# Sovereign AI due diligence: sixteen questions for any provider

*A Sluis guide for procurement, security and privacy teams. Last checked 23 September 2026.*

"Sovereign" appears in almost every AI provider's marketing, and it can mean four different things: where data is processed, who owns the provider, which governments can compel it, and how much of your data it sees in the first place. A provider can be strong on three and weak on the fourth. This guide turns those four areas into sixteen questions you can send to any provider, with what a good answer and a warning sign look like.

## In short

- **Residency** is about where data is processed and stored. It is the easiest to check and the least protective on its own.
- **Ownership** is about who controls the company you contract with. It can change overnight: Aleph Alpha, often cited as Germany's sovereign AI champion, was reported in April 2026 to have been acquired by the Canadian company Cohere.
- **Jurisdiction** is about which governments can order the provider to hand over data. For US-controlled providers this follows control, not location.
- **Data handling** is about what the provider keeps, for how long, and who can read it. It is the area where the contract matters most, and the one most often left to the default terms.
- Ask every question in writing and keep the answers. A provider that cannot answer in writing has given you an answer.

## Residency

| # | Question | Why it matters | Good answer | Warning sign |
|---|---|---|---|---|
| 1 | In which countries are prompts and outputs processed, including during failover and peak load? | Capacity problems are the usual reason traffic leaves a region | Named regions, with failover within the EU written into the contract | "Our EU data centres" with no statement about failover |
| 2 | Where are logs, abuse-monitoring copies, caches, embeddings and fine-tuning data stored, and for how long? | Residency claims usually cover the request, not the copies made around it | A list per data type, with location and retention | Only the inference region is mentioned |
| 3 | Can support or operations staff access production systems from outside the EU? | Remote access is processing, wherever the servers are | No, or only named EU-based roles, logged and reviewable | "Access is restricted" without saying from where |
| 4 | Which sub-processors handle customer content, and how are changes notified? | Each sub-processor adds a location and an owner | A published list with advance notice and a right to object | List available only on request, or no notice period |

## Ownership

| # | Question | Why it matters | Good answer | Warning sign |
|---|---|---|---|---|
| 5 | Which legal entity signs the contract, and where is it registered? | The contracting entity is the one that courts and regulators deal with | A named EU entity with its registration number | A brand name, or a non-EU entity with an EU "presence" |
| 6 | Who is the ultimate parent, and does any non-EU shareholder hold control or veto rights? | Control is what foreign orders attach to | A clear ownership chain with no non-EU control rights | Refusal to disclose, or significant non-EU investors with board rights |
| 7 | Has ownership changed in the last 24 months, and what happens to our contract if it changes? | Your assessment can be overtaken by a transaction | A change-of-control clause that gives you notice and a right to terminate | No notice obligation |
| 8 | Who can instruct the staff who hold production access? | A parent that can instruct operations can compel access | Operations staff employed and directed by the EU entity | Group-wide operations teams |

## Jurisdiction

| # | Question | Why it matters | Good answer | Warning sign |
|---|---|---|---|---|
| 9 | Which governments can compel the contracting entity or its parent to disclose customer data? | This is the actual extraterritorial exposure | A precise answer naming the relevant laws | "We comply with GDPR", which does not answer the question |
| 10 | What do you do when you receive a government order for our data? | Process determines the outcome in practice | Challenge unfounded orders, notify you where legally allowed, disclose the minimum | No written policy |
| 11 | Do you publish government request statistics? | Numbers show whether requests happen | A transparency report with request counts by country | No report |
| 12 | Who holds the encryption keys, and can your staff read content while it is being processed? | Encryption at rest does not protect data the provider can decrypt | Customer-held keys where offered, and a clear statement of when plaintext is accessible | "All data is encrypted", with no mention of keys |

## Data handling and minimisation

| # | Question | Why it matters | Good answer | Warning sign |
|---|---|---|---|---|
| 13 | Is our content used to train or improve models? How is that switched off, and is it in the contract? | Training use is the hardest disclosure to undo | Off by default for business customers, confirmed in the agreement | Opt-out in a settings page only |
| 14 | What is the default retention for inputs and outputs, and what must we sign to reduce it to zero? | Defaults are what apply if nobody asks | Stated in days, with a zero-retention option and its conditions | "As long as necessary" |
| 15 | Do people review content, for example for abuse monitoring? When, and from where? | Human review is disclosure to people, not systems | Only on specific triggers, by named EU-based teams, with the option to opt out | Routine sampling, location unspecified |
| 16 | Does the service work with pseudonymised input, such as «PERSON_NAME_1» in place of names? | The less the provider receives, the less the other fifteen answers matter | Yes, including for structured output and tool calls | Placeholders break features you rely on |

## Recent examples

These show why the answers need to be refreshed, not filed.

- **Aleph Alpha and Cohere.** In April 2026 Cohere, a Canadian company, was reported to have acquired Aleph Alpha. According to the reporting, the infrastructure stays in Germany. For a buyer whose requirement was "EU-owned", the answer to question 6 changed while the answers to questions 1 to 4 did not.
- **AWS European Sovereign Cloud.** Launched on 15 January 2026 in Brandenburg as a partition separate from other AWS regions. According to AWS, it is run by AWS European Sovereign Cloud GmbH, a German company with EU-resident staff and its own certificate authority, network and security operations. This is a serious answer to questions 3, 5 and 8. Whether it answers question 9 has not been tested in court. See our CLOUD Act guide.
- **Microsoft before the French Senate.** In July 2025 Microsoft France's chief legal officer told a Senate inquiry under oath that the company could not guarantee French public-sector data would never be handed to US authorities without the customer's consent. He also said this had not happened, and that Microsoft contractually commits to challenging unfounded requests. Both statements are useful answers to questions 9 and 10.

## A reference point: SecNumCloud

If you need a concrete standard for what "immune from foreign law" means, France's SecNumCloud 3.2 is the most specific one in force. According to reporting on the decree of 12 August 2026, it requires the provider's registered office, decision-making centre and administration to be in the EU, limits non-EU shareholding and rules out non-EU veto rights, alongside some 360 security controls on top of ISO 27001. It now binds a large part of the French central public sector. Even outside France, its ownership criteria are a useful yardstick for questions 5 to 8.

## How to weigh the answers

Not every use needs every answer to be perfect. A practical approach:

| Data you will send | Must be strong | Can be moderate |
|---|---|---|
| No personal or confidential data, such as marketing copy or public documentation | 13, 14 | Everything else |
| Customer or employee personal data, pseudonymised before it leaves you | 1 to 4, 13 to 16 | 5 to 12 |
| Personal data in clear, or confidential business data | All sixteen | None |
| Special category data such as health or HR cases | All sixteen, plus an EU-owned provider or no external model | None |

## Checklist

- [ ] Sixteen questions sent in writing to each shortlisted provider
- [ ] Answers filed with the date received
- [ ] Contracting entity and ultimate parent confirmed from a company register
- [ ] Failover, logs and support access confirmed to stay in the EU
- [ ] Training use off and retention stated in the signed agreement
- [ ] Change-of-control clause in the contract
- [ ] Answers reviewed at each renewal and after any reported ownership change

## Sources

- [AWS, *AWS launches AWS European Sovereign Cloud and announces expansion across Europe*, January 2026](https://press.aboutamazon.com/aws/2026/1/aws-launches-aws-european-sovereign-cloud-and-announces-expansion-across-europe)
- [AWS, *Overview of the AWS European Sovereign Cloud*](https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html)
- [The Register, *Microsoft admits it 'cannot guarantee' data sovereignty*, 25 July 2025, reporting the French Senate hearing of 10 July 2025](https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/)
- The Cohere acquisition of Aleph Alpha is taken from press reporting in April 2026. We have not seen a filing that confirms the terms, and we do not repeat the reported price.
- The SecNumCloud 3.2 requirements are taken from reporting on the decree of 12 August 2026 and ANSSI's published framework.
