Research
Practical research on AI under European rules.
Working guidance for the people who have to deploy AI inside regulated organisations — what the regulations require, how the market is moving, and what actually passes a security review.
Latest research
4 articlesThe Best Sovereign AI Platforms in Europe (2026)
A buyer's comparison of sovereign AI platforms for regulated European organisations in 2026 — how the categories differ, what sovereignty actually means in a contract, and which vendor fits which constraint.
Read GDPR10 min readGDPR-Compliant ChatGPT Alternatives for European Teams
Why public AI assistants are difficult to use with internal company data under GDPR, what a compliant alternative actually requires, and how the realistic options compare for European organisations.
Read Financial Services10 min readWhat DORA Changes About Enterprise AI Governance
DORA has applied to EU financial entities since January 2025. This is what it means when the ICT service you are contracting for is an AI platform — contracts, register of information, exit strategies, and concentration risk.
Read Security9 min readA Practical Path from Shadow AI to Governed Work AI
Banning consumer AI tools does not work. This is a practical sequence for moving an organisation from unmanaged AI use to a governed platform, without losing the productivity people have already found.
ReadSovereign AI glossary
Plain definitions of the 25 terms that come up in European AI procurement, security reviews, and regulation — from data residency to permission-aware retrieval.
About this library
MethodWho writes Diana research?
The Diana team, drawing on the deployment and security reviews we run with regulated organisations. Where we make a claim about a regulation, we cite the primary source so you can check it rather than take our word for it.
How current is this material?
Every article carries a visible last-updated date. Regulatory timelines in particular move — the EU AI Act's high-risk deadlines shifted in 2026 — so we revise these pages when the underlying position changes rather than leaving them to age quietly.
Is this material vendor-neutral?
It is written to be useful first. Diana is a commercial product and we say so plainly wherever it appears, including in our own comparison tables. Where a different approach fits a constraint better, we would rather the article says so than have you discover it during a pilot.
See Diana at work
Bring this to your own systems.
A walkthrough covers the parts these articles cannot: your sources, your permission model, and the deployment topology your security team will accept.
