A Paris business-law firm is about to deploy an AI email assistant to its thirty associates. The shortlisted vendor proudly announces « France region available », « GDPR-compliant », « servers in Europe ». Management is about to sign, until the CISO asks the only question that matters: under which law is the publishing company incorporated? The answer is a Californian name. The contract is put on hold.
This scene has played out dozens of times in France in 2026, inside CPA firms, HR departments of listed companies, general counsel offices of mid-cap groups, university hospitals. The common thread: a late realisation that « hosted in France » and « sovereign » are two distinct notions, often conflated in vendor brochures, almost always conflated in purchasing decisions.
This article dismantles that confusion. It distinguishes data residency (where the servers are) from data sovereignty (under which jurisdiction the processing falls), presents the four hosting configurations available for an AI email assistant, maps out the 2026 landscape of AI models hostable in France, explains the scope of the SecNumCloud label, details the Microsoft 365 and Copilot case, describes the trusted cloud (Bleu, S3ns) and delivers a vendor questionnaire in eight questions. The goal: that you never again sign a sovereign contract without being able to verify each of its building blocks.
📊 Quick answer: A France-hosted AI email assistant is not enough to guarantee sovereignty. You must check four building blocks: server location (data residency), jurisdiction applicable to the publisher (data sovereignty, CLOUD Act), hosting of the AI model itself, and security certifications (SecNumCloud from ANSSI, HDS for healthcare). The reference legal framework is the Schrems II ruling of the CJEU, 16 July 2020.
💡 Key figures — 4 hosting configurations available for an AI email assistant (100% France / France operated by US actor / Europe operated by US actor / United States end-to-end). CJEU Schrems II ruling of 16 July 2020: reference legal framework for transfers outside the EU. SecNumCloud: ANSSI cloud qualification standard, the only label requiring immunity from extraterritorial laws inconsistent with European law.
🎯 Key takeaways
- Data residency ≠ data sovereignty — server location does not determine applicable jurisdiction
- The US CLOUD Act (2018) allows, under its criteria, access to data held by a US-law operator, wherever those data physically sit
- European framework: Schrems II ruling (CJEU C-311/18, 16 July 2020)
- 4 configurations possible — only the first delivers full legal sovereignty
- AI models hostable in France in 2026: Mistral AI, Kyutai, LightOn (FR), Aleph Alpha (DE), Silo AI (FI)
- ANSSI SecNumCloud label: several qualified providers (OVHcloud, 3DS Outscale, Cloud Temple, Oodrive), trusted cloud offerings Bleu and S3ns targeting qualification
- HDS mandatory for healthcare, SecNumCloud required for OIVs (LPM) and comparable requirements for essential entities under NIS 2
- Vendor questionnaire in 8 questions — vague answers are a red flag
- Reversibility mandatory (Article 20 GDPR) — export and deletion without residual retention
📖 Table of contents
- Why the hosting question became central in 2026
- Data residency vs data sovereignty: dismantling the confusion
- The 4 possible hosting configurations for an AI email assistant
- The 2026 landscape of AI models hostable in France
- The SecNumCloud label: the only filter that truly matters
- Use cases by regulated profession
- The Microsoft 365 and Copilot case in France: what the contract says
- The trusted cloud: Bleu, S3ns and the 2026 timeline
- What happens when you click « Generate »?
- Vendor questionnaire: 8 questions to ask
- The Neston approach in practice
- Frequently asked questions (FAQ)
1. Why the hosting question became central in 2026
Three successive waves have tipped the hosting question from a technical concern for the CISO to a purchase-decision criterion at executive-committee level.
The surge of generative AI into sensitive workflows
Since 2023, large language models have entered day-to-day tools: email, office suites, CRM, HR, accounting. Unlike traditional software that processes calibrated transactional data, a generative AI reads all the content: email body, attachments, conversation history, internal notes. The data surface exposed to the vendor explodes. An AI plugin on Outlook potentially reads all of its user’s confidential correspondence — client files, negotiation notes, attorney-client exchanges, HR discussions. This exposure did not exist with a plain email client.
The volume of emails processed per organisation is now counted in hundreds of thousands per month. Every prompt sent to an AI model externalises a fragment of correspondence, under a legal regime that depends on the vendor and its infrastructure. The question is no longer abstract — it bears on real, regulated data, potentially subject to sector-specific confidentiality obligations.
The European framework is tightening
The European Union enacted the AI Act in 2024, introducing transparency and governance obligations for high-risk AI systems, including certain HR and legal use cases. In parallel, the CNIL published in 2024-2025 a series of recommendations on deploying generative AI in enterprise, with an explicit focus on international transfers and vendor selection. The NIS 2 directive, transposed into French law by law no. 2025-391 of 30 April 2025, extends comparable security and resilience requirements to a broader scope of essential and important entities, beyond the sole OIVs. Our complete GDPR guide for AI email assistants details these obligations point by point.
The rising geopolitical risk
Since 2022, the geopolitical context has tightened to the point where technological dependency on a single state has become an explicit strategic risk. The debate on « digital sovereignty » has moved out of technical circles into audit committees, executive boards and boards of directors. For a law firm, a CPA, a hospital or a strategic enterprise, the question is no longer « does it work » — it is « what happens if tomorrow the vendor’s legal regime changes, if a commercial agreement is suspended, if extraterritorial legislation is reinforced ». Sovereignty becomes a building block of the continuity plan.
2. Data residency vs data sovereignty: dismantling the confusion
Two distinct notions, two levels of guarantee, two radically different legal consequences. Conflating them is the first mistake of any enterprise AI project.
Data residency: the physical location
Data residency designates the country in which the servers that store and process the data are physically located. It can be checked on an IP address, an infrastructure invoice, a datacenter audit. A « France-hosted » service has French data residency — the servers are indeed in Roubaix, Marseille, or Paris. That guarantee is real but limited: it addresses latency, business-continuity planning and, in part, physical international transfers. It says nothing about the jurisdiction applicable to the provider.
Data sovereignty: the applicable jurisdiction
Data sovereignty designates the legal regime to which the operator of the data is subject. A service operated by a US-incorporated company can, under the criteria of the CLOUD Act, remain exposed to US disclosure orders regardless of the physical location of its servers. Concretely, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act, enacted in the United States in 2018) allows US judicial authorities to compel a US-law operator to grant access to data it holds — whether that data sits in Chicago, Dublin or Gravelines.
Three concrete examples to settle the point
- Case A — French-law company, listed with the French commercial registry, 100% European capital, servers on OVHcloud in Roubaix. French data residency, French data sovereignty. No exposure to the CLOUD Act.
- Case B — US-law company, French subsidiary, servers on the French region of a US hyperscaler. French data residency, US data sovereignty. The CLOUD Act applies via the parent company.
- Case C — French-law company, servers on an Irish region of a US hyperscaler. EU data residency, French data sovereignty for the publisher, but the underlying infrastructure remains operated by a US-law actor — an intermediate situation that requires precise contractual review.
« France-washing »: the marketing pattern to identify
France-washing designates a marketing narrative that puts French data residency forward to suggest full sovereignty, while remaining silent on the jurisdiction question. Typical formulations: « France region available », « datacenter in Paris », « data stored in Europe ». None of these commits to sovereignty. The formulation that actually commits is different: « French-incorporated company » or « immunity from extraterritorial laws inconsistent with European law » (a phrase drawn from the SecNumCloud standard).
The reference legal framework on this topic is the Schrems II ruling handed down by the Court of Justice of the European Union on 16 July 2020 (case C-311/18). This ruling invalidated the Privacy Shield between the EU and the United States, holding that US mass surveillance — of which the CLOUD Act is one of the pillars — was not compatible with the level of protection required by the GDPR. For deeper analysis, see our detailed piece on CLOUD Act risks for professional email.
3. The 4 possible hosting configurations for an AI email assistant
All offerings on the market fall into one of the four categories below. The table clarifies the essential distinction — in every cell, the question to remember is the same: under which law does the processing of your emails fall?
| Configuration | Data residency | Data sovereignty | CLOUD Act applicable? |
|---|---|---|---|
| 1. 100% France French publisher + French infrastructure (OVHcloud, Scaleway, 3DS Outscale) | France | France / EU | No |
| 2. France operated by US actor US publisher + French region of a US hyperscaler | France | United States | Yes, under the criteria of the CLOUD Act |
| 3. EU operated by US actor US publisher + European region of a US hyperscaler (Ireland, Frankfurt, Amsterdam) | European Union | United States | Yes, under the criteria of the CLOUD Act |
| 4. 100% United States US publisher + US infrastructure | United States | United States | Yes |
What the table reveals
Three configurations out of four can expose the data to the CLOUD Act. Only configuration 1 offers full French legal sovereignty. Configurations 2 and 3 are the prime targets of France-washing: commercially, they can be presented as « hosted in France » (configuration 2) or « GDPR-compliant thanks to European hosting » (configuration 3), but legally they remain equivalent to configuration 4 in the face of a US disclosure order addressed to the parent company.
The special case of « trusted cloud » offerings
A fifth configuration emerged in 2026: trusted clouds, joint ventures pairing a US technology partner with a French operator to create a French-law entity operating the partner’s technology. Two notable offerings: Bleu (Capgemini + Orange, Microsoft Azure technology) and S3ns (Thales, Google Cloud technology). These entities are incorporated under French law, with the explicit goal of satisfying the SecNumCloud requirements on extraterritorial immunity — their qualification timeline is detailed further below.
4. The 2026 landscape of AI models hostable in France
An AI email assistant rests on two distinct building blocks: the application (interface, user base, orchestration) and the AI model itself (the large language model that generates the replies). A service can have its application hosted in France but call a model hosted in the United States. This is the point most often hidden in vendor communications.
European players in generative AI
| Publisher | Country | Main models | Hosting available in France |
|---|---|---|---|
| Mistral AI | France (Paris) | Large, Small, Mixtral, Codestral | Yes — European infrastructure, La Plateforme offering |
| Kyutai | France (Paris) | Moshi (voice), research models | Yes — research lab, funded by Iliad, CMA-CGM and Eric Schmidt in a personal capacity |
| LightOn | France (Paris) | Paradigm | Yes — enterprise-focused, on-premise available |
| Aleph Alpha | Germany (Heidelberg) | Luminous, Pharia | Yes — European infrastructure, sovereignty-oriented |
| Silo AI | Finland (Helsinki) | Poro, Viking (multilingual models) | Yes — acquired by AMD in July 2024, still EU-operated |
The Mistral AI specificity
Mistral AI is today the French reference on LLMs. The company delivers its models via an API hosted in the European Union, with contractual commitments of non-training on customer data for enterprise offerings. The Small (7B and 8x22B) and Large models are usable for an email assistant: reply generation, thread summarisation, deadline extraction. The availability of strictly European infrastructure makes Mistral the most natural option for a sovereign AI email assistant — without being mandatory: every email-assistant publisher chooses its default model and may offer Mistral as an option.
5. The SecNumCloud label: the only filter that truly matters
Among the dozens of labels and certifications in circulation (ISO 27001, ISO 27701, SOC 2, HDS, PCI-DSS), only one explicitly embeds the sovereignty requirement: the SecNumCloud label from ANSSI.
What SecNumCloud guarantees
SecNumCloud is the qualification standard for cloud service providers published by the French National Cybersecurity Agency (ANSSI). It combines technical requirements (physical security, encryption, access management, resilience) with an explicit legal requirement: immunity from extraterritorial laws inconsistent with European law. Concretely, a provider qualified SecNumCloud cannot be compelled by a foreign law (US CLOUD Act, Chinese cybersecurity law, etc.) to disclose customer data.
SecNumCloud-qualified providers in 2026
Several French providers are qualified SecNumCloud on all or part of their offerings. Among the best-known actors:
- OVHcloud — Hosted Private Cloud SecNumCloud offering, reference hosting provider for sensitive application infrastructure
- 3DS Outscale (subsidiary of Dassault Systèmes) — French pioneer of SecNumCloud qualification
- Cloud Temple — sensitive-data specialist, present at many OIVs and administrations
- Oodrive — historical secure file-sharing vendor, certified on its collaborative solutions
Other actors, notably driven by the NumSpot initiative (Docaposte, Bouygues Telecom, Dassault Systèmes, Banque des Territoires), Worldline or the « trusted cloud » projects presented below, are engaged in qualification work on a 2026-2027 horizon. The official list of qualified providers and their exact scopes — qualification of the IS, of a specific service, or of a hosting region — is published on the ANSSI website and evolves regularly. Every purchase decision must rely on that up-to-date list rather than on any isolated commercial communication.
SecNumCloud and HDS: two standards often combined
For projects touching healthcare, the sought-after combination is HDS + SecNumCloud: HDS for the legal obligation on health data, SecNumCloud for legal sovereignty. Several French hosters today hold both qualifications, including OVHcloud, 3DS Outscale and Cloud Temple. This dual qualification considerably simplifies healthcare projects seeking to combine legal obligation and legal sovereignty within a single hoster.
💡 Bottom line — SecNumCloud is the only French standard that combines technical security and extraterritorial immunity requirements. For processing data covered by professional secrecy or by a legal sovereignty obligation, it is the first-level filter. The official list of qualified providers is published by ANSSI.
6. Use cases by regulated profession
Not every profession is exposed to the same level of requirement. Here is the panorama of the main use cases that make France hosting non-negotiable. Our guide on selection criteria for an AI email assistant explores each profile in depth.
Lawyers — professional secrecy and RIN
The National Internal Regulations of the French bar (RIN), published by the Conseil National des Barreaux, frames the absolute professional secrecy of the lawyer (notably at Article 2 of the RIN, which sets the principle and the scope of the secret). Using an AI email assistant subject to an extraterritorial law inconsistent with European law on client-attorney correspondence exposes to a risk of breach of professional secrecy. The CNB regularly publishes reminders on this topic, with an increasingly explicit requirement of French legal sovereignty for any tool that processes such exchanges. The list of recommended or discouraged tools evolves — it is necessary to refer to the CNB’s up-to-date publications.
CPAs — OEC professional secrecy
The professional secrecy of the CPA is provided for in article 226-13 of the French Penal Code, supplemented by the deontological rules of the French institute of chartered accountants (OEC). Client accounting and tax data are covered. The OEC explicitly recommends resorting to sovereign cloud solutions for any automated processing of such data. An AI email assistant that processes correspondence with the clients of an accounting firm falls within this perimeter.
Healthcare — HDS and medical secrecy
The processing of personal health data is framed by article L1111-8 of the French Public Health Code. Hosting must be performed by a hoster certified HDS (Health Data Hosting), a certification issued by the Agence du Numérique en Santé (ANS). For a medical practice, a university hospital or a biology laboratory, an AI email assistant that reads correspondence containing patient information must run on HDS-certified infrastructure. The HDS + SecNumCloud combination is the recommended base for demanding healthcare projects.
Defense, OIVs and essential entities — LPM and NIS 2
The Military Programming Act (LPM) requires Operators of Vital Importance (OIVs) to use SecNumCloud-qualified cloud solutions for sensitive information systems. The NIS 2 European directive, transposed into French law by law no. 2025-391 of 30 April 2025, extends comparable security, resilience and incident-notification requirements to a broader scope of essential entities and important entities — including Operators of Essential Services (OSEs) already covered by the first NIS directive. An AI email assistant deployed in these perimeters must align with these requirements. The precise regime (OIV, essential entity, important entity) determines the exact level of obligation, including on the choice of hosting.
HR — sensitive employee data
HR correspondence regularly contains special-category data under the GDPR: health, union membership, family situation, orientation. An AI email assistant on an HR mailbox must be chosen with reinforced requirements. Even if no formal France-hosting obligation applies, prudence commands preferring a sovereign configuration, in line with the privacy by design principle imposed by article 25 of the GDPR.
7. The Microsoft 365 and Copilot case in France: what the contract says
Microsoft 365 is today the dominant professional email platform in France. Understanding the sovereignty options offered by Microsoft, as well as the operating logic of its integrated AI assistant, is essential for any AI-email-assistant project in this environment. The goal of this section is factual: to describe what the contractual documents and the official documentation say, without caricature.
Advanced Data Residency
Microsoft has offered since 2023 an option called Advanced Data Residency (ADR) allowing Microsoft 365 customers to localise data at rest and certain data in processing within a specific geographic region, including France for several services. This option addresses the data residency question and improves Microsoft’s positioning on localisation. The official Microsoft Learn documentation details the exact scope of covered services and those still hosted outside the selected region.
The CLOUD Act persists at the parent-company level
Microsoft Corporation remains a US-incorporated company. The CLOUD Act therefore applies as the law of the parent company, regardless of the physical location of the data. This is a legal fact, regularly recalled by ANSSI and the CNIL in their recommendations: location alone is not enough to escape the applicability of extraterritorial laws. Microsoft publishes each year a Law Enforcement Requests Report that accounts for the volume and nature of requests received from authorities — this documentary transparency does not change the substantive legal question, but it does allow an organisation to calibrate its risk analysis.
Copilot in Outlook: what the contractual documents say
Microsoft 365 Copilot, the AI assistant integrated into Outlook and the Microsoft 365 suite, is built on Azure OpenAI infrastructure. On the data residency side, Microsoft commitments indicate that prompt and generation data may be kept within the geographic region of the tenant, with the progressive roll-out of the EU Data Boundary. On the data sovereignty side, the regime is that of the Microsoft contract (DPA, Product Terms, Online Services Terms), with the same legal considerations as the rest of Microsoft services.
Two contractual points deserve careful reading before any deployment:
- Non-training on enterprise prompts — Microsoft states in its Copilot terms that enterprise customer prompts and responses are not used to train OpenAI or Microsoft foundation models. This clause is explicit in the documentation and verifiable online.
- Exact scope of processing covered by the EU Data Boundary — not every processing is yet 100% covered by the European perimeter. The list of services and residual flows processed outside the EU is published by Microsoft and evolves with the milestones of the programme.
For an organisation without a strict sovereignty obligation (standard private sector, GDPR requirement without sector-specific constraint), Copilot may represent a pertinent option given its native integration with the Microsoft 365 ecosystem. For an organisation subject to a sovereignty obligation (OIV, NIS 2 essential entity, health data, professional secrecy), the analysis must be conducted case by case, comparing the Microsoft contract to the sector obligations. Organisations that wish to keep the Microsoft environment while satisfying a strict sovereignty requirement may turn to the Bleu offering, presented in the next section.
Coexistence of native AI assistants and third-party plugins
A point often underestimated: Copilot and a third-party email AI plugin are not mutually exclusive. An organisation may decide to activate Copilot for its general office use cases (meeting summaries, drafting assistance in Word, data analysis in Excel) and to use a distinct email AI plugin for the most sensitive correspondence, when an explicit legal sovereignty requirement applies. This two-tier architecture makes it possible to benefit from native integration while reserving the most demanding cases for a dedicated sovereign building block.
8. The trusted cloud: Bleu, S3ns and the 2026 timeline
The concept of « trusted cloud » was formalised by the French government in 2021: associating the technology of a foreign hyperscaler with a French operator, inside a French-law entity, with the explicit goal of satisfying the SecNumCloud requirements on extraterritorial immunity. Two actors embody this strategy today.
Bleu — Capgemini, Orange and Microsoft technology
Bleu is a joint venture created by Capgemini and Orange, operated under French law, leveraging Microsoft Azure technology and part of the Microsoft 365 suite under a national legal status. The announced objective is SecNumCloud qualification, with a historical target of end 2026 regularly adjusted according to the progress of the process. For an organisation that already relies extensively on the Microsoft ecosystem but faces a strict sovereignty requirement (administration, critical operator, sensitive data), Bleu represents a relatively continuous migration path compared with a full switch to another ecosystem.
S3ns — Thales and Google Cloud technology
S3ns applies a comparable scheme on the Google Cloud side: Thales and Google joint venture, French-law entity, Google Cloud technology under national operation, SecNumCloud target. The industrial scheme is comparable to that of Bleu, with a different technology partner.
What SecNumCloud qualification expects from a trusted cloud
A trusted cloud targeting SecNumCloud must demonstrate that effective control of operations and critical processes (key management, access decisions, maintenance operations) are actually exercised from French territory, by French personnel, without the possibility for the technological parent company to intervene on the data. This is the point most scrutinised by ANSSI in the review of applications, and the main element to check before selecting an offer.
Timeline and verification
The qualification timelines initially announced (end 2026 for Bleu, comparable deadlines for S3ns) are likely to be adjusted throughout the review process. The source of truth is the official list of SecNumCloud-qualified providers published by ANSSI, with the exact scope of qualification (covered services, exclusions, regions). Any organisation considering a trusted cloud offering in a sovereignty specification must verify that the qualification is actually in force at the time of choice, and on the exact required scope. A contract concluded on the sole basis of an announced qualification is a bet, not a guarantee.
9. What happens when you click « Generate »?
Understanding the exact journey of your email content at the moment of an AI generation is essential to evaluating the points of exposure. Here is the typical sequence of a modern AI email assistant.
The 6 steps of a generation
- Local extraction — the plugin reads the content of the email displayed in the email client (body, sender, thread history, any attachments).
- Prompt preparation — the content is structured into a prompt that includes context, the user’s style, and optionally the recipient profile.
- Transmission to the backend — the prompt is sent to the publisher’s application server over an encrypted connection (HTTPS/TLS).
- Call to the AI model — the application backend calls the AI model, which may be hosted at the same provider or with a third party (Mistral, OpenAI, Anthropic, Google, others).
- Generation and return — the model produces the reply, which is transmitted back to the backend, then to the plugin, then displayed in the client.
- Optional logging — depending on the publisher’s policy, all or part of the exchange may be logged for monitoring, debugging, or training.
The points of exposure to identify
Three points of exposure appear in this sequence: the application backend of the publisher (step 3), the AI model provider (step 4), and the logs (step 6). Each point may fall under a different jurisdiction. An application backend hosted in France by a US publisher can, under the criteria of the CLOUD Act, remain exposed to the disclosure orders applicable to its parent company. An AI model hosted in the United States exposes the prompt content to US jurisdiction. Logs retained for several months constitute a database of email content in their own right.
The blind spot: logs
Log retention duration is the parameter most often absent from commercial communications. A service that retains prompts and generations for 90 days for « quality of service » purposes de facto constitutes an archive of its users’ email content, with all the associated legal questions: administrator access, subpoenas, exfiltration in case of compromise. A service that practises zero retention (immediate purge after processing) eliminates that residual exposure. This information must appear explicitly in the privacy policy — if not, ask for it in writing and demand a contractual answer.
10. Vendor questionnaire: 8 questions to ask
Here is the evaluation grid to use with any AI email assistant vendor. Each question must receive a written, precise, verifiable answer. Vague formulations (« your data is secure », « we comply with GDPR ») are a red flag.
The 8 questions
- Country of incorporation of the publishing company and its parent company — this is the jurisdiction question. Expected answer: company name, legal form, registration number, country of incorporation. Verifiable in public registries (Infogreffe for France).
- Application hosting — where are the servers running the interface, user database and logs hosted? Expected answer: hoster name, precise geographic region, hoster certifications.
- AI model hosting — is the model called at generation time hosted by the same provider, or by a third party? If third party, which one and where? This is the point most often hidden.
- Security certifications — SecNumCloud, HDS, ISO 27001, ISO 27701, SOC 2. Exact scope of the certification (the whole service or a single component?), date of issuance, renewal deadline.
- Subprocessing chain — full list of subprocessors under Article 28 GDPR (hosting, monitoring, support, AI models, analytics). Each subprocessor must be identified, located and covered by a data processing agreement (DPA).
- Retention period — what is the exact retention period of processed emails, prompts and generations? The target value is zero: immediate purge after processing.
- International transfers — to which non-EU countries is the data transferred, if any? On what legal basis (standard contractual clauses, adequacy decision, binding corporate rules)? An undocumented transfer is a strong signal.
- Reversibility (Article 20 GDPR) — is there a documented procedure for a full data export in a structured format, and for total deletion without retention? Ask to see the procedure.
How to exploit the answers
A serious vendor responds to the 8 questions in writing within 48 hours, with documentary references (public privacy policy, DPA, trust center page or equivalent). A vendor that takes two weeks, that answers vaguely, or that systematically points to generic terms of use is a vendor that should not be short-listed for sensitive data. All building blocks of the privacy policy must be public and verifiable — see for example our own privacy policy.
11. The Neston approach in practice
Here, as an applied example on the 8 questions of the vendor questionnaire, is the way a French publisher of an AI email assistant can respond operationally. The goal of this section is not commercial — it is to show what precise answers must look like in front of a demanding buyer.
- Incorporation — French company registered with the Paris commercial registry, no foreign parent company, 100% French capital.
- Application hosting — application infrastructure hosted on OVHcloud, Gravelines and Roubaix datacenters (France).
- AI model hosting — default general-purpose model, called via a dedicated API with contractual commitment of non-training on customer emails. Mistral EU option available in one click to remain within a strictly European regime.
- Certifications — hoster (OVHcloud) already SecNumCloud-qualified and HDS- and ISO 27001-certified on the offerings selected. Publisher application certifications under way.
This approach illustrates one logic: each building block — company, application, model, subprocessing — is identifiable, locatable, contractualisable. That is the level of precision that must be expected from any AI email assistant vendor solicited for a deployment in a sensitive environment.
Quantify precisely your gain with a sovereign AI email assistant.
The simulator computes your annual savings based on your role, email volume and fully loaded hourly cost — result in 30 seconds.
Launch the simulator →12. Frequently asked questions (FAQ)
In short — the key points to remember
- Data residency ≠ data sovereignty — location says nothing about applicable jurisdiction
- The US CLOUD Act (2018) and the CJEU Schrems II ruling (2020) structure the legal debate
- 4 hosting configurations — only the first (100% France) delivers full legal sovereignty
- Models hostable in France in 2026: Mistral, Kyutai, LightOn (FR), Aleph Alpha (DE), Silo AI (FI)
- ANSSI SecNumCloud: several qualified providers (OVHcloud, 3DS Outscale, Cloud Temple, Oodrive), trusted cloud offerings Bleu and S3ns targeting qualification
- HDS mandatory for healthcare, SecNumCloud required for OIVs (LPM), comparable requirements for essential entities under NIS 2
- Copilot in Outlook: pertinent option in standard use, to be reviewed case by case for organisations under a strict sovereignty obligation
- Vendor questionnaire in 8 questions — vague answers are a red flag
- Reversibility mandatory (Article 20 GDPR) — export and deletion without residual retention
The sovereignty of an AI email assistant is decided less on a brochure than on eight written answers. The right vendor delivers them within 48 hours, without detour, on verifiable paper. For everything covered by professional secrecy — law firms, CPAs, healthcare, HR — that rigour is not a luxury: it is the only safety net that separates real compliance from marketing display.
📚 Further reading
- Generative AI and email in 2026: the complete GDPR framework
- CLOUD Act and professional email: risks in detail
- Manifesto: our vision of digital sovereignty
- Writing professional emails with AI — selection criteria for an AI email assistant
- Generative AI for the inbox: the complete 2026 guide
- Simulator: how much can you save per year?
🔬 Sources & methodology
- ANSSI — SecNumCloud standard for cloud service providers — official publication and list of qualified providers
- CNIL — Transferring data outside the EU — legal framework for international transfers post-Schrems II
- CNIL — Artificial intelligence — recommendations for enterprise deployment of generative AI
- CJEU — Schrems II ruling (C-311/18, 16 July 2020) — reference decision on EU / US data transfers
- Mistral AI — Technology & Enterprise — models hosted in the European Union, enterprise contractual commitments
- Microsoft Learn — Advanced Data Residency — official documentation on Microsoft 365 data localisation
- Agence du Numérique en Santé — HDS certification — health data hosting
- Conseil National des Barreaux — National Internal Regulations (RIN) and deontological publications
Article published August 24, 2026 · Updated August 25, 2026 · Reading time: 18 minutes · ≈ 5,020 words