// WHY SOVEREIGN AI
Why sovereign AI compute matters
EU data residency, Dutch-owned infrastructure, no US-cloud exposure. Here is why the jurisdiction of your compute provider is a technical and legal decision — not just a marketing one.
Your compute provider's jurisdiction is a legal fact
When you run AI workloads on compute operated by a US-headquartered company — or even a European subsidiary of one — your data is subject to US law. The CLOUD Act (2018) allows US federal agencies to compel US companies to produce data stored anywhere in the world, regardless of where the data physically resides.
This is not a theoretical risk for public-sector organisations, health institutions, or any company whose competitive advantage is in its data. It is a structural exposure. The only way to close it is to ensure your compute provider has no US legal nexus.
CLOUD Act (2018): US authorities can demand data from US companies regardless of where it is stored — even in the EU.
EU data residency: what it actually means
Data residency means the data never leaves a defined jurisdiction — not for primary processing, not for replications, not for support tooling, not for anything. At SAIG Compute, every workload runs on European hardware in the Netherlands or Germany. Every S3 bucket lives in an EU region. Egress is free precisely because we want you to own your data relationship, not be locked in by bandwidth costs.
Netherlands & Germany
All compute and storage regions are within the European Union. You choose the region at workspace creation.
No cross-border transfer
Your data does not route through non-EU infrastructure at any point — including support, monitoring and backups.
Egress free
Pulling your data out costs nothing. Data portability is not a product feature — it is a principle.
GDPR and NIS2 alignment
GDPR (General Data Protection Regulation)
Nixpay B.V. acts as data processor under Article 28 GDPR. We sign a Data Processing Agreement (DPA) with every customer. Your data never leaves the EU — the foundational GDPR requirement for international transfers does not arise because there are no international transfers.
NIS2 (EU Network and Information Security Directive)
NIS2 requires operators of essential services to implement appropriate security measures and report incidents to national authorities. As a Dutch operator, Nixpay B.V. reports to Dutch national authorities under Dutch law — not to a non-EU jurisdiction where your incident data could be subject to foreign government requests.
Open-weight models: compute you can audit
Sovereign AI is not just about where the data lives. It is also about whether you can inspect, audit and understand the models processing your data. Closed API models — regardless of where they are hosted — hand control of model behaviour to the model vendor.
SAIG Compute is designed for open-weight models: Llama, Mistral, Falcon, Phi, and any model you have rights to use. You choose the model. You can inspect its weights. You can verify its outputs. You are not dependent on a model vendor's continued operation, pricing or policy changes.
You choose the model
Any open-weight model you have rights to use. No vendor lock-in to a closed API.
Inspect and audit
You have access to model weights. You can validate behaviour, reproduce outputs, and document the model for regulators.
No dependency on a vendor
A model vendor changing pricing, deprecating a version, or ceasing operations does not affect your running infrastructure.
100% Dutch-owned — what that means in practice
Sovereign AI Grid is operated by Nixpay B.V. (KVK 96292148), registered in Amsterdam, the Netherlands. Nixpay B.V. is 100% Dutch-owned. There is no US parent company, no US fund on the cap table, and no US operating entity in the supply chain of your compute.
This matters for procurement: EU public-sector procurement rules, sector-specific regulations (healthcare, finance, defence) and data sovereignty policies increasingly require that the operating entity — not just the infrastructure location — is free of non-EU legal exposure.
Who this is for
Sovereign AI compute is not for everyone. If your workloads contain no personal data, your models are public, and US-cloud exposure is not a concern for your organisation, a hyperscaler may be fine. Sovereign compute is the right choice when:
- You process personal data under GDPR and need an Article 28-compliant processor
- You are a public-sector organisation with data sovereignty requirements in procurement
- Your sector (healthcare, finance, legal, defence) is subject to NIS2 or sector-specific regulation
- Your competitive advantage is in proprietary data you cannot afford to expose
- You want to run open-weight models you can inspect, audit and document
- You want egress-free, no-lock-in data portability as a default, not a premium feature