Data sovereignty: why it matters where your AI runs
Data sovereignty sounds like a legal topic, but at its core it is a very practical question: who has access to your data the moment you let AI touch it? The answer determines what you can and cannot automate.
The problem with 'AI in the cloud'
Most popular AI services send every prompt to American servers. That's fine for brainstorming. But the moment you let AI work on client files, payroll or patient records, you are effectively shipping that data to a country with a different legal reality. The CLOUD Act allows US authorities to demand data held by US companies, even when that data physically sits in Europe.
Three choices, one system
Sovereignty doesn't have to be all-or-nothing. We ship the same Agentic OS in three flavours: our EU cloud (fast launch, we handle it), your own server (full control) or an AI computer with the language model 100% local (literally nothing leaves the box). Same functionality, different privacy dial.
Why this matters now
Three trends are sharpening the question. The AI Act is becoming stricter about handling personal data. Regulators in healthcare, finance and government are spelling out explicit demands on AI vendors. And clients are starting to ask where their data ends up the moment you deploy AI.
Practical consequences
With sovereignty you can let AI work on things you would otherwise never dare: case files, medical data, salaries, legal work. Without sovereignty, AI stays restricted to 'safe' peripheral tasks — and that is precisely where the value isn't.
Closing
Where your AI runs is not a technical footnote. It decides what you're allowed to do, what you dare to do and ultimately what you get out of it.
What sovereignty actually means in practice
Sovereignty isn't only about where the bits sit. It's about who can compel access to them, who can read the prompt history, and who decides when a model gets retrained on what. Three layers matter:
- Storage location. Where the data physically lives and which legal regime applies to that location.
- Processing location. Where the model runs the inference. A prompt sent to a US model is processed in the US, regardless of where the input data was stored.
- Model ownership. Who controls the model weights and the training pipeline. A closed-weights model from a foreign vendor is a black box you have to trust on their terms.
A real sovereignty story addresses all three. Most "EU AI" stories only address the first.
A short comparison
| UPPR Cloud (EU) | Your own server | AI computer (local) | |
|---|---|---|---|
| Data leaves your building | Only to our EU DC | No | No |
| Subject to CLOUD Act | No | No | No |
| Time to live | Days | Weeks | Weeks |
| Maintenance | We handle it | Shared | Shared |
| Maximum sensitivity | High | Very high | Highest |
The right answer depends on what you process. Most organisations end up with a mix: cloud for the bulk, on-prem or local for the regulated edges.
Common objections, addressed
"We already have a DPA with our cloud AI vendor." A DPA helps with GDPR liability but does not stop a CLOUD Act request. If a US court compels disclosure, the vendor complies. The contract sits underneath that, not over it.
"Local models can't keep up with the frontier." Two years ago, true. Today, open-weights models in the Llama and Mistral families are good enough for the overwhelming majority of business tasks — drafting, classifying, extracting, summarising. The frontier matters when you're doing frontier work; most business automation isn't.
"Self-hosting is expensive." Sometimes. But the comparison is rarely apples-to-apples: you save on per-token cost at scale, on integration cost, and on the legal time your DPO no longer has to spend qualifying a new SaaS supplier.
When to pick which
Pick cloud when you want to be live in weeks, your data is not subject to special legal regimes, and you value speed over absolute control.
Pick your own server when you operate in healthcare, finance, government or law, when clients contractually require it, or when your DPO won't sign for cross-border processing.
Pick a local AI computer when even your own network is too exposed: bid teams handling commercially sensitive deals, R&D groups, defence-adjacent work.
Closing
Where your AI runs is a design choice with consequences. Make it on purpose, not by default. The Agentic OS is the same in all three modes — only the sovereignty dial moves.
