The thesis

AI accountability you can inspect.

GAIA Brain exists because contractual assurance, technical control and operating evidence are different things. Regulated organisations need all three.

The decision nobody is making

Every prompt your firm sends to an AI is a data-export decision.

When a prompt leaves your infrastructure for a model on someone else’s servers, data has crossed your boundary. That holds whether the prompt carries a client name, a position, a draft memo, or only the shape of a question you would not want a competitor to read. The provider’s terms may promise not to train on it. The promise can be sincere and the fact is unchanged: the data left.

For most companies that is a manageable risk. For a regulated one it sits at the centre of the problem. Yet in most firms the decision is made by no one. The prompt box is open to everyone, it sends everything, and afterwards nobody can reconstruct what was disclosed. That is not a posture you can take to a supervisor.

The distinction that decides what you can defend

A contractual assurance is not an operating control.

Provider contracts matter: they allocate duties on training, retention, security, incidents and deletion. They are one control layer, not the entire control system. A regulated firm must also understand where processing occurs, what a provider can technically see, who can compel access and what evidence the firm retains.

Technical measures reduce particular risks; they do not create universal guarantees. Customer-hosting, least-authority retrieval, protected-value substitution and evidence logs can make selected data flows more controllable. The residual prompt, configuration, operator, provider and human decision still need governance. The defensible position is layered control with explicit limitations.

The regulatory reality

GDPR, DORA and the AI Act create different duties.

No single architecture satisfies them. The common operating need is to know the data flow, assign responsibility, control providers and retain evidence.

GDPR, Article 9
Special-category data carries the strictest limits on processing. Placing it in a prompt to an external model is a processing event and, when the model runs outside the EEA, a transfer as well. Good intentions do not lower the bar.
DORA
For ICT services that support critical or important functions, exit strategies are mandatory and exit plans must be documented and tested. A model you cannot leave, hosted where you cannot reach it, is a concentration risk by another name.
Schrems II
Where no adequacy decision covers the destination, contractual clauses may not be enough on their own. Supplementary measures can be required, and where the recipient can be compelled to hand data over, technical measures may be the only ones that hold.
EU AI Act
Deployers of high-risk AI systems must assign human oversight, keep the logs the system generates and, where they control the input data, make sure it is relevant. You cannot evidence what you never controlled.

What follows

Put the export decision back inside the firm.

The answer is not a blanket ban or an invisible free-for-all. It is a governed work path that applies approved sources and permissions, makes external dispatch explicit, substitutes supported protected values when configured, keeps human review visible and retains evidence. GAIA Brain is being built to test that approach in bounded workflows.