The checklist
- Does the contract exclude training on your data?
- Where is the data hosted, and can it leave the European Union?
- Will the provider sign a GDPR (opens in a new tab) compliant processing agreement?
- How long is the data kept?
- Is access protected by strong authentication?
- Can you export and delete your data?
- Does the provider publish its security measures?
- Is the intended use classed as high risk under the AI Act (opens in a new tab)?
Official resources
ENISA (opens in a new tab) publishes threat analyses on AI, and data protection authorities such as the ICO (opens in a new tab) publish practical guidance. The European Commission explains the AI regulatory framework (opens in a new tab) and the role of the European AI Office (opens in a new tab).
When an in-house solution is better
Health data, legal files, trade secrets: in these cases private AI removes the transfer question altogether. For overall compliance, see our AI Act support.

