← The journal
Strategy

EU Sovereign AI Stack for Banks and the Public Sector

The layers of an EU sovereign AI stack, and what DORA and the AI Act mean for banks and public bodies.

Swfte Journal / Strategy

An EU sovereign AI stack is a set of layers, each of which you can source from within Europe or from an open, replaceable component: compute, cloud, models, the platform that runs agents and workflows, and the governance layer that proves what happened. Banks and public bodies add two constraints that most companies do not have. They must manage third-party ICT risk with an exit plan, and they must treat their AI use cases against a regulatory calendar that shifted this year.

This post maps the stack layer by layer, summarizes the parts of DORA and the EU AI Act that shape procurement, and ends with a checklist for a bank or public-sector team choosing components. It is a planning aid, not legal advice.

What are the layers of a sovereign AI stack in Europe?

LayerEuropean building blocksWhat to verify
ComputeNational and EuroHPC AI capacity, European GPU clouds, your own hardwareWho owns and operates it; capacity commitments
Cloud and hostingEuropean providers, sovereign regions of global providers, on-premisesJurisdiction of the operator; the sovereignty framework score
ModelsOpen-weight models you can host, European model labsLicense terms; weights you can store; replacement path
PlatformGateway, retrieval, agents, workflowsPortability; no dependence on one hosted model
GovernanceIdentity, policy, audit, evidenceRecords that map to your supervisor's questions

Compute

The EU has been building shared AI compute. The European High-Performance Computing Joint Undertaking lists 19 AI Factories, ecosystems built around AI-optimized supercomputers that provide computing resources and support to industry and research users. A separate effort, the AI Gigafactories, was opened to tender: reporting in July 2026 says the call for up to seven sites with a total of around €30 billion in public and private investment closes on 12 November 2026, with award decisions expected by early 2027, per one monitoring report. For most banks and agencies, these are research and startup resources rather than production inference, so plan for commercial or on-premises capacity. Our GPU procurement strategy post covers the options.

Cloud

The Commission published a Cloud Sovereignty Framework for procurement. As summarized by nLighten, it rates providers on eight objectives: strategic, legal and jurisdictional, data and AI, operational, supply chain, technology, security and compliance, and environmental sustainability, each assessed on a five-level scale called SEAL, and combined into a weighted score. The same summary reports that the Commission awarded a €180 million tender to four European providers in April 2026, the first procurement to use sovereignty as an explicit award criterion, and notes that no official SEAL certificate exists.

You do not have to be an EU institution to borrow the method. Scoring a provider on eight separate axes is more useful than a yes-or-no sovereignty claim.

Models

Open-weight models that you can host and store give you a path that does not depend on any one vendor. Mistral offers open-weight models and describes deployment on-premises or in a private cloud, with the enterprise assistant available self-hosted, according to coverage of the Medium 3 launch. OpenAI's gpt-oss models were released under Apache 2.0, with the larger one designed to fit on a single 80 GB GPU. Models from several other labs are also available as open weights. Our open weights versus proprietary models post tracks where the frontier sits, and Gemma 4 self-hosting is a worked sizing example. Origin matters less than license, weights availability and the ability to run them without a callback to the vendor.

Platform and governance

This is the layer most stacks skip and most supervisors ask about: the gateway, retrieval, agents, policy and audit. A sovereign substrate with no governance is hard to defend. A governance layer with no substrate control is a paper exercise. Swfte covers this layer; see below.

What does DORA mean for a bank's AI stack?

The Digital Operational Resilience Act has applied to EU financial entities since January 2025 and is the clearest regulatory driver for sovereign design in banking, because it makes third-party dependency a managed risk.

  • Register of information. Article 28 requires a register of all contractual arrangements with ICT third-party service providers, and it flags which support critical or important functions. Secondary guidance recommends specific entries such as "AI inference for transaction risk scoring" instead of "AI," per a DORA summary.
  • Exit strategies. For providers supporting critical or important functions, you need a credible plan to switch provider or bring the function in-house, with contract terms that support data export and transition. A hosted model with no export path undermines the plan before it starts.
  • Critical providers. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers, a list reported to include major cloud providers, subject to direct oversight, as reported by a DORA guide. If a model runs on one of them, document the concentration risk.
  • AI vendors can be in scope. Secondary sources report that AI and LLM providers can be captured as ICT third-party providers, and that BaFin issued guidance in December 2025 treating AI systems as network and information systems. Check your own supervisor's position.

The design implication is a gateway that lets you replace a model and a deployment option that lets you move the workload. The lock-in audit gives you a way to score that.

What does the EU AI Act mean for public bodies?

The timetable changed this year. According to Gibson Dunn and Orrick:

  • General-purpose AI obligations have applied since 2 August 2025.
  • Stand-alone high-risk obligations now apply from 2 December 2027, rather than 2 August 2026.
  • AI embedded in regulated products follows on 2 August 2028.
  • AI systems intended for use by public authorities have until 2 August 2030, per Orrick.
  • Article 50 transparency duties largely applied from 2 August 2026, with a transition to 2 December 2026 for certain generative systems placed on the market earlier.

Public bodies should read the last two with care. A later date is a planning window, not an exemption, and uses such as benefits, recruitment or credit decisions are the ones most likely to be classed as high-risk. Treat the next two years as time to build the audit trail, human oversight and documentation that will be demanded. For the full management picture, see enterprise AI governance and risk.

A checklist for banks and public bodies

  • Map each AI use case to its data class and to the regulations that apply.
  • For each, record the provider, the operator's jurisdiction and the exit path.
  • Prefer models you can host, with licenses you have read.
  • Put a gateway between applications and models so a swap is a configuration change.
  • Run agents with defined permissions, approval thresholds and a record of every action.
  • Keep the most sensitive workloads on infrastructure you operate or on isolated dedicated capacity. See enclosed AI and air-gapped LLM deployment.
  • Test the exit plan at least once.

Where does Swfte fit?

Swfte describes its approach as a sovereign intelligence platform: sovereign infrastructure, data and context, models, governed agents, governed workflows and solutions, with governance running through every layer. Cortex is a governed AI desktop that runs local by default. BuildX is a model gateway across 50+ models. Studio and Nexus build agents and enforce policy on what they do. Dedicated cloud offers isolated infrastructure including air-gapped options. The sovereignty, governance and infrastructure pages go deeper.

Swfte is designed to provide the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. It does not by itself make a bank or agency compliant, and the exact posture depends on your use case, jurisdiction, deployment and configuration. To discuss a regulated deployment, contact the team. The sovereign AI explainer and sovereign AI versus private cloud are good companions.

Frequently asked questions

What is a sovereign AI stack?

It is the set of layers needed to run AI under your own control: compute, cloud, models, a platform for agents and workflows, and a governance layer that records and enforces policy. Each layer should be operated by you or replaceable.

Do banks have to use European AI providers?

DORA does not impose that. It requires third-party risk management, a register, contract terms and exit strategies. A provider's jurisdiction is part of the risk assessment, and some institutions adopt stricter internal policies.

When do the EU AI Act high-risk rules apply to public authorities?

According to law firm summaries of the Digital Omnibus on AI, stand-alone high-risk obligations apply from 2 December 2027, and systems intended for public authorities have until 2 August 2030. Verify with the official text.

Can a public sector body use open-weight models?

Yes, subject to the license and procurement rules. Hosting open weights on infrastructure the body controls is a common route to sovereignty at the model layer.

Does a sovereign stack replace compliance work?

No. It provides control and evidence. Classifying use cases, assessing risk and meeting obligations remains your responsibility.

Related: Swfte Connect lets you restrict routing to approved providers and keep sensitive traffic on models you host; see EU-first routing with Connect.

Keep the conversation practical.

Turn an idea into a working next step.

Discuss your use case
0
0
0
0

Enjoyed this article?

Get more insights on AI and enterprise automation delivered to your inbox.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.