SaaS Tech Watch
saas

Data residency and sovereign AI: the architecture patterns EU buyers are now asking about

Every figure states its provenance: measured (we ran it) · reported (vendor says) · derived (we calculated).

Data residency is not a new requirement for European SaaS buyers. What changed since 2024 is that questions moved from “where is the database hosted” to “where does inference run, and who can see the prompts.” AI features added to almost every SaaS product have quietly moved data through jurisdictions the original DPA did not contemplate. EU buyers now ask sharper questions, and vendors who cannot answer them lose deals. This piece covers the architectural patterns vendors are adopting and a buyer’s diligence checklist for evaluating AI-residency claims.

We are not lawyers. This is an architectural and procurement analysis, not legal advice.

Why residency got harder when AI shipped

Pre-AI, “EU region” meant: database in an EU region, backups same, support access bounded, subprocessors listed. The data flow was a small set of well-understood paths.

AI features add three new flows, each potentially leaving the EU:

  • Prompt and context sent to a model provider. If the provider’s endpoint is not in the EU, customer data crosses the Atlantic on every AI call.
  • Embeddings sent to a vector store. Embeddings are customer data in a form many DPAs do not name. Their location matters.
  • Logging and evaluation pipelines. Prompt and output logs retained for quality or safety are a new data store with residency questions of its own.

A vendor offering “EU hosting” while routing AI features through a US model provider has migrated the residency discussion, not answered it.

The architectural patterns in production

Four patterns are visible in vendor architectures this year, weakest to strongest residency posture:

PatternWhat it looks likeWhere it fits
Global architecture, prompt egress acceptedAI calls route to the model provider’s nearest endpoint; no EU-specific AI routingUS-centric vendors; weak fit for regulated EU buyers
Regional processingAI calls routed to EU-region endpoints of model providers where available; global fallbackMost pragmatic mid-market posture
In-region LLM hostingVendor runs model inference inside the EU region — managed open-weights or self-runRegulated industries; public sector
Sovereign cloudFull stack (data, inference, keys, support) inside EU jurisdiction, under EU-operated entitiesPublic sector and strategic industries

Each step right raises cost, narrows model choice, and increases operational ownership. Most buyers do not need the far-right posture. Some do, and last year’s “EU region” marketing no longer satisfies them.

What “regional processing” actually covers

The middle pattern — routing AI calls to EU endpoints of a named model provider — is the de-facto default for enterprise-tier SaaS in 2025–26. It resolves the direct egress question, and not three adjacent ones:

  • Fallback. If the EU endpoint is unavailable or lacks a model feature, what happens? Some vendors silently fall back to US endpoints; that is the difference between marketing and architecture.
  • Abuse-prevention pipelines. Some model providers route traffic through shared safety systems whose location is not always disclosed.
  • Logging and telemetry. Where do prompts, outputs, and model traces land in the vendor’s observability stack? Often a US-located logging SaaS, which quietly re-opens the residency question.

A buyer asking “is inference in the EU” needs the follow-ups, not just the headline.

The buyer’s diligence checklist

This is the checklist we use when evaluating AI-residency claims. It is designed for one structured security-review session, not a prolonged RFI.

On data and flow:

  1. Which customer data reaches which model provider, via which region? Ask for a diagram, not a sentence.
  2. Does any AI call route to a non-EU endpoint under any condition, including failover and feature availability?
  3. Where are prompt and output logs retained, and for how long?
  4. Where are embeddings stored? Is the vector store in the EU region?

On sub-processors and entities: 5. Which model providers are sub-processors? Under what legal entities do they process EU data? 6. Are Standard Contractual Clauses or EU-US Data Privacy Framework relied upon for any AI-related transfer?

On operations: 7. Where is the vendor’s abuse-prevention and safety pipeline? Whose? 8. Who has administrative access to the AI layer, and from which jurisdictions? 9. Can AI features be disabled per-tenant without disabling the rest of the product?

On evidence: 10. Which of the above can the vendor demonstrate in an architecture review, versus only assert in documentation?

Q10 is not a courtesy item. Public whitepapers on AI residency are frequently aspirational; the exercised architecture is what matters.

Trade-offs the diligence will surface

A clean residency posture has real costs; diligence should expect them to surface as price, product limitation, or both:

  • Model choice narrows. Not every frontier model is available on an EU endpoint. Vendors pinned to EU endpoints cannot offer the latest capability at the same cadence.
  • Latency rises for non-EU users. If an EU customer’s AI is pinned to EU infrastructure and their users are global, the farthest users pay in round-trip time.
  • Price rises. In-region inference costs more than a global pool. An enterprise-tier residency premium is now common cost pass-through, not gouging.

Decide which trade-offs are acceptable before the negotiation, not during.

Sovereign AI beyond procurement

A broader policy conversation runs alongside procurement: EU institutions and several member states are pushing for in-country AI capability covering not just data handling but model training and operation. We take no view on whether this “sovereign AI” agenda succeeds. For buyers in the near term it means more in-region hosting options over the next 12–24 months, and a procurement environment that progressively asks non-EU model providers to demonstrate EU processing.

The bottom line

AI turned “EU region” from a checkbox into an architecture question. The three flows that matter are prompts, embeddings, and logs — vendors that can explain where each goes, under what failover conditions, with what evidence, are the short-list. Buyers asking only “where are you hosted” are already running AI features they have not diligenced.

Related reading

from the desk ▸