Ömer CoskunIT Services

AI in your own data centre or an EU cloud: how to keep control of your data

Published

The short answer

Can a company use AI without its data leaving the building or the EU?

Yes. A knowledge search or an assistant can be built so that data, search and language model run in your own environment: in your own cloud account in an EU region, in your own data centre or on your own hardware. The question is not whether AI is used, but where it runs and who decides what it sees.

A fair objection

“We would like to use AI, but our data must not leave the building.” Medium-sized companies say this often, and they are right to. Personal data is subject to the GDPR, which allows transfers to countries outside the EU only under the conditions of its Chapter V. On top of that come trade secrets and the commitments you have made to your own customers.

That is no reason to go without AI. It is a reason to decide exactly where it runs.

Three ways to run it

  1. Your own cloud account in an EU region: the language models come from your cloud, for example through AWS Bedrock or Azure, and run in your account, in a region you choose, with your keys and your logging. Which models are available in which region is up to each provider; this is checked beforehand.
  2. Your own data centre or hardware: open models are self-hosted, with model serving for example through Triton and, where several applications share one GPU, with separated compute and memory, for example through NVIDIA MIG. The data never leaves your network.
  3. A mixed setup: documents, search index and permission check stay with you, and only the wording of the answer is done by a model in your EU cloud. It sees nothing but the passages the permission check has released for that request.

What should stay in your hands

  1. The location: everything runs in your environment, and you decide before any data moves which services are connected.
  2. The choice of model: routing across several models lets you switch the language model without rebuilding the system. You are not tied to one vendor.
  3. The permissions: they are taken over from your existing systems instead of being reinvented, and checked in front of the model.
  4. The evidence: every query is logged traceably, and the log stays with you.
  5. The code: it lives in your repository with its documentation, so you can also run the system yourself.

How to find the right setup

The right setup depends on a few questions. What data is searched: personal, confidential or public? What have you promised your customers? What infrastructure exists, and who runs it? How fast must an answer arrive, and what may it cost?

The last two questions can only be answered honestly with measurement. That is why latency, cost per answer and quality are measured for every request from the start. Only then can you tell whether a self-hosted model pays off or whether a model from the EU cloud is the better choice.

Law and technology go together

Technology can make data sovereignty possible; it does not replace a legal review. Involve your data protection officer early. AI systems are also subject to the EU AI Act (Regulation (EU) 2024/1689). It entered into force in August 2024; its obligations apply in stages and depend on the risk of the use case.

This article describes technical options and is not legal advice.

Sources and evidence

  1. Regulation (EU) 2016/679 (GDPR), Chapter V: transfers to third countries
  2. Regulation (EU) 2024/1689 (AI Act)
  3. NVIDIA: Multi-Instance GPU user guide
  4. Triton Inference Server
  5. Work index: enterprise runtime for language models(own evidence)

Why permissions belong in front of the model, not in the promptFocus area: runs in your environment

Planning something along these lines? Briefly describe your project and you will get an honest assessment.

More articles

All articles