How Frontière AI determines sovereignty
European sovereignty is not measured by where a server physically sits — it is a question of who controls the company that operates it. This page lays out, factor by factor, how we decide a model's label and its Sovereignty Score. Every number below is derived from facts already published in our model registry; nothing is estimated and nothing is guessed.
The four questions
What every model's label is built on
Before a model is labeled EU sovereign, we answer four questions. A single negative answer on the first or third is disqualifying for the sovereign label.
01
Who owns the operating company?
The decisive factor. A model is EU sovereign only if it runs on a provider with no non-EU capital or jurisdictional control — the SecNumCloud principle. Ownership, not geography, is what a US court order can reach.
02
Where does the compute run?
Observed, not declared. Sovereign models run in the EU on OVHcloud or Scaleway regions, or on our own dedicated EU servers. We verify by real API calls, not by reading a datasheet.
03
Who operates the cloud?
EU sovereign work runs on EU-controlled providers or our own infrastructure — never through a US-incorporated company, even when that company operates an EU region.
04
What happens to the data?
Zero prompt and completion retention on API calls, on every provider. We store only the token counts billing requires. This is a product constant, not a per-model option.
The principle
Why “hosted in Europe” is not enough
Any US provider can run a compute region inside the EU and market it as “EU data residency”. That is true and irrelevant: the operating company remains subject to the US CLOUD Act, so a US court order can compel it to hand over the data it processes — even when that data is stored in Frankfurt.
This is why we follow the SecNumCloud reasoning: what decides your exposure is who controls the company operating the infrastructure, not where the servers physically sit. Physical location is one input (it tells us which jurisdiction's law applies to the compute), but capital control and legal jurisdiction are the load-bearing ones.
A model labeled EU sovereign is one where the serving path — operator, cloud, and data — is designed to stay under EU jurisdiction, not US legal process. That intent is what 'outside US jurisdiction by design' means on every model page.
The two labels
EU Sovereign vs fast access
The API returns one of two labels on every model card and in every response, before you call. There is no third, ambiguous state.
Designed to stay outside US jurisdiction
Served via providers with no non-EU capital control — OVHcloud, Scaleway, or our own dedicated EU servers. The corporate structure is designed to keep these workloads under EU jurisdiction. Score: EU Sovereign tier.
- EU server: OVHcloud, Scaleway or our own dedicated EU servers
- EU-controlled operating company (no non-EU capital control)
- Zero prompt / completion retention
→ Sovereign — stays under EU jurisdiction by design
Disclosed, never hidden
Served via infrastructure controlled by a US company (Modal, OpenRouter), which remains subject to the US CLOUD Act even when the region is in the EU. Labeled 'fast access', never sovereign — the choice is yours, made with full information.
- Compute may sit in an EU region
- US-controlled provider (Modal, OpenRouter) — CLOUD Act applies
- Zero prompt / completion retention
→ Not sovereign — usable, but the CLOUD Act applies
The score
The Sovereignty Score
A deterministic 0–100 figure, recomputable by anyone from the public methodology below and the facts in our model registry. It aggregates five weighted factors — it does not add a single new fact, and it makes no claim about security, quality, or legal warranty.
Five factors, weights summing to 100:
- Operating-company ownership
- 40
- Hosting jurisdiction (observed)
- 30
- Cloud-provider control
- 15
- Data retention
- 10
- Deployment control
- 5
Score tiers
| Tier | Range | Meaning |
|---|---|---|
| EU Sovereign | 85–100 | EU-controlled operator, EU hosting observed, zero retention. |
| EU Hosted | 60–84 | EU hosting observed but operator or cloud control is not fully EU-controlled, or verification is incomplete. |
| US Controlled | 0–59 | The serving path involves infrastructure controlled by a US company. Labeled fast access. |
Because the score follows the registry, it updates the moment a model changes provider. You can recompute it yourself on any model page (breakdown included) or from the formula above.
Frontière Verified
Verification and sovereignty are separate
Sovereignty answers 'under which jurisdiction does this run?'. Frontière Verified answers 'did we check this model before it went live?'. The two are complementary — a 6/6-verified model can be fast access, and a sovereign model can still be awaiting a verified check.
License
License checked and confirmed
Provenance
Weights confirmed on HF, publisher verified
Security
Security analysis: known vulns, injections, jailbreak
GDPR assessment
Retention and sub-processors assessed
Benchmarks
Quality, latency, throughput on prod infra
API compatibility
Endpoint tested: streaming, tools, response format
Operators & sub-processors
Who touches your requests
The operators in the serving path are disclosed per model and in the API response. EU sovereign models never route through a US-controlled company.
| Operator | Control | Lane |
|---|---|---|
| OVHcloud AI Endpoints | French, no non-EU capital control | EU Sovereign |
| Scaleway Managed Inference | French, no non-EU capital control | EU Sovereign |
| Frontière AI dedicated EU servers | FLEECE AI SASU, French | EU Sovereign |
| Modal | US company | Fast access (US) |
| OpenRouter | US company | Fast access (US) / fallback |
The legal question
The US CLOUD Act, stated precisely
The CLOUD Act lets US authorities compel data from US-controlled companies, wherever the data sits. Frontière AI is a French company with no US parent and no non-EU capital control; on the EU Sovereign tier, the serving path — operator and cloud — is designed to keep your AI workloads outside US jurisdiction. We state this as intent grounded in corporate structure, not as an absolute legal guarantee — audit our basis, don't take a slogan on faith. Assessed per model, in the API response, before you call.
Deeper analysis: GDPR vs. the CLOUD Act →FAQ
Is physical location enough to be sovereign?
No. A US provider can host compute in the EU and still be subject to the US CLOUD Act, because what matters is who controls the operating company. Location tells us which law applies to the compute; capital control and legal jurisdiction decide exposure.
Can a US authority compel access to my prompts?
On the EU Sovereign tier, the serving path is operated by companies with no non-EU capital control — OVHcloud, Scaleway, or our own dedicated servers — so the chain is not US-controlled by design. Frontière AI additionally stores neither prompts nor completions. We describe this as design grounded in corporate structure, not as a blanket legal guarantee.
Why do you serve some models through US infrastructure at all?
A few frontier models are only reachable, today, through US-controlled infrastructure. We serve them because developers ask for them, and we label them 'fast access' before you call — we never present them as sovereign. When a sovereign path exists (e.g. a self-hosted variant), we list it and mark it as such or as coming soon.
What is the Sovereignty Score?
A deterministic 0–100 aggregation of five weighted factors — ownership, observed hosting jurisdiction, cloud-provider control, data retention, and deployment control. It is recomputable from the public formula and the registry on any model page, and it updates if a provider changes.
How do Sovereignty and Frontière Verified differ?
Sovereignty asks under which jurisdiction a workload runs. Frontière Verified asks whether we ran our 6-criteria checklist on a model before it went live. A model can be sovereign and still have a criterion pending; a 6/6-verified model served via Modal remains fast access.
Inspect any model, down to the factor
Every model page shows its Sovereignty Score, its breakdown, and its verified checklist.