Sovereign AI: what it means for a company or public body
As of 11 October 2026
For an organisation, sovereign AI means keeping the decisions about its AI use in its own hands: where data is stored and processed, who operates the service, which law can reach that operator, which models are allowed, and how to leave. It does not mean training your own large language model. Most of these points can be settled through a contract and a configuration. A few cannot be settled at all if you insist on one particular frontier model.
Two different things called sovereign AI
Governments use the term for national capacity. The UK's AI Opportunities Action Plan of 13 January 2025 proposed a new unit, UK Sovereign AI, “with the power to partner with the private sector to deliver the clear mandate of maximising the UK's stake in frontier AI”. The European Commission has opened a call for tenders for up to seven AI Gigafactories, which it presents as part of a push “to accelerate Europe's technological sovereignty”. Both programmes are about compute and research, and about who builds the next generation of models.
A hospital trust, a district council or a mid-sized insurer will not train a frontier model. Its question is narrower. Can it decide where its prompts and documents go? Can it show that decision to a regulator or an auditor? Can it switch provider in two years without losing its data? These questions have answers you can check, and the rest of this page is about them. Buying European AI helps with some of them, though not with all.
Six controls you can check before you sign
| Control | The question to ask | Evidence worth asking for |
|---|---|---|
| Data location | Where are prompts, files and logs stored, and where does inference run? | Named locations per type of data, including backups and support access |
| Operator | Who runs the servers and the models, and which subprocessors are involved? | Data processing agreement, subprocessor list with locations |
| Applicable law | Which jurisdictions can compel the operator to disclose data? | Legal seat of every operator in the chain, transfer assessment |
| Model choice | Can you restrict models per project or use case? | Settings enforced on the server, visible to admins |
| Exit | Can you take your data and configurations with you in open formats? | Export function and an end-of-contract clause |
| Dependence on non-EU providers | What stops working if one provider changes its terms? | A second model already tested for each critical task |
Location and jurisdiction are often treated as one thing. The UK National Cyber Security Centre warns in principle 2.1 of its cloud security principles that identifying the jurisdictions your data is subject to “may be more complex than simply clarifying the physical locations where data is stored, processed, or accessed by the service provider”. It lists the legal base of the provider and the places from which the service is supported and operated as separate factors.
The US CLOUD Act is the usual example. Under 18 U.S.C. § 2713, a covered provider must disclose data within its “possession, custody, or control”, “regardless of whether such communication, record, or other information is located within or outside of the United States”. A data centre in Frankfurt or London answers the location question. On its own, it leaves the jurisdiction question open.
Security teams usually ask about a second US rule as well. Section 702 of the Foreign Intelligence Surveillance Act (50 U.S.C. § 1881a) allows foreign intelligence collection aimed at people reasonably believed to be outside the United States, and the government can direct an “electronic communication service provider”, a term that includes cloud services, to help in secret. Congress last extended it to 12 June 2026; no further extension had been enacted by 11 October 2026, and directives issued before then remain in effect until they expire.
Model choice and exit are the two controls that get forgotten. A workspace can be hosted in the EU and still send a request to a model provider elsewhere the moment a user picks that model. And a tool that holds two years of prompts and knowledge bases is hard to leave if the only export is a PDF of chat histories.
The UK view
UK organisations work under the UK GDPR and the Data Protection Act 2018. The Information Commission (formerly ICO) calls it a restricted transfer when you send personal data to a separate organisation outside the UK, and its guide of 15 January 2026 says every such transfer “must be covered by one of the following transfer mechanisms”: UK adequacy regulations, appropriate safeguards such as the International Data Transfer Agreement, or an exception. That applies to a US model API in the same way as to a workspace hosted in the EU.
For the AI use itself, the Information Commission expects a data protection impact assessment in most cases: “In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms”. The Information Commission also notes that its AI guidance is under review following the Data (Use and Access) Act 2025, so check the current version before you rely on details. For the operator questions, the NCSC's 14 cloud security principles make a good procurement checklist.
The EU view
In the EU, the GDPR sets the transfer rule in Chapter V. Under Art. 44, a transfer to a third country may only take place if the conditions of that chapter are met. The AI Act adds duties that depend on your role. An organisation that uses an AI system “under its authority” in its professional activity is a deployer under Art. 3(4).
The timetable changed this year. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It softened Art. 4: providers and deployers now “shall take measures to support the development of AI literacy” of their staff, and they no longer have to reach a specific level for each person. The transparency duties in Art. 50 apply from 2 August 2026. Obligations for high-risk systems listed in Annex III apply from 2 December 2027, and for high-risk AI in products covered by Annex I from 2 August 2028.
The AI Act also reaches providers and deployers in third countries “where the output produced by the AI system is used in the Union” (Art. 2(1)(c)). A UK firm with EU customers should read it too.
Neither law requires you to use a European model or a European operator. What both demand is that you know where personal data goes, have a legal basis and a transfer mechanism, and can show it. Sovereignty makes that easier to prove, which is why procurement teams ask for it.
What sovereignty costs
Be honest about the trade-off. If a team depends on one frontier model that is only offered by a provider outside the EU, a strict EU-only rule takes that model away. Open-weight models that run on European infrastructure are a real option for many tasks, and you should test them on your own work instead of trusting a benchmark table.
A workable answer for most organisations is a split by sensitivity. Projects with health data or personnel files run only on models operated in the EU. Other work may use external models, with personal data masked before the request leaves. Because the placeholders are swapped back in the answer, this counts as pseudonymisation under Art. 4(5) GDPR: the provider sees less, but the masked text is still personal data.
What Myra AI Workspace offers, and where it stops
Myra AI Workspace combines chat, projects with knowledge, agents and workflows, built around an AI gateway that decides where each request goes. Myra Security GmbH has no US parent and no US subsidiary. How that bears on the CLOUD Act or FISA in your case is for your counsel to judge. Myra models run on Myra's own EU infrastructure, which holds a BSI C5 Type 2 attestation; that attestation covers the infrastructure and does not extend to the workspace application. A project can be set to “Local only”, which limits it to Myra-hosted models and switches off cloud models, web search and external tools.
EU routing can be enforced per gateway or for the whole organisation. It is off by default; once it is on, routes outside the EU are refused before a provider is called. PII masking is included in every plan. Customer data is not used by Myra to train AI models. At the end of a contract, tenant data can be handed over in open formats (JSON and CSV).
For location requirements beyond that, data can optionally be stored in Switzerland on Myra's own infrastructure, with inference of the Myra models on Myra's EU infrastructure. Hosting in other countries, the UK included, is possible on request, and so is an on-premises deployment, with Myra handling licensing, hardware requirements and deployment support.
The limits are just as concrete. External models run on their providers' infrastructure under those providers' terms, and masking only reduces what they receive. On a paid self-service plan, the Myra-hosted models require the “EU-Gov” add-on. The interface is available in German and English only. Admin changes and security events are logged, and the log can be made tamper-evident with a hash chain on request; customer administrators have no view of that audit log in the interface.
If you are comparing chat tools for everyday work, the guide to a European ChatGPT alternative goes through the options. For the rules and processes around the tool, see AI governance.
Frequently asked questions
Is sovereign AI the same as EU data residency?
No. Data residency answers where data is stored and processed. Sovereignty also asks who operates the service, which law can compel that operator to hand over data, which models your teams may use and whether you can leave with your data. A service can meet a residency requirement and still leave you dependent on one provider outside your jurisdiction.
Can a UK organisation use an AI service hosted in the EU?
Yes, if the UK GDPR transfer rules are met. According to the Information Commission (formerly ICO), sending personal data to a separate organisation outside the UK is a restricted transfer, and it needs UK adequacy regulations, appropriate safeguards or an exception. Check which mechanism covers the destination, and carry out a DPIA for the AI use itself.
Does the EU AI Act require sovereign AI?
Not as such. The AI Act regulates risk and transparency; it does not prescribe where a model runs or who operates it. Questions of location and transfer come from the GDPR. Deployers still have duties, for example the transparency rules in Art. 50, which apply from 2 August 2026.
Do we have to give up models from US providers?
Usually not. Many organisations split their work by sensitivity. Projects with sensitive data use only models operated in the EU, and other work may use external models with personal data masked before the request leaves. In Myra AI Workspace that split is a project setting, “Local only” or “PII protection required”, which the server enforces.
Sources
- UK Government: AI Opportunities Action Plan (13 January 2025), retrieved 11 October 2026
- European Commission: AI Factories and AI Gigafactories, retrieved 11 October 2026
- NCSC: Cloud security principle 2, asset protection and resilience, retrieved 11 October 2026
- 18 U.S.C. § 2713 (CLOUD Act), Legal Information Institute, retrieved 11 October 2026
- 50 U.S.C. § 1881a (FISA Section 702), Legal Information Institute, retrieved 11 October 2026
- 50 U.S.C. § 1881 (definitions, “electronic communication service provider”), Legal Information Institute, retrieved 11 October 2026
- Pub. L. 119-87 of 30 April 2026 (extension of FISA title VII to 12 June 2026), retrieved 11 October 2026
- FISA Amendments Act of 2008, § 404(b) transition procedures, note to 50 U.S.C. § 1801, Legal Information Institute, retrieved 11 October 2026
- Congress.gov: public laws of the 119th Congress, retrieved 11 October 2026
- Information Commission (formerly ICO): A brief guide to international transfers, retrieved 11 October 2026
- Information Commission (formerly ICO): Guidance on AI and data protection, accountability and governance, retrieved 11 October 2026
- Regulation (EU) 2016/679 (GDPR), EUR-Lex, retrieved 11 October 2026
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex, retrieved 11 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, retrieved 11 October 2026
- Myra AI Workspace documentation, retrieved 11 October 2026