← Blog

Sovereign by Design vs Sovereignty Washing: A Buyer's Checklist

    Sovereignty washing is when a vendor markets a product as "European" or "EU-hosted" to imply legal control it does not actually have. The fix is not a better sales pitch from the vendor. It is a scorecard you run yourself. Below is a buyer's checklist that separates sovereign by design from sovereign by marketing. Score each item yes or no, insist on the actual answer rather than the reassuring one, and treat the honest answers as the only ones that count. A vendor that scores clean will welcome the questions. A vendor that is washing will reach for geography every time you ask about jurisdiction.

    This post is the scorecard, not the theory. If you want the legal mechanism behind why an EU address does not equal EU control, read our companion piece on the EU data center CLOUD Act loophole. Here, the job is to hand you the questions and tell you which answers are a hard fail.

    What is sovereignty washing?

    Sovereignty washing is presenting data residency as if it were data sovereignty. The two are not the same thing, and the gap between them is where the marketing lives.

    Definition

    Sovereignty washing is the practice of presenting data residency, an EU storage address, as data sovereignty, legal control over processing. The claim breaks when a US parent company or a US sub-processor can still be compelled to disclose the data under laws like the CLOUD Act, regardless of where the servers physically sit. Residency answers "where is the data." Sovereignty answers "whose law governs it, and who can be forced to hand it over."

    The mechanism is covered in depth in our CLOUD Act loophole explainer, so we will not re-run it here. The short version: a Frankfurt data centre operated by a US-incorporated company is a US company's data, wherever the disk spins. Your scorecard exists to catch exactly that substitution.

    Sovereignty washing AI definition

    Within the context of AI tools specifically, sovereignty washing describes a product claim where a vendor markets an AI system as EU-compliant or European while one or more of the following conditions hold: the AI model runs on infrastructure controlled by a non-EU entity; the transcription, inference, or analysis step routes data through a US-operated API; or the encryption keys, the sub-processor list, or the legal controller sits outside EU jurisdiction. The claim is sovereignty; the mechanism is residency.

    The AI layer is where sovereignty washing is most easily hidden, because AI processing is typically invisible to the buyer. You can audit a data centre region in a contract. You cannot audit which API endpoint a product calls at inference time unless you ask directly and receive a documented answer. Vendors know this, which is why "powered by AI" and "EU-hosted data" often appear in the same sentence while the model call itself exits EU jurisdiction entirely.

    For an AI tool to be genuinely sovereign, sovereignty must hold at every processing step: capture, transcription, inference, storage, and retrieval. A model that self-hosts capture but routes transcription through a US provider, or one that stores in Frankfurt but runs coaching analysis against a US-controlled API, is not sovereign at the AI layer. It is sovereign at the storage layer with a sovereignty washing claim at the inference layer. The scorecard below tests each layer.

    The buyer's scorecard

    Run every prospective vendor through these questions. Each has a strong answer that signals sovereign by design and a weak answer that signals washing. Score yes only when the strong answer is documented, not merely asserted.

    1. Who legally controls the company and the processing? Sovereign: a named EU entity controls the company and every processing decision, with no controlling non-EU parent. Washing: "our European team handles that," with the actual holding company left unnamed.
    2. Under which country's law does the vendor operate? Sovereign: a specific EU member state's law, stated plainly, with the entity registered there. Washing: "we are fully GDPR compliant," with no jurisdiction named at all.
    3. Can you see the full sub-processor list, and where each one runs? Sovereign: a published, current list naming every sub-processor and the jurisdiction each operates under. Washing: no list, a partial list, or "we use industry-standard providers."
    4. Where does model inference and AI analysis run, and on whose models? Sovereign: inference runs in the EU on EU-hosted or self-hosted models the vendor can point to. Washing: "we use a leading AI model" that turns out to be a US API call for every transcript.
    5. What transfer mechanism is relied on, if any? Sovereign: none, because data never leaves EU jurisdiction, so no SCCs or DPF reliance is needed. Washing: Standard Contractual Clauses or the Data Privacy Framework, treated as if permanent.
    6. Could a non-EU parent be compelled to hand over data? Sovereign: no, there is no US parent or US entity subject to the CLOUD Act. Washing: the US parent goes unmentioned until you ask, then "that would never happen in practice."
    7. Where is data physically stored and processed, not just stored? Sovereign: stored and processed in the EU end to end, including transcription and analysis. Washing: "stored in the EU," while processing quietly happens elsewhere.
    8. Are audit rights and access logs available to you? Sovereign: contractual audit rights, plus access and processing logs you can inspect. Washing: "trust our certifications," with no right to verify anything yourself.
    9. Who holds the encryption keys? Sovereign: keys held by an EU entity, or by you, never by a US parent that could be compelled. Washing: keys managed by the vendor's US entity or a US cloud key service.
    10. Can the vendor point to specific infrastructure without hand-waving? Sovereign: named providers, named regions, named entities, offered before you have to dig. Washing: vague reassurance, brand names dropped without detail, and pivots back to "European."

    Red flags that signal washing

    Some answers are washing tells on their own. If you hear these, raise the scrutiny rather than lower it:

    • "EU data center" offered as the whole answer to a jurisdiction question.
    • "We comply with GDPR" with no country's law and no entity named.
    • No sub-processor list, or one that will not name where each provider runs.
    • A US parent company that goes unmentioned until you specifically ask.
    • Reliance on the Data Privacy Framework as though it were permanent, when it has already replaced two frameworks that courts struck down.
    • Encryption keys held by the vendor's US entity or a US-operated key service.

    How to score a vendor

    This is not a points total where strengths average out weaknesses. Sovereignty is a chain, and a chain fails at its weakest link. Score it that way.

    1. Any "no" on jurisdiction, legal control, or key custody is a hard fail, not a minor deduction. These three decide whether anyone outside the EU can be compelled to reach your data.
    2. Residency answers do not offset sovereignty gaps. An impeccable EU storage story does not buy back a US parent or a US key service. You cannot store your way out of a jurisdiction problem.
    3. Undocumented "yes" answers score as "no." If the strong answer cannot be shown in a contract, a sub-processor page, or a log, it does not count.

    For the wider framing of what sovereignty means across the model, hosting, and control layers, see our plain-English guide to sovereign AI. If you want the legal detail on why residency and jurisdiction diverge, the CLOUD Act and EU data sovereignty breakdown covers it.

    What sovereign by design looks like

    A sovereign meeting assistant is a useful worked example, because a meeting tool touches every layer the scorecard tests: it records audio, transcribes it, stores the result, and runs AI analysis over it. Each of those is a chance to leak out of EU jurisdiction, and a washed vendor leaks at the transcription or analysis step even when storage looks clean.

    Sovereign by design means all four stages sit inside EU jurisdiction and you can prove it. Audio capture, transcription, storage, and the AI analysis or coaching all run under EU law. The sub-processors are named rather than implied. The encryption keys sit with an EU entity, not a US parent that could be compelled. And when you ask where inference happens, the answer is a specific region and a specific model, not a gesture at "European infrastructure." That is the difference between a vendor answering the question you asked and a vendor answering a different, easier one.

    This is the standard Numi is built to. See how a sovereign meeting assistant keeps audio, transcription, storage, and coaching under EU jurisdiction, with infrastructure we can point to rather than hand-wave at.

    Frequently asked questions

    What is sovereignty washing?

    Sovereignty washing is when a vendor markets a product as European or EU-hosted to imply legal control over data that it does not actually have. It presents data residency, an EU storage address, as if it were data sovereignty, legal control over processing. The tell is that a US parent or a US sub-processor can still be compelled to disclose the data, so the European framing is marketing rather than a structural guarantee.

    What is the difference between data residency and data sovereignty?

    Data residency describes where data is physically stored, for example a data centre in Frankfurt or Amsterdam. Data sovereignty describes who holds legal control over the processing of that data and which country's law governs it. Residency is a storage address. Sovereignty is jurisdiction. A vendor can offer EU residency while remaining subject to US jurisdiction through a US parent or sub-processor, which means residency alone does not deliver sovereignty.

    How do you check if an AI vendor is really sovereign?

    Score the vendor on jurisdiction, not geography. Ask who legally controls the company, under which country's law it operates, the full list of sub-processors and where each runs, where model inference happens and on whose models, what transfer mechanism is used, whether a non-EU parent could be compelled, where data is processed as well as stored, whether audit rights and logs exist, and who holds the encryption keys. Any no on jurisdiction, control, or keys is a hard fail.

    Is an EU data center enough for sovereignty?

    No. An EU data centre satisfies data residency, but it does not resolve jurisdiction. If the operating company is incorporated in the United States or has a US parent, the US CLOUD Act can compel disclosure of the data regardless of where the servers sit. An EU storage address is a necessary GDPR control, but on its own it is the single most common signal of sovereignty washing rather than proof of sovereignty.

    Do Standard Contractual Clauses or the Data Privacy Framework make a vendor sovereign?

    No. Standard Contractual Clauses and the EU-US Data Privacy Framework are transfer mechanisms that permit data to leave the EU under conditions. Needing them at all means data crosses a jurisdictional boundary. They bind private parties and cannot override a government access order, and the DPF is legally contested, having replaced two frameworks that courts already struck down. A vendor that leans on them as if they were permanent is describing exposure, not sovereignty.

    Numi is built sovereign by design: EU jurisdiction over audio, transcription, storage, and coaching, with infrastructure we can point to.

    Get Early Access