00% SCROLL
By Diana · Compliance · Last updated 27 July 2026

The AI Challenges Facing Regulated Companies in the EU — and How to Overcome Them

Regulated companies across the EU want the productivity of AI — and face a stack of rules that ask where data is processed, who can access it, and whether you can prove what happened. Those questions are not abstract. GDPR, DORA, NIS2 and the EU AI Act all land on the same architectural choice: whether AI runs inside your perimeter, or on someone else's.

This piece sets out the challenges as they actually present to compliance, security and IT leaders — without invented statistics — and the practical ways European teams are overcoming them. Where Diana fits is as one concrete architecture that answers those challenges by design.

Challenge 1: Several regimes, one AI stack

A single generative-AI tool can sit under more than one EU framework at once:

  • GDPR — personal data, lawful basis, and Chapter V rules on transfers to third countries.
  • DORA — in force for financial entities since 17 January 2025; ICT risk management, ICT third-party risk, incident reporting and resilience testing.
  • NIS2 — cybersecurity and supply-chain risk for essential and important entities; member-state transposition has been uneven, but the direction is clear.
  • The EU AI Act — phased in since August 2024; prohibited practices and general-purpose-AI duties already apply, with further high-risk obligations still coming into force on a staged timetable.

None of these bans AI. Together they make “we used a public chatbot” a weak answer when a supervisor asks where data went, who processed it, and how you would exit the vendor. The challenge is not one policy checklist — it is four overlapping ones that all reward control and evidence.

Challenge 2: Shadow AI is already inside the building

Teams paste contracts, filings and notes into consumer tools because the work is hard and the tools are useful. Banning the tools rarely stops the behaviour; it only removes visibility. For a regulated firm that creates a second problem: confidential or personal data may already be leaving the perimeter without a record in the ICT register, without a DPIA, and without an exit plan.

The fix is not another ban. It is giving people a workspace that can do the same kind of work — research, drafting, document production — inside the environment the security team already governs. Otherwise the demand for AI will keep finding the path of least resistance.

Challenge 3: Third-party and concentration risk

Under DORA, an external AI service that supports a critical or important function can become an ICT third-party dependency. That brings obligations around contractual rights, subcontracting transparency, audit access, concentration risk and exit. NIS2 likewise pushes organisations to understand supply-chain cyber risk.

If every prompt leaves your network for a hyperscaler API, your AI adoption is also a vendor-risk programme. That is manageable for some uses — and painful when the same provider sits at the centre of many critical workflows. Architecture that keeps processing local shrinks the third-party surface instead of expanding it.

Challenge 4: Transfers and foreign jurisdiction

GDPR Chapter V restricts transfers of personal data to third countries unless an adequacy decision or another Chapter V safeguard applies. A common mitigation is “EU-region hosting” from a non-EU provider. That helps with physical location; it does not, by itself, remove the legal reach of the provider's home jurisdiction. US law such as the CLOUD Act can still apply to a US-headquartered provider regardless of where the servers sit.

For teams handling client, patient or citizen data, the cleaner control is often simpler: do not transfer the data for processing. Run the model where the data already lives.

Challenge 5: Evidence — what did the system do, and on what?

DORA incident windows, AI Act documentation and logging expectations, GDPR accountability, and ordinary internal audit all ask variants of the same question: can you show what happened? Public endpoints expose only what the vendor chooses to log. Outputs without source citations are hard to defend in a regulated memo or report.

What regulated teams need is boring but decisive: an audit trail they control, and outputs that link claims back to the files and pages they came from. Without that, AI remains useful for brainstorming and weak for anything a supervisor might later open.

How regulated teams overcome these challenges

The pattern that consistently reduces the surface area of the problem is architectural, not contractual:

  • Bring AI to the data. Prefer on-premise, sovereign EU cloud, or air-gapped deployment so personal and confidential material never needs to leave for inference.
  • Treat AI as ICT from day one. Put it in the risk register, define owners, and decide whether any external provider is a critical dependency — before scale makes exit expensive.
  • Require no egress and no training on your data in the deployment model, not only in a marketing FAQ.
  • Demand auditability. Time-stamped logs of reads, exports and agent actions; citations on finished documents.
  • Scope access to existing controls. Connectors and data access should inherit the permissions people already have — nothing wider.
  • Give teams a sanctioned alternative. If the only useful tools are consumer chatbots, shadow AI will continue. A governed workspace is the practical antidote.

None of this requires inventing new compliance theatre. It is the same discipline applied to email, document management and core banking systems — applied to AI.

Where Diana fits

Diana is built for that pattern. It is a sovereign AI workspace for regulated European teams: agents and document workflows run on your hardware, in a sovereign EU cloud, or fully air-gapped. In normal use there is no data egress and no training on your data. Finished outputs — memos, reports, decks — are produced as real files with citations back to source material, and activity is recorded in a tamper-evident Audit Stream.

Connectors are scoped to the systems you already run and reviewed under your security process, rather than bolted on as a fixed public catalog. The architecture is the compliance argument: because processing stays inside your perimeter, transfer, third-party-risk and evidence questions shrink instead of multiplying.

The takeaway

Regulated companies in the EU are not blocked from using AI. They are blocked from using AI that they cannot see, evidence or contain. The challenges — overlapping rules, shadow use, vendor concentration, foreign jurisdiction and weak audit trails — all point to the same remedy: run AI inside the perimeter you already defend, with logs and citations you can show. That is how adoption becomes defensible rather than another risk to explain.

Frequently asked questions

Which EU rules affect AI use in regulated companies?
The main ones are GDPR (personal data and transfers), DORA for financial entities (ICT risk and third-party risk), NIS2 for essential and important entities (cybersecurity and supply-chain risk), and the EU AI Act (governance, documentation and high-risk obligations as they phase in).
Why is “EU hosting” from a US provider not enough?
Server location is not the same as legal control. A provider headquartered outside the EU can remain subject to its home jurisdiction — for example the US CLOUD Act — even when data sits in an EU region. For regulated work, processing inside infrastructure you control is a stronger answer.
What is the practical way to adopt AI without widening regulatory exposure?
Run AI where the data already lives: on-premise, on a sovereign EU cloud, or air-gapped, with no data egress in normal use, no training on your data, and an audit trail you can show. That architecture reduces transfer, third-party-risk and evidence problems at once.
How does Diana address these challenges?
Diana is a sovereign AI workspace that runs inside your perimeter — on your hardware, in a sovereign EU cloud, or fully air-gapped. It produces finished, cited documents with no external call in normal use, never trains on your data, and records activity in a tamper-evident Audit Stream.

Diana is the sovereign AI workspace for regulated European teams — specialist agents produce finished, cited documents inside your own perimeter.

See the security modelSee the product