ATAILA Newsroom · Budapest · 2026-08-21

France has said it: confidential data does not go to American AI. You do not need to be a state to say the same.

Formally, the news is about a procurement decision. In substance, it is about what happens when an organisation has to prove that the confidential data entrusted to it never leaves its own jurisdiction. France has now made that a rule. A mid-sized European company gets the same question not from a minister but from a customer, an auditor or its own legal counsel — and the deadline to answer is just as short.

The article we are responding to

„Kizárták az OpenAI-t a franciák”

portfolio.hu · 2026-08-18

What the article says

According to the Hungarian business daily portfolio.hu, the French government will from now on use only sovereign artificial-intelligence providers, and explicitly excludes OpenAI from that circle. The announcement was made by budget minister David Amiel.

The article also notes the government itself deploys AI tools — to find vulnerabilities in public-administration systems, i.e. for defence.

We do not dispute the diagnosis

The sequence is the point: this decision was not born at the end of a regulatory debate but after an incident. Sovereignty stays a philosophical question until someone asks, in production, where the data is and who can reach it. After that it becomes a procurement rule with a vendor list.

We would sharpen the picture on two points.

First: an “EU region” is not the same as EU jurisdiction. The debate often ends at “the provider has a Frankfurt region”. As we lay out in our guide to GDPR-compliant AI in practice: under the 2018 US CLOUD Act, American authorities can demand data from a US-incorporated provider even when that data is stored in the EU. The French decision recognises exactly this distinction — it looks not at where the server sits, but at whose jurisdiction the operator answers to.

Second: exclusion alone is only half a solution. A state is in a comfortable position: it can appoint a national champion and close the question. A 60-person law firm, accounting practice or engineering shop cannot appoint anyone. Its real question is not what to ban, but what replaces the banned tool on Monday morning — without the team's productivity falling. Because your team already uses AI today; a ban on its own just turns that into shadow AI.

What ATAILA does

1. Sovereign infrastructure, not sovereign marketing

ATAILA Cloud runs on our own European hardware and delivers the building blocks of the big clouds: virtual machines on software-defined networks, S3-compatible object storage, Vault for credentials, a per-project container registry, monitoring and scheduled backups — with a contractual 99.9% availability commitment. Not a rented VM off a reseller price list: a sovereign environment built for production, the same one ATAILA's own operation runs on. The logic mirrors the French decision: you are not choosing a region at an American provider, you are choosing an operator that itself answers to EU jurisdiction.

2. What replaces OpenAI

Our Private ChatGPT is the part of the offer that answers this news directly. The same chat interface your team already knows — served from open-weight models on private EU GPUs that we operate. Prompts, documents, logs and embeddings stay on the platform, with no American data processor, and no model learns from your data. Every public prompt trades a little confidentiality for a little productivity; the private version keeps the productivity and removes the trade.

3. When the hardware must sit inside your walls

Some contracts and internal policies go further and require the hardware itself to be in the organisation's hands. That is what our Enterprise edition is for: the same platform, in your data centre, single-tenant — your data never leaves your own hardware. Operations are run either remotely by us or by your own team with training and support; updates and security patches come from us in both cases. Your AI, your data, your hardware — for us that is not a slogan but the definition of the edition.

4. A sovereign system still has to reach production

Sovereignty on its own is not yet a working system. Factory exists so that a full stack actually stands up from an application's description — with sandbox, dev, uat and prod environments and approval-gated, logged, rollback-able releases — and Studio so that development itself does not leak: code is written in an operated development environment, with private AI running on EU GPUs. Everyone in this market sells one slice — a GPU, a model or development. With us these arrive as a single system, and the value is in the connections.

This is not theoretical: our customer stories include a certification body that, after two years and two failed builds — roughly HUF 20 million written off — got a working, modern application at the centre of its business from us in about two months, with four real environments. At the customer's request we do not publish their name.

What we do not claim

We do not claim sovereign infrastructure protects you from data breaches. The article's own facts show it: it was not OpenAI that breached the French tax authority. Sovereignty answers where the data is and whose jurisdiction it sits under — not whether permissions are managed well, systems are patched, or intrusions get noticed. Whoever expects security from a vendor swap is solving the wrong problem. That is why the platform comes with operations, monitoring and backups, and why we say up front when an architecture also needs security work.

Nor do we claim open-weight models match the largest American closed models on every task. For many workflows — document search, extraction, drafting customer replies, coding — they are plenty; elsewhere they are not. That is worth deciding per task, and we will tell you when they are not enough for yours.

And we do not hold every certification. We design our systems for GDPR compliance, with a written data-processing agreement, but the big enterprise audit labels are still on our roadmap. If a procurement requires one today, we say so up front — not after the contract is signed.

Let's talk about it

If you have a workflow you would not dare put into public AI today — contracts, patient data, financial statements, customer documents — it is worth a conversation before an incident makes the decision for you. We do not promise a demo; we promise an honest answer on whether that workflow can be solved with private AI, and what it costs. If it is not worth it, we will say that too.

Get started →

Source: Kizárták az OpenAI-t a franciák — portfolio.hu, 2026-08-18

← Back to the Newsroom Press inquiries: contact us