Every AI vendor answers to somebody. Usually to three somebodies: a public authority that supervises them, an owner who controls them, and a government that can compel them. Those are three separate chains, they can point in three different directions, and almost every procurement questionnaire asks about one of them.
That is the whole argument of this article. If you take nothing else from it, take the shape.
A note on terms, because two of them get used interchangeably and should not be. Supervision is a public authority’s power to investigate a product, demand documentation and require changes. Compulsion is a government’s power to require a company to hand something over, usually under a specific statute, sometimes without telling the customer. A vendor can be supervised by one country and compellable by another, and neither fact tells you anything about who owns them.
The three chains
The regulatory chain, which just became answerable in Germany
Until recently this was the hardest of the three to ask about, because in Germany there was no settled answer. There is now.
Since 29 July 2026, under the KI-Marktüberwachungs- und Innovationsförderungsgesetz — the KI-MIG — the Bundesnetzagentur is the market-surveillance authority, the national contact point and the complaints office for the EU AI Regulation, and the national coordinator. The same announcement is explicit that the law builds on the established competences of the existing market-surveillance authorities, and that companies keep their familiar contacts, including for questions about the AI Regulation.
So the answer to “which authority supervises this” is now two-part rather than one: there is a central door, and there is whichever sectoral authority already had the remit. We set that out in full in Germany now has an AI supervisor, including what it does not change.
For a buyer, the practical consequence is small and useful. Three questions that had no clean form six weeks ago now have one:
| What you ask | The German answer, since 29 July 2026 |
|---|---|
| Which authority supervises this? | The Bundesnetzagentur — market-surveillance authority, national contact point, complaints office, and national coordinator |
| And the authority we already deal with? | Unchanged. Existing market-surveillance authorities keep their established competences |
| Where does an early scoping question go? | The KI-Service Desk, at bundesnetzagentur.de/ki — before you commission an opinion |
The corporate chain, which is the one that moves
The regulatory chain changes slowly: an authority is designated by law and stays designated. The legal chain changes slowly too — statutes are amended rarely and visibly.
Ownership is different. A supplier’s parent company can change between one procurement cycle and the next, through an acquisition that is announced on a Tuesday and completed months later, and when it changes it can change the answers in the other two chains with it. We used a public example of exactly that in Sovereign AI has two layers — not as a criticism of anyone, but because it is the clearest available demonstration that the ownership answer has a shelf life.
This is where a diligence question gets confused with a political one, so it is worth separating them. The useful question is not which country a supplier comes from. It is whether you know who owns them, whether that has changed recently, and whether anyone on your side would notice if it changed again. The first is diligence. Treating a particular answer as disqualifying on its own is not, and it invites the same question straight back at whoever is asking it.
The legal chain, which is the one people have actually thought about
This is the best-covered of the three, so we will not re-derive it here. The short version: the obligation follows the provider’s jurisdiction, not the data’s location, which is why “hosted in the EU” does not settle it on its own. The US CLOUD Act and your AI vendor works through the mechanism, and Sovereign AI in plain English puts the compulsion question in language you can take into a non-technical meeting.
The one thing worth adding here is the interaction. A supplier who is supervised in Germany, owned in Germany, and compellable only under German and EU law has three chains pointing the same way — and that is a coincidence of their structure rather than a rule. Change any one of the three, and the other two do not follow. That is why they are worth asking about separately.
Five questions, one per chain and two that join them
Deliberately not another vendor checklist — there are plenty, including ours. These hang off the chains, and the value is in noticing which one a given answer belongs to.
Ask, and listen for which chain the answer comes from
- Which authority supervises you — and is it the one I would have guessed?
- If I complained about your system, where would that complaint land? A supplier who has thought about this answers with an organisation, not a support address.
- Which legal entity am I contracting with, who owns it, and when did that last change?
- Which government could compel you, under which statute? Ask them to name the mechanism rather than deny the possibility.
- Which of those four answers changes if you are acquired tomorrow?
The fifth is the one almost nobody asks, and it is the one that ages best. It is also the fastest way to find out whether the first four were understood or recited.
Where we sit, honestly
RAGSuite is self-hosted: it runs on your infrastructure, and there is no third party in the data path between your documents and your users. That changes the shape of the legal chain more than the other two — there is no external party holding your data for anyone to compel — and it does not remove the regulatory or corporate chains, which still apply to whoever wrote the software.
On the corporate chain, since we are asking other people to answer it: RAGSuite is an innovation by NITSAN, with a German team and German service partners, and EU and German hosting. We are not going to make a claim about our own supervisory status while that is a question our counsel has not finished answering, and you should be sceptical of any supplier who answers it faster than their lawyer does.
The honest summary
Three chains. Regulatory, corporate, legal. They are independent, they can point in three different directions, and the most common procurement failure is not asking the wrong question — it is asking one question and believing you have covered all three.
If you want our own answers in one place rather than scattered through a conversation, they are on the sovereignty page. If you want the questions in a form you can put in front of a supplier, the five above are the whole of it.
Frequently asked questions
What are the three chains, briefly?
Regulatory — which public authority supervises this supplier, takes complaints about them, and can require changes. Corporate — which legal entity you are actually contracting with, who owns it, and under which country's company law. Legal — which government could compel that entity to disclose or act, under which statute. They are independent of one another, which is the whole point of separating them.
Who supervises AI in Germany now?
Since 29 July 2026, under Germany's AI market-surveillance and innovation-promotion act (the KI-MIG), the Bundesnetzagentur is the market-surveillance authority, the national contact point and the complaints office for the EU AI Regulation, and the national coordinator. The federal digital ministry's announcement is explicit that the law builds on the established competences of the existing market-surveillance authorities and that companies keep their familiar contacts. So it is a coordination layer over an existing structure, not a handover. We wrote it up in full in Germany now has an AI supervisor.
Isn't the corporate chain just a nationality argument?
No, and it should not be run as one. The useful question is not which flag a supplier flies but whether you know the answer, whether the answer has changed recently, and whether anybody on your side would notice if it changed again. A supplier's ownership is a matter of public record in most jurisdictions; asking about it is diligence, and treating a particular answer as disqualifying on its own is not.
Does self-hosting make these questions go away?
It changes their shape rather than removing them. If software runs on your own infrastructure with no third party in the data path, there is no external party holding your data to compel — which is the legal chain's sharpest edge. The regulatory and corporate chains still apply to whoever made the software, and you still care about them for support, security updates and continuity. Fewer questions, not none.
What should a good answer sound like?
Specific, and often qualified. A supplier who can name their supervisory authority, name the statute a foreign government would use, and tell you the date their ownership last changed is a supplier who has been asked before. One who answers a question about jurisdiction by describing where the servers are has answered a different, easier question — and that substitution is the single most common thing to listen for.
Sources & further reading
- KI-MIG — statutory text (gesetze-im-internet.de) — the German law assigning supervisory roles for the EU AI Regulation
- BMDS — Neues KI-Gesetz tritt in Kraft (press release 47/2026, 29 July 2026) — the announcement, including the clause that companies keep their familiar contacts
- The US CLOUD Act and your AI vendor — the legal chain in detail — jurisdiction follows the provider, not the data
- Sovereign AI has two layers — why ownership at the model layer can change between procurement cycles
- Sovereign AI in plain English — the compulsion question, written without jargon