AI Act readiness

EU-sovereign infrastructure, ready for the AI Act

The AI Act is not the GDPR. Frontière AI gives European companies the EU-sovereign infrastructure and the per-model controls they need to deploy open-weight models in a framework compatible with both — and it does not claim the models are “AI Act compliant”, because under the Act that depends on each model, your role, and how you use the system.

What we can and cannot claim

A compliance claim that overreaches is worse than no claim at all — it breaks the moment a prospect opens the source documents. Frontière AI is precise about the line it will not cross.

What Frontière AI can stand behind

Infrastructure and controls: EU-sovereign hosting with no non-EU capital control on sovereign models, per-model jurisdiction labels, deployment location and host disclosed, no prompt retention for API calls, named EU subprocessors for sovereign routing, and each model's licence and open-weight status published. These are facts under our control, verifiable per call.

What we do not claim

We do not state that Frontière AI, or a model we host, is “AI Act compliant” as such. Under the AI Act, whether a given system complies depends on the model's documentation and classification, the deployer's role and the specific use of the AI system. An infrastructure provider can be ready; it cannot self-certify the model or your use case.

GDPR and the AI Act are two different laws

They are often conflated, but they regulate different things and impose different obligations. Knowing which is which is the difference between a defensible position and a misleading one.

GDPR — personal data protection

The GDPR governs the processing of personal data: lawfulness, purpose limitation, data minimisation, retention, transfers outside the EU, and the rights of individuals. Frontière AI's GDPR-first claim is about data residency and jurisdiction — where your prompts and documents are processed, and by whom.

AI Act — risk, transparency, accountability

The AI Act regulates AI systems by risk: prohibitions for unacceptable risk, obligations for the systems and the providers that build them, transparency and documentation duties, copyright and training-content obligations, and — for general-purpose AI (GPAI) — model documentation and, for the largest models, systemic-risk scrutiny. It is not itself a data-protection law.

Open source is not automatically AI Act compliant

It is a common shortcut to assume an open-weight model is exempt. The Act relaxes some GPAI documentation obligations for providers that make models available under a genuinely free and open source licence with public parameters and use information — but those providers still carry obligations, including on copyright and the summary of training content. And a GPAI model that presents systemic risk does not benefit from the exemption at all. Being open-weight is a factor, not a free pass.

01

A genuine free/open-source licence and public access to the model are necessary conditions for the GPAI simplification — not sufficient by themselves.

02

Remaining obligations for open-licence GPAI providers cover copyright and a summary of the training content, among others.

03

GPAI models with systemic risk fall outside the exemption, so status is determined per model, not per licence.

What Frontière AI can actually document

Instead of a blanket compliance badge, every public placement of a model carries the facts Frontière AI controls — so your DPO reads what is true instead of what sounds good.

  • EU-sovereign infrastructure with no non-EU capital control on sovereign models
  • Deployment location and host (OVHcloud, Scaleway, or dedicated EU servers)
  • Per-model jurisdiction label — sovereign or fast access — on the card and in the API
  • Data retention: no prompt or reply stored for API calls
  • Subprocessors named, for sovereign routing
  • Model licence and open-weight status published per model

Where a fact is not verified, it is shown as a dash rather than invented — a compliance file built on asserted figures is not a compliance file.

Where model-level compliance lives

Being honest about ownership of the remaining obligations is part of the positioning. The blocks below are the responsibility of the model provider and the deployer — Frontière AI's role is to surface, not to self-certify.

Model provider
model card, GPAI classification, systemic-risk status, training-content and copyright documentation
Deployer (you)
your role under the Act, the specific use of the system, your own risk assessment
Frontière AI
EU-sovereign routing, jurisdiction and licence transparency, retention and subprocessor facts

Why now

The AI Act's GPAI obligations are in force, and 2026 is when enforcement attention is turning to them in practice. For a European company that must answer a DPO or a procurement officer, “run it on EU-sovereign infrastructure, with the facts documented” is becoming a requirement, not a nice-to-have. This positioning is not a claim to have solved compliance — it is a claim to be ready for the conversation.

FAQ

Is Frontière AI Act compliant?

We do not claim a blanket “AI Act compliant” label, because under the Act compliance depends on each model, your role and your use of the system. What Frontière AI provides is EU-sovereign infrastructure and per-model controls — jurisdiction, licence, retention, subprocessors — that let enterprises build their own posture within GDPR and AI Act obligations. There is a difference between infrastructure that is ready and a system we would self-certify.

Is Frontière AI GDPR-compliant?

Yes on every model labeled EU sovereign: those run on providers with no non-EU capital control — OVHcloud, Scaleway, or our own dedicated EU servers — designed to stay outside US jurisdiction. Models we can only serve through US-controlled infrastructure carry the “fast access” label before you send anything.

Is an open-weight model automatically exempt under the AI Act?

No. The Act relaxes some GPAI documentation obligations for providers releasing models under a genuinely free and open source licence with public parameters and use information, but those providers still carry obligations on copyright and training-content summaries. A GPAI model with systemic risk does not benefit from the exemption. Open-weight status is a factor, not a free pass.

What compliance documentation does Frontière AI provide per model?

Everything Frontière AI controls: hosting jurisdiction and location, retention (none for API calls), subprocessors, and the model's licence and open-weight status. Model card, GPAI classification and systemic-risk status belong to the model provider — Frontière AI surfaces those from the source rather than self-certifying them. Unverified fields are shown as a dash, not invented.

What is the difference between GDPR and the AI Act?

The GDPR protects personal data — lawfulness, minimisation, retention, transfers and individual rights. The AI Act regulates AI systems by risk — prohibitions, transparency, documentation, copyright, and obligations on general-purpose AI providers. They overlap in practice but are separate legal instruments, and a claim under one does not automatically cover the other.

Does “AI Act-ready” mean Frontière AI guarantees my compliance?

No. Standards like this express that the infrastructure and controls are in place, not that compliance is achieved — that always depends on the model and how you deploy it. Frontière AI is explicit about not self-certifying the model or your use case.

Build your EU AI posture on EU infrastructure

Create an account, top up €10, and start on models whose jurisdiction, licence and hosting are documented — not asserted.

Create an account