Glossary · entity definitions

The concepts that decide the choice of Swedish AI infrastructure

Clear, citable definitions of the terms that determine whether an AI provider is fit for the Swedish public sector, finance and healthcare. Written to be understood by both lawyer and developer.

Sovereign AI

AI infrastructure where data, compute and model weights are guaranteed to stay within a defined jurisdiction, without any foreign actor or foreign law being able to demand access. For Sweden this means, in practice, Swedish or independent European ownership, physical operation in Sweden/the EEA, and no dependency on US parent companies.

Data sovereignty

The principle that data is subject to the laws of the country where it is physically and legally handled. A server standing in the EU is not enough if the provider's parent company is subject to foreign law — the data can then be demanded anyway.

CLOUD Act

US federal law (2018) clarifying that providers of communication and cloud services under US jurisdiction must hand over stored customer data to US law enforcement following a court order, regardless of where in the world the data is stored. The obligation follows the company, not the server: it covers US companies' foreign subsidiaries and can reach non-US companies with sufficient US operations. A targeted criminal-process tool — not mass surveillance — but the reason an 'EU region' at a US-controlled provider does not in itself provide jurisdictional protection. The EDPB and EDPS have assessed that direct disclosure to the US without support in an international agreement generally lacks a legal basis under the GDPR.

FISA 702

Section 702 of the US Foreign Intelligence Surveillance Act lets US authorities compel providers of electronic communication services under US jurisdiction to assist targeted signals intelligence against non-US persons outside the US — without an individual court order; a special court approves only annual programmes and procedures. The provider category is broad (telecoms, email, cloud storage, and since 2024 also certain actors with access to equipment where communications are transmitted or stored) and the provider may not inform the customer. In European assessments, 702 often weighs heavier than the CLOUD Act: it was primarily 702 and EO 12333 that felled Privacy Shield in Schrems II. As with the CLOUD Act, exposure follows the provider's jurisdiction, not the server's location. Status 2026: the statutory basis lapsed on 12 June 2026 without reauthorisation, but collection continues under court-approved certifications from March 2026 (valid until around March 2027) while Congress negotiates.

EO 12333

US executive order (1981) governing intelligence collection outside US territory. Unlike the CLOUD Act and FISA 702 it contains no mechanism to compel providers: collection happens against traffic and infrastructure abroad — for example data in transit — without judicial oversight and essentially without remedies for foreign data subjects. The risk therefore follows data paths and encryption, not the provider's ownership, and cannot be read off an ownership column. Strong transport encryption reduces exposure, but does not protect if the recipient itself can be compelled to hand over keys or plaintext.

Schrems II

The Court of Justice of the EU's ruling (2020) that invalidated the Privacy Shield and tightened the requirements for transferring personal data to a third country — primarily citing FISA 702 and EO 12333, whose proportionality and remedies for EU persons were found wanting. It means providers with third-country exposure must be able to show supplementary safeguards — or avoid the transfer entirely.

Adequacy decision / EU–US Data Privacy Framework (DPF)

An adequacy decision is the European Commission's finding that a country outside the EEA provides an essentially equivalent level of personal-data protection, so transfers there require no additional safeguards. For the US, the EU–US Data Privacy Framework decision has applied since 10 July 2023, resting on US commitments in an executive order (EO 14086) on proportionality and a dedicated review court. The decision is formally in force but its durability is contested: the oversight board PCLOB has lacked a quorum since January 2025, the Court of Justice is reviewing an appeal (C-703/25 P) after the General Court dismissed the first annulment action (September 2025), and in June 2026 the US Supreme Court struck down protection against at-will removal in independent oversight agencies. If adequacy falls, other transfer tools are required — for example standard contractual clauses with supplementary safeguards.

NIL — China's National Intelligence Law

China's National Intelligence Law (2017). Article 7 obliges all Chinese organisations and citizens to support, assist and cooperate with national intelligence work — and to keep it secret. The obligation covers Chinese-registered companies and Chinese citizens; whether foreign subsidiaries of Chinese groups are also caught is disputed but cannot be ruled out. The principle is the same as for the US access laws: exposure follows the provider's ownership and control chain, not where the server sits. China's Data Security Law (2021) additionally prohibits disclosure to foreign authorities without Chinese permission. Similar collection laws exist elsewhere (e.g. Russia's SORM/Yarovaya, Sweden's FRA Act, the UK's IPA) — the relevant difference is what remedies foreign data subjects have.

Third-country transfer

Any processing or transfer of data outside the EEA, including for telemetry, support or logging. An 'unknown' or 'yes' here is often a deal-breaker for regulated organisations.

Model Context Protocol (MCP)

An open protocol (donated to the Linux Foundation) for how agentic AI systems securely connect to tools and data sources. For infrastructure providers the question is whether the network supports MCP over Streamable HTTP and stateful sessions — critical for remote-calling AI agents.

Zero retention

That the provider does not keep prompts, inputs or outputs after the request has been processed. A claim of zero retention should be verified against the data processing agreement (DPA), not just against the marketing page.

Data Processing Agreement (DPA)

The legal agreement that governs how the provider may process the customer's personal data. This is where guarantees of zero retention, no model training on customer data and data residency become binding — which is why we distinguish 'claimed' from 'confirmed against the DPA'.

EU AI Act

The EU's AI regulation, which imposes requirements on transparency, technical documentation and logging depending on the system's risk class. For infrastructure providers it is about being able to support the customer's compliance, not just their own.