← The journal
Strategy

Sovereign Inference in the EU: What 'In-Region' Must Actually Mean

What in-region AI inference must mean in the EU: walk the request path hop by hop with a 10-question checklist.

Swfte Journal / Strategy

"Hosted in the EU" is the easiest sentence in an AI vendor deck and the least informative one. A model call touches a gateway, a retrieval index, GPU compute, logs, backups and a support team, and each of those can sit somewhere different and be administered by someone different. This post defines what in-region inference should mean, hop by hop, and gives you ten questions to put to any provider, including us.

Last verified 2026-10-06. This is not legal advice.

A working definition

For this post, in-region inference means: the prompts, the context and retrieval indexes, the model weights and inference compute, the logs and the backups all sit inside a named region, and you know who is able to administer each of them. The second half matters as much as the first: a GPU in Frankfurt administered from outside the EU is in-region for the hardware and not much else.

The related term EU data boundary is the same idea stated as a contract: the line inside which your data is stored and processed, written down, with the exceptions listed.

Three words that get used as one

These are different properties, and a provider can have the first without the others.

  • Data residency: where data is stored and processed. A location fact.
  • Data sovereignty: whose law reaches the data and who can compel access to it. A legal-exposure fact.
  • Operational sovereignty: who can run, change, pause and inspect the system day to day, and whether you could carry on if a supplier withdrew. A control fact.

Our platform treats sovereignty as seven kinds, because AI estates have more surfaces than storage: data, infrastructure, model, intelligence (your proprietary knowledge and derived insight), operational (agents, workflows and the actions they take), governance (policies, permissions, audit and evidence) and supply-chain (vendors, models, infrastructure and critical dependencies). Sovereignty is your ability to retain meaningful control over your AI estate, not just where a server sits. For the broader argument, see our earlier post on data sovereignty in AI and the sovereignty overview.

Walk the request path

Take one request and follow it. At every hop, ask two questions: where does this sit, and who can administer it?

HopWhat lives thereWhere it commonly leaks
ClientBrowser, app, SDK, IDE pluginClient-side analytics and crash reporters that capture prompt text
GatewayAuth, routing, rate limits, model selectionA global gateway that terminates TLS outside the region before forwarding in
Prompt and context assemblySystem prompts, templates, user data, retrieved passagesAssembly services run as separate global functions
Retrieval index and embeddingsVector store, chunks, embedding model callsThe embedding call goes to a different provider or region than the chat call
Model weights and GPU computeThe model and the hardware serving itFallback routing to another region or another provider when capacity is tight
Logs, traces and evalsPrompts and outputs stored for debugging and qualityObservability vendors that receive full payloads
Backups and replicasSnapshots, cross-region replication, disaster recoveryReplication defaults that copy to a second region
Support and admin accessOperator consoles, break-glass access, support toolingFollow-the-sun support with read access to customer data
Sub-processorsEvery third party in the chainA model provider behind the gateway that processes in its own region
TelemetryUsage metrics, error reports, billing eventsMetadata that is treated as harmless and contains identifiers or prompt fragments

Three of these deserve extra attention.

Embeddings and retrieval. Teams pin the chat model and forget that the embedding model is a separate call, often to a separate endpoint. If your documents are embedded elsewhere, your corpus has left the boundary even if your answers never do.

Fallback routing. Failover to another region or provider is good for availability and bad for a boundary you promised. Ask whether it is configurable, and whether a request fails closed or fails over.

Logs and evals. Observability is where full prompts end up stored. Our guide to LLM observability and prompt analytics covers what to capture; the sovereignty question is where that store sits and who can read it.

Why location alone does not settle foreign-law access

Residency is necessary and not sufficient, for reasons the EU's own legislation recognizes.

Personal data. The GDPR's transfer rules in Chapter V (Articles 44 to 49) apply to personal data that reaches a third country. Transfers rely on an adequacy decision (Article 45), safeguards such as standard contractual clauses or binding corporate rules (Article 46), or narrow derogations (Article 49). In Schrems II (C-311/18, 16 July 2020) the Court of Justice invalidated Privacy Shield and required a transfer impact assessment when relying on standard contractual clauses. See our page on GDPR for AI for how this maps onto model calls.

The EU-US Data Privacy Framework. The Commission adopted an adequacy decision for the framework on 10 July 2023. According to Digital Policy Alert, the General Court dismissed Latombe v Commission on 3 September 2025 and an appeal is pending at the Court of Justice as case C-703/25 P. Check the current status before relying on it, and keep a fallback mechanism in your contract.

Non-personal data. Chapter VII of the Data Act (applicable since 12 September 2025) requires data processing service providers to put safeguards in place against unlawful third-country governmental access to non-personal data. That is a useful lever in a cloud or model-hosting contract: ask the provider how they meet it, and what they do when a foreign request arrives. We cover the wider Act in Data Act for AI.

Be careful with anyone who says their service is "sovereign" as if that were a recognized status.

  • The EU cloud certification scheme, EUCS, is still not adopted. According to Clifford Chance, the Commission's 20 January 2026 proposal to revise the Cybersecurity Act sets a new procedure but excludes sovereignty requirements from certification.
  • The Cloud and AI Development Act (CADA) is a Commission proposal published on 3 June 2026, not law. According to law-firm commentary, it contemplates four Union Assurance Levels (EU location, third-country independence, EU ownership, control and personnel, and full supply-chain control), applied mainly through public procurement, with adoption targeted around 2027.

So no statutory test makes a service "sovereign" today. You have to verify the claim yourself, which is why the walk and the checklist matter more than the label.

Where Swfte stands, plainly

We would rather you hear the limits from us.

  • Our trust page states that customer data is stored in AWS eu-west-1 (Ireland) today.
  • In-country hosting, dedicated deployments and on-prem or hybrid options are what the platform is designed for. They are scoped through a dedicated deployment engagement, not self-serve.
  • Customer-managed keys are designed for dedicated deployments. They are not generally available.
  • An external penetration test, SAML SSO and SCIM, and enforced MFA are in progress or not yet in place. Our data processing agreement is a draft.
  • Zero-data-retention agreements with upstream model providers are not in place, which is the kind of sub-processor gap the checklist below should surface.

If your boundary needs to be stricter than a single EU region, the relevant reading is our on-prem economics analysis and the air-gapped deployment checklist.

The 10-question in-region checklist

Put these to any provider. A good answer names a region, a party and a mechanism.

#QuestionWhat a good answer looks like
1In which region are prompts and outputs processed, and is that contractual?A named region in the contract, not a marketing page
2Where do the embedding calls and the retrieval index run?Same boundary as inference, or the exception is listed
3Where are model weights hosted, and does fallback routing ever leave the region?Failover is configurable; the default fails closed
4Where are logs, traces and eval datasets stored, and for how long?Named region, defined retention, deletion on request
5Where do backups and replicas go?Same boundary, or a documented second in-boundary location
6Who can administer production, and from where?Named roles, location of operators, and an access log you can see
7How is support access to customer data granted and recorded?Just-in-time, approved and audited; no standing access
8Who are the sub-processors, including upstream model providers, and where do they process?A current list with regions and a notice-of-change process
9Which jurisdictions can compel the operator, and how are foreign access requests handled?A written policy and the provider's answer on Data Act Chapter VII safeguards
10Who holds the encryption keys, and what is the exit path?Customer-managed keys where needed, and a tested route to move data and workloads out

Question 10 matters because an exit path is part of sovereignty. Our model exit-cost audit framework is a good companion.

How Swfte supports this

Swfte is built for Europe: sovereign by design, with an EU data boundary you can define and review, and in-region inference as a stated goal of the platform. Concretely, the platform is designed to let you choose where AI runs, pin model and data choices through a Trust Profile that records data residency and approved models per AI system, and keep an auditable trail of who did what. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements; the exact posture depends on use case, jurisdiction, deployment and configuration. See /eu, /platform/governance, /platform/sovereignty and /trust for the current position, including what is in progress.

This is not legal advice. Check the current legal status of transfer mechanisms and pending legislation with qualified counsel before you rely on them.

Related: Swfte Connect lets you restrict routing to approved providers and keep sensitive traffic on models you host; see EU-first routing with Connect.

Keep the conversation practical.

Turn an idea into a working next step.

Discuss your use case
0
0
0
0

Enjoyed this article?

Get more insights on AI and enterprise automation delivered to your inbox.

Deploy a model with Swfte Connect

One gateway, every provider, per-token cost visibility. Swap models without touching your code.