Updated juli 19, 2026
Summary: EuroHPC AI Factories and AI Gigafactories, expanded under Council Regulation (EU) 2026/150, give public-sector and regulated-sector organisations access to high-performance AI compute that stays within European legal jurisdiction. For CISOs and compliance officers, the key question is not just performance but who controls the data, the model weights and the audit trail.

The EuroHPC AI Factory sovereign compute model refers to the provision of high-performance GPU infrastructure, physically hosted within the European Union and governed exclusively by EU law, for the training, fine-tuning and inference of AI models on sensitive data. For compliance officers, CISOs and data protection officers in government, finance, healthcare and legal services, the jurisdictional character of compute infrastructure is as consequential as its raw performance. Choosing where AI workloads run determines which legal regimes can compel access to training data and model outputs.

The Jurisdictional Gap Between US Hyperscalers and EuroHPC

US-controlled AI cloud services operate under statutes that allow extraterritorial government access, creating a structural compliance problem for European regulated organisations. EuroHPC infrastructure does not share this exposure.

When a European hospital trains a diagnostic model on AWS, Google Cloud or Microsoft Azure, the underlying infrastructure is owned by a US-incorporated entity. The US CLOUD Act (2018) allows US authorities to compel those entities to produce data stored anywhere in the world, without necessarily notifying the data subject or the European supervisory authority. FISA Section 702 creates a parallel channel for intelligence access. Neither mechanism requires a mutual legal assistance treaty.

EuroHPC Joint Undertaking supercomputers, by contrast, are owned and operated by European hosting entities, typically national supercomputing centres such as CSC in Finland, CINECA in Italy or BSC in Spain. They are not subsidiaries of US corporations and carry no obligation under US law. This matters precisely because the European Data Protection Supervisor has observed: “Sovereignty in AI is not just about where the data sits. It is about who controls the model, who audits the training process, and who can compel disclosure.”

Let op: Hosting data in an EU data centre owned by a US parent company does not eliminate CLOUD Act exposure. The legal control test, not the physical location test, determines US government access rights. Only infrastructure operated by entities without US-parent ownership or US-nexus removes this risk structurally.

Council Regulation (EU) 2026/150 and the AI Gigafactory Mandate

Council Regulation (EU) 2026/150 formally extends the EuroHPC JU mandate beyond traditional high-performance computing to include the procurement, deployment and operation of AI Gigafactories: very large GPU clusters designed specifically for training frontier and near-frontier AI models.

Before this regulation, EuroHPC’s AI Factory programme was already underway as a policy initiative, but the legal basis for large-scale AI-specific infrastructure procurement was thin. The 2026 regulation creates a structured procurement framework, allocates reserved compute budgets for public-sector and research applicants, and introduces access-allocation obligations. Member states nominate hosting entities and contribute co-financing; in return, their public bodies receive priority access windows for national strategic workloads.

For regulated buyers, this has a direct procurement consequence. Applications for compute time now follow a standardised process with defined eligibility criteria, data classification requirements and review timelines. Organisations that previously navigated ad-hoc arrangements must now comply with the formal access procedures defined under the regulation, including documentation of the intended workload, the data categories involved, and the data protection framework in place.

The European Commission’s InvestAI Facility targets at least 200 billion euros in AI investment by 2030, with AI Gigafactories as a central pillar (European Commission, 2025). This scale of public commitment signals that EuroHPC AI Factory capacity will expand materially over the coming years, making it a credible long-term alternative to hyperscaler compute for regulated workloads.

See how Qsentinel solves this in practice.Start a 10-user pilot →

Eligible Workloads and Sensitivity Classifications

EuroHPC AI Factories are accessible to a range of regulated-sector workloads, but not all sensitivity levels are equally straightforward to accommodate on shared infrastructure.

Health records used to train clinical AI models present the most demanding classification. Processing under GDPR Article 9 (special category data) requires explicit legal basis, a data processing impact assessment, and a GDPR Article 28 processor agreement with the hosting centre. The hosting supercomputing centre acts as a processor; the hospital or health authority remains the controller. The DPA must specify data categories, retention periods and the prohibition on using training data for any purpose other than the contracted workload.

Financial models built on proprietary trading data, client portfolios or credit-risk datasets sit within DORA’s scope for financial entities. DORA Article 29 requires a concentration risk assessment whenever a critical ICT function depends on a single provider. Using EuroHPC compute for AI model training diversifies the provider landscape relative to exclusive hyperscaler reliance, but the resilience benefit only holds if the organisation maintains a documented fallback, including export procedures for trained model weights.

Legal datasets, particularly those containing privileged communications or data subject to professional secrecy, require contractual clauses that go beyond standard GDPR Article 28 terms. Legal professional privilege is a matter of national law and does not appear explicitly in GDPR; organisations in the legal sector must negotiate bespoke confidentiality schedules with the hosting centre before committing privileged datasets to EuroHPC infrastructure.

Sector Key Data Category Applicable Instrument Primary Contractual Requirement
Healthcare Patient records (Art. 9 GDPR) GDPR, NIS-2 Art. 28 DPA with DPIA documentation
Finance Proprietary trading and credit data DORA Art. 29, GDPR Concentration risk assessment and Art. 28 DPA
Legal Privileged communications National secrecy law, GDPR Bespoke confidentiality schedule plus Art. 28 DPA
Public sector Government operational data GDPR, NIS-2, national classification rules Art. 28 DPA with access control audit rights

Contractual and Technical Controls for Model Weight Sovereignty

Using shared EuroHPC infrastructure rather than on-premises GPU clusters introduces a category of risk that is contractual as much as technical: who owns the model artefacts produced during training?

The GDPR Article 28 processor agreement must explicitly address model weights, checkpoints and derivative artefacts. By default, these may not be covered by a standard DPA that focuses on input data rather than model outputs. Organisations must negotiate clauses confirming that trained weights are the exclusive intellectual property of the applicant, that the hosting centre has no licence to access or replicate them, and that deletion procedures apply to all intermediate artefacts upon job completion.

On the technical side, the minimum controls are: encryption of training datasets at rest and in transit using keys held exclusively by the applicant organisation; use of a hardware security module or equivalent key management solution that the hosting centre cannot access; and network isolation of the training job so that output artefacts cannot egress to shared storage visible to other tenants. The EuroHPC JU’s LUMI supercomputer already reached a peak performance of 380 petaflops (EuroHPC JU, 2023), demonstrating that frontier-class compute is available within this governance framework, but performance alone does not substitute for contractual diligence.

Let op: A GDPR Article 28 DPA that covers only input personal data but not model weights or checkpoints leaves a significant sovereignty gap. Fine-tuned weights can encode personal information and may be subject to data subject rights requests. Verify that your DPA template explicitly addresses model artefacts before starting any training run on EuroHPC infrastructure.

EuroHPC AI Factories Versus On-Premises Sovereign AI: A Practical Comparison

On-premises GPU infrastructure gives organisations the highest degree of control but requires capital expenditure, specialist staffing and a procurement cycle that can run twelve to twenty-four months. EuroHPC AI Factories offer a credible middle path: European jurisdiction without the full ownership burden.

From a GDPR Article 28 perspective, both models require a processor agreement if personal data is involved. On-premises infrastructure eliminates the third-party processor relationship entirely when operated by the organisation’s own staff, but introduces new risks if managed-service providers are involved in maintenance. EuroHPC hosting centres are established institutions with existing audit frameworks, ISO 27001 certifications in some cases, and experience handling research-grade sensitive data.

The DORA ICT concentration risk dimension favours a hybrid approach. A financial entity that runs initial model development on EuroHPC and fine-tuning on on-premises hardware demonstrates genuine provider diversification, which supervisors expect under Article 29. A single-provider dependency on either EuroHPC alone or a single on-premises vendor would still require mitigation documentation.

ENISA’s 2023 Threat Landscape reported that ransomware and data breaches targeting public administrations and healthcare accounted for the largest share of high-impact incidents in the EU (ENISA, 2023). This underlines that on-premises sovereignty does not automatically mean better security; organisations without mature security operations centres face higher incident risk than major supercomputing centres with dedicated infrastructure teams.

CADA, InvestAI and the Broader European AI Sovereignty Landscape

EuroHPC AI Factories do not stand alone. The CADA Cloud and AI Leadership Initiatives, launched as part of the European Commission’s broader digital sovereignty agenda, channel national and EU funding towards cloud and AI infrastructure that meets European standards. CADA sits alongside InvestAI as a demand-aggregation mechanism: it helps public-sector buyers express coordinated demand for sovereign AI capacity, which in turn justifies the capital investment in AI Gigafactory infrastructure.

The InvestAI Facility, created to mobilise both public and private investment in European AI compute, uses EuroHPC AI Gigafactories as anchor assets. For regulated buyers, this landscape creates a procurement opportunity that did not exist three years ago: access to frontier-scale GPU compute under EU jurisdiction, with standardised legal frameworks, without building a data centre. Former European Commission Executive Vice-President Margrethe Vestager stated: “EuroHPC supercomputers are world-class machines that can help European researchers and industry develop their own AI models and reduce dependency on non-European providers.”

The practical implication for CISOs and DPOs is that the decision to use EuroHPC AI Factory compute is now a mainstream compliance choice, not an experimental edge case. The regulatory infrastructure, the procurement framework and the compute capacity are converging. Organisations that delay assessment of EuroHPC as a sovereign AI compute option risk locking themselves into US hyperscaler dependencies that will become progressively harder to unwind as model weights, pipelines and workflows accumulate on foreign-controlled infrastructure.

FAQ

Does using an EuroHPC AI Factory expose training data to US jurisdiction?

No. EuroHPC AI Factory infrastructure is physically located in EU member states and governed by EU law. Unlike US hyperscalers subject to the CLOUD Act or FISA 702, EuroHPC hosts are not obliged to comply with US government access demands. However, organisations must verify that no US-parent-owned subprocessors are involved in storage or networking layers before submitting sensitive workloads.

What does Council Regulation (EU) 2026/150 change for regulated-sector applicants?

It formally extends the EuroHPC JU mandate to procure and operate AI Gigafactories: large-scale GPU clusters optimised for foundation-model training. It also introduces structured access-allocation obligations, meaning public-sector and research applicants compete for reserved compute time through a standardised process rather than ad-hoc arrangements, with defined documentation requirements for data classification and protection frameworks.

Is a GDPR Article 28 Data Processing Agreement required when using EuroHPC AI Factory compute?

Yes, whenever personal data is processed during training or inference. The hosting supercomputing centre acts as a data processor; the applicant organisation is the controller. The DPA must specify the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects involved. Organisations should request the hosting centre’s DPA template before submitting compute-time applications, and negotiate explicit clauses covering model weights and intermediate artefacts.

How does EuroHPC AI Factory compute affect DORA ICT concentration risk assessments?

Under DORA Article 29, financial entities must assess concentration risk when a critical ICT function depends on a single provider. Using EuroHPC as an AI compute provider diversifies away from US hyperscalers and can reduce concentration risk, but only if the organisation also maintains documented fallback procedures, including procedures for exporting and redeploying trained model weights, if EuroHPC access is interrupted or terminated.

Can fine-tuned model weights trained on EuroHPC remain exclusively under the organisation’s control?

Yes, provided the data processing agreement explicitly addresses model artefacts. The agreement must specify that trained weights, checkpoints and derived artefacts are the exclusive intellectual property of the applicant organisation and cannot be accessed, copied or used by the hosting centre. This contractual commitment must be backed by technical controls: encrypted storage with keys held by the applicant, hardware security module-based key management and network isolation of training job outputs.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does using an EuroHPC AI Factory expose training data to US jurisdiction?
No. EuroHPC AI Factory infrastructure is physically located in EU member states and governed by EU law. Unlike US hyperscalers subject to the CLOUD Act or FISA 702, EuroHPC hosts are not obliged to comply with US government access demands. However, organisations must still verify that no US-parent-owned subprocessors are involved in storage or networking layers.
What does Council Regulation (EU) 2026/150 change for regulated-sector applicants?
It formally extends the EuroHPC JU mandate to procure and operate AI Gigafactories, which are large-scale GPU clusters optimised for foundation-model training. It also introduces structured access-allocation obligations, meaning public-sector and research applicants compete for reserved compute time through a standardised process rather than ad-hoc arrangements.
Is a GDPR Article 28 Data Processing Agreement required when using EuroHPC AI Factory compute?
Yes, if personal data is processed during training or inference. The hosting supercomputing centre acts as a data processor and must sign a GDPR Article 28 agreement that specifies the subject matter, duration, nature and purpose of processing, the type of personal data, and the categories of data subjects. Organisations should request the DPA template before submitting compute-time applications.
How does EuroHPC AI Factory compute affect DORA ICT concentration risk assessments?
Under DORA Article 29, financial entities must assess concentration risk when a critical ICT function depends on a single provider. Using EuroHPC as a compute provider diversifies away from US hyperscalers and can reduce concentration risk on paper, but only if the organisation maintains genuine operational resilience, including documented fallback procedures if EuroHPC access is interrupted.
Can fine-tuned model weights trained on EuroHPC remain exclusively under the organisation's control?
Yes, provided the data processing agreement explicitly addresses model artefacts. The agreement should specify that trained weights, checkpoints and derived artefacts are the exclusive intellectual property of the applicant organisation and cannot be accessed, copied or used by the hosting centre or any third party. This must be backed by technical controls such as encrypted storage and key management held by the applicant.