Status. The Plan IA360 was announced on 21 September 2026 and still has no call or published governing rules; its dates are subject to regulatory development. What follows doesn't depend on any funding: it's the question you have to answer every time someone at your business opens an AI tool.
The Plan IA360's draft Royal Decree on data centres, which the plan describes as having been put out for public consultation, regulates «los requisitos de sostenibilidad energética y medioambiental, de resiliencia y de soberanía digital» (the requirements on energy and environmental sustainability, resilience and digital sovereignty) of the large facilities that sustain the country's compute, with approval planned for October 2026 (Plan IA360, flagship project 2). It's a regulation aimed at national-scale infrastructure, designed for the largest facilities, not for any office with a server. At the scale of your business, the phrase digital sovereignty translates into something far more concrete and far more immediate: when someone on your team pastes a document into an AI, where does that text end up?
Three places your data can live when you use AI
A generic public cloud, with no corporate contract. This is the free version of an AI chat that anyone can open in a browser. The data leaves the business's perimeter for a service whose terms of use have rarely been read, with no record of who sent it or what it contained. It's the most common — and least visible — way confidential information stops being under your control.
A cloud with a corporate contract and defined data residency. The provider processes the data under an agreement that fixes where it's hosted — within the European Union, for example — how long it's retained and whether it's used to train other models. The data still sits on a third party's infrastructure, but under written, enforceable rules, not the generic terms of a free service.
Your own or sovereign infrastructure. The model is deployed inside the business's own network, and the data never leaves it. This is the option with the most control and, almost always, the most cost and operational complexity: someone has to maintain that infrastructure, not just use it.
The risk is not knowing where your data goes, not using AI itself
When someone on your team pastes a contract, a customer database or source code into a free AI tool, that data leaves your perimeter without anyone knowing — it's rarely bad faith, it's that the tool solves the problem faster than the official channel does. Using AI isn't the problem; using it with no control over what leaves, with whom and under what condition, is. Training the workforce is useful, among other things, for learning to tell these three scenarios apart before pasting anything. A corporate AI Gateway is the layer placed between your team and the AI models: it filters what data can leave, decides which tools are allowed by role or department, and logs every query, instead of leaving the decision to each person's own judgement in the moment.
When the project is yours, the question is answered in the design, not afterwards
If the project isn't "someone using a chat", but a system that answers questions about your own documents — contracts, manuals, procedures — where the data sits stops being a usage policy and becomes an architecture decision. In a well-built RAG, the vector store respects the source system's permissions and every answer cites the specific document it comes from, so whoever's asking can check it. That traceability — which document, which page, who can see it — only works if you decide from the start where each piece of the system lives, not as a patch added once there's already an incident to explain.
Frequently asked questions
How do I find out what AI tools my team is already using, even if nobody authorised them?
Without a controlled channel, you normally don't know until there's an incident. A corporate AI Gateway logs which tools are used and what data passes through them; without that layer, the only way to find out is to ask team by team, and the answer is usually incomplete.
What exactly does it mean for a model to be "in the EU"?
That the provider processes and hosts the data in centres located within the European Union, under a contract that fixes this in writing. It isn't the same as a generic compliance statement: it's worth asking for that condition explicitly before signing, rather than assuming it from the provider's name.
Is sovereign or on-premise AI only for large businesses?
It's the option with the highest maintenance cost, and that's why it tends to be reserved for cases with the most sensitive data or specific regulatory requirements, not for every use at a business equally. Many SME projects work well with a corporate cloud with defined data residency, with no need for that investment.
What if an employee has already pasted a customer's data into a free AI tool?
Treat it like any other personal data breach: identify what information left, whether it included personal data and whether it needs reporting under the GDPR, and from there close off the route it happened through — usually by putting a controlled corporate channel in place instead of leaving it to individual judgement.
Further reading
The digital sovereignty the Royal Decree on data centres pursues is a matter for the country. Yours is decided in the contract with each provider and in the design of each system. The rest of the plan is in the complete guide to the Plan IA360, and how an SME will be able to test AI with its own data is in the Red NEURONA.