Sovereign Inference in the EU: What 'In-Region' Must Actually Mean
What in-region AI inference must mean in the EU: walk the request path hop by hop with a 10-question checklist.
"Hosted in the EU" is the easiest sentence in an AI vendor deck and the least informative one. A model call touches a gateway, a retrieval index, GPU compute, logs, backups and a support team, and each of those can sit somewhere different and be administered by someone different. This post defines what in-region inference should mean, hop by hop, and gives you ten questions to put to any provider, including us.
Last verified 2026-10-06. This is not legal advice.
A working definition
For this post, in-region inference means: the prompts, the context and retrieval indexes, the model weights and inference compute, the logs and the backups all sit inside a named region, and you know who is able to administer each of them. The second half matters as much as the first: a GPU in Frankfurt administered from outside the EU is in-region for the hardware and not much else.
The related term EU data boundary is the same idea stated as a contract: the line inside which your data is stored and processed, written down, with the exceptions listed.
Three words that get used as one
These are different properties, and a provider can have the first without the others.
- Data residency: where data is stored and processed. A location fact.
- Data sovereignty: whose law reaches the data and who can compel access to it. A legal-exposure fact.
- Operational sovereignty: who can run, change, pause and inspect the system day to day, and whether you could carry on if a supplier withdrew. A control fact.
Our platform treats sovereignty as seven kinds, because AI estates have more surfaces than storage: data, infrastructure, model, intelligence (your proprietary knowledge and derived insight), operational (agents, workflows and the actions they take), governance (policies, permissions, audit and evidence) and supply-chain (vendors, models, infrastructure and critical dependencies). Sovereignty is your ability to retain meaningful control over your AI estate, not just where a server sits. For the broader argument, see our earlier post on data sovereignty in AI and the sovereignty overview.
Walk the request path
Take one request and follow it. At every hop, ask two questions: where does this sit, and who can administer it?
| Hop | What lives there | Where it commonly leaks |
|---|---|---|
| Client | Browser, app, SDK, IDE plugin | Client-side analytics and crash reporters that capture prompt text |
| Gateway | Auth, routing, rate limits, model selection | A global gateway that terminates TLS outside the region before forwarding in |
| Prompt and context assembly | System prompts, templates, user data, retrieved passages | Assembly services run as separate global functions |
| Retrieval index and embeddings | Vector store, chunks, embedding model calls | The embedding call goes to a different provider or region than the chat call |
| Model weights and GPU compute | The model and the hardware serving it | Fallback routing to another region or another provider when capacity is tight |
| Logs, traces and evals | Prompts and outputs stored for debugging and quality | Observability vendors that receive full payloads |
| Backups and replicas | Snapshots, cross-region replication, disaster recovery | Replication defaults that copy to a second region |
| Support and admin access | Operator consoles, break-glass access, support tooling | Follow-the-sun support with read access to customer data |
| Sub-processors | Every third party in the chain | A model provider behind the gateway that processes in its own region |
| Telemetry | Usage metrics, error reports, billing events | Metadata that is treated as harmless and contains identifiers or prompt fragments |
Three of these deserve extra attention.
Embeddings and retrieval. Teams pin the chat model and forget that the embedding model is a separate call, often to a separate endpoint. If your documents are embedded elsewhere, your corpus has left the boundary even if your answers never do.
Fallback routing. Failover to another region or provider is good for availability and bad for a boundary you promised. Ask whether it is configurable, and whether a request fails closed or fails over.
Logs and evals. Observability is where full prompts end up stored. Our guide to LLM observability and prompt analytics covers what to capture; the sovereignty question is where that store sits and who can read it.
Why location alone does not settle foreign-law access
Residency is necessary and not sufficient, for reasons the EU's own legislation recognizes.
Personal data. The GDPR's transfer rules in Chapter V (Articles 44 to 49) apply to personal data that reaches a third country. Transfers rely on an adequacy decision (Article 45), safeguards such as standard contractual clauses or binding corporate rules (Article 46), or narrow derogations (Article 49). In Schrems II (C-311/18, 16 July 2020) the Court of Justice invalidated Privacy Shield and required a transfer impact assessment when relying on standard contractual clauses. See our page on GDPR for AI for how this maps onto model calls.
The EU-US Data Privacy Framework. The Commission adopted an adequacy decision for the framework on 10 July 2023. According to Digital Policy Alert, the General Court dismissed Latombe v Commission on 3 September 2025 and an appeal is pending at the Court of Justice as case C-703/25 P. Check the current status before relying on it, and keep a fallback mechanism in your contract.
Non-personal data. Chapter VII of the Data Act (applicable since 12 September 2025) requires data processing service providers to put safeguards in place against unlawful third-country governmental access to non-personal data. That is a useful lever in a cloud or model-hosting contract: ask the provider how they meet it, and what they do when a foreign request arrives. We cover the wider Act in Data Act for AI.
There is no legal "sovereign" label yet
Be careful with anyone who says their service is "sovereign" as if that were a recognized status.
- The EU cloud certification scheme, EUCS, is still not adopted. According to Clifford Chance, the Commission's 20 January 2026 proposal to revise the Cybersecurity Act sets a new procedure but excludes sovereignty requirements from certification.
- The Cloud and AI Development Act (CADA) is a Commission proposal published on 3 June 2026, not law. According to law-firm commentary, it contemplates four Union Assurance Levels (EU location, third-country independence, EU ownership, control and personnel, and full supply-chain control), applied mainly through public procurement, with adoption targeted around 2027.
So no statutory test makes a service "sovereign" today. You have to verify the claim yourself, which is why the walk and the checklist matter more than the label.
Where Swfte stands, plainly
We would rather you hear the limits from us.
- Our trust page states that customer data is stored in AWS eu-west-1 (Ireland) today.
- In-country hosting, dedicated deployments and on-prem or hybrid options are what the platform is designed for. They are scoped through a dedicated deployment engagement, not self-serve.
- Customer-managed keys are designed for dedicated deployments. They are not generally available.
- An external penetration test, SAML SSO and SCIM, and enforced MFA are in progress or not yet in place. Our data processing agreement is a draft.
- Zero-data-retention agreements with upstream model providers are not in place, which is the kind of sub-processor gap the checklist below should surface.
If your boundary needs to be stricter than a single EU region, the relevant reading is our on-prem economics analysis and the air-gapped deployment checklist.
The 10-question in-region checklist
Put these to any provider. A good answer names a region, a party and a mechanism.
| # | Question | What a good answer looks like |
|---|---|---|
| 1 | In which region are prompts and outputs processed, and is that contractual? | A named region in the contract, not a marketing page |
| 2 | Where do the embedding calls and the retrieval index run? | Same boundary as inference, or the exception is listed |
| 3 | Where are model weights hosted, and does fallback routing ever leave the region? | Failover is configurable; the default fails closed |
| 4 | Where are logs, traces and eval datasets stored, and for how long? | Named region, defined retention, deletion on request |
| 5 | Where do backups and replicas go? | Same boundary, or a documented second in-boundary location |
| 6 | Who can administer production, and from where? | Named roles, location of operators, and an access log you can see |
| 7 | How is support access to customer data granted and recorded? | Just-in-time, approved and audited; no standing access |
| 8 | Who are the sub-processors, including upstream model providers, and where do they process? | A current list with regions and a notice-of-change process |
| 9 | Which jurisdictions can compel the operator, and how are foreign access requests handled? | A written policy and the provider's answer on Data Act Chapter VII safeguards |
| 10 | Who holds the encryption keys, and what is the exit path? | Customer-managed keys where needed, and a tested route to move data and workloads out |
Question 10 matters because an exit path is part of sovereignty. Our model exit-cost audit framework is a good companion.
How Swfte supports this
Swfte is built for Europe: sovereign by design, with an EU data boundary you can define and review, and in-region inference as a stated goal of the platform. Concretely, the platform is designed to let you choose where AI runs, pin model and data choices through a Trust Profile that records data residency and approved models per AI system, and keep an auditable trail of who did what. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements; the exact posture depends on use case, jurisdiction, deployment and configuration. See /eu, /platform/governance, /platform/sovereignty and /trust for the current position, including what is in progress.
This is not legal advice. Check the current legal status of transfer mechanisms and pending legislation with qualified counsel before you rely on them.
Related: Swfte Connect lets you restrict routing to approved providers and keep sensitive traffic on models you host; see EU-first routing with Connect.