Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

Server racks inside a dashed boundary; a switch on the boundary is open and a pipe passes through it to a single rack outside.

Analysis

An EU region option is not EU residency

By Marta Reinders

Published on August 5, 2026

In late July the European Commission opened its call for AI Gigafactories, a tender to expand Europe's computing capacity for training and serving frontier models. The premise of the programme is that Europe's AI sovereignty problem is capacity. For the engineer, DPO or procurement lead auditing an AI vendor this quarter, the registry's data points somewhere less grand: at the region dropdown, the default nobody changed, and the fallback that fires under load.

The registry currently grades 58 AI services on data sovereignty. The largest residency class among them is the one the record pages print as "EU region selectable": the vendor offers an EU region alongside non-EU ones, and the buyer picks. There are 21 such rows. Their median sovereignty score is 57, next to a registry-wide median of 57.5. The class performs like the registry at large, which is another way of saying the checkbox on its own adds nothing.

The band breakdown is blunter. Of those 21 rows, 19 sit in the mid band, a score of 50 to 79, and 2 sit below 50. None reaches the A-band, a score of 80 or above. Every class that fixes residency structurally, instead of offering it as an option, sits above them.

What each residency class actually delivers

Residency class

Rows

Median score

A-band rows (80+)

Customer controlled (you run it)

6

90

5

EU only

9

84

8

EU by default

2

82

1

Adequacy-covered country only

3

73

1

EU region selectable

21

57

none

EU only via a third party

3

46

none

No EU residency

13

44

none

PRC only

1

24

none

The line through the middle of that table is the finding. Above it, residency is a property of the architecture: either the buyer runs the model, or the vendor has no non-EU region to route to. Below it, residency is a property of a configuration, and configurations have defaults, carve-outs and fallbacks. How residency feeds the grade is documented on /methodology.

Where the checkbox leaks

Reading the selectable rows, the same mechanisms keep appearing.

The default points away from Europe. Fireworks AI Platform has zero data retention by default and a documented single-region option in Frankfurt. But a deployment is multi-region and global unless the customer asks otherwise: the sovereign configuration exists, and it is not the one you get. Microsoft 365 Copilot is sold as an EU Data Boundary service, yet flex routing, on by default for newly created tenants, lets model inferencing leave the boundary during periods of peak demand. EU-only inferencing is reachable, but only through an explicit admin setting, which makes it a configuration you can get wrong rather than a guarantee. GitHub Copilot Business and Enterprise now supports EU data residency aligned to the same Microsoft boundary; the policy is disabled by default, requires the data-residency flavour of Enterprise Cloud, and changes request pricing.

The claim covers less than it sounds like. Notion AI offers Europe residency on its Enterprise plan, but the commitment covers data at rest only, and Notion explicitly excludes data processed by its subprocessors. The AI feature is delivered by those subprocessors, so the inference path has no EU option at any price. Cortex AI is stronger by design, since Snowflake deploys every model it offers inside its own service perimeter and EU regions are selectable. The exception is a feature flag: enabling cross-region inference adds the hyperscalers as subprocessors specifically to serve requests from other regions, so an EU account's inference can leave the EU with one setting.

The region does not move the company. A residency setting pins compute, not jurisdiction. 33 of the 58 vendors in the registry carry US CLOUD Act exposure, and selecting a Frankfurt region does not change which legal entity answers a United States production order. The registry's crosstab of score band against government access exposure shows the consequence: all 15 rows in the A-band are rows with no extraterritorial access regime recorded in the data path. Not a single CLOUD Act-exposed vendor reaches the band, whatever regions it sells.

The exceptions show what to ask for

Inside the selectable class, Agentforce 360 is the only row in its category that lets a European customer make inference fail rather than leave the region. Salesforce ships a setting named Enable In-Region Model Requests Only, which disables region fallback entirely, plus a separate toggle that switches off the final fallback to the United States. The row still grades as conditional for other reasons, including United States jurisdiction and data masking currently disabled for agents. But the shape of the control is exactly right: the buyer can choose breakage over leakage. That is the question to put to any vendor in this class. Not whether an EU region exists, but whether requests can be made to fail rather than leave it.

Outside the class, the registry's strongest hosted rows never hand the buyer that decision in the first place. AI Model Serving from STACKIT, the highest scoring hosted service at 88, runs on group-owned data centres in Germany and Austria, with development and operations in Germany; there is no non-EU region to fall back to. AI Model Hub from IONOS, at 86, processes inference in German data centres and discards requests once they are served. The registry's note on that row makes the general point: its sovereignty is structural rather than contractual, and there is no configuration a buyer can get wrong.

What to check in your own stack

If you run one of the selectable-region vendors today, the gap in the table is not an argument to rip anything out. It is a checklist.

  • Find where the region is actually fixed. If it is a contract term, good. If it is a console toggle, restrict who can change it and alert on changes.
  • Ask the peak-load question in writing: when the selected region is at capacity, do requests fail or fall back to another region. Fallback behaviour tends to be documented under routing or capacity, not on the residency page.
  • Map the residency claim to the data path. Data at rest, inference, and subprocessor processing are separate claims; Notion's at-rest-only carve-out and Snowflake's cross-region flag both live in the gaps between them.
  • Check the operating entity's jurisdiction separately from the data centre's location. If the entity is exposed to an extraterritorial access law, the region setting does not remove that exposure.
  • If the workload could run on an EU-only host or on your own hardware, price that option. The top of the table is not occupied by vendors with better checkboxes; it is occupied by vendors with no checkbox at all. The grading rubric is on /methodology.

This article was researched and written by an automated pipeline from the Sovereign AI Registry's own data, then published without human review. Every figure is computed from the registry's live records. Corrections: open an issue.