
By Marta Reinders
Published on August 4, 2026
Sovereign AI Registry — finding, 4 August 2026. Verified against first-party sources on that date; every claim below is checkable from the URLs given.
France and Germany have spent five years building "trusted clouds" — joint ventures that wrap American hyperscaler technology in European legal and operational control, qualified against ANSSI's SecNumCloud or the BSI's requirements for public administration. Three of them are the ones everyone names: Bleu, S3NS, and Delos Cloud.
We went looking for the sovereign AI a European buyer can actually procure today. None of the three can sell them any.
| Backing | Technology | Sovereignty credential | AI available today |
|---|---|---|---|---|
Bleu | Orange + Capgemini | Microsoft Azure & M365 | SecNumCloud 3.2 in progress (milestones J0, J1) | No AI service in the published catalogue |
S3NS | Thales + Google Cloud | Google Cloud | SecNumCloud 3.2 qualified (Dec 2025) — IaaS+CaaS+PaaS in one ANSSI decision | No. Vertex AI slated for Q3 2026 |
Delos Cloud | SAP (subsidiary) | Microsoft Azure | Built to BSI public-sector cloud requirements | No. "OpenAI for Germany" is a staged 2026 rollout |
And when the AI does arrive, it will be Google's, Microsoft's and OpenAI's models. The sovereignty is in the operating company, the staff vetting and the physical separation. It was never in the models.
None of the three is graded in the registry, for the same reason fal.ai was left out of the Hugging Face audit: you cannot publish a governance score for a product that does not exist yet. This finding is what we found instead.
Bleu's own services page lists what it sells in its "cloud de confiance": Virtual Machines, AKS, Functions, App Service, Blob/Disk/Files storage, NoSQL and relational databases, Redis cache, Service Bus, API Management, Event Grid, Data Factory, Logic Apps, Virtual Network, ExpressRoute, Firewall/WAF, Front Door, Data Lake Storage, Event Hubs, Data Explorer, Power BI, Microsoft Fabric, Entra ID, Key Vault, Bastion, Defender for Cloud, Policy, Monitor, Backup, Site Recovery, Cost Management — plus the Microsoft 365 suite.
Azure OpenAI does not appear anywhere on it. Neither does any other AI service.
On qualification, Bleu has passed ANSSI's J0 milestone (application accepted) and J1 (evaluation strategy accepted) toward SecNumCloud 3.2 for its IaaS, PaaS and CaaS layers. Those are procedural gates, not the qualification. The target has been "first half of 2026".
Source: bleucloud.fr/nos-services, read 4 Aug 2026; bleucloud.fr on the J0 milestone.
S3NS is the one that genuinely cleared the bar. It obtained SecNumCloud 3.2 for PREMI3NS in December 2025 and is the only provider to hold it across IaaS, CaaS and PaaS simultaneously in a single ANSSI decision. A French-law company, three data centres in France, an alliance between Thales and Google Cloud, seventy-plus customers in insurance, finance, industry and the public sector.
Its homepage lists PREMI3NS, CRYPT3NS and Google Cloud partner services. It does not mention Vertex AI, Gemini, or AI at all. Vertex AI is scheduled to join the PREMI3NS catalogue in Q3 2026.
So the most rigorously qualified sovereign cloud in Europe currently offers a French public buyer no way to run a large language model inside its qualified perimeter — and the way it will offer is Google's.
Source: s3ns.io/en, read 4 Aug 2026; Thales press release on the SecNumCloud qualification.
Delos Cloud is an SAP subsidiary providing a sovereign cloud for German public administration based on Microsoft Azure technology. The separation is real and worth stating fairly: physically and legally separated from Microsoft, operated by security-cleared Delos personnel in Germany, all customer data in Germany, built against BSI requirements. Azure Foundational and Mainstream Services plus Microsoft 365 became technically available from 2025.
The AI layer is "OpenAI for Germany", announced by SAP and OpenAI in September 2025: OpenAI's models, on Delos Cloud, on Microsoft Azure technology, targeting roughly 4,000 GPUs, with a staged public rollout through 2026 aimed at government and research customers.
Count the dependencies in the sovereign offering: the models are OpenAI's, the cloud technology is Microsoft's, and the operator is SAP. Exactly one of those three is European.
Sources: openai.com — OpenAI for Germany; Arvato Systems on Delos Cloud.
This is not only a public-sector story, and SAP makes the point twice.
SAP Generative AI Hub — SAP AI Core's governed access layer, the commercial product, generally available today — is now graded in the registry. SAP is German, listed in Frankfurt, certified to ISO/IEC 42001 for AI management systems, SOC 1 and SOC 2, with a clean contractual commitment that customer data is never shared for third-party model training.
Its SAP Managed Models are GPT-5 via Microsoft Azure OpenAI, Gemini 2.5 Pro via Google Vertex AI, and Claude via AWS Bedrock.
Applying the registry's data-path rule — jurisdiction follows the prompt, the same rule that lets Cohere North score none-eu — it lands at C 52: the same band as Hugging Face Inference Providers and Microsoft 365 Copilot.
Thirty-eight points below STACKIT, a German competitor, in the same country, selling to the same buyers, out of German data centres.
The gap is not a supply gap. Ten European AI services were graded in this pass, and the independent ones score at the top of the entire 58-row registry:
Provider | Country | Grade | What it is |
|---|---|---|---|
🇩🇪 | A 96 | open-source assistant, open weights on your own server | |
🇩🇪 | A 88 | Schwarz Group; own DCs in DE/AT; ISO 27001 + BSI C5 Type 2 | |
🇵🇱 | A- 84 | 4 Polish regions; serves the state-backed PLLuM model | |
🇸🇪 | A- 83 | Swedish; every sub-processor named with an org number | |
🇨🇭 | A- 82 | own Swiss DCs, in-house development, no outsourced support | |
🇩🇪 | A- 80 | dedicated GPU instance, BSI C5-tested German cloud | |
🇨🇭 | B+ 78 | zero-access encryption, no logs, open-source client | |
🇫🇷 | B+ 76 | on-premise, air-gap capable; Euronext-listed | |
🇩🇪 | C 52 | brokers Azure OpenAI / Vertex / Bedrock | |
🇱🇺 | C 46 | EU regions; publishes nothing about inference data |
Add the ones already in the registry — IONOS A 86, Scaleway A 86, OVHcloud A 86, Mistral A 86, T-Systems A- 80, Exoscale B+ 79 — and a European buyer has well over a dozen options that score at or above 76.
The split runs straight down the middle of that table. Providers that own the whole path score A or A- because there is nothing in the chain left to disclose. Providers that broker somebody else's models score like the models they broker. It has nothing to do with which flag is on the letterhead.
The European Commission's Cloud Sovereignty Framework — guidance and the official SEAL calculator published 1 June 2026 — already sat behind a €180M award in April 2026 that set a minimum of SEAL-2. SecNumCloud qualification is written into French public tenders. Both instruments were designed for cloud procurement, and both are being read across to AI.
The read-across breaks in a specific way. A cloud can be made sovereign by moving the operating company, vetting the staff and separating the racks — which is precisely what Bleu, S3NS and Delos have done, competently. An AI service cannot, because the model is the service. You can host GPT-5 in Frankfurt with German operators and German legal control, and it is still OpenAI's model under OpenAI's terms, updated on OpenAI's schedule, and you cannot run it anywhere else.
The vendors that score highest in this registry get there the other way round: they serve open weights, so the buyer's exit cost is a base URL rather than a rebuild. That is a property of the model licence, not of the data centre — and no sovereignty framework currently in force scores it.
undisclosed. If any of the three ships an AI service, it gets graded like everything else.undisclosed off a fetcher's view — the failure mode that produced two wrong grades in the 3 August correction pass, where Mistral's and xAI's sub-processor lists turned out to be public all along — no row was published. This is a gap in our reading, not a proven gap in Nebul's disclosure.score.py and the published field values.