EU-first AI platform

The EU-first AI platform

Built for Europe. Sovereign by design. Swfte maps the Sovereign Intelligence Platform to the EU rulebook: EU AI Act, GDPR, NIS2, DORA, the Data Act and sector rules, with audit-ready records and evidence on demand.

What EU-first means here

Each term below has a concrete meaning on this site. None of them is a certification.

  • EU-first

    Start from the EU rulebook, then map controls to it, rather than retrofitting a US-first stack.

  • Sovereign by design

    Control over data, infrastructure, models, intelligence, operations, governance and supply chain, not only server location.

  • EU data boundary

    A boundary you can describe: where prompts, context, model compute, logs and backups sit, and who can administer them.

  • Audit-ready, evidence on demand

    Records produced as AI runs, so an auditor or regulator question starts from an export, not a project.

  • In-region inference

    Model compute located where you decide, with the boundary written into the Trust Profile.

  • AI Act readiness

    Controls mapped to Articles 4, 9 to 15, 26 and 50 so you use the runway before 2 Dec 2027.

Compliance-by-design map

One platform, mapped to the EU rulebook. Status lines were verified against primary sources on the date above.

  • EU AI Act

    Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744

    Risk-tiered rules for AI systems and general-purpose AI models.

    Status: Prohibitions, AI literacy and GPAI duties apply. Transparency (Art. 50) and Commission GPAI enforcement from 2 Aug 2026. Annex III high-risk from 2 Dec 2027; Annex I from 2 Aug 2028.

  • GDPR

    Regulation (EU) 2016/679

    Lawful basis, DPIAs, processor terms, transfers and automated decisions for any AI that touches personal data.

    Status: In force and unchanged. The GDPR half of the Digital Omnibus is a proposal, not law.

  • NIS2

    Directive (EU) 2022/2555

    Cybersecurity risk management, supply-chain security and incident reporting for essential and important entities.

    Status: Transposition deadline was 17 Oct 2024. National laws differ. Four Member States were referred to the Court of Justice on 8 Jul 2026.

  • DORA

    Regulation (EU) 2022/2554

    ICT third-party risk, exit strategies and concentration risk for financial entities.

    Status: Applies since 17 Jan 2025. The ESAs published the first list of critical ICT third-party providers on 18 Nov 2025.

  • Data Act

    Regulation (EU) 2023/2854

    Cloud switching rights, data portability and safeguards against unlawful third-country access to non-personal data.

    Status: Applies since 12 Sep 2025. Switching charges end on 12 Jan 2027.

  • Sector rules

    Financial, health, public-sector and product-safety law

    Sector regulators layer their own expectations on top of the horizontal rules.

    Status: Check your sector regulator. Annex I product-safety AI follows its own AI Act date: 2 Aug 2028.

Requirement, control, evidence

What you are asked to do, the platform control that supports it, and the evidence it produces. Evidence on demand means exports, not projects.

RequirementRegimePlatform controlEvidence
Know every AI system and who owns it (AI Act roles, Art. 25 value chain)EU AI ActTrust Profile per AI system: identity, owner, risk level, approved models, permitted systems.Trust Profile export; AI system inventory with role and risk classification.
Logs of operation, kept at least six months by deployers (Art. 12, Art. 26(6))EU AI ActPer-request and per-action audit trail across gateway, agents and workflows.Exportable audit log tied to identity, model, tools called, policy applied and outcome.
Human oversight by people with competence, training and authority (Art. 14, Art. 26(2))EU AI ActHuman-approval rules and escalation by autonomy level (L1 Assist to L5 Adaptive).Approval records: who approved what, when, under which rule.
Tell people they are dealing with AI; label synthetic content (Art. 50)EU AI ActPolicy-enforced disclosure and output handling, configured per use case.Policy configuration and sampled output records.
Lawful basis, purpose limitation, minimisation for personal data in prompts and contextGDPRData classification and data controls on what an agent can read; filtering and masking verbs.Data-access records and policy decisions per request; classification map.
Processor terms and sub-processor transparency (Art. 28)GDPRPublished sub-processor list and a Data Processing Agreement.Sub-processor list and DPA. The DPA is a draft template pending legal review.
Security of processing: encryption, access control, resilience, testing (Art. 32)GDPRTLS in transit, encryption at rest, scoped access, identity for every actor.Security overview and architecture description on request; access records.
DPIA before high-risk processing (Art. 35)GDPRTrust Profile and traceability supply the facts a DPIA needs.Processing description, data flows and oversight design, ready to paste into your DPIA.
Supply-chain security and secure development (NIS2 Art. 21(2)(d), 21(3))NIS2Approved-model list, pinned local models with checksum verification, sub-processor transparency.Approved-model register; model provenance records; sub-processor list.
Incident handling and 24h / 72h / one-month reporting clocks (NIS2 Art. 23)NIS2Full action trace so an agent incident can be reconstructed quickly.Reconstructable timeline: request, tool calls, data accessed, approvals, outcome.
Exit strategy and concentration risk for ICT services (DORA Art. 28, 29)DORAModel gateway across 50+ LLMs so a model or vendor can be swapped without rebuilding the application.Documented fallback models and tested switch-over records.
Switching rights and data portability (Data Act Chapter VI)Data ActOpen interfaces and exportable data, designed so you can leave.Export and migration runbook agreed in the contract.

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Thirteen facets of the Trust & Governance Fabric

The evidence in the table comes from the fabric that runs through all six platform layers. It is not a seventh layer.

  • Identity
  • Access
  • Data controls
  • Policy
  • Security
  • Privacy
  • Compliance
  • Risk
  • Human oversight
  • Auditability
  • Traceability
  • Evidence
  • Monitoring

Deployment options

Where and how AI runs is your decision. These options describe the platform position and what it is designed to let you do.

  • EU region

    Run in an EU region so prompts, retrieval context, logs and backups stay inside the EU data boundary.

    Status: Customer data is stored in AWS eu-west-1 (Ireland) today, as stated on the trust page.

  • In-country

    Pin workloads to a single country when national rules, a sector regulator or a procurement policy require it.

    Status: Designed for. Agreed per dedicated deployment; not self-serve.

  • Dedicated

    Single-tenant infrastructure and in-region inference on capacity reserved for you.

    Status: Designed for. Available through a dedicated deployment engagement scoped with you.

  • On-prem or hybrid

    Keep the most sensitive workloads on infrastructure you operate, and connect them to governed cloud workloads.

    Status: Designed for. Scoped with you. On-device mode on a Mac keeps prompts local and is available today.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

See AI sovereignty for the seven kinds of control, the Trust Profile for the data-residency record, and the trust centre for what is true today and what is not claimed.

Guides in this cluster

Each guide states who it applies to, what the rule requires with sources, how the platform supports it, and what it does not cover.

  • EU AI Act timeline

    Verified EU AI Act dates as of October 2026: what applies now, what moved to 2 Dec 2027 and 2 Aug 2028, and what applies to providers, deployers and GPAI providers.

  • High-risk checklist

    A practical EU AI Act high-risk checklist: Annex III areas, the Article 6(3) derogation, Articles 9 to 15 provider duties, Article 26 deployer duties, dates and evidence. Verified October 2026.

  • GPAI obligations

    EU AI Act general-purpose AI obligations: documentation, copyright policy, training summary, systemic-risk duties, the Code of Practice, dates and what downstream builders should ask for.

  • AI literacy (Article 4)

    Article 4 AI literacy explained: who it applies to, what the Digital Omnibus softened, how to evidence training and role-based measures. Verified October 2026.

  • AI Act penalties

    EU AI Act fines explained: EUR 35M or 7%, EUR 15M or 3%, EUR 7.5M or 1%, the SME lower-of rule, GPAI fines under Article 101, and what regulators weigh. Verified October 2026.

  • AI Act for startups

    The EU AI Act for startups and scale-ups: what applies, SME and small mid-cap relief from the Digital Omnibus, lower-of fines, sandboxes and a practical first 90 days. Verified October 2026.

  • AI regulatory sandboxes

    EU AI Act sandboxes explained: the Article 57 duty, the moved 2 August 2027 date, good-faith fine protection, exit reports, SME priority access and what is verified today.

  • GDPR for AI

    GDPR for AI explained: lawful basis and legitimate interest after EDPB Opinion 28/2024, Article 22 and the SCHUFA ruling, DPIAs, processors, security and EU-US transfers. Verified October 2026.

  • DPIA for AI

    When a DPIA is required for AI, what Article 35(7) must contain, how it links to the AI Act Article 26(9) and Article 27 FRIA, and a copyable template-style checklist.

  • NIS2 for AI

    How NIS2 applies to AI: Article 21 measures, supply-chain security, 24h/72h/one-month incident reporting, management liability, fines and transposition status. Verified October 2026.

  • DORA for AI

    How DORA applies to AI and LLM vendors: Articles 28 to 30, exit strategies, concentration risk, key contract clauses, critical provider designation and a vendor checklist.

  • Data Act and AI

    What the EU Data Act means for AI: cloud switching notice and transition periods, switching charges ending 12 January 2027, third-country access safeguards and exit planning.

  • EU AI Act guide

    Risk tiers, Articles 9 to 15 and GPAI rules in one page.

Frequently asked questions

Does using Swfte meet my EU AI Act obligations?

We do not apply a compliance label to any platform, because AI Act obligations attach to specific systems, roles and uses. Swfte is built compliance-by-design: it provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Where is my data stored?

Customer data is stored in AWS eu-west-1 (Ireland) today, as stated on the trust page. Other EU regions, in-country hosting, dedicated and on-prem deployments are the platform position and are scoped with you through a dedicated deployment engagement. They are not self-serve.

What does EU-first mean in practice?

It means the design starts from the EU rulebook. We map each requirement to a control and an evidence artefact, keep the EU data boundary explicit, and say plainly what each control does not cover. It does not mean that using the platform removes your own obligations as a provider or deployer.

When do the EU AI Act high-risk rules apply?

After the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded high-risk obligations from 2 August 2028. Prohibitions, AI literacy and general-purpose AI obligations already apply, and Article 50 transparency rules apply from 2 August 2026.

Does in-region inference mean the data never leaves the EU?

Only if the whole boundary is in the EU: prompts, retrieval context, model compute, logs, backups and administrative access. The Data Act and GDPR transfer rules also look at who can access data, not only where it sits. We describe the boundary per deployment so you can assess it.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build AI for Europe, with the evidence built in

Start with one entry point. Add governance, in-region options and evidence on demand as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.