All Neiegkeeten

Algora · Blog

2026-09-17Luxembourg

Where your AI runs matters: cloud and data sovereignty at Algora

Algora built an agentic workstation for portfolio managers, analysts and family offices from Luxembourg, running on European infrastructure.

Use of Artificial Intelligence (AI) in the European financial sector is starting to cross the line from experiment to infrastructure. In the latest joint survey by Luxembourg's financial regulator (CSSF) and central bank (BCL), half of the 461 supervised financial institutions surveyed said they are using or planning to use AI.1

Current status of AI adoption in the Luxembourg financial sector. Source: CSSF/BCL, Thematic review on the use of AI in the Luxembourg financial sector, May 2025.
Figure 1: Current status of AI adoption in the Luxembourg financial sector. Source: CSSF/BCL, Thematic review on the use of AI in the Luxembourg financial sector, May 2025.

Behind that adoption sits a quieter shift: where the AI actually runs. In the same survey, 45% of institutions said their AI workloads run on commercial cloud, up from just 14% in the previous survey two years earlier. And the move is being pulled along by generative AI: in 75% of cases, the increase in cloud usage is linked to GenAI adoption.1

Technical infrastructure supporting AI processes. Source: CSSF/BCL, May 2025.
Figure 2: Technical infrastructure supporting AI processes. Source: CSSF/BCL, May 2025.

The industry has, in effect, already decided: AI runs in the cloud. The real questions, and the one we spent the most time on when designing Algora's infrastructure, are: whose cloud, in which jurisdiction, under which laws?

The industry's top AI concern isn't models. It's data.

When you ask financial institutions what worries them about AI, the answer is not model quality. In the CSSF/BCL survey, the top three challenges were in relation to data, its quality, protection, and governance, ahead of cybersecurity, regulatory compliance and everything else.1

Main AI challenges reported by financial institutions. Source: CSSF/BCL, May 2025.
Figure 3: Main AI challenges reported by financial institutions. Source: CSSF/BCL, May 2025.

For a platform like Algora, where users work with proprietary research, client documents and position-level data, ensuring the safety and sovereignty of this data is essential. If our users can't answer “where is my data, and who can reach it?” with confidence, nothing else we build matters. And the honest legal answer to that question is more complicated than most like to admit.

Why we chose Google Cloud, and how we use it

Here's the uncomfortable trade-off every European software company faces: The three US hyperscalers hold roughly 70% of the European cloud market, while European providers' combined share has fallen from 29% in 2017 to about 15%, even as their revenues grew.7 That dominance exists for a reason: the hyperscalers are years ahead on the infrastructure that modern AI platforms need. Managed databases, GPU availability, global networking, security tooling and certified operations, at a depth no European alternative currently matches.

Even Mistral, the company most often held up as Europe's answer to Silicon Valley, builds with Microsoft, another US hyperscaler, rather than against it. The lesson here is not that sovereignty is hopeless. The lesson is that capability and sovereignty have to be engineered together, not chosen between.

We call this pragmatic sovereignty: take the best infrastructure available anywhere, then constrain it to operate in Europe, under European rules, with layered controls, all while being honest about which risks are eliminated and which are only mitigated.

That is what we did. We chose Google Cloud Platform, configured deliberately for European operation:

  • Primary region: Frankfurt (europe-west3). Algora's workloads and client data live in Germany. That keeps data residency inside the EU, a first-class expectation of Luxembourg's outsourcing framework for supervised entities (Circular CSSF 22/806, as amended), which our financial-industry clients apply to us as their provider.9
  • EU multi-region routing for resilience. Where we use multi-region storage and routing, we use Google Cloud's EU multi-region, which is contractually defined as data centers within EU member states. Google explicitly excludes London and Zürich from it.10 Redundancy without leaving the Union.
  • No training on your data. Client data is never used to train third party models. Your research stays yours.

Is this approach future-proof?

Unlikely. In March 2018, the United States enacted the CLOUD Act (Clarifying Lawful Overseas Use of Data Act)2 which rules that any provider subject to US jurisdiction must disclose data in its “possession, custody, or control” when served with a valid US legal order, regardless of whether that data is stored inside or outside the United States (18 U.S.C. § 2713).

Read that again with European eyes. It means US jurisdiction attaches to the company, not the data center. A server in Frankfurt operated by a US provider is, legally speaking, still within reach of a US warrant. “Our data is stored in Europe” is a statement about geography, not about law.

European regulators noticed immediately. In their July 2019 joint assessment, the European Data Protection Board and the European Data Protection Supervisor concluded that unless a CLOUD Act warrant is recognised through an international agreement, the lawfulness of complying with it under the GDPR “cannot be ascertained”. In plain terms: a company handing over EU personal data directly under a US warrant would generally lack a legal basis under GDPR.3 Out of this disagreement sprung the current mechanism, the EU-US Data Privacy Framework, adopted in July 2023.5 The EU General Court upheld it in September 2025, but that ruling is now under appeal before the Court of Justice (Case C-703/25 P), decision still pending.6 We have seen this before: the Safe Harbor framework was struck down by the EU Court of Justice in 2015. Its successor, Privacy Shield, was invalidated because US surveillance law was found not to offer protection “essentially equivalent” to EU law.4

At Algora we are already preparing for any potential new US-EU rift in 2 important ways:

  • All our data and workloads are set such that they can run locally on an Algora-hosted server. To this end we have put in place a state-of-the-art architecture ensuring independence from who is hosting our workloads and avoiding being locked-in by any single cloud provider.
  • Luxembourg hosts 25% of Tier 4 data centres in Europe13 and we are in conversation with a number of local providers to ensure smooth and rapid migration when the time is right.

Why not just self-host open-source models?

We have played around with hosting the best open-source models locally, but they are simply too slow or not smart enough. In short: Performance matters too. Today, the strongest reasoning models are still commercial frontier models, and the market's revealed preference reflects that: in the CSSF/BCL survey, 75% of GenAI use cases in the Luxembourg financial sector rely solely on commercial models; only 11% use open-source models (a further 11% use both).

Commercial vs open-source models in GenAI use cases. Source: CSSF/BCL, May 2025.
Figure 4: Commercial vs open-source models in GenAI use cases. Source: CSSF/BCL, May 2025.

But this picture is moving fast. Open-source models are closing the capability gap quicker than most people expected, and for regulated European firms they open a genuinely interesting door: frontier-adjacent performance on infrastructure you fully control. Where that stands today, and what it means for European data sovereignty tomorrow, deserves its own post.

What this means for you

If you use Algora, the summary is simple:

  • We tell you honestly where the sovereignty risks lie and are already working on solutions to eliminate them.
  • Your data is stored and processed in the EU, with Frankfurt as our primary location and EU-only multi-region routing for resilience.
  • Our architecture does not depend on EU-US transfer mechanisms surviving their next court date as we can switch to an even more European setup at a moment's notice.
  • We work within Luxembourg's regulatory framework for financial-sector outsourcing and are in regular contact with the CSSF to ensure compliance.

Questions about our infrastructure or compliance setup? Talk to us at info@algora.lu.

Sources

  1. CSSF & BCL, Thematic review on the use of Artificial Intelligence in the Luxembourg financial sector, May 2025 (cssf.lu)
  2. CLOUD Act, H.R. 4943, 115th Congress, enacted 23 March 2018 (congress.gov); see also US DOJ white paper, April 2019 (justice.gov)
  3. EDPB and EDPS, Joint Response to the LIBE Committee on the impact of the US CLOUD Act, 10 July 2019 (edpb.europa.eu; legal annex, PDF)
  4. CJEU, Case C-311/18 (Schrems II), judgment of 16 July 2020 (curia.europa.eu press release)
  5. European Commission, adequacy decision for the EU-US Data Privacy Framework, 10 July 2023 (ec.europa.eu)
  6. EU General Court, Case T-553/23 (Latombe v Commission), judgment of 3 September 2025; appeal pending before the CJEU as Case C-703/25 P (iapp.org)
  7. Synergy Research Group, European cloud market data, 2024: €61bn market, European providers ~15% share vs 29% in 2017, AWS+Microsoft+Google ~70%+ (srgresearch.com)
  8. Microsoft & Mistral AI, expanded strategic partnership, 21 July 2026 (news.microsoft.com); original partnership introducing Mistral Large on Azure, February 2024 (azure.microsoft.com)
  9. Circular CSSF 22/806 on outsourcing arrangements, as amended by Circular CSSF 25/883 (cssf.lu)
  10. Google Cloud Storage locations documentation, EU multi-region definition (cloud.google.com)
  11. Google Cloud Assured Workloads, EU Data Boundary control package (cloud.google.com)
  12. T-Systems & Google Cloud sovereign cloud partnership for Germany, September 2021 (googlecloudpresscorner.com)
  13. Luxembourg for Finance, Fintech, December 2023