Data sovereignty: training an AI without losing control of your data
Data sovereignty refers to an organization's ability to keep legal and physical control of its data: where it is stored, who can access it, which law it falls under. The challenge of sovereign AI: benefit from a collectively trained model without ever ceding that control. Confidential federated learning, the approach of Mesh (Mesh Universe), answers this natively: the data is never gathered.
Sovereign by design: your data never leaves your infrastructure.
What is data sovereignty?
Data sovereignty is an organization keeping full and complete control of its data: deciding where it is stored, which people and systems can access it, and which legal framework it is subject to. It is not only a hosting question: it is a question of control, end to end.
The topic became central with AI, because the most useful data to train a model is often the most sensitive: health records, industrial data, transactions, personal data. Sending it to a third party to train a model means losing control of it: vendor dependence, legal exposure, competitive risk. Data sovereignty asks the opposite question: how do you capture the value of AI without ever letting go of your data?
Sovereign AI: what are we talking about?
We speak of sovereign AI when an organization can train and use models without depending on a third party for access to its data or for control of its infrastructure. Three requirements come up systematically:
- Location and control of the data. The data stays where its holder decides, under the law the holder controls.
- Independence of the technical chain. No mandatory chokepoint that would see the data in the clear without its owner's consent.
- Reversibility. Being able to change host or partner without rebuilding the data asset.
Sovereignty is today a shared foundation among many European privacy tech players: it is a ticket to entry, not a singularity. The real divide is not "sovereign or not," but how you obtain a useful model without gathering the data.
Sovereign federated learning
This is where federated learning changes the game. Rather than bringing the data to a central model, you send the model to the data: each actor trains locally, on its own data, and shares only the learned parameters. The data is never gathered, copied or transferred.
Sovereignty is then not an option added on top: it is a direct consequence of the mechanism. You are sovereign because you are federated: nothing leaves. This is what we call sovereign federated learning: control of the data is preserved by construction, not by contractual promise. → see Federated learning: definition and how it works.
Is Mesh sovereign? What grounds it
Yes, by design. Here is what grounds Mesh's sovereignty, in order:
- Nothing leaves. That's the mechanism: Mesh is sovereign because it is federated. Raw data never leaves its holder's infrastructure.
- No central database. There is no warehouse where everyone's data would be gathered. No pooling: only the model weights travel.
- End-to-end encryption. The transport of the weights is end-to-end encrypted. As an option, aggregation can run inside a Secrecy enclave (French technology). Note: this is transport encryption, not computation on encrypted data.
- European hosting available. For the components that must be hosted (coordination, exchange of the weights), hosting in Europe is available and at the client's choice. Mesh imposes no host and excludes none.
- GDPR-friendly. By natively applying data minimization, the approach helps with compliance. The EDPS (TechDispatch #1/2025) notes these techniques can contribute to it, under conditions, never automatic compliance.
- French publisher. Mesh (Mesh Universe) is published in France.
Data sovereignty and the GDPR
Sovereignty and the GDPR reinforce each other, but are not the same. Keeping data with its holder natively applies minimization (no copy, no transfer, no centralization), which helps with compliance, without guaranteeing it. Final compliance depends on the concrete deployment and is assessed, case by case, with a lawyer. → details on Federated learning and the GDPR and on Confidential AI and the GDPR.
How Mesh preserves data sovereignty
Mesh is a confidential federated learning platform. Several organizations (including competitors) train a shared AI model without any data ever leaving home, and therefore without losing control of it. Three ways into the collective:
- The Collective: you join a consortium and leave with an engine trained by the group, better than yours alone.
- Data Dividend: you get paid for your data's contribution, without ever exposing it.
- Engine, Ready: you pick up an already-trained engine, to run and fine-tune at home.
FAQ: Data sovereignty
What is data sovereignty?
It's an organization's ability to keep legal and physical control of its data: deciding where it is stored, who can access it and which law it falls under. Applied to AI, it requires being able to train or use a model without ceding that control to a third party.
What is sovereign federated learning?
It's federated learning where each actor trains the model locally, on its own data, which is never gathered or copied elsewhere. Sovereignty is not an added layer: it follows from the mechanism: nothing leaves. This is the approach of Mesh (Mesh Universe).
Is Mesh sovereign?
Yes, by design: data never leaves its holder's infrastructure, there is no central database, the transport of the weights is end-to-end encrypted (as an option, aggregation can run inside a Secrecy enclave, French technology) and European hosting is available, at the client's choice. Sovereignty, however, is a foundation shared by many European players; what sets Mesh apart is confidential federated learning: the data is never gathered.
Where is data hosted with Mesh?
Raw data stays with each participant: it is neither copied nor transferred. For the components that must be hosted (coordination, exchange of encrypted weights), European hosting is available and at the client's choice. Mesh does not impose a host.
Does data sovereignty guarantee GDPR compliance?
No, not automatically. By keeping data with its holder, federated learning natively applies minimization and helps with compliance: the EDPS (TechDispatch #1/2025) notes that these techniques can contribute to it, under conditions. Final compliance depends on the deployment and must be validated, case by case, with a lawyer.
Let's see it on your data
An interactive demonstration is available on request: we'll give you access.