← All articles

EU AI Sovereignty Gets Compute and a Calendar

· ozeye
sovereigntyai-actdata-sovereigntyeu-cloud

European AI sovereignty: compute infrastructure meeting regulatory timelines

Germany opened one of Europe's largest AI computing facilities in Munich on 5 February 2026, and the EU Digital Omnibus just locked in fixed compliance dates for high-risk AI systems. Sovereign AI infrastructure and binding regulation are converging at the same moment. EU companies deploying AI now face a clear choice: build on infrastructure that meets EU jurisdiction requirements, or explain why not when the audits start.

The Industrial AI Cloud: Sovereign Compute, Not Just Hardware

Deutsche Telekom's Industrial AI Cloud, built with NVIDIA and data centre partner Polarise, went live in Munich after roughly six months of construction. The numbers are significant: nearly 10,000 NVIDIA Blackwell GPUs delivering up to 0.5 exaFLOPS of compute. Telekom claims that is enough for all 450 million EU citizens to use an AI assistant simultaneously.

The technical specifications matter less than the jurisdictional ones. The facility operates under German and EU data protection rules. Data stays under European legal jurisdiction. Germany's Finance Minister Lars Klingbeil framed it as proof that "technological leadership must be at the core of Germany's future business model" and that the factory "strengthens digital sovereignty."

The project also integrates with the Deutschland Stack, combining cloud infrastructure, business software from SAP, and AI tools into a single platform. Siemens is already running parts of its SIMCenter simulation portfolio on the AI Cloud, with an executive noting it "drastically reduces simulation times." Around ten companies are live on the system.

Environmental claims follow the pattern of newer EU data centres: 100% renewable energy, river water cooling, and waste heat fed back into Munich's district heating.

The Digital Omnibus: Fixed Dates Replace Ambiguous Timelines

While Germany was building hardware, Brussels was tightening the software of regulation. The EU Digital Omnibus, which amends the AI Act, has moved through its legislative phases at speed. On 13 March 2026, the Council of the EU agreed its negotiating position. On 26 March, the European Parliament confirmed its position in plenary. Trilogue negotiations are underway, with a potential final agreement targeted for as early as 28 April.

The most consequential change: fixed application dates replace the earlier approach of linking compliance to the availability of technical standards.

Obligation Application Date
High-risk AI systems listed in the regulation (employment, education, law enforcement, biometrics, critical infrastructure) 2 December 2027
AI systems embedded in regulated products (medical devices, machinery) 2 August 2028
Watermarking requirements for AI-generated content 2 November 2026

This is not a delay. It is certainty. Organisations deploying AI in hiring, credit scoring, law enforcement, or critical infrastructure can no longer defer governance planning while waiting for harmonised standards. The dates are fixed. The compliance architecture needs to be designed now, tested before the deadline, and applied consistently across systems.

What the Omnibus Changes Beyond Timelines

The Omnibus is not only about dates. Three additional shifts affect how EU companies should think about AI compliance.

Prohibited practices expand. The Parliament's position adds a ban on systems capable of generating or manipulating non-consensual intimate imagery, expanding AI Act Article 5. This is the first significant expansion of the prohibited practices list since the original text, and it targets generative AI capabilities directly.

Sensitive data for bias detection stays tightly scoped. The Commission proposed expanding the use of sensitive personal data for bias testing. The Council pushed back. Processing must remain "strictly necessary" and tied to specific risks affecting health, safety, or fundamental rights. The evidentiary threshold is high. A financial institution testing lending models for discriminatory outcomes, for instance, must demonstrate that including sensitive attributes is the only viable approach and that safeguards exist throughout the process. This interacts directly with GDPR Article 9 restrictions on processing special categories of data.

Oversight structures split between EU and national levels. The EU AI Office gains expanded supervisory authority over general-purpose AI models, but national regulators retain control over sector-specific areas like financial services, law enforcement, and critical infrastructure. For companies operating across sectors, this means reporting to multiple supervisory bodies with potentially overlapping requirements.

Why Compute Without Compliance Is Incomplete

The Industrial AI Cloud solves one half of the sovereignty equation: where compute happens and whose laws govern it. The Digital Omnibus solves the other half: when and how compliance obligations attach to AI systems.

Neither is sufficient alone. Sovereign compute running non-compliant AI systems is a regulatory risk. Compliant AI systems running on non-sovereign infrastructure is a data sovereignty risk. EU companies need both, and the timeline pressure is real. Watermarking obligations arrive in November 2026. High-risk system obligations follow in December 2027.

For teams consuming AI through APIs rather than building on bare metal, the question is simpler but no less urgent: does your inference provider operate under EU jurisdiction, process data in EU data centres, and guarantee zero data retention? If not, every API call is a potential compliance gap.

This is where infrastructure choices matter. Platforms that guarantee EU-only inference - where every provider in the network is vetted for EU incorporation, EU data centres, and EU jurisdiction - eliminate the data sovereignty question at the API layer. Combined with zero data retention guarantees, the inference supply chain becomes auditable by design. The full subprocessor list and data processing agreement should be available without an NDA.

From Policy to Operations

The convergence of sovereign compute and fixed regulation changes the planning horizon. The debate over whether EU AI regulation will slow innovation is being replaced by a more practical question: can you demonstrate compliance by the dates that are now locked in?

Companies that treat AI governance as a separate track from infrastructure procurement will find both out of sync. The watermarking deadline is seven months away. High-risk system compliance is eighteen months out. The infrastructure exists. The dates are set. The remaining variable is whether your AI supply chain - from model provider to inference endpoint to data processing agreement - is documented, auditable, and jurisdictionally consistent.

Sources