Sovereignty · 14 August 2026

On 2 August 2026, Article 50 of the AI Act made it mandatory, for a chatbot or an agent that talks to people, to indicate that the counterpart is AI, unless that is obvious. The same day, the AI Office was able to open investigations into providers of general-purpose models. Many directors concluded, too quickly, that “Europe has settled the American cloud”. No. Transparency is not sovereignty. An honest banner on a widget whose prompts go to the United States complies with Article 50. It is not a choice of data location. The two topics overlap in the customer’s head. They do not overlap in the text.

What the AI Act settles, and what it does not

The AI Act requires the deployer to inform, to mark synthetic content (with a deadline of 2 December 2026 for machine-readable marking of systems already on the market before 2 August), to label professional deepfakes, to guarantee a minimum of literacy (Article 4, since 2 February 2025). High-risk systems under Annex III are postponed to 2 December 2027; embedded Annex I to 2 August 2028 (Regulation EU 2026/1744, in force on 27 July 2026). Transparency fines go up to €15 million or 3% of worldwide turnover; prohibited practices up to €35 million or 7%.

Nothing in this timetable obliges an SME to host its model in France. Nothing bans GPT, Claude or an equivalent, subject to other law (GDPR, trade secrets, customer contracts). The US cloud did not become illegal on 2 August. It became, for the deployer, a choice that must be explainable: to whom, for which data, with what user information.

On 13 August 2026, OpenAI and Cerebras announced GPT-5.6 Sol Ultrafast (up to 750 output tokens per second, preview by invitation). The press cited $5 per million input tokens and $30 output for Standard/Fast. Cybernecs does not have access to Ultrafast. Speed does not carry your files into a French legal regime. It carries them faster.

France cloud, US cloud, box: three architectures, one deployer role

In all three cases, if you put the agent in front of a human, you are a deployer. Article 50 disclosure follows you. What changes is the path of the data and your ability to cut it.

US cloud. Latency often good, recent models, usage billing. Counterpart: a processor outside the EU, unilateral changes to terms, a surface of investigation and seizure you do not control. Acceptable for low-sensitivity flows, poorly framed for an employee file, a plan, a manufacturing secret.

France / EU cloud. The same API logic, a closer jurisdiction, still a processor. Useful when you want elastic load without operating everything. This is not on-premise. An incident at the host remains an incident at your door in the customer’s eyes.

Local box. At Cybernecs, the Synapse Box (Synapse OS) runs the agent inside your walls. You gain control of the network, the logs, the emergency stop. You lose the race for the latest model of the month. For a VSE, that trade is often the right one: a good-enough agent, on a cleaned corpus, beats a cutting-edge model wired to PDFs in a heap.

Five decisions to take on your flows, not on a keynote

  • Classify the data. Public, internal, confidential, personal. Only confidential and personal generally justify ruling out a US cloud. RAG cleaning avoids sending “by mistake” an entire directory.
  • Separate the agents. Public FAQ in the cloud, case file on-prem. A single omniscient agent is a lazy architecture choice, not a sovereignty choice.
  • Write the user information. Wherever it runs, the “you are talking to AI” banner is due. Add, if it is true, a sentence on data processing (stays in the company / processed by a named processor). Do not promise “your data does not leave France” if a side tool goes elsewhere.
  • Measure cost and lock-in. API at $30 per million output tokens, loops that lengthen: a high-performing cloud can cost more than an amortised box, quite apart from the risk of an account cut-off.
  • Plan the incident. Who cuts, where the logs are, what is said to the customer. AI cybersecurity does not change nature between cloud and box. The delay to unplug does.

Sovereignty: a word to use with precision

Patrick Dajan Mouelle, director of Cybernecs, avoids the slogan. Sovereignty, for an SME, means: knowing which flow leaves, being able to stop it, not being hostage to an invitation-only nor to a tariff change overnight. It is not “no bit crosses a border”, a slogan rarely held once you open messaging.

The AI solutions for VSEs and SMEs we deploy start from that sort. France cloud when it accelerates a public use. Synapse Box when the business cannot afford a leak or a jurisdictional latency. The AI Act, in both cases, applies to the disclosure. It does not choose for you.

To decide on a real case

Bring three uses (for example: site chat, quote assistant, internal document search). We will say which hold in the cloud, which must stay local, and which information wordings match reality. Contact: cybernecs.com/contact. Transparency and sovereignty are designed together. They are not the same thing.

Sources: Artificial Intelligence Regulation (AI Act), Regulation EU 2026/1744 (Digital Omnibus), Touteleurope, L’Express, Cerebras, TechCrunch.

Post a comment

Your email address will not be published.

Articles de la même catégorie