Two years ago, sovereign AI at a European summit was a keynote topic: stirring, vague, safely in the future. At this year's European Sovereign AI Summit in Brussels it was a procurement topic. The conversations happened in front of whiteboards, with data protection officers in the room, and the question was no longer whether Europe should run its own AI. It was which workloads are already non-compliant if it doesn't.
Assessment sat near the top of that list, and for once the regulation and the technology are pointing the same way. This is what changed, what it demands, and what we took to Brussels.
The ratchet, dated
The regulatory direction is not new; what is new is that every stage of it now has a date in the past or the near future. GDPR gave Europeans Article 22: the right not to be subject to a purely automated decision with significant effect, and the right to meaningful information about the logic involved. The EU AI Act then named the stakes plainly: systems that evaluate learning outcomes or steer access to education are high-risk under Annex III, with the full weight of the Act's obligations arriving in August 2026. The UK's Data (Use and Access) Act rewrote the domestic frame last year, and UK GDPR keeps the same Article 22 spine.
Add the direction of travel in guidance from the European Data Protection Board and the ICO, and the conclusion writes itself. A qualification marked by an offshore API, on infrastructure nobody can inspect, by a model whose reasoning nobody can reproduce, is not a grey area waiting for clarification. It is a finding waiting for an audit.
The obligations, in order
- 01 · GDPRArt 22 · automated decisions, 2018
- 02 · AI Act in forceAugust 2024
- 03 · GPAI dutiesAugust 2025
- 04 · High-risk biteseducation assessment · August 2026
- 05 · Full applicationAugust 2027
Why in-house and in-region stopped being optional
High-risk status is not a label; it is a workload. Risk management, data governance, technical documentation, human oversight, logging that survives an inspection. An institution cannot document what it cannot see, and cannot oversee what it cannot reproduce. That is the part of the Act the summit kept circling: compliance is now an architectural property. You cannot procure it as a wrapper around a system built somewhere else, on someone else's terms.
The numbers behind the urgency were on every slide in Brussels.
The stakes, as the regulation writes them
Or 7% of global turnover: the AI Act's maximum penalty tier
€35m
Evaluating learning outcomes is named high-risk, in writing
Annex III
Of European awarding organisations reviewing AI vendors for data residency this year
72%
up from 41% in 2025
When high-risk obligations apply to systems already in use
Aug 2026
What sovereign delivery actually looks like
Our position in Brussels was a working system, not a policy paper. Sokros is built in the UK, runs with zero third-party AI in the marking path, and deploys where the institution draws the boundary: UK, EU or Gulf hosting, or on-premise on the institution's own GPU floor. Every decision the pipeline records replays byte for byte, which is what Article 22's "meaningful information about the logic" looks like when you build for it from the start rather than translate it afterwards.
The choice European providers are now making
Sovereign pipeline
- Models run in-region or in-building, under the institution's own governance
- Learner work never trains a model and never leaves the drawn boundary
- Every grade replays byte for byte for a DPO, a regulator or an appeal
- Human oversight is structural: assessors sign grades, flags are signals
Offshore API marking
- Learner work crosses jurisdictions the institution cannot inspect
- Training-use terms sit in a vendor's policy page, not the contract
- The logic behind a grade is a prompt and a prayer, not a record
- Oversight means trusting the dashboard the vendor provides
Europe does not need to choose between capable AI and lawful AI. It needs to stop buying systems that force the choice.
The opening for the UK and Europe
There is a tendency to frame sovereign AI as defensive: a wall against someone else's platform. The more useful frame came from the floor in Brussels. The UK and Europe hold the densest concentration of regulated-institution expertise in the world: awarding bodies, regulators, professions that run on documented judgement. AI built to survive that scrutiny is not a consolation prize. It is the export. The institutions that get their own house in order first will sell the blueprint to everyone regulation reaches next.