GenAI you can put in front of an auditor.
Self-hosted or air-gapped, DSGVO by design, with a citation on every answer and a full audit trail. The control a DPO, a CISO and a Betriebsrat can all sign off — because nothing leaves your perimeter.
Three forces push AI on-premise — the EU AI Act is only one.
Data-protection law is already here, the EU AI Act is phasing in through 2028, and the wider drive for digital independence keeps building. You don’t have to bet on a single deadline — you have to prove control whenever it’s asked of you.
- 2 Feb 2025
Prohibited practices
Banned AI uses and AI-literacy duties apply.
- 2 Aug 2025
GPAI models
Obligations for general-purpose AI models and the governance framework apply.
- 2 Aug 2026
Transparency duties
In force. Article 50 applies to providers and deployers: people must be told when they are interacting with an AI, and AI-generated content must be marked. Not limited to high-risk systems — and open-source systems are not exempt. National market-surveillance authorities can enforce from this date.
- 2 Dec 2026
New prohibitions
Two further Article 5 bans (AI nudification, AI-generated CSAM) take effect. Generative systems placed on the market before 2 August 2026 have until this date to meet the machine-readable marking requirement.
- 2 Dec 2027
High-risk · standalone
Annex III systems must comply — moved back from Aug 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744.
- 2 Aug 2028
High-risk · embedded
AI built into regulated products (Annex I) must comply.
No data leaves your building. No new sub-processor.
Personal data stays inside your controllership and your existing processing agreements. There is no RAGSuite sub-processor to assess, because there isn’t one — the cleanest path to Art. 5, 25 and 32.
Two ways to answer “is this DSGVO-safe?”
One path papers over a US cloud with contracts and hope. The other removes the question by design.
- A new sub-processor your DPO must assess
- Transfer-impact assessments and SCCs to maintain
- Answers you can’t fully trace or audit
- The Betriebsrat asks where the data goes
- No new sub-processor — data stays in your controllership
- No cross-border transfer to justify
- A citation on every answer, plus a full audit trail
- Betriebsrat-friendly: nothing leaves the building
What a compliance team asks for.
Self-hosted / air-gapped
On your servers, your private cloud, or fully disconnected. Nothing phones home.
Citations & feedback
A source on every answer; feedback collection to catch what slips.
Full audit & exports
Unlimited retention, severity and filters, compliance exports, legal hold.
Built in Germany & the EU
An innovation by NITSAN, with German service partners and DE/EN support.
Every claim documented for your DPO · read the Trust Center →
Compliance you can demonstrate, line by line — not something you outsource.
For compliance teams, answered
Does any data leave our environment?
No — not by default. Documents, vectors and metadata stay in your own databases; with local Ollama there is zero outbound traffic. If you use a hosted model, only the prompt you choose to send leaves.
Is it Betriebsrat-friendly?
Yes. No covert employee tracking and no external data flows to explain — the transparency that makes works-council sign-off straightforward.
What about the EU AI Act?
Prohibited-practice rules apply since Feb 2025 and GPAI duties since Aug 2025; Article 50 transparency duties have applied since 2 Aug 2026 to providers and deployers (not limited to high-risk, and open source is not exempt); high-risk obligations were deferred by the Digital Omnibus on AI, Regulation (EU) 2026/1744, to 2 Dec 2027 (standalone) and 2 Aug 2028 (embedded). Self-hosting lets you evidence compliance on your own terms. See sovereignty.
“In healthcare a wrong answer isn’t an option. Every RAGSuite answer cites its source — that’s what made it a fit for our clients.”
De-risk DSGVO and the EU AI Act.
Talk to our compliance lead about your obligations — data protection, audit, and a deployment your DPO will sign off.