Of the ten regions OpenAI's data residency documentation sells, seven - Australia, Canada, Japan, India, Singapore, South Korea and the United Kingdom - are listed as regional storage yes, regional processing no. A UK residency contract on those terms keeps the record of your request at home and computes the request elsewhere. One word covers both states without distinguishing them, which is why it survives so many architecture reviews intact.
EU AI data residency is a storage property. Sovereignty is a jurisdiction property. The gap between them turns expensive later, in a court or a supervisory authority's inbox. The fix is a chain of five questions, each with a checkable answer.
Five questions that survive a procurement meeting
Start with the legal entity that operates the endpoint your code calls, and the law under which it contracts and litigates. Then ask where inference physically runs. Retention is third: what is kept from the request, for how long, and who can read it. Last, the sub-processor list behind the endpoint, including whichever company terminates your TLS. Every item is a sentence a vendor can sign, and the ones who will not are telling you something.
Run OpenAI through it. The contracting entity for EEA and Swiss customers is OpenAI Ireland Limited, registered in Dublin, so the first two questions have decent answers. The third narrows fast: regional processing exists for the United States, the EEA plus Switzerland, and the United Arab Emirates, and nowhere else. OpenAI's own documentation says requests to eu.api.openai.com use Cloudflare Regional Services so TLS terminates inside the region, which means the sub-processor OpenAI names for that job, Cloudflare, Ltd., decrypts the traffic on the European endpoint, with an ultimate parent incorporated in the United States. That page also excludes account data, metadata and usage data from residency, and the EU endpoint carries a published 10 percent uplift on models released from 5 March 2026. Sovereignty has a list price.
The CLOUD Act argument that nobody applies to model endpoints
The statute is short enough to read in full. 18 U.S.C. 2713 obliges a provider to disclose material within its possession, custody or control, regardless of whether it sits inside or outside the United States. Possession there describes a corporate relationship, not a location, so at a model endpoint the duty settles on whoever holds the prompt logs: the model vendor, not the cloud region a customer selected. An EU region bought from a US-incorporated vendor moves the bytes and leaves the obligation untouched. On 10 June 2025 Anton Carniaux, director of public and legal affairs at Microsoft France, told a French Senate hearing under oath that he could not guarantee French citizens' data would never be transmitted to US authorities without French authorisation, adding that no such transfer had occurred. Only one of those halves is a control.
Anthropic's commercial terms answer the entity question precisely: Anthropic means Anthropic Ireland, Limited if the customer resides in the EEA, Switzerland or the UK, and Anthropic, PBC otherwise, with Irish law and Dublin arbitration for the former and California law for the rest. That settles the first two questions and not the third. The Claude API has no first-party EU inference region, and EU-region processing runs through AWS Bedrock or Vertex AI, both operated by US-incorporated providers.
The framework underneath all this is less settled than the marketing suggests. The General Court dismissed the first challenge to the EU-US Data Privacy Framework in Latombe v Commission on 3 September 2025, and the appeal is pending as C-703/25 P. On 29 June 2026 the US Supreme Court decided Trump v. Slaughter, overruling Humphrey's Executor and holding for-cause removal protection for FTC commissioners unconstitutional. The Data Privacy Framework leans on the FTC for the independent enforcement that made it adequate in the first place.
Retention is a separate question from EU AI data residency
By default OpenAI generates abuse-monitoring logs of prompts and responses for all API traffic and retains them for up to 30 days. Zero Data Retention and Modified Abuse Monitoring both exist and both require prior approval, and any non-US residency region needs that approval plus a signed modified retention amendment. The honest description of a default deployment is that your prompts sit in someone else's log for a month, and the sovereign version starts with an application form.
GDPR Article 4(2) counts storage, retrieval, consultation and use as processing, so an inference call is a processing event rather than a transmission, and a call to a non-EU region is a Chapter V transfer every time it happens - a thousand times a day, if that is your traffic. The EDPB's Opinion 28/2024, adopted 17 December 2024, closes the other exit: a model trained on personal data cannot be declared anonymous.
What the genuinely European sovereign AI options give up
Mistral made regional endpoints generally available on 11 August 2026, and its own announcement carries the caveat that matters: inference and the associated processing take place in the selected region, subject to limited, safeguarded transfers to sub-processors that may occur outside that region. The same announcement commits to up to 1 GW of European compute by 2030, which does not help a decision you make this quarter.
Ownership is the harder half of the fifth question. On 24 April 2026 Canada's Cohere announced it would acquire and merge with Germany's Aleph Alpha in a 20 billion dollar deal, with Aleph Alpha backer Schwarz Group putting 600 million into Cohere's Series E. Germany's flagship sovereign AI champion has agreed to become part of a company that is not EU-owned, and the deal has still to clear regulators. A sovereignty argument resting on a vendor's nationality had someone else's corporate development team as a single point of failure.
That leaves open-weight models on EU infrastructure you control, or in your own building, which answer the whole list without qualification. The hardware stopped being exotic. Hetzner's GEX131, launched 11 December 2025, pairs an NVIDIA RTX PRO 6000 Blackwell Max-Q with 96 GB of GDDR7 and a 24-core Xeon Gold, at 889 euros a month in German or Finnish datacentres. What you give up should be said plainly: open weights are within a few points of the frontier on coding and mathematics benchmarks such as SWE-bench Verified, and clearly behind on multi-hour agentic work, where the gap has not closed since 2025. You have also bought an operations job, and teams underestimate that far more than the hardware. We are not neutral on that trade, since running other people's infrastructure is what we sell. The narrower point: Sencai's model backend is pluggable, so moving from a hosted provider to open weights on a machine like that one changes the answer to question three without a migration.
The regulator will grade this, not tick it
The regulatory clock is not the one people quote. The EU AI Act became generally applicable on 2 August 2026, Article 50 transparency duties included, but the Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and high-risk AI inside regulated products to 2 August 2028. The Commission's Cloud and AI Development Act proposal of 3 June 2026 would grade sovereignty for public procurement rather than score it yes or no. Classify your workloads the same way: a support-ticket summariser and a model reading pseudonymised patient records do not deserve one answer.
We ran our own product through the same five. Sencai names its model providers in a public sub-processor list, engaged only when a customer uses an AI feature and never for the platform. Platform data is stored in the EU, and the free configuration has no AI at all.
Exactly one configuration of ours answers all five without a qualifier, and it is the one most teams should not buy: the on-premise edition, a complete server in your own rack with an optional local AI server beside it, automating the estate on site while nothing leaves the building. Everything else, ours included, answers partially, which is survivable when the partial answer is written down. A vendor who will put the datacentre, the retention window and the TLS terminator into a signed sentence has told you where its product sits; one who will only put it on a marketing page has told you that too.