Analysis

Sovereign AI: what it actually changes for a business

Sovereignty is not a flag. It is the answer to a concrete question: who can access your data, and under which law?

Fluid blue and purple shapes curling on a dark background
Sovereignty is decided by the applicable law, not by the shop front

The phrase “sovereign AI” has become a sales argument, and lost part of its meaning along the way. It appears on offers hosted in France by companies subject to foreign law, on European models accessed from American servers, on tools that promise to keep nothing without any way to check. For a business, the question is not whether an offer calls itself sovereign. It is who can access its data, and under which law.

Put that way, the question has precise answers. They depend on four elements — the data, the model, the infrastructure and the applicable law — and they are not equally relevant to every business. A communications agency and a laboratory preparing a regulatory file do not have the same need, even if they use the same tool.

Sovereign AI: what are we talking about? Data, model, infrastructure, applicable law

Any use of generative artificial intelligence involves four elements. Sovereignty is at stake on each of them, and an offer can be sovereign on one without being so on the others.

  • The data. What is submitted to the tool — questions, documents, files — and what it keeps: logs, history, possible reuse to train other models.
  • The model. The program that produces the answers. Is it available only as a remote service, or can it be run in-house? Some vendors publish their models under an open licence; others make them available only through their own platform.
  • The infrastructure. The machines the model runs on and the data passes through: your own, a hosting provider’s, the vendor’s.
  • The applicable law. The law the infrastructure operator is subject to. It is the element most often forgotten, and the most decisive.

The last point explains most misunderstandings. The CLOUD Act, passed by the United States in March 2018, allows US authorities to require a provider subject to their law to disclose data in its possession, custody or control, wherever it is stored. A data centre located in France, operated by a company subject to that law, therefore does not put data out of those authorities’ reach. Location is a condition; it is not a guarantee.

The framework for transfers to the United States has itself changed several times. The Court of Justice of the European Union struck down the previous arrangement in the Schrems II judgment of 16 July 2020, because of the access possibilities available to US intelligence services. The current arrangement, adopted on 10 July 2023, was upheld by the EU General Court on 3 September 2025. A business relying on it is relying on a framework the courts have already undone twice under other names.

Digital sovereignty: the three levels

Digital sovereignty is not a binary state. It is more useful to think of it in three levels, each more demanding than the last, and to ask which level the business must reach for which data.

LevelWhat it guaranteesWhat it does not guarantee
1. LocationData is stored and processed in the European UnionThat no foreign authority can access it
2. JurisdictionThe operator is subject to no non-European law requiring it to hand over the dataThat the business can do without this operator
3. ControlThe business can run the model itself, or change provider without losing its usesThe performance of the largest models, most of which remain closed

The first level is the one most “hosted in France” offers claim. The second is the one targeted by ANSSI’s SecNumCloud qualification, whose framework includes requirements for protection against extraterritorial laws. The third requires open models that can run outside their vendor’s platform — and the trade-off it implies must be stated plainly: the best-performing models on the market remain, for the most part, available only as remote services.

Which businesses are most concerned

The need depends neither on sector nor on size, but on how sensitive the data entrusted to the tool is. The same business may use a consumer assistant to reword a sales message, and need a controlled environment to analyse its client files. Some situations nonetheless call for particular attention:

  • health and research, where health data follows specific rules — hosting it on behalf of others requires an HDS-certified host — and where preclinical and regulatory files are highly valuable;
  • professions bound by secrecy — lawyers, accountants, advisers — whose client files cannot circulate without control;
  • finance and wealth management, where personal data and non-public transactions are of obvious value to third parties;
  • industry, for plans, processes and patents in the course of filing, which fall under trade secrecy;
  • suppliers to the public sector, as the State strengthens its own requirements on hosting its sensitive data.

On this last point, the trend is clear. The French law of 21 May 2024 on securing and regulating the digital space requires State administrations, for particularly sensitive data entrusted to a private provider, to ensure protection against any unauthorised access by third-country authorities. Its implementing decree was published on 14 April 2026, and the SecNumCloud 3.2 framework was formally approved for that purpose by an order of 12 August 2026. These texts do not apply to private businesses; they show the direction their public-sector clients’ requirements are taking.

The CNIL, for its part, recommends that generative AI deployments favour local systems where personal data of clients or staff is involved, and otherwise that use of external infrastructure be governed by a processing contract. The question is therefore not a marginal one: the supervisory authority itself is asking it.

The options in France today

For a French business wanting to use generative AI without exposing its sensitive data, five families of options exist. They are not mutually exclusive: many businesses will combine several depending on how sensitive the use is.

  • Run an open model on your own hardware. The highest level of control, now realistic for a small business; its uses, hardware and limits are covered in Local AI: running an LLM in the business.
  • Have an open model run by a qualified host. SecNumCloud qualification is checked in ANSSI’s catalogue, not in a brochure; what a sovereign cloud really protects deserves close examination.
  • Use a European vendor’s services. Mistral AI, a French vendor, for instance publishes some of its models under the Apache 2.0 licence. For its online service, one still needs to check where it runs and what its terms provide.
  • Use the business offers of the major providers. They often come with solid contractual commitments — no training on the data, residency in Europe — but their operator remains subject to US law. That is the first level, not the second; what this choice involves is covered in ChatGPT and the GDPR.
  • Entrust execution to a provider running its own hardware in France. This is the model of Maeliom’s sovereign AI offer, open in early access: inference runs on hardware physically installed in France, with no third party the data could go to.

To choose, three questions are usually enough, asked use by use. What would happen if this data were read by a third party — a competitor, a foreign authority, the provider itself? Is the business bound, by law, by contract or by professional secrecy, to guarantee that it does not leave? And does the performance gain of a large closed model justify, for this specific use, accepting the first level rather than the second? The answers almost always draw a map with two zones: everyday uses, for which a well-governed business offer is enough, and a small number of sensitive uses, which justify a controlled environment.

None of these options is right for everything. The choice is made use by use, based on how sensitive the data is. For a business starting out, beginning with a measurable use rather than a tool remains the safest starting point — and it is often by mapping those uses that the sovereignty question finds its proper place.

Common questions

Is an AI hosted in France necessarily sovereign?

No. The location of the servers says nothing about the law their operator is subject to. If the operator falls under US law, the CLOUD Act allows US authorities to request the data from it, even when stored in France.

Does a small business really need sovereign AI?

Not for all its uses. It needs it for those involving sensitive data: client files, personal data, industrial secrets, health data. For the rest, a well-governed business offer may be enough.

Is a sovereign model less capable?

Often, yes, compared with the largest closed models on the market. For most everyday business tasks — summarising, drafting, classifying, extracting — current open models are enough. The trade-off is judged use by use.

How can you check that a cloud offer is SecNumCloud-qualified?

By consulting the catalogue of qualified solutions published by ANSSI. Qualification applies to a specific service, not to a company as a whole: check that the service being used is the one that is qualified.

Sources: US Department of Justice, CLOUD Act; 18 U.S.C. § 2713; CJEU, C-311/18, 16 July 2020; adequacy decision (EU) 2023/1795; EU General Court, T-553/23, 3 September 2025; ANSSI, catalogue of qualified solutions; CNIL, deploying generative AI (July 2024); Mistral AI, model list (consulted September 2026); Law No. 2024-449, Decree No. 2026-272 and Order of 12 August 2026.


Next article

Local AI: running an LLM inside the business, without the cloud

Read

A transformation to support?