
By Marta Reinders
Published on August 4, 2026
Sovereign AI Registry · finding · 2026-08-04 · all figures recomputable from /api/records
Hugging Face's Inference Providers feature routes your prompt to one of 17 third-party inference companies, selected in the same API call, with Hugging Face as the contracting party. Its own security page is unusually clean about the routing layer:
"Hugging Face does not store any user data for training purposes. We do not store therequest body or response when routing requests through Hugging Face."
And then:
"External providers are responsible for their own security measures, so please refer totheir respective security policies for more details."
None of the 17 appears on Hugging Face's published subprocessor list. That list — Discourse, AWS SES, AWS, Metronome, Stripe, MongoDB Atlas, GCP, GitHub, OVHcloud, Slack, Hugging Face SAS — is the list for running the Hub. The companies that receive your prompts are not on it.
So we went and graded them.
Provider | Grade | Score | Jurisdiction | Supply chain | Residency |
|---|---|---|---|---|---|
Cohere ⚠ | A | 87 | | | |
A | 86 | | | | |
A | 86 | | | | |
C+ | 64 | | | | |
C+ | 58 | | | | |
C+ | 57 | | | | |
C | 54 | | | | |
C | 52 | | | | |
C | 52 | | | | |
C | 48 | | | | |
C | 45 | | | | |
D | 43 | | | | |
D | 36 | | | | |
D | 36 | | | | |
F | 27 | | | | |
F | 13 | | | | |
Fal AI | — | — | not assessed | — | — |
⚠ Cohere caveat: the registry's Cohere row is Cohere North on-prem, a customer-deployed product — not the hosted Cohere API reached through Hugging Face. Its A 87 is not transferable to the routed service and should be read as "not assessed" for this table.
OVHcloud AI Endpoints (A 86) and Scaleway Generative APIs (A 86) are both vertically integrated inside the EU with no third-party model vendor in the path. Nscale (C+ 58) publishes the best-structured subprocessor disclosure in the whole registry — per-entry location and named transfer safeguard, with EEA colocation marked "N/A (EEA)" — and is careful to say its controls are ISO 27001-aligned rather than certified.
If you route through Hugging Face and pick one of those three, the sovereignty story holds. If you let the platform pick, it does not.
Public AI (C+ 57) is a nonprofit inference utility for public and sovereign models — Apertus from EPFL/ETH Zurich/CSCS, SEA-LION from Singapore, EuroLLM, ALIA — with open weights, open frontend, open application and published governance. It runs on AWS in Zurich. A project built as the answer to hyperscaler dependence reaches production on a hyperscaler, because at that scale the sovereign alternative is not yet there. That is not a gotcha; it is the current cost of building public AI infrastructure, and it belongs in the record.
Every value traces to a dated snapshot of a first-party source, taken with a fetcher that escalates to headless Chromium when a cheap fetch returns something a human browser would not see. undisclosed is recorded only after multiple candidate paths were probed and the vendor's own public documents were read in full — the rule exists because two launch rows recorded false undisclosed values in August 2026, one behind a JS-rendered trust center and one behind a bot-blocking CDN. Scoring is methodology v1.2, executed by score.py; all 58 live rows recompute exactly from the published API.