Back
Kevin Riedl

11 min read · 21 Jun 2026
Last reviewed

Next
Made on your device, with no Instagram connection. We copy the post link for Instagram’s Link sticker.

EU Data Residency for AI APIs in 2026: Provider Guide

EU location controls for AI APIs are specific to the project, endpoint, deployment type, model, feature, and complete processing chain. OpenAI documents regional storage and processing for eligible European API projects through eu.api.openai.com. Azure and AWS tie processing location to the deployment or inference-profile type. Mistral now documents a dedicated api.eu.mistral.ai regional-inference endpoint. Self-hosting can provide direct infrastructure control, but only if every model, gateway, log, backup, support path, and subprocessor stays within the intended boundary.

This is an engineering view, not a legal opinion or vendor pitch. Claims were re-checked on 2 September 2026 and have a short shelf life. Before signing, verify storage, processing, retention, training, subprocessors, support access, transfers, and governing jurisdiction as separate contract fields.

Need an evidence-backed map of where prompts, logs, embeddings, and support data travel?

 Map My AI Data Flow

First, get the words straight

Most confusion in EU AI procurement comes from mixing up terms that mean different things. Pin these down before you compare anything.

  • Data residency is a location claim: where data physically sits. It is a convention, not a term defined in the GDPR.
  • Data sovereignty is broader than physical location and can include applicable law, provider control, access paths, keys, and operational dependency. A provider's nationality does not by itself prove that a particular disclosure law applies to particular data. The legal analysis belongs in the contract, transfer assessment, and applicable-law review, not in the word "residency."
  • Storage at rest is where your data is persisted. Processing or inference is where the GPU actually runs the call. Under GDPR Article 4(2), "processing" explicitly includes both storing and using data, so an inference call in a non-EU region is itself a processing event even if storage stays in the EU.
  • Zero data retention (ZDR) is a provider-defined control with endpoint and safety exceptions, not a universal promise that no related data exists anywhere. "No training on your data" is separate and says nothing by itself about abuse logs, application state, metadata, or support data.

The one sentence to remember: a vendor's "EU residency" label does not by itself prove EU-only inference. Some products now include both storage and processing, while others scope them separately. Verify the exact endpoint, deployment type, eligible services, retention mode, and exceptions.

The comparison at a glance

How the main options compare across common procurement dimensions. All entries were reviewed on 2 September 2026 and should be re-verified per provider, endpoint, model, and feature.

DimensionOpenAI APIAzure OpenAIMistralAWS BedrockHetzner (self-host)
EU storage at restEligible Europe-region projects, subject to supported-service and system-data exclusionsApplication state follows the resource geography and deployment documentationDepends on product, endpoint, feature, and contractDepends on selected region, service, model, and retention behaviorOnly if every storage, log, backup, and support component is configured there
EU in-region processingeu.api.openai.com for supported endpoints and modelsEU Data Zone or a supported single-region deploymentapi.eu.mistral.ai for eligible inference; control-plane and feature scope remain separateGeographic EU inference profiles for supported modelsOnly if the complete stack and operations stay in-region
No model training by defaultAPI data is excluded unless the customer opts inPrompts and outputs are not made available to OpenAI or used to train foundation modelsAPI documentation says calls are not used for training; Labs, Preview, feedback, and configured opt-ins differAWS says Bedrock inputs and outputs are not shared with model providers or used to train base modelsDepends on every model, service, telemetry, and support provider selected
Zero-retention controlApproval, amendment, endpoint eligibility, and exceptions applyModified abuse monitoring is approval-gated and feature-specificSeparate from regional inference; endpoint, plan, request, and exclusion rules applydata_retention_mode: none blocks models that require retentionMust be engineered across logs, caches, backups, observability, and support
Access constraintProject eligibility, ZDR amendment, supported endpoint and modelDeployment-type, model, region, quota, and feature availabilityEndpoint, plan, model, feature, and contractInference-profile, model, region, IAM, and retention compatibilityCapacity, software, licensing, security, and operations
Jurisdiction and disclosure analysisAssess the contracting entity, corporate control, subprocessors, support access, keys, applicable law, and transfer mechanism for the exact architecture. Headquarters alone is not a yes-or-no answer.
Ops burdenLowLow to mediumLowMediumHigh
Model qualityEvaluate the exact model and workflow on representative data. Vendor category, headquarters, or hosting model does not establish quality.

Mistral and Hetzner are EU-headquartered, while OpenAI, Microsoft, and AWS are US-headquartered. That difference can matter, but it does not decide a transfer or government-access analysis by itself. Review contracting entities, corporate control, subprocessors, support, remote access, key control, enabled features, and applicable law. Customer-managed keys can be one supplementary measure, not a complete answer.

OpenAI API

OpenAI's Europe region covers the EEA and Switzerland and documents regional storage and regional processing for supported API endpoints. Create an eligible project in that region and send traffic to https://eu.api.openai.com. For non-US regions, OpenAI currently requires approval for abuse-monitoring controls and execution of a Zero Data Retention amendment. Supported endpoints, models, tools, and snapshots differ; system data, third-party services, extended caching, background mode, tracing, and other features have separate exclusions. Use the current control table rather than treating one regional toggle as universal. API data is not used to train models by default unless the customer opts in.

Azure OpenAI

For Azure-hosted models, the deployment type controls the inference geography. Global deployments may process wherever the model is deployed. Data Zone deployments stay within the specified zone; Microsoft's EU Data Zone follows the Azure EU Data Boundary and can include EFTA locations such as Norway and Switzerland. Supported single-region deployments pin processing more narrowly. Application state remains in the resource geography, but model and feature availability varies. Batch has Global and Data Zone variants, so do not infer its route from the resource name. Check the current deployment matrix and the product terms for the exact model and service.

Mistral

Mistral is EU-headquartered and now documents three inference paths: a global endpoint with no specific inference-location commitment, api.eu.mistral.ai across multiple EU and EFTA data centers, and a US endpoint. Regional inference and zero retention are separate controls, and the regional endpoint does not make every control-plane or optional feature regional. Current API documentation says API calls are not used for model training, but Labs or Preview models, feedback, product modes, and configured opt-ins have different rules. Self-hosted and cloud-marketplace deployments follow their own complete architecture and provider terms, not the managed API's endpoint promise.

Hetzner and self-hosting

Hetzner is general-purpose infrastructure, not a managed LLM API, so you select the location, hardware, model, serving stack, gateways, storage, logs, backups, and support path. An EU server does not automatically keep the complete system in the EU or remove every third party. Hardware SKUs and capacity change, so size against current specifications and measured workload rather than fixed GPU examples. Self-hosting also makes you responsible for access control, patching, secrets, isolation, abuse handling, backups, observability, availability, and secure model updates.

If you self-host open weights, check the exact model card and license version. Mistral, Llama, Qwen, and other families use mixed licenses across releases; do not generalize a family-wide commercial right from one model. Self-hosting can improve control, but cost and quality depend on utilization, hardware, operations, workload, and the selected model.

The decision tree

Pick the first branch that matches your hard constraint, not your preference.

  1. Your policy restricts particular jurisdictions or remote-access paths. Translate that requirement into contracting-entity, corporate-control, subprocessor, support, key-management, network, logging, and disclosure-law criteria. An EU host or open-weight model alone cannot prove the complete result.
  2. You need EU storage and processing, low ops, and a US provider is acceptable with the required transfer safeguards. Compare Azure OpenAI's EU Data Zone with an eligible OpenAI Europe-region project using eu.api.openai.com. Confirm model, endpoint, retention mode, support access, and exceptions.
  3. You want an EU-headquartered managed API. Evaluate Mistral's EU regional endpoint, model coverage, pricing, zero-retention eligibility, control-plane scope, subprocessors, and optional features.
  4. You already live in AWS and want EU-contained inference. Bedrock with EU cross-region inference profiles, plus zero data retention if you need it.
  5. You have a justified self-hosting case and operating capability. Compare a complete EU-hosted stack against managed alternatives using measured workload, licensing, security, availability, staffing, and lifecycle cost.
Kevin Riedl

"Do not procure an EU label. Procure a named endpoint, deployment type, processing boundary, retention mode, subprocessor list, and exception policy. That is the evidence an architecture review can test."

Where residency fits the bigger picture

Residency is one input into a defensible EU AI system, not the whole answer. The harder problems tend to be retrieval quality, per-user permissions, evals, and cost, which we cover in our RAG production-readiness checklist for the EU. And residency sits inside a wider compliance stack of RAG data flows, GDPR, and the AI Act, which we untangle in how GDPR and the AI Act stack for a DACH SaaS. Get the residency model right early, because retrofitting data location after launch is one of the more expensive things you can do.

Residency also does not minimize the payload. Use the PII redaction pipeline for LLM prompts to compare local Presidio and Privacy Filter with cloud DLP, then keep unnecessary identifiers out of the model request in the first place.

A bought pseudonymization platform is the packaged version of that minimisation, and it raises a separate legal question: does a pseudonymization gateway take the prompt out of GDPR scope? The short answer is that it can change the model provider's status, never yours, and only against the EDPB conditions for a third-country transfer.

Mapping the data flow before choosing where anything runs is the first step in AI software development in Austria, and taking on the retrieval, permissions and evaluation layers around it is our AI enablement service. Twinsoft AI is a worked example of the production system those constraints end up shaping.

Frequently Asked Questions

Does EU data residency mean my prompts are processed in the EU?
Not by label alone. OpenAI's eligible Europe-region API projects now support both storage and processing when requests use eu.api.openai.com. Azure and AWS depend on the chosen deployment or inference profile. Verify the exact product path and its exceptions.
Is "no training on my data" the same as zero data retention?
No. No-training terms govern model improvement. Zero-retention controls govern eligible request and response content, with provider-specific endpoint, safety, metadata, application-state, and feature exceptions. Read both scopes.
Which options avoid a US parent company?
Mistral and Hetzner are EU-headquartered. Still review subprocessors and optional features because an EU parent company does not automatically mean every support or processing path stays in the EU. OpenAI, Microsoft, and AWS remain US providers even when workloads are EU-resident.
What is the EU Data Zone in Azure?
A deployment type that confines inference to the EU Data Boundary. It is distinct from the broader EU Data Boundary residency commitment, and the exact list of in-zone regions changes over time, so check the current Microsoft documentation.
Does Azure Batch stay in the EU?
Only if you use the Data Zone batch variant. Plain Batch defaults to Global processing, which may run in any Azure region worldwide.
Which Mistral endpoint keeps inference in Europe?
Mistral documents api.eu.mistral.ai for eligible inference across multiple EU and EFTA data centers. The global endpoint has no specific inference-location commitment. Review control-plane, feature, retention, and subprocessor scope separately.
What does OpenAI require for EU processing?
Use an eligible Europe-region API project and supported requests through eu.api.openai.com. OpenAI currently requires approval for abuse-monitoring controls plus a Zero Data Retention amendment for non-US residency. Coverage is not universal.
When is self-hosting on Hetzner actually worth it?
When a measured workload and risk assessment justify direct infrastructure control and the team can operate the complete stack. Include gateways, logs, backups, support, licensing, security, availability, staffing, and lifecycle cost.
Which open-weight model is cleanest for EU commercial self-hosting?
There is no family-wide answer. License terms differ by exact model and release across Mistral, Llama, Qwen, and others. Review the model card, license, acceptable-use terms, dependencies, and intended distribution.
How often does this change?
Often. These claims were checked on 2 September 2026; re-verify the provider documentation, order form, subprocessor list, and architecture before a contractual or technical commitment.

Final thoughts

EU data residency is not one switch. It is a set of testable scopes for storage, inference, application state, retention, training, support, subprocessors, transfers, keys, and jurisdiction. OpenAI, Azure, Mistral, AWS, and self-hosting each express those scopes differently.

Start with the real constraint, then record the exact project, endpoint, deployment or inference profile, model, feature set, retention mode, exceptions, contracting entity, subprocessors, and evidence date. Test the complete data flow and review it when any provider term or architecture component changes.

Production AI help

Building an AI product and worried about inference cost, architecture, or production readiness? Wavect helps founders turn AI prototypes into reliable production systems.

Explore the service path:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Kevin Riedl

11 min read · 21 Jun 2026
Last reviewed

Next

Get the next Business and regulation field note

One concise email when we publish. No tracking pixels, and no inbox filler.

Free, double opt-in, no tracking pixels.