In 2026, AI assistants, document processing and automated service requests are moving into everyday operations at many small and mid-sized companies. That brings a question to the fore that long took a back seat to features: where exactly does the system run – and under which jurisdiction does its processing take place?
Three developments changed this question in 2026. First, the AI Act's transparency rules (Article 50) have applied since 2 August 2026, so a hosted AI assistant is now subject to ongoing supervision. AI Act Service Desk: timeline. Second, the foundation of the EU-US Data Privacy Framework has been shaken. A US Supreme Court ruling of 29 June 2026 ended the independence of the FTC; on 30 June 2026 the privacy organisation noyb formally asked the European Commission to withdraw the adequacy decision. noyb: Supreme Court ruling. Third, European infrastructure is more available than ever – from the AWS European Sovereign Cloud in Brandenburg to Microsoft's completed EU Data Boundary, complemented by the proposal for an EU Cloud and AI Development Act of 3 June 2026. Commission: Cloud and AI Development Act.
EU hosting has therefore become easier to access and, for many use cases, the more coherent choice. But it does not run itself: an “EU server” on its own fulfils not a single GDPR or AI Act obligation. The seven questions in this article structure your initial conversation with a service provider or your internal decision – before the contract and setup are fixed and a correction becomes expensive.
The legal position and the market moved several times in 2026. This article reflects the situation as of 6 October 2026. It offers practical guidance, not a binding classification of your individual case.
Why EU hosting faces stricter scrutiny in 2026
| Development | Date | What it means for your hosting choice |
|---|---|---|
| AI Act transparency rules (Article 50) apply | 2 August 2026 | AI interaction must be recognisable; high-risk deadlines were postponed, the disclosure duty was not |
| AI Omnibus in force | 27 July 2026 | High-risk rules for Annex III apply from 2 December 2027, for Annex I products from 2 August 2028 Commission: AI Omnibus |
| US Supreme Court ends FTC independence | 29 June 2026 | EU–US adequacy decision formally in force but under scrutiny; an appeal is pending before the Court of Justice DPF: status after Latombe |
| AWS European Sovereign Cloud launched in Brandenburg | 15 January 2026 | A European-led, separately operated cloud region of a major US provider Digital Chiefs: Digital sovereignty 2026 |
| Cloud and AI Development Act proposed | 3 June 2026 | A planned four-level EU assurance scheme for cloud services – evidence you will be able to request in future tenders Parliament: Legislative Train CADA |
The direction is clear: “data in the EU” is shifting from a nice-to-have to an item that is checked in tenders, customer questionnaires and conversations with authorities. At the same time, the dispute over the Data Privacy Framework shows that legal certainty built on a third country's assurances is politically vulnerable. If you already host and process in the EU, this risk simply is not on your table.
Question 1: Where does your system really process personal data?
The most common mistake: equating the location of your application's server with the location of the AI processing. An assistant whose web interface runs in Frankfurt can still forward every request to a model API outside the EU – including logging, support data and backup paths.
Map the data flow in four building blocks:
| Building block | Typical unknowns | What you can require |
|---|---|---|
| Input (website, chat, form) | Where are inputs cached, and for how long? | Storage location and retention fixed in writing |
| Orchestration (your application) | Which data is passed to the model – all of it or filtered? | Hand-over logic and field list in the specification |
| Model | In which region does the provider process prompts? Is the prompt stored? | Choose an EU region or enable a zero-data-retention option |
| Side channels | Logging, monitoring, support tickets, backups | Include these “secondary systems” in the data processing agreement |
A look at your configuration is rarely enough – ask explicitly. The provider must be able to answer “Does any personal data leave the EU in any call?” with yes or no, not with “normally not”.
Question 2: Who has which role – and who is liable?
The GDPR distinguishes controllers and processors; the AI Act distinguishes providers and deployers. Both classifications follow the specific product, not the type of contract:
- The controller is usually your company: you decide on the purposes and means of processing customer data.
- Processors are hosting providers and model services that process data on your instructions. You need a data processing agreement (DPA) under Article 28 GDPR – with a list of subprocessors, technical and organisational measures and a deletion policy.
- The deployer of the AI system is typically you, even if a third-party language model runs in the background. The AI Act provider role may still fall to you – for example, if the assistant is put into service under your brand. Clarify roles before launch; a hosting contract alone does not answer this.
We explain the details in our article on the EU AI Act for small businesses. For your hosting choice, the consequence is enough: ask your service provider in writing which role it takes on, which subprocessors it uses and who responds to an enquiry from a supervisory authority. A provider who answers this with “we'll just handle it” does not have the answer.
Question 3: Is “a server in Frankfurt” enough for the GDPR?
No – and that is exactly why the distinction between data residency and lawfulness matters.
Data residency answers a single question: where is data stored and processed? Lawfulness answers everything else: legal basis, purpose limitation, data minimisation, information duties, retention periods, data subject rights. A data centre in Frankfurt does not make processing for an unrelated purpose lawful, and it does not replace a legal basis.
What EU hosting actually delivers is a reduction of one specific residual risk: access by US authorities to data held by a US provider. This very risk is the Achilles' heel of the EU-US Data Privacy Framework. The framework formally remains in force – the EU General Court upheld the adequacy decision in the Latombe case in September 2025, and the Court of Justice has not yet ruled on the appeal DPF: status after Latombe. But the legal analysis has become considerably more critical since June 2026 Analysis: Transatlantic data transfers in 2026: noyb cites the FTC ruling, calls on the Commission to withdraw the decision and has announced its own lawsuit. noyb expects two to three years until a Court of Justice ruling, so 2028/2029 at the earliest noyb: Supreme Court ruling.
Practical consequences for your initial conversation:
- If all processing stays in the EU, the GDPR question of third-country transfers largely falls away – document clearly why this is the case.
- If part of the data flow goes to the USA, check the provider's DPF certification – and also require standard contractual clauses as a second pillar. Anyone with only one pillar has a weak spot.
- Record in your record of processing activities which transfer mechanism you rely on. If the legal position changes, you will immediately know which systems are affected.
Question 4: What happens to your data at the model provider?
The second data question is the most uncomfortable one: what does the model provider do with your prompts? Three settings are common:
- Retention: Is the prompt deleted after the response, after 30 days, or kept for abuse monitoring? Both are legitimate – but retention must fit into your deletion policy.
- Use for training: Commercial API offerings do not use customer data for training by default; free or consumer offerings often do. Confirm the setting in writing, not via an FAQ page.
- Logging and staff: Who can view logs – and from which country? EU log storage with a support team outside the EU creates its own transfer question.
With major US providers, EU regions and zero-data-retention options are now standard – Microsoft completed its EU Data Boundary in early 2025, so customer data, pseudonymised data and support data for its core cloud services remain within the EU and EFTA Microsoft: EU Data Boundary. These offerings are serious candidates – “EU provider” and “EU hosting” are not the same thing, and neither automatically means “right for your case”.
Question 5: What evidence can the provider supply?
Ask for an evidence pack rather than a sales promise. The following six documents are sufficient for a typical SME project:
- DPA under Article 28 GDPR, including a current list of subprocessors and a right to approve or object to changes.
- Data centre locations: a list of the specific regions for storage, processing, backup and logging – not “EU-wide”.
- Certifications: at least ISO 27001; for more sensitive cases BSI C5 or comparable evidence. Ask which specific services the certification covers.
- Model data policy: retention, use for training, access rules – as a contract annex, not a blog post.
- Operational documents: SLA with outage history, maintenance windows, support response times.
- Exit documentation: the format in which you can export data on termination and how long the deletion periods run afterwards.
Looking ahead: the proposed EU Cloud and AI Development Act provides for a tiered EU assurance scheme for cloud services – US providers partnered with EU companies could reach level 2, EU providers alone level 3 and some emerging EU offerings level 4 Parliament: Legislative Train CADA. The legislation is still in progress, but you can already use the direction in tenders: ask how the provider expects to be classified under future assurance levels – the answer shows how seriously it takes European autonomy.
Question 6: What does the AI Act change about your hosting choice?
In short: not the risk class, but the governance.
The AI Omnibus entered into force on 27 July 2026 and mainly postponed deadlines: high-risk rules for Annex III systems (such as pre-screening job applicants) apply only from 2 December 2027, and for high-risk systems embedded in products from 2 August 2028 Commission: AI Omnibus. The transparency obligations under Article 50 are unaffected and have applied since 2 August 2026 AI Act Service Desk: timeline. The risk classes themselves were left untouched Analysis: AI Act Digital Omnibus.
For your hosting choice, this means:
- EU hosting does not make a system less risky. An assistant that pre-sorts job applicants remains high-risk – whichever server it runs on.
- A recognisable AI notice remains mandatory; our article on the EU AI Act for small businesses covers how to implement it.
- Processing that stays in the EU end to end noticeably simplifies documentation: one jurisdiction, one supervisory structure, no transfer assessment for every new component. It is no substitute for compliance, but it saves real time in every audit.
Question 7: What does EU hosting really cost – and what happens in an emergency?
The honest answer to the cost question is a comparison. EU infrastructure can be somewhat more expensive to run – there are price and latency differences compared with US offerings for models, capacity or regional availability. On the other side are three items that only become visible when problems arise: transfer assessments and evidence for third-country processing, reconfiguration after a political or legal change in the third country, and the cost of an outage when a single model endpoint fails.
Three points therefore belong in every hosting design:
- Use your switching rights: the EU Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025 and gives you switching and exit rights for cloud services – use them as leverage when negotiating export formats and transition periods Commission: Data Act.
- Define a fallback path: which second model provider can take over without you rewriting prompts, knowledge base and integration code? A RAG-based setup with a cleanly separated knowledge base makes this switch realistic – see Five layers of an AI agent.
- Rehearse an outage scenario: what happens if the provider shuts down – data export, transition periods, communication with customers? Half a day of testing achieves more here than any contract clause.
Working through the seven questions in 30 minutes
For a first impression you do not need a data protection law firm – a structured half hour with your service provider is enough:
- Map the data flow: input, orchestration, model, side channels – with the region for each block (question 1, 5 min).
- Clarify roles: who is controller, who is processor, who is provider, who is deployer? (question 2, 4 min)
- Check the transfer question: does any personal data leave the EU? If so, under which mechanism? (question 3, 4 min)
- Pin down the model policy: request retention, use for training and log access in writing (question 4, 4 min).
- Request the evidence pack: DPA, list of regions, certifications, SLA, exit format (question 5, 4 min).
- Record the AI Act classification: note the system's purpose, risk class and AI notice (question 6, 4 min).
- Clarify the fallback and emergency plan: name a second provider, data export and transition; record open points with an owner and a date (question 7, 5 min).
It is normal for some points to remain open afterwards. What matters is that the open points are named – not that the conversation blurs them.
What EU hosting does not take care of
Finally, the limits, so that expectations stay realistic:
- EU hosting does not replace a legal basis. You assess purpose, legal basis, information duties and retention periods regardless of the server location – the GDPR checklist for chatbots takes you through the key points in half an hour.
- EU hosting does not replace the AI notice. Whether the AI interaction is recognisable is a question of interface design, not of infrastructure.
- Not every AI application strictly needs EU hosting. For a low-risk task without personal data, a third-country model can be justifiable – but as a documented decision with a named transfer mechanism, not by accident.
- EU hosting does not guarantee model quality. Answer quality, latency and cost depend on the specific use case and model – choosing a region is a compliance and risk decision, not a question of quality.
Running AI in the EU is today the simpler choice and the one that is easier to document robustly – not the most convenient one in every individual case. That is exactly why a structured start beats a gut decision.
We set up AI assistants, document processing and automation for small and mid-sized companies – with EU hosting, clear roles and an evidence pack you can show your customers and auditors. Our page on the LindenTech AI Platform provides the product context; our services give an overview of hosting and integration. For your specific project, you can discuss it with us.