Most European companies running AI believe they have solved data sovereignty. They chose the EU region. Frankfurt, Paris, Dublin. The data sits on European soil, so it is European, and the matter is closed.
It is not closed. And you do not have to take our word for that, because the provider said so.
In June 2025, at a hearing of the French Senate, Microsoft’s Director of Public and Legal Affairs for France was asked a plain question under oath: could he guarantee that French citizens’ data held in Microsoft’s cloud would never be passed to US authorities without the approval of the French state? His answer was equally plain.
No, I cannot guarantee it.
Said under oath, by the provider, that one sentence ends a long argument. Choosing the EU region does not make your data sovereign.
Residency is not sovereignty
The whole confusion lives in the gap between two ideas that sound the same and are not.
- Data residency is about where your data physically sits. An EU region gives you this. Your bytes are in Frankfurt.
- Data sovereignty is about who holds legal power over it. That does not follow the server. It follows the company.
When the company holding your data is US-controlled, US law reaches it wherever it sits. The CLOUD Act lets US authorities compel a US-based provider to produce data the company holds anywhere in the world, including its European data centres, without notifying you and without involving any European authority. A German or French legal entity with a sovereign label on the door does not sever this, because the US parent still exists, and the parent is still bound.
So the EU region solves residency, which is real and useful. It does not touch sovereignty, which is the thing a regulated buyer actually needs.

What happens to your prompts after you hit send
Here is the part a compliance review feels, not just the part a lawyer argues.
“We do not train on your data” is the reassurance everyone repeats. It is probably true. It is also only half of the question. Whether a provider trains on your data and whether it keeps your data are two separate promises, governed by two separate controls. A provider can honestly say it does not train on your prompts while still storing them.
And by default, it stores them. On the major US platforms, standard API traffic is retained for a window, commonly up to 30 days, for abuse monitoring, on US infrastructure. Zero data retention exists, but it is not the default. It is an option you have to request, get approved on the right account tier, and then verify is actually live. Teams routinely assume it is on because someone submitted the request, while production traffic runs for weeks under the standard window.
Even when zero retention is approved, it is a contractual commitment, not a technical guarantee. No major provider hands you cryptographic proof that nothing was kept. You are trusting a promise you cannot inspect.
And a free text prompt almost always contains personal data, a name, an account number, a case detail, even when you were not trying to collect it. GDPR asks that personal data be kept no longer than necessary. A retention window on someone else’s infrastructure becomes a data minimisation problem the moment a user types a name.

The legal ground is moving too
Underneath all of this sits the mechanism meant to make transatlantic data flows lawful in the first place, the EU-US Data Privacy Framework. It is under live legal challenge again. The two frameworks before it were both struck down. Building your compliance on the third while it is being contested is building on ground that has already moved twice.
The point most people miss
Every fix above is a better promise. A stronger contract. A sovereign-region rebrand. A zero-retention request. They are all the same shape: trust us, we will protect your data.
Sovereignty is not a better promise. Sovereignty is an architecture in which the provider is not capable of betraying the promise, because it never held your data in a place where it could be compelled to hand it over.
You do not want a provider who promises not to look. You want a provider who structurally cannot.
How TensorX closes it
This is exactly why TensorX is built the way it is.
- EU-incorporated, EU-resident. There is no US parent to compel. The CLOUD Act has no hook here, because there is no US company anywhere in the chain.
- Zero data retention by design, for everyone. Not a request, not a tier, not an assumption. We do not store your prompts or your outputs, so there is nothing to retain and nothing to produce.
- Open-weight models on our own EU hardware. Your data never leaves European jurisdiction, and it never touches infrastructure a foreign government can reach.
You are not choosing a provider who will fight for your data. You are choosing an architecture where the fight cannot start, because the access that would start it does not exist.
The honest version
To be precise, because precision is the whole point: this is not the claim that using a US provider is illegal. It is narrower and harder to argue with. For a bank under DORA, a hospital, an insurer or a public body, the acceptable level of unresolved jurisdictional risk is zero. “We would resist an unfounded request” is a statement about willingness. It is not a statement about capability. And when the provider’s own lawyer has said, under oath, that he cannot guarantee the outcome, willingness is all that is left.
You can do better than willingness. You can choose architecture.
See the five questions every enterprise should ask its AI vendor, or talk to us about sovereign inference.
Related reading: We ran the 4-bit (NVFP4) build of GLM-5.2 through the model makers’ own benchmark harnesses, and published the honest results, including the one place FP8 still wins.
Related reading: Europe is sleepwalking into US AI dependence, and Ireland just set the alarm. What the EU AI Act enforcement wave means for where your data actually runs.