AI in the EU: what data residency actually commits to
Keeping AI processing in the EU is four separate commitments and most vendors meet some of them. Here is what each one covers and which you need.
A client contract says the data must stay in Europe. Or a tender does, or your own head of legal does. You put the requirement to your model provider and the answer is yes, we support that. You put it to the next one and the answer is also yes. Both answers are true and they are not the same answer.
This is the half of the self-hosting conversation that never gets written down. We have already argued that most companies asking to run AI on their own hardware want residency rather than a server room, and that the arithmetic on owning the hardware rarely survives contact with the electricity bill. That leaves the question nobody answers: you have decided you need European processing, so what exactly do you buy, and what does each option commit to.
The short answer
“In the EU” is not one commitment, it is four: where the model runs, where the data sits afterwards, who can reach the machines to support them, and whose courts can compel the company operating them. A region setting buys the first. An enterprise data boundary buys the first two and most of the third, with published exceptions. A sovereign cloud run by a separate European entity is the only option that addresses the fourth. Your own hardware covers all four and costs more than all of them. Most of the disagreement in this category is one party buying the first and believing they bought the fourth.
The four things people mean
Where the model runs
This is the one everybody checks, and it is the cheapest to fix. Anthropic exposes it as a parameter on the request rather than as an account-level setting: inference_geo defaults to global, and its data residency documentation describes the geographic controls as managing where model inference runs and where data is stored. Restricting inference to a single geography carries a 1.1x pricing multiplier on its newer models, which the pricing page scopes to Claude Sonnet 4.5, Haiku 4.5, Opus 4.5 and all future models, with earlier releases keeping their existing pricing. Figures read from the live pricing page on 13 August 2026.
A per-request parameter is a good design and a bad hiding place. It means the guarantee is only as good as the code path, and every integration that forgets to set it is running globally while your policy document says otherwise. If this dimension matters to you, it belongs in a wrapper that no caller can bypass, not in a note in the runbook.
Where the data sits afterwards
Inference is a moment. Storage is a period, and providers describe the two with deliberately different verbs. Microsoft’s EU Data Boundary commits to “store and process Customer Data and personal data” within the boundary for Azure, Dynamics 365, Power Platform and Microsoft 365, and in the very next sentence says “Professional Services Data will be stored at rest for these services.” Read on the live page on 13 August 2026.
Stored at rest is a narrower promise than stored and processed, and the sentence is split in two because the two categories get different treatment. When you are comparing vendors, compare the verbs. A page that says data is stored in Europe has told you nothing about where it is processed, and a page that says it is processed in Europe has told you nothing about the logs, the backups or the abuse-detection copies.
Who can reach the machines
This is the dimension buyers discover last and lawyers ask about first. Microsoft states on the same page that its commitments “are subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary”, and that the documentation sets out those transfers. Professional Services Data is defined on that page to cover consulting services and “technical support services provided by Microsoft that help customers identify and resolve issues affecting Products”.
Take that at face value, because it is more disclosure than most vendors offer. A support engineer who needs to look at a failing tenant is doing something the boundary contemplates, and the vendor that publishes its exception list is in a better position than the vendor whose marketing page has no exceptions in it at all. A boundary is a strong contractual commitment with documented holes, not a wall.
The practical version: ask for the exception list, in writing, before you sign. If nobody can produce one, that is not evidence the exceptions do not exist.
Whose law binds the operator
No region setting touches this, and it is the requirement most often meant when somebody says the data cannot leave Europe. It is not about geography at all. It is about which entity operates the infrastructure and which state can compel that entity.
AWS made this the whole product when it announced general availability of the AWS European Sovereign Cloud from Potsdam on 15 January 2026, describing it as “a new, independent cloud for Europe entirely located within the EU, and physically and logically separate from other AWS Regions” and as “the only fully featured, independently operated sovereign cloud backed by strong technical controls, sovereign assurances, and legal protections”. The same release names an appointed managing director for the operating entity, a separate lead responsible for management and operations, and an advisory board that includes two independent members, and it sets out planned expansion through sovereign AWS Local Zones in Belgium, the Netherlands and Portugal. Read live on 13 August 2026.
Notice what that is a claim about. Not latency, not the flag on the datacentre, but separation of the operation from the rest of the company. Whether it satisfies your particular regulator is a question for your counsel, and the reason the offering exists is that a region inside the ordinary operation demonstrably did not satisfy some of them.
The ladder, and where most companies should stop
| What you buy | Inference location | Storage location | Operational access | Operator’s jurisdiction |
|---|---|---|---|---|
| Default hosted API | Not committed | Not committed | Not committed | Provider’s home law |
| Region-restricted API | Committed, per request | Depends on the service | Not usually addressed | Provider’s home law |
| Enterprise data boundary | Committed | Committed, read the verbs | Committed with published exceptions | Provider’s home law |
| European sovereign cloud | Committed | Committed | Committed, EU-operated | Separate European entity |
| Your own hardware | Yours | Yours | Yours | Yours |
Read the table downward and cost rises with every step, the first one by a published multiplier and the rest by negotiation. Read it across and notice that the region-restricted row closes exactly one column and leaves the other three open or conditional. That is the gap between what a region setting delivers and what a client contract usually asks for.
Most companies should stop at row three. The step from there to row four is bought by organisations whose requirement is written in terms of compulsion rather than location: public sector, defence, health, and any private company whose own client contract inherits one of those. The step to row five is bought by the far smaller set whose data may not touch a third party at all, and the cost of that step is worked through in the self-hosting piece.
What the first three rows all rest on
Every row above row four rests on a legal instrument rather than on physics, and legal instruments move. The Commission’s own page on EU to US transfers carries its 2015 communication on transfers following the Court of Justice judgment in Case C-362/14, and describes the current framework’s binding safeguards as introduced “to address the points raised by Court of Justice of the European Union in its Schrems II decision of July 2020”. Read live on 13 August 2026. That is a mechanism which has twice been rebuilt after a court decision, which is a reason to write review dates into the contract rather than a reason to buy hardware. Build on it, do not assume it is permanent, and know which row you would move to if it changed.
The AI Act is not a residency rule
This one is worth stating plainly, because it became applicable this month and the timing invites the mistake. The AI Act “entered into force on 1 August 2024 and became applicable on 2 August 2026”, with the governance rules and the obligations for general purpose AI models applicable since 2 August 2025. Verified on the Commission’s live page on 13 August 2026.
It regulates what an AI system may do, how it is classified by risk, and what has to be disclosed to the people on the other side of it. It says nothing about where inference runs or where data is stored, because that ground belongs to GDPR and to your processor contract.
The two questions turn up in the same meeting, get merged into one line on a procurement form, and produce the two mirror-image errors. A company buys a sovereign endpoint and treats an AI Act obligation as discharged, which it is not. Or a company completes an AI Act assessment and treats residency as settled, which it also is not. They are separate requirements with separate evidence, and the fastest way to keep them apart is to write them on separate lines from the start.
What to write down before anyone quotes you
Four things, in this order, and they take an afternoon rather than a project.
The sentence that requires it. Quote the clause, from the contract, the tender or the regulation. If nobody can find it, you have a preference rather than a specification, and preferences do not need sovereign infrastructure.
Which of the four columns it constrains. A clause about where data is stored is a different purchase from a clause about who can be compelled to produce it. Most clauses constrain one or two columns, not all four.
The exception list. Ask each vendor for the documented circumstances in which data leaves. Compare the answers rather than the marketing pages. A published exception list beats an unqualified promise.
Who enforces it in your own code. The strongest commitment in the world is undone by one integration that calls the global endpoint. Whatever you buy, one place in your code should set it and no caller should be able to override it.
If you want a second opinion on which row you actually need before somebody quotes you for the top of the ladder, that is a short conversation and a cheap one: AI and automation.