MICKAI®ArticlesDoes the EU AI Act or GDPR Requir…
Article · 26 August 2026

Does the EU AI Act or GDPR Require On-Premise AI?

A straight answer to a procurement myth: no rule names a deployment model, but the duties both laws impose are far easier to satisfy when the model runs inside your walls and every action is sealed to a verifiable audit record.

Author
Micky Irons
Published
26 August 2026
Follow Micky Irons
LinkedInX
EU AI ActGDPRComplianceOn-Premise AISovereign AI
Does the EU AI Act or GDPR Require On-Premise AI?

No. Neither the EU AI Act nor the GDPR requires on-premise AI. Neither text names a deployment model, and no clause in either law requires you to run AI in any particular place. If a vendor or a procurement checklist tells you the regulation mandates on-premise, that is a myth, and it is worth retiring before it shapes a purchase.

The accurate version is more useful. Both laws are deliberately technology-neutral. They set out duties: govern your data, keep records, keep a human in control, protect the information you hold. Where the model runs is left to you. What is true, and what the myth garbles, is that those duties are far easier to satisfy when the model runs inside your own walls and every action it takes is sealed to a verifiable audit record. On-premise is not required. It is simply the shortest route to the evidence the law asks for.

The short answer:

  • Neither the EU AI Act nor the GDPR mandates on-premise, cloud or any specific deployment model. Both are outcome-based and technology-neutral.
  • The EU AI Act's demanding duties for high-risk systems (data governance, record-keeping, human oversight, technical documentation) describe what you must be able to evidence, not where the compute sits.
  • The GDPR requires a lawful basis, data minimisation, appropriate security and lawful handling of international transfers. It never prescribes a server location.
  • Running the model on hardware you own does not tick a legal box by itself, but it collapses the distance between the duty and the proof.

What the EU AI Act actually requires

The EU AI Act is risk-based. Most of the heavy obligations attach to systems it classifies as high-risk, and for those it is specific. Article 9 wants a risk-management process. Article 10 wants data and data governance you can account for. Article 11 wants technical documentation. Article 12 wants record-keeping: automatic logging of events across the system's lifetime, so its operation is traceable. Article 14 wants human oversight, meaning a person who can understand the system, intervene in it and, if necessary, stop it. Article 15 wants accuracy, robustness and cybersecurity.

Read that list again and notice what is not on it: a location. Nowhere does the Act say the model must run in your building, in a particular country, or off the public internet. It regulates outcomes and evidence. The obligations phase in across 2026 and 2027, with the most demanding landing on high-risk systems, and every one of them is a question about what you can show, not about where you host.

What the GDPR actually requires

The GDPR is older and even more explicitly technology-neutral. It asks for a lawful basis for processing personal data, for data minimisation and purpose limitation under Article 5, and under Article 32 for "appropriate technical and organisational measures" to keep that data secure. Where personal data leaves the European Economic Area, Chapter V sets conditions on the transfer.

None of that says on-premise. A compliant system can run in a cloud region under the right contracts and safeguards. But the GDPR's centre of gravity is control: you must know what data you hold, why you hold it, where it goes and who can reach it. Every hop your data takes to a third party is another link in that chain that you have to document, contract for and defend. Keeping the data and the model in the same building you already control removes links rather than adding them.

Why on-premise makes the duties easier

Here is the mechanism the myth is reaching for but getting wrong. The law does not reward the location. It rewards the evidence, and location changes how hard the evidence is to produce.

  • Record-keeping (AI Act, Article 12). Logging is trivial to promise and hard to prove tamper-free when the logs live on infrastructure you do not own. When the system runs on your hardware and seals each action to an audit record you hold, the log is yours and its integrity is checkable.
  • Human oversight (Article 14). Oversight is meaningful when a named person can actually reach the system and halt it. That is straightforward when the system is in the room and answers to your controls, and more abstract when it is a shared endpoint someone else operates.
  • Data governance and security (Article 10; GDPR Articles 5 and 32). Data you never send out is data you do not have to track across borders, contract into third-party processors, or reconstruct the journey of after the fact. Minimisation and control are easier when nothing leaves.

On-premise does not satisfy these duties for you. Nothing does that automatically. What it does is shorten the distance between the obligation and the artefact that proves you met it.

How we approach it

We built Mickai, our Sovereign Intelligence Operating System (SIOS), around exactly that gap. It is designed to run offline on hardware the organisation already owns, on Poros, our sovereign inference engine, so that sensitive data never has to become someone else's network traffic. Nothing leaves the building by design.

Then we make the evidence the regulation asks for a property of the system rather than an afterthought. Every action is sealed under post-quantum cryptography to a tamper-evident, independently verifiable Offline Attestation Record (OAR). It is tamper-evident, not unbreakable: what it rules out is silent, unnoticed alteration, so when someone entitled to ask wants to know which model ran, on which machine, for a given action, you have a signed record to hand rather than a shrug. Record-keeping, traceability and a defensible account of oversight stop being paperwork you assemble under pressure and become a by-product of the system running.

That is the honest relationship between the regulation and the architecture. The EU AI Act and the GDPR do not require on-premise AI. They require you to govern data, keep records and stay in control, and a system that runs inside your walls and proves what it did is the plainest way we know to be able to show it.

Mickai is a registered UK trademark, built and held by Mickai LTD (Companies House 17166618). We hold 104 filed UK patent applications carrying 2,340 claims at the UK Intellectual Property Office under named inventor Micky Irons, on the mechanisms that make sovereignty and auditability enforceable rather than merely promised. None of this is legal advice: treat it as an engineering account of how the duties map to a design, and take formal compliance questions to your own counsel.

Frequently asked questions

Does the EU AI Act require on-premise AI?

No. The EU AI Act does not name any deployment model. It sets outcome-based duties for high-risk systems, including risk management, data governance, record-keeping, human oversight, and robustness, and it leaves where the model runs entirely to you. On-premise is not mandated. It is simply an easier way to evidence those duties.

Does the GDPR require you to keep data on-premise?

No. The GDPR is technology-neutral. It requires a lawful basis, data minimisation, appropriate security under Article 32, and lawful handling of international transfers under Chapter V. A cloud deployment can be compliant with the right safeguards. Keeping data in-house simply removes transfer and third-party links you would otherwise have to document and defend.

Where does the on-premise myth come from?

It comes from conflating the duty with the easiest way to meet it. Record-keeping, traceability, human oversight and data control are all simpler to prove when the system runs on hardware you own. People shorten "easier to comply on-premise" into "compliance requires on-premise", which neither text actually says.

If it is not required, why run AI on-premise at all?

Because it collapses the distance between an obligation and the proof of it. Data that never leaves does not have to be tracked across borders or contracted into third parties, logs you hold can be made tamper-evident, and a named person can actually reach and halt a system that is in the room. You keep control, and you keep the evidence.

Does running AI in an EU cloud region satisfy the AI Act and GDPR?

It can, with appropriate contracts, safeguards and documentation. Neither law forbids cloud. The trade-off is that each external hop adds a link you must govern, document and defend. On-premise reduces those links; EU-region cloud manages them. Both can be lawful, so the choice is one of risk and evidence, not of legal permission.

How does Mickai help satisfy these duties?

Mickai (SIOS) is designed to run offline on hardware you own, on our Poros engine, so nothing leaves the building. Every action is sealed to a tamper-evident, independently verifiable Offline Attestation Record, which turns record-keeping and traceability into a by-product of the system rather than paperwork assembled after the fact. It supports your compliance work; it is not a substitute for your own legal advice.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/does-the-eu-ai-act-require-on-premise-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles