What to check in an
EU-hosted AI agent platform.
An EU-hosted AI agent platform should keep your data, and the model calls made on it, in the EU. You should also know who operates it, which model providers it uses, which laws can reach it and how you leave. “Hosted in the EU” on its own answers only the first of those questions.
This is the checklist we would use on any vendor, us included. Ortelian is a platform plus a forward deployed team, and the platform is hosted in the EU. Where an answer applies to us, we say so at the end.
Why hosting is not enough
Hosting is one question out of six.
An agent platform is not a database you put data into. Agents read your systems, send what they read to a language model and write results back. So the data moves: to the platform, to a model provider and sometimes to the vendor’s own staff. Each step has its own location, its own operator and its own legal reach.
Under the GDPR, a processor may only bring in another processor with the controller’s written authorisation (Article 28). So the full chain should be on paper before the first agent runs. Not legal advice: involve your data protection officer or a lawyer for your own case.
01 · Where data and inference run
Where does each piece of data sit, and where is it processed?
Model providers have moved here. OpenAI introduced data residency in Europe in February 2025: API requests in European projects are handled in the region with zero data retention. Still ask which provider and which region each agent uses, because a platform can be hosted in the EU and send its model calls elsewhere.
- Data at rest
Where are your records, the agents’ working data and the logs stored? Ask for the region of each, not only the main database.
- Model calls
When an agent sends text to a language model, where does that model run? Hosting the platform in the EU does not move the model calls with it.
- Retention
Does the model provider keep prompts and outputs, and for how long? Zero data retention means requests and responses are not stored after the call.
- Backups and support
Where are backups kept, and from which countries can support staff reach your data?
02 · Who operates it
Who runs the platform, and who can see your data?
- The operator
Does the vendor host and operate the platform itself, or does it run in your cloud account or a partner’s? Each puts a different party in charge of security and access.
- People with access
Who at the vendor can see your data, and is that access logged?
- Sub-processors
Is there a written list of every sub-processor, including hosting and model providers, with their locations?
- Changes
Will you be told before a sub-processor or model provider changes, and can you object?
03 · Legal reach
Which laws can reach the data, wherever it sits?
Location is not the same as jurisdiction. The US CLOUD Act requires providers subject to US jurisdiction to disclose data in their “possession, custody, or control” in answer to a valid order, “regardless of whether” it is stored inside or outside the United States (the text, as quoted by the US Supreme Court). The US Department of Justice notes that the Act did not expand which companies US courts have jurisdiction over (DOJ white paper).
For personal data sent to the US, the European Commission’s adequacy decision for the EU-US Data Privacy Framework has applied since 10 July 2023. The EU General Court upheld it on 3 September 2025, and an appeal to the Court of Justice was filed in October 2025.
- Where the vendor is incorporated
Is the vendor, or its parent, subject to US or other non-EU jurisdiction? Ask the same of the hosting company and each model provider.
- Transfer basis
If any personal data leaves the EU, what is the legal basis: an adequacy decision, standard contractual clauses or something else?
- Government requests
Will the vendor tell you about a government request where the law allows it, and challenge one that conflicts with EU law?
04 · Model providers
Which models do the agents use, and can you change them?
- Named providers
Which model providers can each agent use, and under which terms?
- Training
Is your data excluded from model training in the contract, not only in a policy page?
- Switching
Can you move to another model provider, or limit agents to providers you approve, without rebuilding the work?
05 · Export and exit
Can you take everything with you?
The EU Data Act has applied since 12 September 2025 and makes it easier to switch between data processing services. From 12 January 2027, providers may no longer charge for switching or for data egress (European Commission). For an agent platform, the raw data is only part of what you would need to move.
- Your data
Can you export the data the platform holds, in a usable format, at any time?
- The model of your business
Can you export what was built on top of it: the ontology, the connected records and what people and agents added?
- The setup
Can you export how each agent and workflow was configured, with its history?
- The records
Can you keep the record of what each agent did, and on which sources, after you leave?
06 · Control
Can you see what each agent did, and stop it?
Hosting does not cover control. The questions in AI agent governance apply wherever the platform runs: scoped permissions, approvals for anything that leaves the company, a record of every action and evaluations that keep running. If any agent ranks, scores or allocates people, read what the EU AI Act asks of B2B companies first.
Where Ortelian fits
Where Ortelian fits, and where it may not.
Ortelian hosts and operates the platform, and it is hosted in the EU. Agents use models with zero data retention only, and your data is never used to train models. You own your data and world model and can export both, along with the full history of how your agents were set up. We agree access, model providers and data handling for each deployment before we start. The details are on the platform page.
Where it may not fit: Ortelian, Inc. is a Delaware corporation, so the jurisdiction questions above apply to us as they do to any US-incorporated vendor. If your policy requires a vendor that is not a US company, we do not meet it. Ortelian is also not a self-service product: access to the platform comes with an engagement and our team working with yours.
Questions
Questions people ask about EU-hosted AI agents.
What is an EU-hosted AI agent platform?
A platform for running AI agents where your data, and ideally the model calls made on it, are stored and processed in the EU. Check who operates it and which laws reach it as well, because the hosting location alone does not answer those.
Does EU hosting make an AI agent GDPR compliant?
No. Location helps with the rules on transfers, but the GDPR also covers the purpose of processing, sub-processors, retention and people’s rights. Those depend on how the agents are set up, not only on where they run.
Does the CLOUD Act apply to data hosted in the EU?
It can. It applies to providers subject to US jurisdiction and covers data in their possession, custody or control wherever it is stored. Whether a given vendor is subject to US jurisdiction depends on the facts, so ask each one, including us.
Can we use OpenAI models and keep data in Europe?
OpenAI offers European data residency for eligible API projects and for new ChatGPT Enterprise and Edu workspaces, introduced in February 2025. Check eligibility for the endpoints your agents actually use.
Is this legal advice?
No. It is the list we would work through with any vendor. For transfer and jurisdiction questions, involve your data protection officer or a lawyer.
Bring your data and access requirements.
On a call, we go through this list for your deployment, including where each answer applies to us.
