Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

A bar diagram of seven columns on a baseline. Three short columns are capped by a solid horizontal bar drawn across their tops. Four taller columns rise past that bar and reach a dashed horizontal line near the top of the frame.

Analysis

Three ceilings that cap an AI vendor's sovereignty grade

By Marta Reinders

Published on August 31, 2026

Of the 83 vendor records in this registry, 44 sit under US CLOUD Act exposure. Their median sovereignty score is 52, and the best score any of them reaches is 66. The A band, which the registry draws at 80 and above, holds 20 records. Every one of them is a vendor graded as having no extraterritorial government access exposure at all.

The same shape appears on two other properties of the data path, and in each case it behaves like a ceiling rather than a tendency. Who can compel access to the data, whose sub-processors sit inside the path, and where the data comes to rest each put a hard cap on the score a record can reach. What a vendor does on top of that, publishing a data processing agreement, getting audited, committing in writing never to train on customer content, moves a record around inside its band. It does not move a record through the ceiling. The methodology grades the weakest link in the data path, so the lowest-rated element of a stack sets the result for the whole stack.

Three ceilings, measured

Property of the data path

Records

Median

Best score

US CLOUD Act exposure

44

52

66

Sub-processors non-EU

32

52

66

Sub-processors undisclosed

13

34

54

Residency non-EU only

23

38

54

No government access exposure

27

86

96

Sub-processors structurally none

11

93

96

Residency customer controlled

13

93

96

The three capped classes stop at 66, 54 and 54. The three uncapped classes carry medians of 86, 93 and 93. Nothing in the capped classes appears in the A band.

Jurisdiction attaches to the operator, not the region

Of the 44 records with US CLOUD Act exposure, 21 fall in the registry's low band, 23 in the mid band, and none in the A band. This is a statement about legal reach over the entity that runs the service. It is not a statement about how carefully that service is engineered, and the two get confused constantly in procurement.

Microsoft 365 Copilot has EU Data Boundary residency, an AI management system certification and a written never-train commitment. Its record also notes that flex routing is on by default for newer EU and EFTA tenants, which permits inference to leave the boundary during peak demand. GitHub Copilot (Business / Enterprise) supports EU data residency aligned to the same boundary, has it disabled by default, and every AI inference sub-processor on its published list discloses United States processing. Both are well-documented products from vendors with deep compliance functions. Both sit under the same ceiling, because the ceiling is not about documentation.

The 27 records with no extraterritorial government access exposure have a median of 86 and supply all 20 A band entries.

The sub-processor ceiling is the harshest of the three

Three kinds of sub-processor chain produce three outcomes. The 32 records with a disclosed non-EU chain have a median of 52 and top out at 66. The 13 records where the chain is undisclosed have a median of 34 and top out at 54. The 11 records with no sub-processor in the inference path at all have a median of 93.

The undisclosed cap deserves a precise reading. It is not a finding that those vendors mishandle data. It is a finding that a buyer has nothing to check, which under GDPR accountability is the buyer's problem regardless of what the vendor actually does. Qodo Gen and Qodo Merge scores 32 and states on both its pricing and enterprise pages that it does not train on customer code, but its trust centre refused every automated request path attempted, so no roster was readable. Augment Code scores 34 while holding an AI management system certification and an independent security attestation, and directs anyone wanting the sub-processor list to contact the company. Windsurf publishes a sub-processor URL whose body reads that the page does not exist.

Among the 20 A band records, 10 have no sub-processor in the path, 5 are vertically integrated inside the EU, 4 have an EU-only chain, and 1 is mixed. No record with a non-EU or undisclosed chain is in there.

Where the data comes to rest

The 23 records with non-EU-only residency have a median of 38 and a best score of 54. The 13 records where residency is customer controlled, meaning the buyer picks the machine, have a median of 93.

This is the ceiling buyers most often try to solve with a region setting. The point worth adding here is narrower than the region argument: residency and jurisdiction are separate caps, and both apply at once. Clearing one does not clear the other.

What moves a score inside its band

Plenty, and it is worth knowing what, because most procurement negotiation happens in this space rather than at the ceiling.

Zero data retention: 52 records have it available, with a median of 61.5, against 18 that do not, with a median of 47. A further 13 records have no value recorded for the field, so read that comparison as covering only the rows where it is known.

A data processing agreement: 69 records have one, median 56, against 8 that do not, median 42.

Deployment shape moves the most. The 68 hosted records have a median of 52.5. The 6 records deployed as self-hosted weights have a median of 95.5 and a minimum of 93. The existence of a self-host option is a much weaker signal than actually using it: the 26 records where a self-host option is available have a median of 77.5, but they range from 24 to 96, because the registry grades the deployment described rather than the one available.

The shapes that clear all three ceilings

Self-hosted weights clear all three by removing the vendor from the path: Duo Self-Hosted at 96, Continue at 96, Nextcloud Assistant at 96, Whisper at 95, Mistral open-weights models at 93 and DeepSeek R1 at 93. Three of those six are published by US companies and one by a Chinese company, which is the clearest evidence that the ceilings track the data path and not the vendor's passport.

A vendor-operated service can also clear them by being wholly EU-resident and vertically integrated, as STACKIT AI Model Serving does at 88, alongside IONOS AI Model Hub and Scaleway Generative APIs. So can a commercial product that runs inside the customer's own infrastructure: Cohere North at 87 and Speechmatics on-premises containers at 86.

Across the whole registry, 22 of 83 records carry a pass on EU procurement readiness.

What to check in your own stack

Work the three ceilings first, in this order, before you read a single certification.

  • Establish who can be compelled. Find the contracting entity and its ultimate parent, not the data centre location. A US parent means CLOUD Act exposure whatever region you selected, and in this registry that caps a record at 66.
  • Get the sub-processor roster in writing, with countries. If the vendor's answer is to contact sales, treat the chain as undisclosed. That is the harshest cap in the data, a best score of 54, and it is also the one most often fixable by simply asking before you sign.
  • Separate residency at rest from residency at inference. Several records in this registry store data in the EU and send the prompt somewhere else, sometimes under a default an admin has to turn off rather than on.
  • Check whether region enforcement fails closed. A setting that silently falls back to another region under load is not residency, it is a preference.
  • Then evaluate what moves a score inside the band. Zero retention availability, a real data processing agreement and a deployment you control are where negotiation actually pays, once you have accepted which band the vendor can reach.

If the workload genuinely cannot sit under a foreign access regime, the ceiling is not something to negotiate around. The data says the only reliable route past it is to change the data path: run the weights yourself, or buy from a vendor with no non-EU link in its chain to begin with.

This article was researched and written by an automated pipeline from the Sovereign AI Registry's own data, then published without human review. Every figure is computed from the registry's live records. Corrections: open an issue.