🇫🇷 Sovereignty & GDPR

France-hosted AI email assistant: the 2026 guide

A Paris business-law firm is about to deploy an AI email assistant to its thirty associates. The shortlisted vendor proudly announces « France region available », « GDPR-compliant », « servers in Europe ». Management is about to sign, until the CISO asks the only question that matters: under which law is the publishing company incorporated? The answer is a Californian name. The contract is put on hold.

This scene has played out dozens of times in France in 2026, inside CPA firms, HR departments of listed companies, general counsel offices of mid-cap groups, university hospitals. The common thread: a late realisation that « hosted in France » and « sovereign » are two distinct notions, often conflated in vendor brochures, almost always conflated in purchasing decisions.

This article dismantles that confusion. It distinguishes data residency (where the servers are) from data sovereignty (under which jurisdiction the processing falls), presents the four hosting configurations available for an AI email assistant, maps out the 2026 landscape of AI models hostable in France, explains the scope of the SecNumCloud label, details the Microsoft 365 and Copilot case, describes the trusted cloud (Bleu, S3ns) and delivers a vendor questionnaire in eight questions. The goal: that you never again sign a sovereign contract without being able to verify each of its building blocks.

📊 Quick answer: A France-hosted AI email assistant is not enough to guarantee sovereignty. You must check four building blocks: server location (data residency), jurisdiction applicable to the publisher (data sovereignty, CLOUD Act), hosting of the AI model itself, and security certifications (SecNumCloud from ANSSI, HDS for healthcare). The reference legal framework is the Schrems II ruling of the CJEU, 16 July 2020.

💡 Key figures4 hosting configurations available for an AI email assistant (100% France / France operated by US actor / Europe operated by US actor / United States end-to-end). CJEU Schrems II ruling of 16 July 2020: reference legal framework for transfers outside the EU. SecNumCloud: ANSSI cloud qualification standard, the only label requiring immunity from extraterritorial laws inconsistent with European law.

🎯 Key takeaways

📖 Table of contents

  1. Why the hosting question became central in 2026
  2. Data residency vs data sovereignty: dismantling the confusion
  3. The 4 possible hosting configurations for an AI email assistant
  4. The 2026 landscape of AI models hostable in France
  5. The SecNumCloud label: the only filter that truly matters
  6. Use cases by regulated profession
  7. The Microsoft 365 and Copilot case in France: what the contract says
  8. The trusted cloud: Bleu, S3ns and the 2026 timeline
  9. What happens when you click « Generate »?
  10. Vendor questionnaire: 8 questions to ask
  11. The Neston approach in practice
  12. Frequently asked questions (FAQ)

1. Why the hosting question became central in 2026

Three successive waves have tipped the hosting question from a technical concern for the CISO to a purchase-decision criterion at executive-committee level.

The surge of generative AI into sensitive workflows

Since 2023, large language models have entered day-to-day tools: email, office suites, CRM, HR, accounting. Unlike traditional software that processes calibrated transactional data, a generative AI reads all the content: email body, attachments, conversation history, internal notes. The data surface exposed to the vendor explodes. An AI plugin on Outlook potentially reads all of its user’s confidential correspondence — client files, negotiation notes, attorney-client exchanges, HR discussions. This exposure did not exist with a plain email client.

The volume of emails processed per organisation is now counted in hundreds of thousands per month. Every prompt sent to an AI model externalises a fragment of correspondence, under a legal regime that depends on the vendor and its infrastructure. The question is no longer abstract — it bears on real, regulated data, potentially subject to sector-specific confidentiality obligations.

The European framework is tightening

The European Union enacted the AI Act in 2024, introducing transparency and governance obligations for high-risk AI systems, including certain HR and legal use cases. In parallel, the CNIL published in 2024-2025 a series of recommendations on deploying generative AI in enterprise, with an explicit focus on international transfers and vendor selection. The NIS 2 directive, transposed into French law by law no. 2025-391 of 30 April 2025, extends comparable security and resilience requirements to a broader scope of essential and important entities, beyond the sole OIVs. Our complete GDPR guide for AI email assistants details these obligations point by point.

The rising geopolitical risk

Since 2022, the geopolitical context has tightened to the point where technological dependency on a single state has become an explicit strategic risk. The debate on « digital sovereignty » has moved out of technical circles into audit committees, executive boards and boards of directors. For a law firm, a CPA, a hospital or a strategic enterprise, the question is no longer « does it work » — it is « what happens if tomorrow the vendor’s legal regime changes, if a commercial agreement is suspended, if extraterritorial legislation is reinforced ». Sovereignty becomes a building block of the continuity plan.

2. Data residency vs data sovereignty: dismantling the confusion

Two distinct notions, two levels of guarantee, two radically different legal consequences. Conflating them is the first mistake of any enterprise AI project.

Data residency: the physical location

Data residency designates the country in which the servers that store and process the data are physically located. It can be checked on an IP address, an infrastructure invoice, a datacenter audit. A « France-hosted » service has French data residency — the servers are indeed in Roubaix, Marseille, or Paris. That guarantee is real but limited: it addresses latency, business-continuity planning and, in part, physical international transfers. It says nothing about the jurisdiction applicable to the provider.

Data sovereignty: the applicable jurisdiction

Data sovereignty designates the legal regime to which the operator of the data is subject. A service operated by a US-incorporated company can, under the criteria of the CLOUD Act, remain exposed to US disclosure orders regardless of the physical location of its servers. Concretely, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act, enacted in the United States in 2018) allows US judicial authorities to compel a US-law operator to grant access to data it holds — whether that data sits in Chicago, Dublin or Gravelines.

Three concrete examples to settle the point

« France-washing »: the marketing pattern to identify

France-washing designates a marketing narrative that puts French data residency forward to suggest full sovereignty, while remaining silent on the jurisdiction question. Typical formulations: « France region available », « datacenter in Paris », « data stored in Europe ». None of these commits to sovereignty. The formulation that actually commits is different: « French-incorporated company » or « immunity from extraterritorial laws inconsistent with European law » (a phrase drawn from the SecNumCloud standard).

The reference legal framework on this topic is the Schrems II ruling handed down by the Court of Justice of the European Union on 16 July 2020 (case C-311/18). This ruling invalidated the Privacy Shield between the EU and the United States, holding that US mass surveillance — of which the CLOUD Act is one of the pillars — was not compatible with the level of protection required by the GDPR. For deeper analysis, see our detailed piece on CLOUD Act risks for professional email.

3. The 4 possible hosting configurations for an AI email assistant

All offerings on the market fall into one of the four categories below. The table clarifies the essential distinction — in every cell, the question to remember is the same: under which law does the processing of your emails fall?

Configuration Data residency Data sovereignty CLOUD Act applicable?
1. 100% France
French publisher + French infrastructure (OVHcloud, Scaleway, 3DS Outscale)
FranceFrance / EUNo
2. France operated by US actor
US publisher + French region of a US hyperscaler
FranceUnited StatesYes, under the criteria of the CLOUD Act
3. EU operated by US actor
US publisher + European region of a US hyperscaler (Ireland, Frankfurt, Amsterdam)
European UnionUnited StatesYes, under the criteria of the CLOUD Act
4. 100% United States
US publisher + US infrastructure
United StatesUnited StatesYes

What the table reveals

Three configurations out of four can expose the data to the CLOUD Act. Only configuration 1 offers full French legal sovereignty. Configurations 2 and 3 are the prime targets of France-washing: commercially, they can be presented as « hosted in France » (configuration 2) or « GDPR-compliant thanks to European hosting » (configuration 3), but legally they remain equivalent to configuration 4 in the face of a US disclosure order addressed to the parent company.

The special case of « trusted cloud » offerings

A fifth configuration emerged in 2026: trusted clouds, joint ventures pairing a US technology partner with a French operator to create a French-law entity operating the partner’s technology. Two notable offerings: Bleu (Capgemini + Orange, Microsoft Azure technology) and S3ns (Thales, Google Cloud technology). These entities are incorporated under French law, with the explicit goal of satisfying the SecNumCloud requirements on extraterritorial immunity — their qualification timeline is detailed further below.

4. The 2026 landscape of AI models hostable in France

An AI email assistant rests on two distinct building blocks: the application (interface, user base, orchestration) and the AI model itself (the large language model that generates the replies). A service can have its application hosted in France but call a model hosted in the United States. This is the point most often hidden in vendor communications.

European players in generative AI

Publisher Country Main models Hosting available in France
Mistral AIFrance (Paris)Large, Small, Mixtral, CodestralYes — European infrastructure, La Plateforme offering
KyutaiFrance (Paris)Moshi (voice), research modelsYes — research lab, funded by Iliad, CMA-CGM and Eric Schmidt in a personal capacity
LightOnFrance (Paris)ParadigmYes — enterprise-focused, on-premise available
Aleph AlphaGermany (Heidelberg)Luminous, PhariaYes — European infrastructure, sovereignty-oriented
Silo AIFinland (Helsinki)Poro, Viking (multilingual models)Yes — acquired by AMD in July 2024, still EU-operated

The Mistral AI specificity

Mistral AI is today the French reference on LLMs. The company delivers its models via an API hosted in the European Union, with contractual commitments of non-training on customer data for enterprise offerings. The Small (7B and 8x22B) and Large models are usable for an email assistant: reply generation, thread summarisation, deadline extraction. The availability of strictly European infrastructure makes Mistral the most natural option for a sovereign AI email assistant — without being mandatory: every email-assistant publisher chooses its default model and may offer Mistral as an option.

5. The SecNumCloud label: the only filter that truly matters

Among the dozens of labels and certifications in circulation (ISO 27001, ISO 27701, SOC 2, HDS, PCI-DSS), only one explicitly embeds the sovereignty requirement: the SecNumCloud label from ANSSI.

What SecNumCloud guarantees

SecNumCloud is the qualification standard for cloud service providers published by the French National Cybersecurity Agency (ANSSI). It combines technical requirements (physical security, encryption, access management, resilience) with an explicit legal requirement: immunity from extraterritorial laws inconsistent with European law. Concretely, a provider qualified SecNumCloud cannot be compelled by a foreign law (US CLOUD Act, Chinese cybersecurity law, etc.) to disclose customer data.

SecNumCloud-qualified providers in 2026

Several French providers are qualified SecNumCloud on all or part of their offerings. Among the best-known actors:

Other actors, notably driven by the NumSpot initiative (Docaposte, Bouygues Telecom, Dassault Systèmes, Banque des Territoires), Worldline or the « trusted cloud » projects presented below, are engaged in qualification work on a 2026-2027 horizon. The official list of qualified providers and their exact scopes — qualification of the IS, of a specific service, or of a hosting region — is published on the ANSSI website and evolves regularly. Every purchase decision must rely on that up-to-date list rather than on any isolated commercial communication.

SecNumCloud and HDS: two standards often combined

For projects touching healthcare, the sought-after combination is HDS + SecNumCloud: HDS for the legal obligation on health data, SecNumCloud for legal sovereignty. Several French hosters today hold both qualifications, including OVHcloud, 3DS Outscale and Cloud Temple. This dual qualification considerably simplifies healthcare projects seeking to combine legal obligation and legal sovereignty within a single hoster.

💡 Bottom line — SecNumCloud is the only French standard that combines technical security and extraterritorial immunity requirements. For processing data covered by professional secrecy or by a legal sovereignty obligation, it is the first-level filter. The official list of qualified providers is published by ANSSI.

6. Use cases by regulated profession

Not every profession is exposed to the same level of requirement. Here is the panorama of the main use cases that make France hosting non-negotiable. Our guide on selection criteria for an AI email assistant explores each profile in depth.

Lawyers — professional secrecy and RIN

The National Internal Regulations of the French bar (RIN), published by the Conseil National des Barreaux, frames the absolute professional secrecy of the lawyer (notably at Article 2 of the RIN, which sets the principle and the scope of the secret). Using an AI email assistant subject to an extraterritorial law inconsistent with European law on client-attorney correspondence exposes to a risk of breach of professional secrecy. The CNB regularly publishes reminders on this topic, with an increasingly explicit requirement of French legal sovereignty for any tool that processes such exchanges. The list of recommended or discouraged tools evolves — it is necessary to refer to the CNB’s up-to-date publications.

CPAs — OEC professional secrecy

The professional secrecy of the CPA is provided for in article 226-13 of the French Penal Code, supplemented by the deontological rules of the French institute of chartered accountants (OEC). Client accounting and tax data are covered. The OEC explicitly recommends resorting to sovereign cloud solutions for any automated processing of such data. An AI email assistant that processes correspondence with the clients of an accounting firm falls within this perimeter.

Healthcare — HDS and medical secrecy

The processing of personal health data is framed by article L1111-8 of the French Public Health Code. Hosting must be performed by a hoster certified HDS (Health Data Hosting), a certification issued by the Agence du Numérique en Santé (ANS). For a medical practice, a university hospital or a biology laboratory, an AI email assistant that reads correspondence containing patient information must run on HDS-certified infrastructure. The HDS + SecNumCloud combination is the recommended base for demanding healthcare projects.

Defense, OIVs and essential entities — LPM and NIS 2

The Military Programming Act (LPM) requires Operators of Vital Importance (OIVs) to use SecNumCloud-qualified cloud solutions for sensitive information systems. The NIS 2 European directive, transposed into French law by law no. 2025-391 of 30 April 2025, extends comparable security, resilience and incident-notification requirements to a broader scope of essential entities and important entities — including Operators of Essential Services (OSEs) already covered by the first NIS directive. An AI email assistant deployed in these perimeters must align with these requirements. The precise regime (OIV, essential entity, important entity) determines the exact level of obligation, including on the choice of hosting.

HR — sensitive employee data

HR correspondence regularly contains special-category data under the GDPR: health, union membership, family situation, orientation. An AI email assistant on an HR mailbox must be chosen with reinforced requirements. Even if no formal France-hosting obligation applies, prudence commands preferring a sovereign configuration, in line with the privacy by design principle imposed by article 25 of the GDPR.

7. The Microsoft 365 and Copilot case in France: what the contract says

Microsoft 365 is today the dominant professional email platform in France. Understanding the sovereignty options offered by Microsoft, as well as the operating logic of its integrated AI assistant, is essential for any AI-email-assistant project in this environment. The goal of this section is factual: to describe what the contractual documents and the official documentation say, without caricature.

Advanced Data Residency

Microsoft has offered since 2023 an option called Advanced Data Residency (ADR) allowing Microsoft 365 customers to localise data at rest and certain data in processing within a specific geographic region, including France for several services. This option addresses the data residency question and improves Microsoft’s positioning on localisation. The official Microsoft Learn documentation details the exact scope of covered services and those still hosted outside the selected region.

The CLOUD Act persists at the parent-company level

Microsoft Corporation remains a US-incorporated company. The CLOUD Act therefore applies as the law of the parent company, regardless of the physical location of the data. This is a legal fact, regularly recalled by ANSSI and the CNIL in their recommendations: location alone is not enough to escape the applicability of extraterritorial laws. Microsoft publishes each year a Law Enforcement Requests Report that accounts for the volume and nature of requests received from authorities — this documentary transparency does not change the substantive legal question, but it does allow an organisation to calibrate its risk analysis.

Copilot in Outlook: what the contractual documents say

Microsoft 365 Copilot, the AI assistant integrated into Outlook and the Microsoft 365 suite, is built on Azure OpenAI infrastructure. On the data residency side, Microsoft commitments indicate that prompt and generation data may be kept within the geographic region of the tenant, with the progressive roll-out of the EU Data Boundary. On the data sovereignty side, the regime is that of the Microsoft contract (DPA, Product Terms, Online Services Terms), with the same legal considerations as the rest of Microsoft services.

Two contractual points deserve careful reading before any deployment:

For an organisation without a strict sovereignty obligation (standard private sector, GDPR requirement without sector-specific constraint), Copilot may represent a pertinent option given its native integration with the Microsoft 365 ecosystem. For an organisation subject to a sovereignty obligation (OIV, NIS 2 essential entity, health data, professional secrecy), the analysis must be conducted case by case, comparing the Microsoft contract to the sector obligations. Organisations that wish to keep the Microsoft environment while satisfying a strict sovereignty requirement may turn to the Bleu offering, presented in the next section.

Coexistence of native AI assistants and third-party plugins

A point often underestimated: Copilot and a third-party email AI plugin are not mutually exclusive. An organisation may decide to activate Copilot for its general office use cases (meeting summaries, drafting assistance in Word, data analysis in Excel) and to use a distinct email AI plugin for the most sensitive correspondence, when an explicit legal sovereignty requirement applies. This two-tier architecture makes it possible to benefit from native integration while reserving the most demanding cases for a dedicated sovereign building block.

8. The trusted cloud: Bleu, S3ns and the 2026 timeline

The concept of « trusted cloud » was formalised by the French government in 2021: associating the technology of a foreign hyperscaler with a French operator, inside a French-law entity, with the explicit goal of satisfying the SecNumCloud requirements on extraterritorial immunity. Two actors embody this strategy today.

Bleu — Capgemini, Orange and Microsoft technology

Bleu is a joint venture created by Capgemini and Orange, operated under French law, leveraging Microsoft Azure technology and part of the Microsoft 365 suite under a national legal status. The announced objective is SecNumCloud qualification, with a historical target of end 2026 regularly adjusted according to the progress of the process. For an organisation that already relies extensively on the Microsoft ecosystem but faces a strict sovereignty requirement (administration, critical operator, sensitive data), Bleu represents a relatively continuous migration path compared with a full switch to another ecosystem.

S3ns — Thales and Google Cloud technology

S3ns applies a comparable scheme on the Google Cloud side: Thales and Google joint venture, French-law entity, Google Cloud technology under national operation, SecNumCloud target. The industrial scheme is comparable to that of Bleu, with a different technology partner.

What SecNumCloud qualification expects from a trusted cloud

A trusted cloud targeting SecNumCloud must demonstrate that effective control of operations and critical processes (key management, access decisions, maintenance operations) are actually exercised from French territory, by French personnel, without the possibility for the technological parent company to intervene on the data. This is the point most scrutinised by ANSSI in the review of applications, and the main element to check before selecting an offer.

Timeline and verification

The qualification timelines initially announced (end 2026 for Bleu, comparable deadlines for S3ns) are likely to be adjusted throughout the review process. The source of truth is the official list of SecNumCloud-qualified providers published by ANSSI, with the exact scope of qualification (covered services, exclusions, regions). Any organisation considering a trusted cloud offering in a sovereignty specification must verify that the qualification is actually in force at the time of choice, and on the exact required scope. A contract concluded on the sole basis of an announced qualification is a bet, not a guarantee.

9. What happens when you click « Generate »?

Understanding the exact journey of your email content at the moment of an AI generation is essential to evaluating the points of exposure. Here is the typical sequence of a modern AI email assistant.

The 6 steps of a generation

  1. Local extraction — the plugin reads the content of the email displayed in the email client (body, sender, thread history, any attachments).
  2. Prompt preparation — the content is structured into a prompt that includes context, the user’s style, and optionally the recipient profile.
  3. Transmission to the backend — the prompt is sent to the publisher’s application server over an encrypted connection (HTTPS/TLS).
  4. Call to the AI model — the application backend calls the AI model, which may be hosted at the same provider or with a third party (Mistral, OpenAI, Anthropic, Google, others).
  5. Generation and return — the model produces the reply, which is transmitted back to the backend, then to the plugin, then displayed in the client.
  6. Optional logging — depending on the publisher’s policy, all or part of the exchange may be logged for monitoring, debugging, or training.

The points of exposure to identify

Three points of exposure appear in this sequence: the application backend of the publisher (step 3), the AI model provider (step 4), and the logs (step 6). Each point may fall under a different jurisdiction. An application backend hosted in France by a US publisher can, under the criteria of the CLOUD Act, remain exposed to the disclosure orders applicable to its parent company. An AI model hosted in the United States exposes the prompt content to US jurisdiction. Logs retained for several months constitute a database of email content in their own right.

The blind spot: logs

Log retention duration is the parameter most often absent from commercial communications. A service that retains prompts and generations for 90 days for « quality of service » purposes de facto constitutes an archive of its users’ email content, with all the associated legal questions: administrator access, subpoenas, exfiltration in case of compromise. A service that practises zero retention (immediate purge after processing) eliminates that residual exposure. This information must appear explicitly in the privacy policy — if not, ask for it in writing and demand a contractual answer.

10. Vendor questionnaire: 8 questions to ask

Here is the evaluation grid to use with any AI email assistant vendor. Each question must receive a written, precise, verifiable answer. Vague formulations (« your data is secure », « we comply with GDPR ») are a red flag.

The 8 questions

  1. Country of incorporation of the publishing company and its parent company — this is the jurisdiction question. Expected answer: company name, legal form, registration number, country of incorporation. Verifiable in public registries (Infogreffe for France).
  2. Application hosting — where are the servers running the interface, user database and logs hosted? Expected answer: hoster name, precise geographic region, hoster certifications.
  3. AI model hosting — is the model called at generation time hosted by the same provider, or by a third party? If third party, which one and where? This is the point most often hidden.
  4. Security certifications — SecNumCloud, HDS, ISO 27001, ISO 27701, SOC 2. Exact scope of the certification (the whole service or a single component?), date of issuance, renewal deadline.
  5. Subprocessing chain — full list of subprocessors under Article 28 GDPR (hosting, monitoring, support, AI models, analytics). Each subprocessor must be identified, located and covered by a data processing agreement (DPA).
  6. Retention period — what is the exact retention period of processed emails, prompts and generations? The target value is zero: immediate purge after processing.
  7. International transfers — to which non-EU countries is the data transferred, if any? On what legal basis (standard contractual clauses, adequacy decision, binding corporate rules)? An undocumented transfer is a strong signal.
  8. Reversibility (Article 20 GDPR) — is there a documented procedure for a full data export in a structured format, and for total deletion without retention? Ask to see the procedure.

How to exploit the answers

A serious vendor responds to the 8 questions in writing within 48 hours, with documentary references (public privacy policy, DPA, trust center page or equivalent). A vendor that takes two weeks, that answers vaguely, or that systematically points to generic terms of use is a vendor that should not be short-listed for sensitive data. All building blocks of the privacy policy must be public and verifiable — see for example our own privacy policy.

11. The Neston approach in practice

Here, as an applied example on the 8 questions of the vendor questionnaire, is the way a French publisher of an AI email assistant can respond operationally. The goal of this section is not commercial — it is to show what precise answers must look like in front of a demanding buyer.

  1. Incorporation — French company registered with the Paris commercial registry, no foreign parent company, 100% French capital.
  2. Application hosting — application infrastructure hosted on OVHcloud, Gravelines and Roubaix datacenters (France).
  3. AI model hosting — default general-purpose model, called via a dedicated API with contractual commitment of non-training on customer emails. Mistral EU option available in one click to remain within a strictly European regime.
  4. Certifications — hoster (OVHcloud) already SecNumCloud-qualified and HDS- and ISO 27001-certified on the offerings selected. Publisher application certifications under way.

This approach illustrates one logic: each building block — company, application, model, subprocessing — is identifiable, locatable, contractualisable. That is the level of precision that must be expected from any AI email assistant vendor solicited for a deployment in a sensitive environment.

Quantify precisely your gain with a sovereign AI email assistant.

The simulator computes your annual savings based on your role, email volume and fully loaded hourly cost — result in 30 seconds.

Launch the simulator →

12. Frequently asked questions (FAQ)

1. Does hosting in France alone guarantee GDPR compliance?
No. Physical hosting in France resolves the data residency question (server location), but not the data sovereignty question (applicable jurisdiction). A service operated by a company incorporated under US law can, under the criteria of the CLOUD Act, remain exposed to US disclosure orders even when its servers are physically located in Roubaix or Paris. Full GDPR compliance requires both: location within the European Union AND a data controller outside the scope of extraterritorial laws inconsistent with European law, following the logic set out by the CJEU in the Schrems II ruling of 16 July 2020.
2. What exactly is data residency?
Data residency refers to the physical location of the servers that store and process the data — the country where the datacenter is located. It can be verified on an invoice, an IP address, or an infrastructure audit. It is necessary but not sufficient for sovereignty: data sovereignty adds the question of the jurisdiction applicable to the provider, which may differ from the country of hosting. A French subsidiary of a US group can, under the criteria of the CLOUD Act, remain exposed to the disclosure orders applicable to its parent company.
3. What is « France-washing » in the cloud?
France-washing refers to marketing communications that present a service as « France-hosted » or « sovereign » when only data residency is true, with legal sovereignty remaining under foreign law. The typical formulation is « France region available » or « datacenters in Paris », without mention of the publishing company or its parent. This is a factual misrepresentation: location alone is not enough to escape the CLOUD Act or a disclosure order from a third-country state.
4. Which AI models can be hosted in France in 2026?
Five players dominate the European sovereign landscape. Three French publishers: Mistral AI (Paris, Large, Small, Mixtral models), Kyutai (Paris research lab, funded by Iliad, CMA-CGM and Eric Schmidt in a personal capacity) and LightOn (Paris, Paradigm models). Two European players: Aleph Alpha (Heidelberg, Germany, Luminous models) and Silo AI (Helsinki, Finland, acquired by AMD in July 2024). These models can be called from infrastructure hosted in France or in Europe, under a strict European legal regime.
5. Is the SecNumCloud label relevant for an AI email assistant?
Yes, it is the most demanding security standard in France. Published by ANSSI, SecNumCloud imposes legal immunity from extraterritorial laws inconsistent with European law, which de facto excludes US hyperscalers from their standard offering. In 2026, several providers are SecNumCloud-qualified on all or part of their cloud offerings, including OVHcloud, 3DS Outscale, Cloud Temple and Oodrive. The label is mandatory for OIVs (operators of vital importance) and strongly recommended for sensitive data (health, defense, professional secrecy). The official up-to-date list is published on the ANSSI website.
6. Can a Microsoft AI assistant be used with a French sovereignty requirement?
Microsoft has offered since 2023 an Advanced Data Residency option that allows localization of Microsoft 365 tenant data in a European region, including France for certain services. Microsoft Corporation nonetheless remains a US-incorporated company, and therefore subject to the CLOUD Act. For organizations with a strict sovereignty requirement, the Bleu offering — a Capgemini and Orange joint venture leveraging Azure technology, operated under French law and targeting SecNumCloud qualification — broadens the palette. Exact qualification timelines must be verified with ANSSI, which publishes the official list of qualified providers.
7. Is the HDS label mandatory for an email assistant in the healthcare sector?
The HDS label (Health Data Hosting, certified by ANS) is mandatory for any service that hosts or processes personal health data. For an email assistant used by a physician, a radiology practice or a hospital, if the processed emails contain patient data, the infrastructure processing those emails (including temporarily at the moment of AI generation) must be HDS-certified. Several French hosters combine HDS and SecNumCloud, including OVHcloud, 3DS Outscale and Cloud Temple, which constitutes the reference base for healthcare projects seeking to combine legal obligation and legal sovereignty.
8. How much does French hosting cost compared to US hosting?
The gap has narrowed sharply since 2022. In 2026, French hyperscalers (OVHcloud, Scaleway) and SecNumCloud-qualified providers remain, on average, slightly more expensive than US hyperscalers on equivalent configurations, with significant variance by service. The exact differential varies from one provider to another, but remains marginal relative to the total cost of an AI email assistant subscription: on a user price of 20 to 40 euros per month, infrastructure represents less than one euro, so the gap has no noticeable impact on the final price.
9. Can an Outlook plugin be hosted in France if Outlook itself is hosted in the United States?
Yes, technically. An Outlook plugin is a third-party component that runs inside the email client and communicates with its own backend, independent of Microsoft's infrastructure. Email content does transit through Microsoft servers (since the mailbox is hosted there), but the AI processing — reply generation, model call, any storage — can be performed on French sovereign infrastructure. The plugin adds a processing layer whose jurisdiction is its own.
10. Is reversibility mandatory?
Yes, Article 20 of the GDPR establishes a right to data portability for every data subject: the ability to retrieve their data in a structured, commonly used and machine-readable format. For an AI email assistant, this means the publisher must allow you at any time to export all the data you have entrusted to it (style profile, generation history, preferences) and to delete your account without retention. The absence of a reversibility mechanism is a GDPR breach, regardless of the country of hosting.

In short — the key points to remember

The sovereignty of an AI email assistant is decided less on a brochure than on eight written answers. The right vendor delivers them within 48 hours, without detour, on verifiable paper. For everything covered by professional secrecy — law firms, CPAs, healthcare, HR — that rigour is not a luxury: it is the only safety net that separates real compliance from marketing display.

YB
Yvan Bosser
Founder of Neston · Former founder of Comptasanté (exit IK Partners 2023)
Yvan founded Comptasanté (110 employees, a healthcare-focused accounting firm), sold to the IK Partners fund in 2023. He now builds an AI email assistant embedded in Outlook, with a deliberate French sovereignty requirement. Contact: yvan@neston.fr · LinkedIn.

📚 Further reading

🔬 Sources & methodology

Article published August 24, 2026 · Updated August 25, 2026 · Reading time: 18 minutes · ≈ 5,020 words