EU AI Act
In shortRegulates AI risk and transparency, not location. Location becomes an issue anyway.
The AI Act sorts systems by risk: prohibited practices, high-risk systems with extensive obligations, systems carrying transparency duties, and the large remainder with no particular requirements.
The provisions phase in: prohibited practices and AI literacy duties since February 2025, obligations for general-purpose models since August 2025, with the high-risk rules following later.
What this has to do with sovereignty
Directly: nothing. The regulation tells nobody to use European models.
Indirectly: a great deal. It requires documentation of which systems are used, for what, on what data basis, and with what human oversight. And it puts obligations on deployers, not only providers.
A company that does not know which AI services its departments use cannot meet that duty. So the regulation forces exactly the inventory that makes shadow IT visible.
The practical effect
Two routes lead out of that problem. One is a ban, which does not work because the tools are reachable through a browser. The other is a provided, documented endpoint good enough that nobody goes around it.
The second route is also the more sovereignty-friendly one: if you are providing a central endpoint anyway, you can put it at a European provider without anyone noticing in daily work.
The most common misconception
That the regulation makes AI use harder. It makes undocumented AI use harder. That is a different thing, and arguably in the company's interest regardless of the legal position.