AI for Public Sector — Sovereign Cloud and Compliance
As of 2026-09-27
What is AI for Public Sector?
EU public-sector AI now runs on a dual constraint — data residency enforced at infrastructure level plus EU AI Act high-risk obligations from 2027-12-02 (Digital Omnibus, in force since 2026-07-27) — which is exactly why sovereign stacks like SAP on Bleu and Delos Cloud exist.
What it is
AI deployment inside European public-sector organisations — ministries, health systems, tax authorities, defence-adjacent agencies — operates under a sovereignty constraint that has essentially no private-sector equivalent: data residency has to be enforced at the infrastructure level by law, not just by policy, and any AI model that influences a decision affecting a citizen may itself qualify as a high-risk system under the EU AI Act. Those two constraints together shape a distinct architecture pattern: sovereign-cloud-first SAP, with AI capability scoped to whatever can legally run inside that boundary rather than to whatever the vendor's default region happens to offer.
Why it matters
- Default BTP/Datasphere hyperscaler tenants (AWS eu-west-1, Azure West Europe) satisfy GDPR but fail French HDS and German BSI C5 requirements — a gap most standard SAP proposals miss.
- Two named sovereign joint ventures (SAP on Bleu with Capgemini/Orange; Delos Cloud with Arvato/Bertelsmann/Microsoft) map directly to France vs. Germany deployment decisions.
- Explainability is a hard requirement, not a nice-to-have: Joule agents must surface their reasoning chain for citizen-impacting decisions.
Key points
- EU public-sector AI runs under a dual constraint: data residency enforced at infrastructure level by law, plus EU AI Act obligations for systems that influence decisions about citizens.
- Default BTP and Datasphere tenants run on hyperscaler regions (AWS Ireland, Azure Netherlands) — GDPR-compliant for standard processing, not sufficient where national sovereignty rules apply.
- Sovereign stacks such as SAP on Bleu (France) or Delos Cloud (Germany) exist precisely to keep SAP workloads inside a legally recognised boundary.
- Scope AI capability to what can legally run inside that boundary, not to what the vendor's default region offers.
- Model governance under EU AI Act Art. 9-49 is a real effort line: 200-800 person-days per high-risk system — budget and schedule for it explicitly, it's not a checkbox.
- Sovereign platforms trade feature currency for legal certainty: expect Delos Cloud or SAP on Bleu to lag standard hyperscaler BTP by one to several release cycles on new AI capability.
- GDPR compliance and national hosting standards (HDS, BSI C5) are separate bars — passing one does not imply passing the other.
- Data residency and EU AI Act risk classification are two distinct problems: a system can sit entirely inside a sovereign boundary and still be an undocumented, non-compliant Annex III high-risk system.
Terms used on this page
- Agent reliability
- The consistency, cost, safety, and policy compliance of an agent across repeated runs.
- HDS (Hébergement de Données de Santé)
- French health-data hosting certification required for any platform storing or processing French health data — stricter than baseline GDPR, a gate SAP on Bleu is specifically positioned to satisfy.
- BSI C5
- German Federal Office for Information Security (BSI) Cloud Computing Compliance Criteria Catalogue — an attestation standard German public bodies require for certain cloud workload classifications; satisfied via Azure Germany or Delos Cloud, not by a default hyperscaler region alone.
- ANSSI
- Agence nationale de la sécurité des systèmes d'information — the French national cybersecurity agency whose requirements SAP on Bleu is aligned to for French public-sector and health-data workloads.
- Sovereign cloud
- A cloud deployment operated under a jurisdiction's own legal, personnel and infrastructure controls, so that data residency and government-access rules are enforced technically and organisationally, not just contractually.
- Annex III (EU AI Act)
- The list of high-risk AI system use cases in the EU AI Act — including systems that influence decisions affecting individuals in public-sector contexts — that trigger Articles 9-49 documentation, oversight and monitoring obligations, effective 2027-12-02 following the Digital Omnibus.
Sources
- Regulation (EU) 2024/1689 — EU AI Act full text
- SAP on Bleu — sovereign cloud for France
- SAP BTP Privacy and Security — data residency
- BSI C5 — Cloud Computing Compliance Criteria Catalogue
- SAP Datasphere — Help Portal
- SAP Datasphere — official product page
- European Commission — Cloud sovereignty policy
- How to Connect S4HANA Public Cloud With SAP Datasphere — SAP Community (Technology Blog Posts by Members)
- S/4HANA Public Cloud Integration with SAP Datasphere — SAP Community (Enterprise Architecture Blog Posts)
- Leveraging AI and Google Solutions for automating flatfile upload into SAP datasphere — SAP Community (Technology Blog Posts by Members)
- Google Vertex AI triggering calculations / ML in SAP Data Warehouse Cloud — SAP Community (Technology Blog Posts by SAP)
- Federated Machine Learning using SAP Datasphere & Google Cloud Vertex AI 2.0 — SAP Community (Technology Blog Posts by SAP)
- Federated Machine Learning using SAP Data Warehouse Cloud and Google Cloud Vertex AI — SAP Community (Technology Blog Posts by SAP)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.