AI in Europe
Artificial intelligence with your data inside the European Union.
For public bodies and organisations handling sensitive data, where AI processes information is a strategic decision. We guarantee processing in the EU, through our partners, or on the client's own premises — matched to the requirements of each project.
- Processing within the EU
- GDPR and the AI Act
- Also on your premises
Why it matters
Data sovereignty is not a technical detail.
Where processing happens has legal, contractual and trust consequences.
-
Data protection
Avoiding international transfers simplifies GDPR compliance and reduces legal risk.
-
Public-sector requirements
Many public procurement procedures require data and services hosted within Europe.
-
Strategic autonomy
Less dependence on external jurisdictions and greater control over service continuity.
-
Trust
Citizens, patients and customers trust services more when they know where their data is.
Deployment options
Three ways to keep AI in Europe.
We choose the right combination with each client — and can mix options in the same project, depending on the sensitivity of each process.
| Partner infrastructure in the EU | Commercial models with EU residency | On your premises | |
|---|---|---|---|
| Where the model runs | Dedicated servers in EU data centres | European regions of cloud providers | The organisation's own infrastructure |
| Models | Open-weight, controlled by Datapoint and the client | Leading commercial models | Open-weight, sized to the hardware |
| Control | High | Contractual | Full |
| Best for | Sensitive data with elasticity | Demanding tasks with moderate-risk data | Maximum isolation requirements |
Models matched to the data
Not all data needs the same model.
We classify the information in each process and choose the right model and processing location. The same MCP server serves every option.
- Public or internal data: the most capable model for the task, with EU data residency.
- Personal data: models hosted in the EU through our partners, with pseudonymisation.
- Sensitive or health data: open-weight models in the EU or on the organisation's premises, never sent to third parties.
- In every case: MCP servers and audit logs inside the European perimeter.
Compliance by design
The European framework, built into every project.
-
GDPR
Impact assessment, minimisation, legal bases and data subject rights addressed from the start.
-
AI Act
Risk classification of the system, transparency for users and documented human oversight.
-
NIS2 and cybersecurity
Access management, logging, vulnerability management and service continuity.
-
Documentation
Records of processing, model fact sheets and audit trails available on request.
How we decide
Four questions before choosing a model.
-
What data is involved?
We classify the information in each process: public, internal, personal or sensitive.
-
What will the AI do?
Search, summarisation, extraction, classification and drafting need different capabilities.
-
Where should it run?
Partner infrastructure in the EU, European cloud regions or the client's premises.
-
How is it demonstrated?
Documentation, logs and audit trails that prove where and how the data was processed.
Frequently asked questions
About processing in the EU.
Does data ever leave the European Union?
No, when the solution is configured for EU processing. Models, MCP servers and logs stay inside the European perimeter, and this is documented.
Are open-weight models good enough?
For many administrative tasks — extraction, classification, summarisation and search — yes. We evaluate each case with test data before recommending.
Can we use our own infrastructure?
Yes. We install and operate the models and MCP servers on the organisation's premises, sized to the available hardware.
Is our data used to train models?
No. Client data is not used to train models, and this is set out in the contract.
Do you have data location requirements?
Share them with us. We will propose an architecture that meets them, with the right model options.