- Home
- AI governance platforms
List · September 2026 · DACH mid-market
The 10 platforms for AI governance in the mid-market
An EU region does not make data sovereign. Microsoft said so under oath. The platforms that actually carry GDPR and the EU AI Act are the ones where you own the chain from model to application layer — not rent it.
Open source · EU-hosted or your own servers · Ranked by stack ownership, not by promises
Your stack
Rented
- ApplicationNavigator · open source
- InfrastructureEU cloud, ZDR or on-prem
- ModelsLocal, BYO or EU-routed
- CopilotClosed application
- Azure EU regionResidency, not sovereignty
- US parentCLOUD Act hooks here
An oath is not enough
Residency is not sovereignty
Your EU region is not sovereign
Most European companies running AI believe they have closed the file: Frankfurt, Paris, Dublin. The data sits on European soil, so it is European. That is residency. Sovereignty follows the company, not the server.
“No, I cannot guarantee it.”
The CLOUD Act follows the company
A US provider must hand over data it holds anywhere. Including in the EU. Without telling you. A German subsidiary does not change that.
What happens to your prompts after you hit send
No training does not mean no storage. On US platforms, prompts often sit for 30 days. Zero-retention exists only on request. A prompt almost always has names in it.
The AI Act lands with your sector regulator
Oversight sits with the regulators you already answer to. Where does your AI send data? Can anyone outside the EU compel access?
A contract does not change that. Sovereignty is an architecture. That is why Navigator is open source. You own the chain.
Four layers you can actually own
Sovereignty here means you can keep running if a supplier changes the rules.
Software
Open source you are allowed to run yourself — not only rent. Auditable, forkable, still running if you stop paying us.
Models
Open-weight and your own endpoints, so a switch in another jurisdiction cannot turn them off. Keep frontier models where they earn their place.
Infrastructure
EU cloud, zero-data-retention, or hardware that answers to you. The machine has to obey you, not a US parent.
Data
Documents, tickets and history behind retrieval on infrastructure you control — not inside a service whose terms can shift without you.
The list
10 platforms, ranked for AI governance & data sovereignty
This is our editorial ranking for DACH mid-market teams, not a paid study. GRC documentation tools (DataGuard, caralegal, OneTrust) belong in the FAQ: they describe AI systems. They do not run them.
- 1Recommended — you own the chain
keinsaas Navigator
Open source · EU-hosted or your own servers
On your servers. Fitted to your processes. Not a generic AI workspace.
You can host Navigator on your own servers. We adapt it to how your company actually works. It is not a generic AI workspace like the others on this list. Models route by risk: in the EU, with zero-retention, or local. That is why Navigator is number one.
- Host it on your own servers. No Enterprise gate
- Fitted to your processes. Not a stock workspace
- Any inference endpoint you control
- EU cloud, zero-retention or on-prem
- 2Strong workspace, closed binary
Langdock
Germany · Frankfurt hosting
The closest German AI workspace. EU residency is real. Ownership of the application layer is not.
Langdock sells to the same buyer: a GDPR-compliant enterprise workspace with chat, agents, workflows, RAG and MCP. Frankfurt hosting is residency. On-premise on your Kubernetes exists — behind an Enterprise contract, typically sized for 1,000+ users, still licensed per seat, as a closed binary. For mid-market DACH it is the best closed-source alternative. It is still rent.
- EU hosting in Frankfurt; on-prem exists, but it is Enterprise
- No public source you can audit or fork
- Included models are fair-use capped; fallback to a cheaper model
- BYOK: your keys, their model list
- 3EU company, still a hosted product
Mistral Le Chat Enterprise
France · EU law
No US parent. That closes the CLOUD Act hook. You still do not own the application layer.
Mistral is EU-headquartered, processes in the EU, ships a DPA under EU law, and offers on-prem for regulated deployments. ISO 27001 is public. The jurisdiction argument is the strongest after an open-source application you run yourself. Pricing sits in genuine enterprise (quotes, often well above mid-market budgets), and what you buy is Mistral’s product — not your fork.
- EU headquarters, no CLOUD Act hook via a US parent
- On-prem available; entry is enterprise pricing, not mid-market
- Application layer stays closed
- Models are also sold via US clouds (Bedrock, Vertex) — the routing path counts
- 4Strong model layer, not a workspace OS
Aleph Alpha Pharia
Germany · sovereign models
German models, on-prem and EU-sovereign operating models. For mid-market teams the missing piece is the application layer where the work happens.
Aleph Alpha has oriented around sovereignty for government, defence and regulated industry. Pharia offers on-prem and EU-sovereign deployment, a DPA under German law, and a no-training commitment. That is a model layer that survives a CLOUD Act conversation. It is not an open-source workspace with agents, workflows and MCP for marketing, legal and sales. Buy Pharia for inference — you still need something that owns the application.
- On-prem and EU-sovereign, DPA under German law
- Built for sovereign and regulated deployments, not a typical mid-market rollout
- No public workspace you can fork
- Fits as a model behind Navigator, not as a replacement for it
- 5The DACH default inside ERP, not stack ownership
SAP Joule
Germany · ERP copilot
Joule lives in the SAP landscape. Sovereign-cloud options and European models do not change who owns the application.
For SAP mid-market, Joule is the path of least resistance. It is model-agnostic (including Mistral and Aleph Alpha) and SAP markets Sovereign Cloud. The generative AI hub is not classic on-prem with the LLM on your servers. The application layer stays SAP. Governance here means SAP processes plus SAP control — not a workspace you can fork when the contract ends.
- ERP depth no generic workspace replaces
- Sovereign-cloud tiers; not a classic on-prem LLM on your hardware
- Application layer closed, seat-licensed
- Sensible beside a workspace you own — not instead of one
- 6Policy layer, not the stack
IBM watsonx.governance
USA · governance overlay
Inventory, risk, evidence. Exactly what a KI-policy file does not do — and still not the inference chain.
watsonx.governance is the most mature dedicated governance suite on this list: model inventory, risk scoring, policy, evidence for the AI Act. Mid-market teams rarely buy it alone. IBM is a US parent. The overlay documents systems that often run on IBM or hyperscaler cloud. A policy in watsonx does not change who can compel your prompts.
- Strong for inventory, risk and AI Act evidence
- US parent; CLOUD Act stays relevant where inference sits on IBM/hyperscalers
- Does not replace a workspace or your own model layer
- Complementary to a stack you own
- 7Best models, US jurisdiction, export control
Anthropic Claude Enterprise
USA · frontier models
Claude is often the strongest model in the room. Availability and jurisdiction are set by someone else.
On 12 June a US export-control order told Anthropic to cut off its two newest models for foreign nationals. Anthropic disabled them for everyone, three days after launch. That is not GDPR theory. That is a switch. Enterprise residency and zero-retention options exist; they are promises from a US provider. For mid-market: use frontier where it earns the price, and put the work that has to keep running on models you can host.
- Frontier quality that routine work rarely needs
- US parent; export control can cut access with no warning
- Zero retention is an option and a contract, not a proof
- Fits behind routing you control — not as the only layer
- 8EU region, US parent
Google Gemini Enterprise
USA · EU regions
Vertex AI in europe-west is residency. The company holding the bytes is still Google.
Gemini for Workspace and Vertex AI are the second default after Copilot once Google is already in the building. EU regions, a DPA, no-training on the enterprise tier: all residency and contract. The CLOUD Act still reaches the US parent. For AI privacy (processor terms, RoPA) that can be enough. For sovereignty under the AI Act — who can compel access — it is not.
- EU regions and Workspace integration are real
- US parent; CLOUD Act and DPF risk unchanged
- Application layer closed
- No mid-market self-host of the workspace
- 9EU residency option, US parent
OpenAI ChatGPT Enterprise
USA · EU residency option
The name on every AI policy. Residency and no-training on Enterprise are real controls. They are not sovereignty.
ChatGPT Enterprise and the API with zero-data-retention (on the right account) are what most mid-market AI policies describe today. Default API retention remains a window, commonly up to 30 days, on US infrastructure until ZDR is approved and verified. The company is US-controlled. The EU-US Data Privacy Framework many transfers sit on is the third attempt and is in court again. The two before it were struck down.
- Enterprise: no-training, SSO, residency options — documented controls
- Default retention is not zero; ZDR is a request plus verification
- US parent; CLOUD Act and DPF challenge
- You rent the application layer entirely
- 10Residency, not sovereignty — the default that misleads
Microsoft 365 Copilot
USA · Azure EU region
The most common tick in a mid-market AI policy. Microsoft’s own lawyer said under oath that he cannot guarantee the outcome.
Copilot wins procurement because Office is already there and “EU data boundary” is on the slide. Residency in Azure EU regions is real and useful. Sovereignty follows the US parent. In June 2025 Microsoft’s Director of Public and Legal Affairs for France told the Senate, under oath, that he could not guarantee French citizens’ data would never reach US authorities without the French state’s approval. For a bank under DORA, a hospital, an insurer or a public body, the acceptable level of unresolved jurisdictional risk is zero. Willingness is not capability.
- Deepest Office integration, lowest rollout friction
- EU region = residency; US parent = CLOUD Act
- Own statement under oath: no guarantee against US access
- AI policy and Purview document use — they do not change the architecture
The same question, four answers
Navigator, the best closed DACH alternative, the strongest EU vendor, and the default most policies tick.
| Navigator | Langdock | Mistral Enterprise | Microsoft Copilot | |
|---|---|---|---|---|
| Source code | Open source | Closed | Closed | Closed |
| Self-host the application | Any size, day one | Enterprise, ~1,000+ users | On-prem, enterprise pricing | |
| Licence on your hardware | €0 | Per seat | Contract | n/a — cloud only |
| US parent / CLOUD Act | No US parent | DE company; models may route US | FR company; check the routing path | ❌ US parent, not guaranteed under oath |
| Model layer | Any endpoint, local or EU | BYOK, their list | Mistral plus upstream, their product | Azure models |
| GDPR residency | EU, zero-retention or on-prem | Frankfurt | EU hosting | Azure EU region |
| Sovereignty (who can compel) | Architecture: you hold the chain | Residency + closed binary | EU law, hosted product | ❌ Residency, US jurisdiction |
| Mid-market without 1,000 seats | Cloud yes, on-prem no | Budget typically enterprise | Seats, not sovereignty |
- Source codeOpen sourceClosed
- Self-host the applicationAny size, day oneEnterprise, ~1,000+ users
- Licence on your hardware€0Per seat
- US parent / CLOUD ActNo US parentDE company; models may route US
- Model layerAny endpoint, local or EUBYOK, their list
- GDPR residencyEU, zero-retention or on-premFrankfurt
- Sovereignty (who can compel)Architecture: you hold the chainResidency + closed binary
- Mid-market without 1,000 seatsCloud yes, on-prem no
Drawn from publicly documented vendor behaviour and Microsoft’s Senate testimony (June 2025), as of September 2026. Cells that cannot be confirmed absent read 🟡 documented behaviour, never ❌. Navigator pricing and deployment as on /navigator.
The fix
The chain from model to application, in your hands
You host Navigator on your servers. We fit it to your processes. Not a generic AI workspace.
- 1
01 · Application
On your servers. Fitted to your processes
You host Navigator yourself. We build it around marketing, legal, sales — the way you actually work. Not a stock workspace. The code is public. It keeps running if you stop paying us.
- 2
02 · Infrastructure
EU cloud, zero-retention, or hardware you own
Managed on Scaleway in Paris, zero-data-retention via TensorX and Featherless AI, or entirely inside your network. You pick the layer — not a sovereign label on a US subsidiary.
- 3
03 · Models
Whatever model the task needs — including yours
Routine work on open-weight models you host. Frontier where it earns the price. Fine-tuned models on your data via any endpoint you control. The routing belongs to you.
Frequently asked questions
Start with architecture, not the policy file. AI governance in the mid-market means knowing which systems run, which data they see, and whether anyone outside the EU can compel access. An AI policy and a register (RoPA, AI inventory) are necessary — they do not change where the prompts land. The practical start is a stack you can own: an open-source application, models you can host, infrastructure in the EU or on-prem. That is what Navigator is built for. A process audit shows which department moves first.
Own the chain before your regulator asks
In a process audit we look at which department can move first onto a stack you hold — models, infrastructure, application.