EU-hosted AI for software teams: what “European” actually has to mean
“EU-hosted” is claimed far more often than it is enforced. Six questions separate a policy sentence from a control: where does inference run, where does the data rest, who can be compelled to hand it over, what happens on fallback, can the rule be enforced at call time, and can you prove it afterwards. A configuration that refuses a non-EU model at the moment of the call is worth more than any paragraph in a privacy statement.
European hosting has become a checkbox in procurement, which means it has become a sentence in a lot of marketing. For a software team the sentence is not the interesting part. The interesting part is what happens at the moment a model call is made, and whether anyone could tell afterwards.
Six questions turn the claim into something checkable. They are the ones we would ask a supplier, which is why we have tried to answer them here about ourselves.
1. Where does inference actually run?
Not where the company is registered, not where the dashboard is served from — where the GPU is. A European vendor calling a US API is a European vendor whose data leaves. The only useful form of this answer names the region and the provider.
For Turnado: process work — turning an analysis into tickets, planning, deriving test cases, composing release notes — runs on our own process model at Mistral in France. Code work runs on whichever model you configure, which may well be outside the EU. The platform says which, per model, on the screen where you choose it.

2. Where does the data rest, as opposed to pass through?
Inference location and storage location are separate questions and are often answered as one. Your work items, tickets, conversations and audit log live in a database somewhere; that somewhere has its own jurisdiction, its own backups, and its own replicas. Ask about the replicas — that is where the surprise usually is.
3. Who can be compelled to hand it over?
This is the question data residency was invented for and the one it answers least well. A European datacentre operated by a company subject to non-European disclosure law is a European datacentre with a caveat. Whether that caveat matters depends entirely on your sector; pretending it does not exist is what makes people distrust the whole conversation.
4. What happens on fallback?
The most common way an EU-only guarantee quietly fails is a fallback path: the European model is unavailable, and something has to answer, so a secondary provider gets the call. If a fallback exists, it needs to be as constrained as the primary — and the substitution has to be recorded with its reason, so “which model actually did this work” is answerable after the fact rather than assumed.
5. Can the rule be enforced at call time?
This is the question that separates a policy from a control. A policy says non-EU models should not be used. A control refuses the call. In Turnado an organisation can set that only EU-hosted models may be used, and a choice outside that is refused with the reason attached — not logged for review, refused.
6. Can you prove it afterwards?
An auditor does not want your configuration; they want evidence about what happened. Every agent run recorded with its model, its duration and its cost gives you that: you can answer “which model processed this customer’s requirement, on what date, at what cost” per work item rather than per quarter.
The AI Act angle, briefly and without drama
Most software delivery tooling is not high-risk under the EU AI Act, and vendors implying otherwise are selling fear. What does apply generally is more mundane and more useful: knowing which system was used for what, keeping records of automated processing, and being able to describe how humans remain involved in consequential decisions. If your platform records runs per work item and enforces which decisions stay human, you have most of that as a by-product.
The GDPR question is more immediate for most teams: whatever ends up in your tickets — customer names in bug reports, personal data in test cases, an e-mail thread pasted into an analysis — is being processed, and the model provider is a processor. That is a data processing agreement and a retention answer, not an architecture problem.
Saying what is not true yet
Turnado‑1, our process model, is not its own weights file. It is our prompts, our tool contract and our yardstick running on an open European model from Mistral. We say so on the site because the alternative — letting people assume we trained something — is a claim that quietly becomes a lie, and “European AI” is precisely the area where the industry has trained everyone to expect exaggeration.
What does EU-hosted AI actually mean?
That inference runs on infrastructure located in the EU, which is a separate question from where your data is stored, who operates the infrastructure, and which jurisdiction can compel disclosure. A useful claim names the provider and the region for each of those.
How do I enforce that no data leaves the EU?
Enforce it at call time rather than in policy: a setting that refuses any model hosted outside the EU, applied when the call is made, with the reason attached. Then check what happens on fallback — that is where the guarantee usually leaks.
Does the EU AI Act apply to software delivery tooling?
Usually not as high-risk. What tends to apply is transparency and record-keeping around automated processing, plus meaningful human involvement in consequential decisions — which a platform that records every agent run per work item and keeps approvals human largely produces as a by-product.