tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

Sovereign AI, translated for a five-person business

Work out which level of control over your AI data your work actually requires, then buy exactly that instead of the deployment topology in the press release.

Published 2026-09-05 · Updated 2026-09-05 · Read 8 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

A client sends back your contract with a new clause: their data may not be processed outside the EU. Or a hospital administrator asks, politely, whether anything you type goes to a third party. Suddenly you are reading vendor pages with the word “sovereign” in the headline, written for buyers who have a procurement department, a security questionnaire, and a lawyer on retainer. You have a laptop, four clients, and a deadline on Thursday.

This guide is for that reader: a freelancer or a small team who has been handed a data constraint and now has to buy the right thing without overbuying. It is not for you if nobody has ever asked where your data is processed, because your paid business plan already covers it and you can spend the next 10 minutes on something else. It is also not for you if your organisation has in-house counsel, because they will have views that outrank this page.

The word sovereign hides four different products

When vendors say sovereignty, they are describing at least four things that cost wildly different amounts. The first is a training promise: the vendor will not use what you type to improve its models. The second is a retention promise: your inputs and outputs are deleted on a schedule you can name. The third is a location promise: the request is processed inside a defined geography. The fourth is a topology promise: the model runs on hardware you control, possibly with no route to the internet at all.

Those are not steps on one ladder, even though marketing pages present them that way. You can have the training promise and no location promise. You can pin a region and still be on a plan where retention is indefinite. The Microsoft and Mistral announcement of 21 July 2026 is a fair example of the top of the range being sold as one bundle: Mistral Medium 3.5 and OCR 4 now available in Microsoft Foundry, Medium 3.5 in Microsoft Copilot Studio, and deployment “across cloud, cloud-connected and fully disconnected environments”, underpinned by “a new multibillion-dollar agreement focused on expanding AI infrastructure in Europe” [1]. Almost none of that is what a five-person firm needs, and the part you probably do need was already sitting in your existing subscription.

The business tier already carries the promise most contracts ask for

Read the clause your client actually sent. In most cases it says two things: do not train on our material, and delete it when we ask. Both are default behaviour on paid business plans today [3][5], and you can point at a page rather than negotiate.

OpenAI states that it does not train on your data by default, and that data from ChatGPT Business, Enterprise, Healthcare, Edu, Teachers and the API Platform is not used for training unless customers explicitly opt in [3]. Deleted conversations are removed from its systems within 30 days on the Business, Enterprise, Edu and Teachers plans unless it is legally required to retain them, and API inputs and outputs may be securely retained for up to 30 days [3]. Anthropic states that by default it will not use inputs or outputs from its commercial products to train its models, again unless you opt in [5]. The opt-in is worth knowing about in detail: pressing thumbs up or thumbs down on a response is the opt-in, the whole related conversation can then be stored for up to 5 years, and a Team or Enterprise owner can switch the ability off for the organisation under the “Rate chats” setting [5].

Retention is a separate dial from training, and it is the one people get wrong. On Anthropic’s commercial products, data is retained indefinitely unless a custom retention period is set, and the minimum period you can set is 30 days [6]. That is not a scandal; it is a default, and defaults are what auditors ask about. The practical move is to go into the admin settings of whatever you already pay for and set the retention period before you tell a client it is set.

Region on the invoice is not the same as region in the request path

Here is the distinction that decides most sovereignty arguments, and it almost never appears in the sales conversation. Storing data in a country and processing a request in that country are two separate commitments, sold separately.

Microsoft’s own documentation is unusually clear about this. Across Foundry deployment types, “data stored at rest remains in the designated Azure geography” [2]. Processing is where the types diverge. Global types may be processed in any Azure region. Data Zone types process data only within the Microsoft-specified data zone, which is US, EU or Asia Pacific. Standard and regional provisioned types process prompts and responses within the customer-specified Azure geography, and might process between regions within that geography for operational purposes [2]. Same platform, same invoice, three different answers to “where is my data”.

So when someone tells you their setup is European, the useful follow-up is which deployment type they selected, because the constrained option is a distinct thing you have to choose rather than something you get by signing up. If you are the one signing, write the deployment type into your own notes, and expect to justify it later.

The same question applies one level down, to anyone you subcontract to. If you hand client material to a designer, a bookkeeper or a virtual assistant who runs it through their own account, their plan tier and their region setting are now part of your answer, and you cannot see either from where you sit. Ask them the same three things you would want asked of you: which product tier, which region or deployment type, and what retention period is set. It is a two-line email, and it is the part of the chain that fails quietly.

Disconnected is real now, and it is a project rather than a setting

The genuinely new thing over the last couple of years is that running a current, capable model on hardware you control stopped being a downgrade. The July 2026 Microsoft and Mistral arrangement covers Azure Local deployments “that can operate independently of external connectivity for highly sensitive, constrained or mission-critical environments” [1], and Brad Smith framed the aim as Europe having “access to the world’s most capable AI without compromising control over their data, operations or digital future” [1]. Mistral separately documents that its “models can be self-deployed on your own infrastructure through various inference engines”, recommending vLLM and naming TensorRT-LLM and TGI as alternatives [7].

That is a real option and it is not a settings toggle. If you take it, you have bought an inference stack, a GPU bill, a patching schedule, and the job of re-running your own quality checks every time you change model versions. For a business with no dedicated infrastructure person, the licence is the cheap part. Before you go down this road, put your actual numbers into the arithmetic and see what the premium is.

calculator
Monthly premium for running the model yourself
— $ / month

GPU hours × your rate, minus the API spend you would avoid. Use rates from your own quotes and your own token bill; a positive number is what self-hosting costs you before any staff time. Computed in the page; nothing is sent anywhere.

The default of 730 hours is simply a month of a machine left running. If your workload is bursty, the honest comparison is worse than the calculator suggests, because a rented GPU bills by the hour whether or not it is busy, while the API bills only for the tokens you send.

Write the requirement down before you shop

Most overbuying starts because nobody wrote the requirement in a sentence. Do that first, in three parts: which class of data is constrained, which instrument constrains it, and what evidence would satisfy the person asking.

The middle part matters more than people expect. If the constraint comes from EU data protection law, the question is usually about lawful transfer rather than physical geography. Article 44 of the GDPR says that any transfer of personal data to a third country or an international organisation “shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers” [8]. A chapter of conditions is a legal test, and a data processing agreement can be part of passing it. Hardware in a rack is one way to avoid the question entirely, not the only way to answer it.

The third part, evidence, is where small firms lose time they did not need to spend. What satisfies most of the people asking is short and boring: a link to the vendor’s own policy page for the exact tier you pay for, the retention period you have configured, the region or deployment type in use, and the date you last checked all three. That is a paragraph in an email, and it is stronger than a paid audit, because it is falsifiable and the client can go and read the same page you read. Vague reassurance is what triggers follow-up questionnaires.

Once the sentence exists, shopping is quick. A no-training default and a set retention period answer most professional services clauses [3][5][6]. A named processing region answers most public sector and finance clauses, provided you can say which deployment type you are on [2]. Disconnected hardware answers the small set of cases where the network boundary itself is the requirement [1]. Buy at the level your sentence names and no higher, and keep the sentence, because the next client will ask a slightly different version of the same question.

checklist
Before you promise a client where their data goes
0 of 8 · saved in this browser only

What still goes wrong

The most common failure is promising a control that does not extend to the feature you built on. OpenAI’s zero data retention is subject to prior approval and acceptance of additional requirements, and it does not cover every endpoint: with it enabled, the store parameter on /v1/responses and /v1/chat/completions is always treated as false, and a list of endpoints is marked ineligible, including /v1/conversations, /v1/assistants, /v1/threads, /v1/vector_stores, /v1/files, /v1/fine_tuning/jobs, /v1/evals, /v1/batches and /v1/videos [4]. If your product stores documents for retrieval or runs batch jobs overnight, the control you promised may not cover the part of the system that holds the sensitive material.

The second failure is drift. Every promise above is a default or a setting, and both change. Indefinite retention until you set a period [6], a 5-year window on feedback you opted into [5], abuse monitoring logs retained for up to 30 days unless longer retention is required by law [4]: none of these are wrong, and all of them will surprise a client who was told “we delete everything”. Re-read the policy pages when you renew, and put the date in the note.

The third is that self-hosting moves risk rather than removing it. A disconnected deployment means no vendor is patching your inference stack, no one else is watching for a bad model update, and the evaluation work is now yours. That trade is worth it when the network boundary is genuinely the requirement. It is a poor trade when the requirement was a sentence in a contract that a properly configured business plan would have satisfied for the price of an afternoon.

sources
  1. 01Microsoft — Microsoft and Mistral expand strategic partnership to give enterprises and regulated industries frontier AI they can controlnews.microsoft.com
  2. 02Microsoft Learn — Deployment types in Microsoft Foundrylearn.microsoft.com
  3. 03OpenAI — Enterprise privacyopenai.com
  4. 04OpenAI — API data controls and zero data retentiondevelopers.openai.com
  5. 05Anthropic Privacy Center — Is my data used for model training?privacy.claude.com
  6. 06Anthropic Privacy Center — How long do you store my data?privacy.claude.com
  7. 07Mistral AI docs — Self-deployment overviewdocs.mistral.ai
  8. 08GDPR Article 44 — General principle for transfersgdpr-info.eu
next guide
The economics of running AI models on your own machine
9 min · verified 2026-09-05
related guides