Back to Blog

Sovereign AI in Europe: Mistral, EU Clouds and Your Options

Where your AI runs now matters as much as what it does. Four ways to keep company data under European control, from Mistral to EU clouds to your own server.

Sovereign AI in Europe: Mistral, EU Clouds and Your Options

In June 2025, a French Senate committee put a simple question to a Microsoft France director, under oath. Could he guarantee that data stored in France for French public bodies would never be handed to US authorities without France’s agreement? His answer: “No, I cannot guarantee it”.

Fifteen months later, “sovereign AI” is on every vendor’s homepage, and it means something different on each one. This post explains what the term covers, the four options a European SME actually has, and how to pick one.

The short version:

  • “Hosted in the EU” tells you where your data is. It does not tell you whose law applies to the company holding it. Those are separate questions.
  • You have four options, from a US model in an EU data centre, to Mistral, to open models on a European cloud, to a server in your own office.
  • Each step gives you more control and costs a little convenience or model quality.
  • You do not have to choose once for the whole company. Choose per type of data.

Residency, jurisdiction, control: three different questions

Most of the confusion comes from treating three questions as one. Keep them apart and every vendor claim becomes easy to check.

Three columns, one per question, each under its own icon. Residency asks where the data sits, and is solved by an EU region from any provider. Jurisdiction asks whose law binds the operator, and is solved only by an operator that is under EU law alone. Control asks whether you can leave, and is solved by open weights and a standard API

  • Residency: where does the data sit? A server in Frankfurt or Paris answers this. It is what most “EU region” offers sell, and it is the easy part.
  • Jurisdiction: whose law binds the company running that server? A US law, the CLOUD Act, lets American authorities order a US company to hand over data it controls, wherever in the world that data is stored. So a US provider’s data centre in Europe solves residency and leaves this question open. That was the point of the Senate answer.
  • Control: can you leave? If your assistant only works with one vendor’s model, you depend on that vendor’s prices, terms and politics. Two things make leaving possible. The first is open weights: the AI model is published as a file that anyone may download and run on their own machines, instead of being reachable only through its maker’s service. The second is a standard connection format, so that swapping one provider for another is a setting, not a rebuild.

None of this makes US providers illegal to use. Sending personal data to the US rests on an agreement called the EU-US Data Privacy Framework, and an EU court confirmed it in September 2025. But the two agreements that came before it were both struck down by the EU’s highest court, and an appeal against this one is waiting there now.

For SMEs: using a US provider is legal today. The question is how much of your business you want to depend on a court ruling you have no say in.

The four options below are steps on a staircase. Each step up answers one more of the three questions, and the chart shows which.

A staircase of four steps, each taller than the last, with an arrow showing control rising as you climb, above a grid of ticks and crosses. Step 1, a US model in an EU region: data in the EU, but the operator is not under EU law only and switching is hard. Step 2, Mistral's own platform: data in the EU, EU law only, switching partly possible. Step 3, open weights on an EU cloud such as Scaleway, OVHcloud or IONOS, and step 4, your own server: all three boxes ticked

Option 1: a US model in an EU region

This is the default today. You use Claude, GPT or Gemini, but through a data centre in Europe: Google and Microsoft both run one in Belgium, and Amazon offers the same. Since January 2026 Amazon also has the AWS European Sovereign Cloud, a physically separate installation in Germany staffed only by EU residents.

What you get: the strongest models available, data that stays in the EU, and contracts your lawyer already knows.

What you do not get: a change of jurisdiction. The parent company is still American, so the CLOUD Act question gets the same answer as in the Senate hearing.

For SMEs: for a website chatbot answering questions about opening hours and return policies, this is a perfectly reasonable place to be. Most of the AI we run for clients started here, and for public-facing content it is often still the right call.

Option 2: Mistral, the European model maker

Mistral AI is a French company, based in Paris, and the only European lab whose models compete with the American leaders. With Mistral, Europe is the default rather than a region you have to ask for. Its help centre states it plainly: “By default, your data is hosted in the European Union”. A US option exists, but you have to choose it.

What changed in 2026 is that Mistral stopped renting all of its computing power from others. In March it borrowed $830 million from a group of banks, including BNP Paribas, Crédit Agricole and France’s public investment bank, to buy 13,800 Nvidia chips for its own data centre in Bruyères-le-Châtel, south of Paris. Two years ago, a European model running on European-owned machines was a slide in a pitch deck. Now it is a building.

Its three main models, as of September 2026. All three are open weights, so they can be downloaded and run outside Mistral’s own service (the exact licence differs per model):

ModelIn plain termsGood for
Mistral Large 3The biggest and most capableThe hardest reasoning and long documents
Mistral Medium 3.5The all-rounderMost business assistants, agents and coding
Mistral Small 4The light oneFast, cheap, and able to run on a single office machine

There are three ways to use them:

Read the small print before calling it done, though. The same help page says that, depending on the feature you use, data “can be temporarily transferred outside of the European Union” to the subcontractors listed in Mistral’s Trust Center, and that Enterprise customers can switch those features off. What you send is also kept for a while to detect abuse, unless your contract says otherwise.

For SMEs: “French company” is a strong starting point, not a substitute for reading the data processing agreement. Ask two questions: which features send data outside the EU, and how long is what we send kept?

One detail shows how slippery the labels are. In July 2026 Microsoft and Mistral expanded their partnership, and Microsoft will now sell Mistral’s models too, including on servers that sit in the customer’s own building with no internet connection at all. Run that way, a Mistral model is fully under your control, whoever sold you the server. Used through Microsoft’s ordinary cloud, the very same model puts you back at option 1. Where a model comes from matters less than who runs the machine it runs on.

Option 3: open-weight models on a European cloud

Because Mistral publishes its models as open weights, you do not have to buy them from Mistral. European cloud companies run these models, and other open ones, on their own servers and rent them out, billed by usage:

  • Scaleway Generative APIs (France, data centres in Paris): Mistral Medium 3.5 at €1.50 per million tokens read and €7.50 per million written, a smaller Mistral model at €0.15 and €0.35, and the first million tokens free. At those prices, a customer question answered from a few pages of your documentation costs less than one cent.
  • OVHcloud AI Endpoints (France): more than 40 models served from OVHcloud’s EU data centres. When we checked in September 2026, the catalogue offered open models from Alibaba (Qwen), Meta (Llama) and OpenAI (gpt-oss), but none from Mistral.
  • IONOS AI Model Hub (Germany): a similar catalogue of open models, billed per million tokens.

Two things make this option more interesting than it looks.

First, these services all plug in the same way. They follow the connection format OpenAI made standard, so moving an assistant from one provider to another is a change of settings, not a rebuild. That is the “control” question answered in practice.

Second, where a model was made is not who can see your data. Llama comes from Meta and Qwen from Alibaba, but once the model file sits on a French provider’s servers, neither company sees a single one of your requests. A model is a file, and a file does not call home. Who can reach your data is decided by who runs the server.

The price you pay is at the very top of the quality range. The best open models are very good, and roughly one generation behind the best closed ones. For answering from your own documents, drafting replies and sorting tickets, you will rarely notice. For the hardest multi-step reasoning, you still will.

For SMEs: this is the step with the best balance of protection and effort. You still pay only for what you use, the company holding your data answers to EU law alone, and you can change provider in an afternoon.

Option 4: your own hardware

The last step takes the cloud out entirely. Mistral Small 4 is built to use only a small part of itself for each answer, so in compressed form it runs on one powerful workstation rather than a rack of servers. That machine can sit under a desk, or in a rented cabinet in a Belgian data centre, and serve ten to twenty people. There is no usage bill, and documents that were already in your office never leave it.

We are direct with clients about the trade-offs:

  • Capacity is fixed. You cannot add power for one busy week.
  • Quality is one notch below the best. Fine for working from your documents, weaker on the hardest reasoning.
  • Somebody has to look after it. Security updates and new models mean a monthly maintenance fee.

For SMEs: for a law firm, a medical practice or an engineering office whose documents may not leave the building, those are easy prices to pay. For a webshop’s FAQ bot, they are not.

The four options side by side

1. US model, EU region2. Mistral platform3. Open weights, EU cloud4. Your own server
Data stays in the EUYesYes by default, check featuresYesYes, in your building
Company holding it answers to EU law onlyNoYesYesThat company is you
Model qualityHighestHighHighGood
Switching model or providerHardPartly, the models are openEasyEasy
How you payBy usageBy usage or per userBy usageHardware plus maintenance
Best forPublic content, hardest tasksTeams wanting one European vendorClient data, internal documentsRegulated or confidential files

What still is not European

Be wary of anyone selling you 100% sovereignty. Every option above runs on Nvidia chips designed in California. Mistral’s investors include American funds. Your laptop’s operating system is probably American too. Sovereignty is a matter of degree, and the honest question is which dependencies could actually hurt you.

The word is also about to get a legal meaning. On 3 June 2026 the European Commission proposed the Cloud and AI Development Act. It defines four sovereignty levels for cloud services. Level 1 only requires that data is processed in the EU. The top level requires European ownership, protection from foreign control and independent audits. It is a proposal, not yet law, but it shows where public tenders and regulated sectors are heading: “sovereign” will soon be something a provider has to prove, not just print.

How to choose: start from the data, not the model

You do not have to pick one step for the whole company. Sort your data into three piles and let each pile decide:

  1. Public content (website pages, product catalogue, opening hours): option 1 is fine. Use the best model.
  2. Internal and client data (quotes, contracts, support tickets, email): option 2 or 3. A European company holds the data, and you can leave when you want.
  3. Regulated or confidential files (health, legal, HR, defence-adjacent work): option 3 with a strict contract, or option 4.

Three kinds of data on the left, each flowing through one assistant to a different destination on the right. Public content such as the website, catalogue and opening hours goes to the best model in an EU region, option 1. Internal and client data such as quotes, contracts and tickets goes to a European operator, option 2 or 3. Regulated files such as health, legal and HR go to a strict option 3 or to your own server, option 4

One assistant can even do the sorting for you: a sensitive request goes to the European model, a harmless one to the strongest model available. That only works if your assistant was not built around a single vendor in the first place.

What we build for you

Every Flowful package runs on Vectoria, our platform, which is not tied to any one AI model: changing the model behind an assistant is a single setting. That is what makes three hosting options possible for the same product:

  • EU cloud, standard. The application, databases and backups sit in Germany. The AI models come from the best available providers, with the standard EU contract clauses covering the American ones, and we are gradually moving this tier to European providers only.
  • EU or Swiss strict. Your own separate environment, where every request to an AI model stays inside EU or Swiss data centres: Mistral through its own platform, other models through their Belgian cloud regions. This is the usual choice for health, finance and the public sector.
  • On-premise or Belgian data centre. Everything, the AI model included, in your server room or in a rented cabinet in a data centre near Brussels, running open models such as Mistral’s. Hardware runs from roughly €3,000 for a five-person office to around €15,000 firm-wide.

The package where this matters most is the Internal Chatbot, because it is the one that reads your contracts, procedures and client files. It also applies to the Web Chatbot when conversations carry personal data, and to custom projects that process your documents. If you are also working through your obligations under the EU AI Act, knowing where each model runs is the first line of that inventory.

Tell us what data your assistant would touch, and we will tell you which step it belongs on, and what it would cost there.

Facts, models and prices in this post were checked in September 2026 and move fast. We build AI systems, we are not lawyers: verify legal questions with your counsel and current terms with each vendor.

Ready to transform your business with AI?

Let's discuss how we can help you achieve your goals.

Get in Touch