European deployment reference

EU deployment, data residency and open-weight AI.

A practical layer for teams evaluating where a model comes from, where it can run, what data leaves the EEA and which legal questions remain after self-hosting.

Direct answer: Open weights can make EU/EEA-controlled inference possible because the model can be operated on infrastructure selected by the deployer. That can reduce or avoid transfers of prompts to the original model publisher. It does not, by itself, make a system GDPR-compliant or determine AI Act obligations.
Four separate questions

Do not collapse origin, residency and compliance into one badge.

Provider origin describes the primary organization publishing the model. Data residency describes where operational data is processed or stored. Deployment location describes where the inference stack runs. Compliance depends on the concrete legal and technical context.

OpenWeightModels records these dimensions separately so a French, US, Chinese or Canadian model can be evaluated without implying where a European deployer stores prompts, RAG documents, logs or backups.

1 · Provider originWho publishes the model?
2 · Model licenseWhat rights and conditions apply?
3 · Deployment pathCan the weights run on EU/EEA infrastructure?
4 · Data flowWhere do prompts, RAG, logs and telemetry go?
Provider country

Descriptive, not decisive

A flag indicates publisher origin. It is not a statement about training-data origin, cloud region or jurisdiction of every supplier.

EU self-hosting

Infrastructure optionality

Downloadable weights can allow inference on EU/EEA hardware selected by the operator, subject to license and runtime feasibility.

GDPR

System-level assessment

Legal basis, purpose limitation, minimisation, access, deletion, security, processors and international transfers still matter.

AI Act

Role-specific obligations

Provider and deployer obligations are not determined by a model flag. General-purpose AI rules depend on the actor and use context.

Data residency

What must stay in the architecture diagram?

LayerEU/EEA questionTypical risk
Inference serverWhere do the weights execute?External API or remote GPU processing
RAG / document storeWhere are source documents and chunks stored?Sensitive content copied to another region
EmbeddingsIs embedding generation local or external?Text leaves the selected inference environment
Logs / tracesWhere are prompts, outputs and traces retained?Operational logs become a second data store
Monitoring / telemetryWhich vendors receive runtime metadata?Hidden third-party transfers
BackupsWhere are snapshots replicated?Residency differs from the primary region
Practical rule: “EU-hosted model” is not enough. Map the complete inference and data path.
Commercial use

License and deployment are different gates.

Permissive licenses such as Apache 2.0 or MIT are generally easier to integrate commercially, but the exact license text, notices, patent terms and any separate use policy remain authoritative. Custom model licenses require a model-specific review.

A technically self-hostable model can still carry contractual restrictions. Conversely, a permissively licensed model can still be deployed in a way that creates privacy, security or regulatory obligations.

EU AI Act

Open weight is not an automatic exemption.

The European Commission states that general-purpose AI model providers have documentation, copyright-policy and training-content-summary obligations, with additional obligations for models with systemic risk. The Commission's GPAI guidance entered into application from 2 August 2025.

For downstream organizations, the relevant role can differ. A company merely deploying a model internally is not automatically in the same legal position as the organization placing or significantly modifying a GPAI model on the market.

Operational checklist

Before an EU production deployment.

Identity

Pin the checkpoint

Record exact model, revision, quantization and runtime. Family names are not enough.

License

Record usage rights

Commercial use, redistribution, fine-tuning, hosted service conditions and notices.

Data

Map the full flow

Prompts, RAG, embeddings, logs, monitoring, backups and incident data.

Security

Control access

Authentication, network boundaries, encryption, patching and model-server exposure.

Governance

Document roles

Controller/processor relationships, AI Act role, responsible teams and change management.

Evidence

Keep primary sources

Model card, license, runtime documentation and dated verification records.

FAQ

Common EU deployment questions.

Does an EU model provider make a deployment GDPR compliant?

No. Provider origin may matter for procurement and sovereignty strategy, but GDPR compliance depends on the concrete processing and data flows.

Can a US or Chinese open-weight model be hosted entirely in the EU?

Technically yes, when its downloadable weights and the complete runtime stack are operated on EU/EEA infrastructure. Connected services must be assessed separately.

Does self-hosting eliminate international transfers?

Not automatically. External logging, monitoring, embeddings, backups or support services can still transfer personal data outside the EEA.

Is open weight the same as open source under EU law?

No. Weight availability is an access property. Open-source status and any AI Act treatment depend on additional conditions and the relevant legal framework.