Deployment guide
Deploy an LLM in the EU: residency, jurisdiction and in-region inference
What EU-first deployment actually requires beyond choosing a European region.
“Hosted in the EU” is a location. Sovereignty is control. A model can run in a Frankfurt data center and still be operated by a company whose legal exposure sits elsewhere, reached through a dependency you did not list, or licensed in a way that excludes you. EU-first deployment means asking all of those questions, and then choosing infrastructure, models and operating practice so the answers are ones you can defend.
Residency is not sovereignty
Data residency answers one question: where are data stored and processed. Sovereignty asks who retains meaningful control over the AI estate: its data, infrastructure, models, operations, governance and supply chain. A residency promise from a provider can coexist with a model API that sends prompts to another region for abuse monitoring, a support process with access from outside the EU, or an operator whose parent company is subject to non-EU law that can compel disclosure. Legal exposure follows the company, not only the rack.
The practical answer is to reduce the number of parties between the prompt and the answer. A model you run yourself, on dedicated infrastructure in an EU region, has no lab-side API in the loop at all: weights are files, and inference is a process on hardware you control. That removes a class of questions rather than answering them one by one. It does not remove the need to ask who operates the hardware, who can administer it, and what law they are under, and you should get legal advice on that for your situation.
An EU-first deployment, step by step
Classify the data
Decide what the model will see: personal data, special-category data, confidential business data. The classification sets the residency and access rules for everything that follows.
Choose the region and the operator
Pick an EU region and be explicit about who administers it and under which jurisdiction. Where you need to, use dedicated, single-tenant infrastructure so no other customer’s workload shares the hardware.
Check the licence for EU use
Read the licence and acceptable use policy for the exact checkpoint. Llama 4’s policy, for example, withholds rights to its multimodal models from EU-domiciled individuals and companies. Qwen, Gemma 4 and most Mistral releases ship under Apache 2.0.
Test in your languages
A model that is strong in English can be weaker, or less careful, in German, Polish or Portuguese. Evaluate refusal and quality in the languages you serve, not only translated English prompts.
Keep traffic in-region
Route inference, logs and telemetry inside the region. Decide what, if anything, may leave, and make it explicit policy rather than a default setting.
Write down the evidence
Keep the model revision, weights hash, licence, evaluation results and approval record. You will want them if a regulator, customer or auditor asks.
The EU AI Act and open-weight models, in outline
| Topic | What the rules say | What it means for you |
|---|---|---|
| General-purpose AI model providers | Obligations for providers of general-purpose AI models apply from 2 August 2025: technical documentation, information for downstream providers, a copyright policy and a public training-content summary. Models placed on the market before that date have until 2 August 2027. | Ask your model supplier what documentation they provide. Open-source providers are partly exempt from some documentation duties, but not if the model presents systemic risk. |
| Systemic-risk models | Training compute above 10^25 FLOPs creates a presumption of systemic risk, with extra duties including adversarial testing and incident reporting. | Most models you will fine-tune are not in this class, but the largest open-weight releases may be. |
| Fine-tuning | The Commission’s guidelines give an indicative test for when a downstream modifier becomes a provider: compute used for the modification above one third of the original model’s training compute. | Light fine-tunes are unlikely to cross it, but check before a large continued-training run. |
| Your use case | Whether a system is high-risk depends on what it is used for, not on which model sits inside it. Timing for those rules has been moving, so check the current Official Journal text. | Classify the use case first. Model choice comes second. |
This is an outline for orientation, not legal advice. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
EU languages and EU model makers
Language coverage is a safety property as well as a quality one. Safety training is typically strongest in English, and refusal and prompt-injection resilience can degrade in lower-resource languages. Include multilingual cases in the gate and compare against English behavior, so a gap shows up as a number you can act on rather than a user complaint.
The maker’s base also matters. Mistral AI is a French lab and ships most recent open-weight models under Apache 2.0, which makes it a natural candidate for EU-first deployments, though it should be evaluated like any other. Models from outside the EU can be run on EU infrastructure in exactly the same way, because the weights are files and no lab-side API is needed.
How Swfte supports an EU-first deployment
Swfte deploys models on dedicated, single-tenant infrastructure in the region you choose, behind the Connect gateway, with the evaluation gate, rollback and audit trail described on the deploy models hub. <EU regions and facilities offered — founder to fill>.
Swfte does not hold a SOC 2 report or an ISO 27001 certificate and does not sign HIPAA BAAs today; a SOC 2 Type I audit is in preparation, and the trust page has the current status. Your own regulatory position depends on your use case, jurisdiction and configuration.
Frequently asked questions
What is the difference between data residency and data sovereignty for AI?
Residency is where data are stored and processed. Sovereignty is meaningful control over the whole AI estate: data, infrastructure, models, operations, governance and supply chain, including which jurisdiction the operator is under.
Can I run a non-EU model on EU infrastructure?
Yes. Open weights are files, so a model made outside the EU can run on infrastructure in an EU region with no lab-side API involved. Check its licence for EU use first.
Can EU companies use Llama?
Check the current licence and acceptable use policy for the specific model. The Llama 4 policy states that rights for its multimodal models are not granted to EU-domiciled individuals or EU-headquartered companies. Have counsel read it.
When do EU AI Act obligations for general-purpose models apply?
From 2 August 2025 for providers placing new models on the market, and by 2 August 2027 for models that were already on the market. Obligations for high-risk systems depend on the use case and their timing has been changing, so check the Official Journal.
Does deploying in the EU settle my GDPR or EU AI Act position?
No. Location is one control among many. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.