More and more companies ask the same question before rolling out AI: will our data really stay in Europe? Platforms like Langdock answer with EU hosting, German servers, ISO 27001 and GDPR compliance. That sounds like the safe choice, and in one important sense it is. Yet “EU-compliant” promises more than the term delivers.
What Langdock does well
To be fair: the Berlin-based Langdock GmbH is a serious product. It bundles more than forty AI models behind a single interface with governance and access controls, hosts the application on EU servers, encrypts data and, by its own account, does not use it for training. ISO 27001 and SOC 2 Type II are independently audited. There is little to fault in the craftsmanship.
Where “EU-compliant” gets blurry
The catch sits in the sub-processor list. The models run on Microsoft Azure, Google Cloud, AWS and OpenAI, all US corporations. That brings in the US CLOUD Act: a US-controlled provider can be compelled by US authorities to hand over data, no matter where the servers sit. An EU data centre changes where the data lives, not which jurisdiction can reach it in an emergency. Langdock says as much to customers quite openly: the risk is not zero, but there is no direct or automatic access. That is correct, just not the same as “ruled out”. All the more so because the legal basis for such transfers, the EU-US Data Privacy Framework, is itself on shaky legal ground in 2026.
Location is not control
In mid-2026 a second point emerged. Lawyer Martin Steiger showed via the commercial register that Langdock GmbH is 100 percent owned by a Langdock Inc. in Delaware. That does not make the company shady; a US holding is normal for venture-backed startups, and US ownership alone does not place the GmbH under the CLOUD Act. Steiger’s real criticism is transparency: anyone marketing European sovereignty should not stay silent about US control. Langdock has since responded. Co-CEO Judith Dada calls Delaware a Y Combinator requirement, the cap table “mostly European” and the CLOUD Act a known risk. The core stays the same: server location, compliance and control are three different things.
How to close the gap
The path to more sovereignty is technical, not a matter of principle. With Bring Your Own Key the models run on your own, even self-hosted keys; with your own cloud or on-premise everything stays in your environment; and instead of US models you can run European ones like Mistral or open ones like Llama on EU infrastructure. That is exactly where we come in at hundredlabs. A lot runs reliably on open models kept under your own control at Hetzner or IONOS. For sensitive data from law firms, medical practices or accounting, that is often the calmer solution.
So: really EU-compliant?
The honest answer has two parts. In the sense of the GDPR, Langdock can be run in a legally compliant way. But if “EU-compliant” is meant to say that no US jurisdiction can ever reach the data, then not in the standard configuration, and honestly with almost no tool built on US hyperscalers. The difference is not hair-splitting. It is a decision every company should make deliberately for its most sensitive data.
This article is an assessment, not legal advice.