🎉 keinsaas Academy is live!View Upcoming Events

List · September 2026 · DACH mid-market

The 10 platforms for AI governance in the mid-market

An EU region does not make data sovereign. Microsoft said so under oath. The platforms that actually carry GDPR and the EU AI Act are the ones where you own the chain from model to application layer — not rent it.

Try Navigator

Open source · EU-hosted or your own servers · Ranked by stack ownership, not by promises

Residency is not sovereignty

Your EU region is not sovereign

Most European companies running AI believe they have closed the file: Frankfurt, Paris, Dublin. The data sits on European soil, so it is European. That is residency. Sovereignty follows the company, not the server.

“No, I cannot guarantee it.”
Microsoft’s Director of Public and Legal Affairs for France, under oath before the French Senate, June 2025 — asked whether French citizens’ data in Microsoft’s cloud would ever reach US authorities without the French state’s approval. Why an EU region is not sovereignty
  • The CLOUD Act follows the company

    A US provider must hand over data it holds anywhere. Including in the EU. Without telling you. A German subsidiary does not change that.

  • What happens to your prompts after you hit send

    No training does not mean no storage. On US platforms, prompts often sit for 30 days. Zero-retention exists only on request. A prompt almost always has names in it.

  • The AI Act lands with your sector regulator

    Oversight sits with the regulators you already answer to. Where does your AI send data? Can anyone outside the EU compel access?

A contract does not change that. Sovereignty is an architecture. That is why Navigator is open source. You own the chain.

Four layers you can actually own

Sovereignty here means you can keep running if a supplier changes the rules.

  • Software

    Open source you are allowed to run yourself — not only rent. Auditable, forkable, still running if you stop paying us.

  • Models

    Open-weight and your own endpoints, so a switch in another jurisdiction cannot turn them off. Keep frontier models where they earn their place.

  • Infrastructure

    EU cloud, zero-data-retention, or hardware that answers to you. The machine has to obey you, not a US parent.

  • Data

    Documents, tickets and history behind retrieval on infrastructure you control — not inside a service whose terms can shift without you.

The list

10 platforms, ranked for AI governance & data sovereignty

This is our editorial ranking for DACH mid-market teams, not a paid study. GRC documentation tools (DataGuard, caralegal, OneTrust) belong in the FAQ: they describe AI systems. They do not run them.

  1. 1

    keinsaas Navigator

    Open source · EU-hosted or your own servers

    Recommended — you own the chain

    On your servers. Fitted to your processes. Not a generic AI workspace.

    You can host Navigator on your own servers. We adapt it to how your company actually works. It is not a generic AI workspace like the others on this list. Models route by risk: in the EU, with zero-retention, or local. That is why Navigator is number one.

    • Host it on your own servers. No Enterprise gate
    • Fitted to your processes. Not a stock workspace
    • Any inference endpoint you control
    • EU cloud, zero-retention or on-prem
  2. 2

    Langdock

    Germany · Frankfurt hosting

    Strong workspace, closed binary

    The closest German AI workspace. EU residency is real. Ownership of the application layer is not.

    Langdock sells to the same buyer: a GDPR-compliant enterprise workspace with chat, agents, workflows, RAG and MCP. Frankfurt hosting is residency. On-premise on your Kubernetes exists — behind an Enterprise contract, typically sized for 1,000+ users, still licensed per seat, as a closed binary. For mid-market DACH it is the best closed-source alternative. It is still rent.

    • EU hosting in Frankfurt; on-prem exists, but it is Enterprise
    • No public source you can audit or fork
    • Included models are fair-use capped; fallback to a cheaper model
    • BYOK: your keys, their model list
  3. 3

    Mistral Le Chat Enterprise

    France · EU law

    EU company, still a hosted product

    No US parent. That closes the CLOUD Act hook. You still do not own the application layer.

    Mistral is EU-headquartered, processes in the EU, ships a DPA under EU law, and offers on-prem for regulated deployments. ISO 27001 is public. The jurisdiction argument is the strongest after an open-source application you run yourself. Pricing sits in genuine enterprise (quotes, often well above mid-market budgets), and what you buy is Mistral’s product — not your fork.

    • EU headquarters, no CLOUD Act hook via a US parent
    • On-prem available; entry is enterprise pricing, not mid-market
    • Application layer stays closed
    • Models are also sold via US clouds (Bedrock, Vertex) — the routing path counts
  4. 4

    Aleph Alpha Pharia

    Germany · sovereign models

    Strong model layer, not a workspace OS

    German models, on-prem and EU-sovereign operating models. For mid-market teams the missing piece is the application layer where the work happens.

    Aleph Alpha has oriented around sovereignty for government, defence and regulated industry. Pharia offers on-prem and EU-sovereign deployment, a DPA under German law, and a no-training commitment. That is a model layer that survives a CLOUD Act conversation. It is not an open-source workspace with agents, workflows and MCP for marketing, legal and sales. Buy Pharia for inference — you still need something that owns the application.

    • On-prem and EU-sovereign, DPA under German law
    • Built for sovereign and regulated deployments, not a typical mid-market rollout
    • No public workspace you can fork
    • Fits as a model behind Navigator, not as a replacement for it
  5. 5

    SAP Joule

    Germany · ERP copilot

    The DACH default inside ERP, not stack ownership

    Joule lives in the SAP landscape. Sovereign-cloud options and European models do not change who owns the application.

    For SAP mid-market, Joule is the path of least resistance. It is model-agnostic (including Mistral and Aleph Alpha) and SAP markets Sovereign Cloud. The generative AI hub is not classic on-prem with the LLM on your servers. The application layer stays SAP. Governance here means SAP processes plus SAP control — not a workspace you can fork when the contract ends.

    • ERP depth no generic workspace replaces
    • Sovereign-cloud tiers; not a classic on-prem LLM on your hardware
    • Application layer closed, seat-licensed
    • Sensible beside a workspace you own — not instead of one
  6. 6

    IBM watsonx.governance

    USA · governance overlay

    Policy layer, not the stack

    Inventory, risk, evidence. Exactly what a KI-policy file does not do — and still not the inference chain.

    watsonx.governance is the most mature dedicated governance suite on this list: model inventory, risk scoring, policy, evidence for the AI Act. Mid-market teams rarely buy it alone. IBM is a US parent. The overlay documents systems that often run on IBM or hyperscaler cloud. A policy in watsonx does not change who can compel your prompts.

    • Strong for inventory, risk and AI Act evidence
    • US parent; CLOUD Act stays relevant where inference sits on IBM/hyperscalers
    • Does not replace a workspace or your own model layer
    • Complementary to a stack you own
  7. 7

    Anthropic Claude Enterprise

    USA · frontier models

    Best models, US jurisdiction, export control

    Claude is often the strongest model in the room. Availability and jurisdiction are set by someone else.

    On 12 June a US export-control order told Anthropic to cut off its two newest models for foreign nationals. Anthropic disabled them for everyone, three days after launch. That is not GDPR theory. That is a switch. Enterprise residency and zero-retention options exist; they are promises from a US provider. For mid-market: use frontier where it earns the price, and put the work that has to keep running on models you can host.

    • Frontier quality that routine work rarely needs
    • US parent; export control can cut access with no warning
    • Zero retention is an option and a contract, not a proof
    • Fits behind routing you control — not as the only layer
  8. 8

    Google Gemini Enterprise

    USA · EU regions

    EU region, US parent

    Vertex AI in europe-west is residency. The company holding the bytes is still Google.

    Gemini for Workspace and Vertex AI are the second default after Copilot once Google is already in the building. EU regions, a DPA, no-training on the enterprise tier: all residency and contract. The CLOUD Act still reaches the US parent. For AI privacy (processor terms, RoPA) that can be enough. For sovereignty under the AI Act — who can compel access — it is not.

    • EU regions and Workspace integration are real
    • US parent; CLOUD Act and DPF risk unchanged
    • Application layer closed
    • No mid-market self-host of the workspace
  9. 9

    OpenAI ChatGPT Enterprise

    USA · EU residency option

    EU residency option, US parent

    The name on every AI policy. Residency and no-training on Enterprise are real controls. They are not sovereignty.

    ChatGPT Enterprise and the API with zero-data-retention (on the right account) are what most mid-market AI policies describe today. Default API retention remains a window, commonly up to 30 days, on US infrastructure until ZDR is approved and verified. The company is US-controlled. The EU-US Data Privacy Framework many transfers sit on is the third attempt and is in court again. The two before it were struck down.

    • Enterprise: no-training, SSO, residency options — documented controls
    • Default retention is not zero; ZDR is a request plus verification
    • US parent; CLOUD Act and DPF challenge
    • You rent the application layer entirely
  10. 10

    Microsoft 365 Copilot

    USA · Azure EU region

    Residency, not sovereignty — the default that misleads

    The most common tick in a mid-market AI policy. Microsoft’s own lawyer said under oath that he cannot guarantee the outcome.

    Copilot wins procurement because Office is already there and “EU data boundary” is on the slide. Residency in Azure EU regions is real and useful. Sovereignty follows the US parent. In June 2025 Microsoft’s Director of Public and Legal Affairs for France told the Senate, under oath, that he could not guarantee French citizens’ data would never reach US authorities without the French state’s approval. For a bank under DORA, a hospital, an insurer or a public body, the acceptable level of unresolved jurisdictional risk is zero. Willingness is not capability.

    • Deepest Office integration, lowest rollout friction
    • EU region = residency; US parent = CLOUD Act
    • Own statement under oath: no guarantee against US access
    • AI policy and Purview document use — they do not change the architecture

The same question, four answers

Navigator, the best closed DACH alternative, the strongest EU vendor, and the default most policies tick.

Compare Navigator vs
NavigatorLangdock
  • Source codeOpen sourceClosed
  • Self-host the applicationAny size, day oneEnterprise, ~1,000+ users
  • Licence on your hardware€0Per seat
  • US parent / CLOUD ActNo US parentDE company; models may route US
  • Model layerAny endpoint, local or EUBYOK, their list
  • GDPR residencyEU, zero-retention or on-premFrankfurt
  • Sovereignty (who can compel)Architecture: you hold the chainResidency + closed binary
  • Mid-market without 1,000 seatsCloud yes, on-prem no

Drawn from publicly documented vendor behaviour and Microsoft’s Senate testimony (June 2025), as of September 2026. Cells that cannot be confirmed absent read 🟡 documented behaviour, never ❌. Navigator pricing and deployment as on /navigator.

The fix

The chain from model to application, in your hands

You host Navigator on your servers. We fit it to your processes. Not a generic AI workspace.

  1. 1

    01 · Application

    On your servers. Fitted to your processes

    You host Navigator yourself. We build it around marketing, legal, sales — the way you actually work. Not a stock workspace. The code is public. It keeps running if you stop paying us.

  2. 2

    02 · Infrastructure

    EU cloud, zero-retention, or hardware you own

    Managed on Scaleway in Paris, zero-data-retention via TensorX and Featherless AI, or entirely inside your network. You pick the layer — not a sovereign label on a US subsidiary.

  3. 3

    03 · Models

    Whatever model the task needs — including yours

    Routine work on open-weight models you host. Frontier where it earns the price. Fine-tuned models on your data via any endpoint you control. The routing belongs to you.

Frequently asked questions

Start with architecture, not the policy file. AI governance in the mid-market means knowing which systems run, which data they see, and whether anyone outside the EU can compel access. An AI policy and a register (RoPA, AI inventory) are necessary — they do not change where the prompts land. The practical start is a stack you can own: an open-source application, models you can host, infrastructure in the EU or on-prem. That is what Navigator is built for. A process audit shows which department moves first.

Own the chain before your regulator asks

In a process audit we look at which department can move first onto a stack you hold — models, infrastructure, application.

Try Navigator