For three years, the dominant narrative around European AI sovereignty has boiled down to one line: we finally have our champions. Mistral AI is valued in the billions of euros, deployed to a million French civil servants, and held up as proof that Europe can compete with the American giants. The trouble is that this industrial win obscures a stubborn operational reality. A joint study by Cigref and the Institut Montaigne published this summer found that 80% of European cloud spending still flows to American providers, and 70% of French data remains hosted outside EU borders. Having a homegrown model says nothing about where the data fed into it actually travels, sits, and gets processed. That confusion is worth unpacking.
The model is just one link in the chain
An AI system's sovereignty isn't decided at the moment a user types a prompt. It's decided upstream, in the infrastructure hosting the model, in the orchestration layers that prepare data before sending it off, and in the technical logs that retain a trace of every exchange. A company can perfectly well query a French model hosted on American cloud infrastructure, through an API whose metadata passes through servers subject to the Cloud Act. In that scenario, the model choice is sovereign; the data handling is not. The 2026 open-weight LLM sovereignty index from La Gazette IA makes a related point: a model's sovereignty is measured by whether it can actually be audited, hosted, and run independently. Three conditions rarely met at once by organizations that simply swap model vendors without rethinking their data architecture.
The American Cloud Act, in force since 2018, allows US authorities to compel access to data held by American companies, even when that data physically sits on European soil. Largely unknown outside specialist circles, this law quietly shapes a substantial share of French professional data flows. A law firm, an HR department, or an accounting practice feeding case files into an AI tool needs to ask a sharper question than "which model am I using?" - namely, which infrastructure does my data actually pass through, and under which jurisdiction?
Part of this imbalance also comes down to a thin market. Mistral absorbs most of the attention and funding on the French side, yet remains, on a global scale, a modest player, with roughly $400 million in annualized revenue as of 2026 - a fraction of the American giants it's up against. Outside of Cohere, a Canadian company that announced a merger with Germany's Aleph Alpha in early 2026 to form a transatlantic player, few non-American competitors carry real weight in the frontier general-purpose model segment today. Lacking a French or European alternative mature enough at the cloud and orchestration layers, the vast majority of the roughly one thousand French AI startups counted in early 2026 still build their products on AWS, Azure, or Google Cloud. Mistral is carrying the sovereign push on the model side almost single-handedly; without credible competitors across the rest of the infrastructure stack, the dependency documented by Cigref has, mechanically, little reason to recede.
This concentration around a single player is itself a resilience problem. A sovereignty strategy resting on one company, however solid, exposes the entire European ecosystem to that company's own contingencies: strategic pivots, funding pressure, a foreign takeover, or a simple shift in commercial priorities. Encouraging credible competitors to Mistral to emerge, both on the model layer and on the surrounding cloud and orchestration infrastructure, would reduce this single-point-of-failure risk while introducing competitive pressure on pricing and hosting terms - two levers that would directly benefit organizations looking to diversify suppliers without sacrificing GDPR compliance.
Hybrid approaches beat the fantasy of total autonomy
Given this, the idea of "total" sovereignty, hosting, running, and auditing everything in-house, is largely a fantasy for most organizations, particularly smaller ones that lack the resources or expertise to operate their own infrastructure. The pattern taking shape in 2026 instead looks like deliberate hybridization: mapping use cases by sensitivity level, reserving the most critical processing for sovereign environments or for methods that strip out identifying data before it ever leaves the organization's perimeter, and accepting more generic solutions for use cases that carry no real confidentiality risk.
This reframes the question entirely. It's no longer "which AI model should I choose?" but "what data am I allowed to expose, and in what form?" Data pseudonymized upstream, before it ever reaches a model's API, mechanically reduces an organization's legal and geopolitical exposure, regardless of where the model it's subsequently sent to happens to be hosted. It's a defense-in-depth logic rather than an illusory quest for digital autarky. The World Economic Forum's recent GovTech Compass pushes governments themselves toward this kind of pragmatic trade-off rather than a costly, dogmatic pursuit of sovereignty.
To conclude, one question few organizations ask head-on remains: how many have actually audited, beyond the model name printed on their contract, the real path their data takes before it reaches inference? Until that mapping exists, the debate over French AI sovereignty will stay largely symbolic - a tricolor flag planted on infrastructure whose actual location, internally, almost nobody can quite pin down.


