessary condition, not a sufficient one.
1The law that applies to your vendor
The vendor must be governed by European law. The French subsidiary of a US group, on the other hand, remains within the reach of the Cloud Act: the US executive can freeze a service with no trial.
2The infrastructure hosting your data
Your vendor's hosting provider stores your data. It must be governed by European law too.
3The models processing your requests
The model receives requests containing company data. It must be governed by European law too.
Hosting in Europe is not enough to make AI sovereign
Truth is, it is not even useful on its own. What matters is your vendor's regulator: if it is a US company, or the subsidiary of one, its regulator stays American, wherever your data sits. Frankfurt or Atlanta, it makes no difference.
The Cloud Act and the Patriot Act allow US authorities to request access to data held by a US company, including when that data is hosted abroad. The decisive criterion is therefore not the geography of the server, but the legal nationality of whoever controls it.
Sovereign AI is judged on the full chain: storage, document retrieval, inference, logging, backups. A single non-European link is enough to reopen the question.
Read our analysis of European digital dependencyA certification does not prove sovereignty
The European cloud certification scheme, EUCS, was initially meant to include, at its highest assurance level, a criterion of immunity from extraterritorial laws. That criterion was dropped under pressure from several member states and part of the industry.
The consequence, documented by specialists: a service certified at the highest level does not rule out exposure to the Cloud Act. A certification tells you about technical and cyber robustness, not about legal immunity.
The same caution applies to so-called trusted cloud offerings, where US technology is operated under licence by a French-law joint venture. The structure makes a US order harder to execute, but whether it fully escapes one is not settled by consensus.
Continuity
Sovereignty is not just about confidentiality
Sovereignty is almost always debated as a confidentiality question: who is legally able to read your data. That risk is real, but it is not what brings a company to a halt. The second risk, far less discussed, is the software you cannot afford to switch off being switched off, for reasons that have nothing to do with service quality. Washington has already shown two precedents: targeted individuals, like the ICC, but also its own best products, like Mythos, one of the most advanced AI models in the world. The trade war has only just begun: nothing says it stops there.
February 2025: the International Criminal Court loses its email
Following a US executive order sanctioning the ICC prosecutor, he lost access to his Microsoft mailbox and had to move to a Swiss provider. No technical outage, no breach of contract, no court proceedings: a foreign policy decision, applied by a vendor governed by US law.
The target was neither a US company nor even an entity governed by US law, but an international court. In October 2025, the ICC confirmed its move from the Microsoft suite to a European open source alternative.
Source: Dalloz ActualitéJune 2026: Washington cuts off access to Mythos, allies included
The US Department of Commerce ordered Anthropic to suspend access to its most advanced models, Mythos 5 and Fable 5, for any foreign national, including its own non-US employees. The stated reason: a national security risk, which Anthropic publicly disputed.
The immediate effect: allied governments and companies in the UK, the EU and Canada that relied on Mythos, including for cybersecurity work, lost access overnight. This time the target was not a sanctioned individual. It was one of the best AI products in the world, cut off for an entire continent.
Source: TechPolicy.PressMonths pass between a unilateral decision and any judicial review of it, and by then the effects have already happened. For an IT department, the risk is therefore not measured by the likelihood of litigation, but by how fast an outside decision can reach the tools your teams work with every day.
The two risks call for different answers. Confidentiality is handled by minimising what is sent and by contractual commitments. Continuity is handled by the law that governs your vendor, and by the ability to switch models without rebuilding your platform.
Cost of dependency
Dependency has a price, and it is rising
Sovereignty is not only a legal topic. It ends up on a budget line.
+8.7%
a year on cloud and software
Average price increase recorded over the past three years, with an expected acceleration to 12% a year over the next five: more than three times the sector's reference inflation.
+51%
at some contract renewals
Average increase recorded at some contract renewals, with peaks reported as high as 300%.
40%
of IT leaders already hit by vendor lock-in
Share of IT departments that say they suffered technological or contractual lock-in over the past three years: switching vendors then costs more than accepting the increase.
These increases come from a position of strength, not a market accident. Microsoft announced a 5% to 43% increase across Microsoft 365 licences, effective 1 July 2026. At the same time, 52% of IT leaders see AI-related productivity gains without being able to measure them.
That is the direct link between sovereignty and budget: a vendor you cannot leave has no reason to hold its prices. Reversibility is the only real negotiating lever, and it is prepared when you choose, not when you renew.
Sources: Asterès study for Cigref (May 2026) and Microsoft Licensing pricing announcements (December 2025).
Assessment grid
8 questions to ask a sovereign AI vendor
These questions are enough, in a single meeting, to separate real sovereignty from a sales argument.
- 1
Which country's law governs the vendor and its controlling shareholders?
Applicable law follows the company, not the server. A European subsidiary of a non-European group remains exposed to its parent company's obligations.
- 2
Where are documents, vector indexes, logs and backups hosted?
Vector indexes and logs often contain excerpts of your content. They are too often left out of localisation commitments.
- 3
Which model providers are called, and from which jurisdiction?
This is the least visible and most decisive layer. Ask for a named list of providers, not a generic statement.
- 4
Can I restrict AI processing to European providers only?
Sovereignty that cannot be configured is a promise. It should be an explicit, auditable and reversible setting.
- 5
What is actually sent to the model on each request?
Sending the question plus relevant excerpts does not carry the same risk profile as sending whole documents or an entire repository.
- 6
Can my content be used to train a model?
The no-training commitment must be contractual and must also cover the third-party providers the platform calls.
- 7
If I leave, what do I take with me?
Configurations, connectors, prompts, custom developments: reversibility is the economic side of sovereignty.
- 8
Which certifications do you hold, and what exactly do they cover?
A label attests to technical robustness, rarely to legal immunity. Ask what the certification does not rule out, not only what it guarantees.
Sovereign AI in France: where do we stand?
France mostly has know-how, strong French-law hosting providers (OVHcloud, Scaleway, Outscale), and inference providers able to run models on European GPUs. French model publishers, Mistral AI first among them, and public initiatives such as Albert are a bonus, not the foundation. The question is no longer “Is there a French AI?” but “How do you assemble these blocks into a system that works in production?”.
This is where most projects stall. Picking a French model solves neither document ingestion, nor access rights, nor source citation, nor answer quality evaluation. Sovereign AI in France is not decided at the model layer: it is built at the platform layer around it.
One honest trade-off remains: on some tasks, the performance gap between European and US models has not disappeared. The right reflex is not to deny it, but to make it explicit and controllable, use case by use case.
Still, out of habit, most organisations default to consuming American. And the “French AI” label is not enough: plenty of French AI vendors are themselves not sovereign at all across the full chain.
See our survey of 14 French vendors put to the testOur approach
Sovereign AI at Ask This Guy
We would rather document our trade-offs than sell theoretical sovereignty.
A French company
Ask This Guy is a French company, governed by French and European law. Your contractual commitments and your contacts are in France.
European infrastructure
Platform, PostgreSQL and PGVector databases, document storage and backups hosted in the European Union, on dedicated OVHcloud servers in Gravelines, with redundancy in Frankfurt. An on-premise deployment in your own environment can be considered depending on your constraints.
Our own GPUs in Europe
We operate some models ourselves on dedicated GPUs at Verda, in Finland and Iceland. Inference then stays within a European perimeter covered by GDPR.
An AI policy you choose
The “EU only” mode restricts processing to European providers and to the models we run ourselves. The “Worldwide” mode opens access to selected international providers. You can switch at any time.
No training on your data
Models used through ATG do not train on your content. We send the question and the excerpts needed to answer it, not your document repositories.
Reversibility by default
Your configurations, your connectors and the custom developments built for you remain yours. Sovereignty does not stop at hosting: it includes the right to leave.
What you can deploy with sovereign AI
Sovereignty only matters if it serves real use cases. These are the ones we put into production.
Internal assistant on your documents
An enterprise RAG connected to your drives, SharePoint, Confluence or Notion, with inherited permissions and cited sources.
Turnkey enterprise RAGAI agents and automation
Agents that process your files, feed your databases and produce your recurring reports, connected to your tools through MCP.
Agentic AI and automationQuerying your business data
Ask a plain-language question of your SQL databases, your ERP or your CRM, with no export and no intermediate spreadsheet.
Talk to DataFraming and upskilling
AI governance, roadmap, team training and industrialisation of your POCs, without locking yourself into a single vendor.
CIO supportFrequently asked questions about sovereign AI
What is sovereign AI?
Sovereign AI is an artificial intelligence solution where the organisation using it controls the legal framework applying to the vendor, the location and governing law of the infrastructure hosting its data, and the identity of the models processing its requests. Using a European model is not enough if the operator or the infrastructure falls outside that perimeter.
Is AI hosted in Europe automatically sovereign?
No. European hosting is necessary but not sufficient. A platform can store your files in France and call, on every request, an inference provider governed by a non-European jurisdiction. The Cloud Act also allows US authorities to request access to data held by a US company, even when hosted abroad. You have to examine the full chain: storage, retrieval, inference, logs and backups.
What is the difference between sovereign AI, French AI and European AI?
French AI usually refers to a model published by a French company, such as those from Mistral AI. European AI widens that to the Union. Sovereign AI is broader and more demanding: it covers the whole chain, from the law applying to the vendor through to the models being called, including hosting. You can use a French model inside an architecture that is not sovereign, and the other way round.
Do you need to self-host an LLM to have sovereign AI?
Not necessarily. Running an LLM on your own GPUs carries high infrastructure and operating costs, often out of proportion with the actual use cases. You can separate the layers instead: data and document retrieval on your side or in Europe, platform operated by a European vendor, inference on European GPUs. You get most of the guarantees without rebuilding the entire stack, and full on-premise remains an option for contexts that genuinely require it.
Are sovereign AI and GDPR the same thing?
No. GDPR governs the processing of personal data and applies wherever the data sits, as soon as people in the Union are concerned. Sovereignty is about control and dependency: who can lawfully access your data or cut off your service. A solution can be GDPR-compliant without being sovereign.
What sovereign AI options exist in France?
The French ecosystem brings together model publishers such as Mistral AI, French hosting providers such as OVHcloud, Scaleway or Outscale, and public initiatives such as Albert, the French State's generative AI platform. The difficulty is no longer finding sovereign building blocks, but assembling them into a usable platform: document ingestion, access rights, source citation, evaluation and monitoring.
Is sovereign AI less performant?
On some tasks a performance gap remains between European and US models, particularly on inference speed and complex reasoning. That gap is narrowing and does not affect every use case. The pragmatic approach is to make the trade-off explicit: an “EU only” policy for sensitive processing, broader access where performance delivers measurable value.
How do you verify that a vendor is genuinely sovereign?
Ask in writing for: the nationality of the publishing company and its controlling shareholders, a named list of the model providers called and their jurisdiction, the location of storage, vector indexes, logs and backups, the ability to restrict processing to European providers, the contractual no-training commitment on your content, and what you get back if you leave.
Let's talk about your sovereign chain
Tell us about your sources, your regulatory constraints and your use cases. In 30 minutes we will tell you which architecture is realistic, and at what level of sovereignty.