QDNAAdvisory and architecture for LLM inference and training platforms, on-premises or hybrid

What Is a Sovereign AI Platform?

Models, data, and logs on your own hardware, under your control: here is the definition, the technical choices, and the legal framework.

A glass dome protecting a server, a model chip, data cylinders and log books, standing on ground delimited by a border line.
Short answer. A sovereign AI platform is an artificial intelligence infrastructure that runs models on your own hardware, on-premises or hybrid, with data and logs under your legal and technical control. It relies on open-weight models and complies with GDPR, HDS certification, and SecNumCloud qualification.

What does sovereignty mean for an AI platform?

Sovereignty is the ability to decide alone where your data and models sit, who accesses them, and how they are used. A sovereign AI platform brings together three guarantees: model weights run on infrastructure you control, your users' data never leaves that infrastructure, and compliance with French and European law remains demonstrable.

Concretely, sovereignty is checked on three components, and each is observed rather than declared:

Sovereign AI platform: local or hybrid?

Local mode keeps everything on-premises, since models, data, memory, and logs remain on your hardware, and no information leaves, this mode applying by default to sensitive data and healthcare.

Hybrid mode processes sensitive data locally and lets non-sensitive innovation overflow to a remote service during load peaks. A semantic router classifies each request before the call: confidential content goes to a local model, public content can use an external model. This filtering prevents sensitive data from leaving the infrastructure by mistake.

Sovereign, hybrid, EU-hosted cloud, US hyperscaler: what is the difference?

Sovereign on-premises, hybrid, EU-hosted cloud or US hyperscaler: the four options differ by where the weights run, where the data goes, and which law applies to whoever accesses it. The table sums up what this page details, without figures: costs are in our comparator.

CriterionSovereign on-premisesHybrid with routerEU-hosted cloudUS hyperscaler
Where the weights runyour hardwareyour hardware, external overflow for non-sensitive workprovider's hardware, inside the Unionprovider's hardware, region of your choice
Where sensitive data goesyour perimeter onlyyour perimeter, the router sorts before the callat the provider, under contractat the provider, under contract
Exposure to the Cloud Actnonenone for sensitive datadepends on the provider's ownershipyes, wherever the servers are
Health data (HDS)possible, certified-host obligation to meetpossible for sensitive datapossible if the provider is HDS-certifiedpossible if the provider is HDS-certified
SecNumCloudnot applicable, no providernot applicable for sensitive dataif the provider is qualifiednot qualified to date
Cost modelfixed, written downfixed on sensitive, per token on the restusage or reservationper token

Which hardware for a sovereign AI platform?

The hardware of a sovereign platform is sized on actual need: a workstation such as the Mac Studio Ultra or the DGX Spark is enough for a small structure, while a small or medium enterprise deploys an RTX PRO 6000 server or a GB300 station.

A large enterprise moves to an H200 SXM server, B200 and B300 platforms, up to a GB300 NVL72 rack for a private AI cloud, and from the H200 onward, the same platform serves both inference and training.

Which open models for a sovereign platform?

A sovereign platform relies on open-weight models that you download once and then run in-house. The 2026 references include GLM, Kimi, DeepSeek, Nemotron, MiniMax, Mistral, and Qwen. A single gateway makes them interchangeable: switching models comes down to changing a configuration line, without rewriting application code.

How much does a sovereign AI platform cost?

An interface billed per token is paid for at every request, while an on-premises installation pays off over time. Agentic workloads are dominated by input tokens, and free reuse of the KV cache makes repeated loops nearly free locally. For hosting, two paths exist: on-premises, or managed colocation in a sovereign French data center.

This point is detailed in our analysis of the LLM cost break-even point.

Which French and European rules apply?

The rules apply according to where the model runs. On-premises execution grants full physical and legal control, outside the reach of the US Cloud Act, while for health data, using an HDS-certified host is a legal obligation (Article L. 1111-8 of the French Public Health Code), and ANSSI's SecNumCloud qualification adds extraterritorial immunity.

The framework also covers GDPR, the European AI Act, and the NIS2 directive, with safeguards masking personal data before any submission to a model.

The European AI Act applies in stages. Two obligations already bind every deployer: training users (Article 4, since 2 February 2025) and disclosing that content comes from an AI (Article 50, since 2 August 2026). The obligations for Annex III high-risk systems, recruitment and social benefits included, were postponed to 2 December 2027 by Regulation (EU) 2026/1744 of 8 July 2026, and those of Annex I to 2 August 2028. Many materials still announce 2 August 2026: they are outdated.

Data sovereignty is achievable today. Paired with open-weight models run locally, it also delivers artificial intelligence sovereignty.

Frequently asked questions

What is a sovereign AI platform?

It is an AI infrastructure that hosts models, data, and logs on your own hardware, on-premises or hybrid, under your control. It uses open-weight models and complies with GDPR, HDS, and SecNumCloud.

What is the difference between local AI and hybrid AI?

Local keeps everything on-premises, with no data leaving the site. Hybrid processes sensitive data locally and overflows to a remote service for non-sensitive workloads, using a semantic router that prevents leakage.

Is this compliant with French law?

Yes. On-premises deployment gives full control outside the reach of the Cloud Act. Healthcare requires an HDS-certified host, and SecNumCloud adds extraterritorial immunity.

Is a sovereign AI cloud the same thing as a sovereign AI platform?

No. A sovereign AI cloud is a service hosted in the Union by a provider, whose sovereignty depends on ownership and, for extraterritorial immunity, on SecNumCloud qualification. A sovereign AI platform runs the weights on your own hardware: there is no provider between your data and the model. The two can combine in hybrid mode, the semantic router keeping sensitive data on site.

What does EU-hosted AI mean?

That the servers are physically in the Union, which settles the data transfer question under GDPR but not access by a foreign authority: a provider under US law remains subject to the Cloud Act wherever its servers are. Location is necessary; it is not sufficient.

Scope your sovereign AI platform

A no-commitment conversation to assess your needs and your hardware.

Book a call

References