Is EU data residency enough for compliance?
No. EU storage is not a general GDPR requirement and does not alone establish compliance. Location does not determine who can access data or be compelled to disclose it.
Residency concerns location; sovereignty concerns legal and operational control. EU storage does not exclude CLOUD Act requests where a covered provider is subject to US jurisdiction and possesses, holds or controls the data.
Lawful basis, security, applicable Chapter V transfer rules and any required DPIA remain necessary. GAIA Brain is designed for customer-controlled EU infrastructure. The customer remains responsible; architecture and audit records support, but do not prove, compliance.
What does DORA require for AI and ICT third-party providers?
DORA (Regulation (EU) 2022/2554) applies from 17 January 2025, including to AIFMs other than those referred to in Article 3(2) AIFMD. Third-party AI services can be ICT services; additional requirements apply where they support critical or important functions.
Articles 28 to 30 require proportionate ICT third-party risk management, an information register and at least annual reporting on new arrangements. Financial entities other than microenterprises and the entities under the simplified framework of Article 16(1) must adopt an ICT third-party risk strategy. Responsibility remains with the financial entity.
Article 30(2) sets basic contractual requirements, including data locations, security, incident assistance and termination. Article 30(3) adds audit, access and exit provisions for critical or important functions. Self-hosting can change dependencies, not remove DORA duties. GAIA Brain supports the work; it does not guarantee compliance.
Can an AIFM use foreign LLMs like ChatGPT?
There is no blanket ban. The AIFM must first assess confidentiality, personal-data processing, any international transfers and applicable DORA requirements for the specific service.
The issue is not just model quality but provider access and control. Foreign ownership alone does not establish a GDPR transfer; actual disclosure, access and jurisdiction matter. US jurisdiction may also create CLOUD Act exposure.
GAIA-CORE can substitute supported protected values with reversible surrogates before egress and restore them locally. The mechanism is default-off pending witnessed customer-hosted activation and representative tests. Residual context may remain personal or confidential. Provider, transfer, DPIA, RoPA and lawful-basis assessments remain the AIFM's responsibility. AIFMs are an example audience, not a claimed customer.
Does the US CLOUD Act reach data stored in the EU?
It can. Enacted on 23 March 2018, it clarifies that covered providers under US jurisdiction must comply with valid disclosure process for data in their possession, custody or control, wherever stored.
The key issues are jurisdiction and possession, custody or control, not server location alone. US ownership does not automatically establish control of every subsidiary's data.
The EDPB and EDPS's joint response of 10 July 2019 explains that a CLOUD Act request alone does not establish GDPR compliance. Disclosure needs a lawful processing basis and a valid Chapter V transfer basis. Customer-hosting and substitution can reduce disclosure, not automatically eliminate transfers or identifying context.
What is an LLM gateway?
A control point between applications and model providers, through which configured prompts and responses pass.
It centralises routing, policy enforcement, logging and data handling. GAIA-CORE's protected-egress mechanism can substitute supported values and restore valid surrogates locally. It is default-off, not generally available, and requires pilot validation.
Configured events create a tamper-evident record of requests, destinations and responses. This central control point helps demonstrate governance to a DPO, auditor or supervisor; completeness depends on configuration and preventing bypass.
Is GAIA Brain production-ready?
GAIA Brain is just short of MVP; it is not generally available and has no official customer deployment.
The internal assessment of 10 October 2026 recorded 130,595 tracked TypeScript lines and 1,430/1,430 regression criteria passed. Separate HTTP integration suites passed 10/10 and 18/18. These are internal engineering results, not certification or customer validation.
Protected egress is default-off. Key material is sealed to the host’s TPM and backups are encrypted before they leave the host. The development installation runs on an encrypted disk; on a pilot, disk encryption is set up and verified on the customer’s infrastructure. The final customer configuration still needs validation, and an external security review has not yet been carried out. The next step is a paid, bounded design-partner pilot, not a production purchase.
What licence will GAIA-CORE carry, and why does that matter?
GAIA-CORE will be released under GNU AGPLv3. Its repository remains private and no release date has been announced.
Before release, pilot buyers can negotiate controlled source review, dependency and test evidence, reproducible builds, source escrow or agreed access, and export and transition terms. These require explicit agreement.
Source access and appropriate licence rights support inspection and continuity if the supplier changes or fails. Skills and dependencies still matter. The proprietary sector layer is licensed separately.
Where does my data go when the gateway calls an external model?
It depends on routing and runtime configuration. A local route can stay within the customer environment; an external route sends the residual prompt to the provider.
When enabled and validated, substitution replaces supported values before dispatch and restores them locally. Residual context may remain personal or confidential; processor and transfer obligations may still apply.
Configured events can enter the tamper-evident audit trail. Protected egress is default-off and must be validated in the intended customer-hosted pilot.
Do you (GAIA25) see my data?
The proposed model is customer-hosted or operated by an approved implementation partner, not a GAIA25 cloud. We do not currently offer managed hosting.
Access depends on the signed support and remote-access terms. The intended default is no standing production access; temporary access must be explicitly authorised, least-privilege and logged.
Verify this boundary through architecture, deployment settings, contracts and access logs.
How does self-hosting help with a DORA exit plan?
Article 28(8) requires exit strategies and documented, sufficiently tested, periodically reviewed plans for ICT services supporting critical or important functions. Article 30(3)(f) requires supporting contractual transition provisions.
Customer-hosting can facilitate export, backup and replacement. Continuity still needs licence rights, reproducible builds, documentation, skills and tested migration. After an AGPLv3 release, customers could maintain the core themselves under that licence.
Self-hosting may reduce particular provider dependencies, not necessarily overall concentration or ICT risk. The firm must document and test its own exit plan. GAIA Brain aims to lower technical barriers, not replace that responsibility.
What is the difference between data residency and data sovereignty?
Residency concerns where data is stored and processed, for example in EU infrastructure.
Sovereignty concerns legal and operational control. EU storage alone does not exclude foreign legal demands; jurisdiction, control and access matter. Neither term replaces a GDPR assessment.
GAIA Brain targets EU infrastructure and customer-controlled operation. Its built substitution mechanism is default-off. Actual control depends on hosting, support, external routes and the deployed configuration, not the product label.
Does GAIA Brain make my firm compliant?
No. Compliance remains your firm's responsibility under its applicable roles and regulatory duties. GAIA Brain cannot determine or certify it.
It maps its architecture to relevant requirements and provides supporting tools and evidence, including tamper-evident records and DPIA/RoPA endpoints. Applicability and adequacy require customer assessment; these tools do not complete the legal analysis.
No DPA, ESMA or national competent authority has endorsed or approved GAIA Brain. We make no such claim. It is control and evidence infrastructure, not a compliance certificate.