EU data residency for AI at work
EU data residency for AI at work means the company room is hosted in the EU, and consumer ChatGPT is not that room. A 22-person legal shop can have a DPA on a slide and still have client PDFs sitting in someone's personal ChatGPT on a US consumer stack. This is not a GDPR whitepaper. It is where Friday's file actually lives in August 2026.
Clients already ask the short question: where does this go when we talk to your AI. If the honest answer is "Ana's phone, OpenAI, maybe Claude", you do not have residency. You have a story.
What does EU data residency mean on a Tuesday?
It means a place you can point at.
The workspace is in the EU. The files you uploaded sit there. The threads sit there. The logs sit there. When a partner in München asks "where is the Müller memo", you do not say "in the model". You say "in the Delivery workspace, on our instance".
It does not mean no model in the US will ever see a prompt. Teams that pretend otherwise are writing fiction. Residency is about the company room: storage, access, admin, the copy you keep. It is about not using a consumer product as the filing cabinet. It is about being able to revoke a person without losing the cabinet.
A 18-person accounting desk in Cluj already does this split with the real DMS. The working papers live in a system the firm administers. The AI, until now, did not. Tuesday is when an associate pastes the working paper into ChatGPT because the question will not open in their head. That paste is the residency failure. Not the privacy policy page.
Why is consumer ChatGPT not an EU company room?
Because it is a product for a person.
You did not issue the account. You cannot see the upload history. You cannot put the Müller PDF in a matter folder the next associate will open. You cannot answer a client questionnaire with "our ChatGPT", because it is not yours. It is a consumer stack that happened to be handy.
A DPA with a lab does not fix that. The DPA is a paper about a vendor. The paste is a person using a different product, often the free one, often on a personal email. GDPR conversations die here for a reason. The company talks about processors. The work happens in a tab IT has never seen.
This is the same leak as client files in consumer ChatGPT, just asked from the EU side. The file is the job. The model is a tool. If the only place the file can meet the model is a US consumer chat, every useful person will keep doing that, including people who passed the annual training.
A 40-person agency in Warsaw has the brand book in Drive (good) and in three ChatGPT histories (the actual AI). Drive residency does not cover the histories. The client asked about AI. Drive was not the answer they wanted.
Dust's sovereignty writing is adjacent: do not lock the company's intelligence to one lab's infrastructure. Fine. For this size of shop the first lock is worse. The intelligence is not even in a lab contract. It is in a personal login.
What do clients already ask?
Not Article numbers. Three practical things.
Where is it stored. Who can see it. What happens when someone leaves.
If you cannot answer those in a sentence, the rest of the questionnaire is theatre. "We take GDPR seriously" is not a sentence about storage. "Ana used ChatGPT, we have a policy" is not a sentence about access. "We would ask her to delete the chats" is not a sentence about leaving.
A German Mittelstand buyer, a Dutch ecommerce brand, a Bucharest in-house counsel: they have all learned to ask where the AI lives. They have also learned that vendors say "EU" and mean "a region toggle on a consumer plan". Your job is to show a room. Named workspace. Named people. Files that do not train models. An admin who can revoke.
They will also ask whether you send their files to train a public model. The answer has to be operational, not poetic. Prompts and uploads stay the company's. If you cannot say that about the tool people actually use, stop pointing at the handbook.
Where does hosting and admin actually sit?
On DIMA, the company instance is EU hosted. Data residency by default, not as a later upgrade you remember during procurement.
Administration is the control you can show a client. Accounts you issued. Roles. 2FA. A catalog of models you allowed. An audit of who ran what. Suspend the person, keep the matter. That is residency plus offboarding in the same gesture. Company chat is where the file meets the model without a consumer detour. The memo stays in the workspace. The thread is the company's. A partner in the EU can open it. A personal ChatGPT project named muller_final cannot be opened by the partner, the DPO, or the next hire.
You still choose which models the room may call. That is a policy in admin, not a hope in Slack. If a provider is not acceptable for a class of file, turn it off. People then cannot "just this once" in the company product. They can still do it in a consumer tab. That remaining leak is a management problem. Give them a room that works, or they will keep the tab.
What can a shop this size do this month?
Stop writing a whitepaper. Move one matter.
Pick the practice that already pastes client files into ChatGPT. Legal. Delivery. Ecommerce ops with supplier sheets. Put that folder into a workspace on an EU-hosted company system. Start the next thread there. Run the next memo there.
Tell the team the consumer tab is closed for that client. Mean it. The leave test is the check: revoke a spare login, see if the matter remains, see if a second person can continue. If the matter only existed in ChatGPT, you just found the residency hole without a lawyer.
Write the client answer in one paragraph you can reuse. Where it is hosted. Who can open it. What you do when someone leaves. What you do not use for training. Keep it boring. Boring is what in-house counsel can file.
A 12-person IT shop doing this for SMB customers has to answer the same paragraph when the customer is the one in the EU. Your runbook in a personal GPT is their data. Treat it like their data.
If you want a person in the room while you move the first matter, book a half hour. Bring one client file that today lives in a consumer chat. Do not bring a GDPR checklist.
FAQ
What is EU data residency for AI at work?
It is a company AI room hosted in the EU, with files, threads, and logs you can point at, under accounts you can revoke. It is not a privacy policy, and it is not a personal ChatGPT with the region set to something hopeful.
Is ChatGPT GDPR-compliant for a company?
The wrong question. A lab contract does not turn a personal consumer chat into a company filing cabinet. If client files sit in a login IT did not issue, you do not have a company answer, whatever the DPA says.
Where should an EU company host AI work?
In a system the company administers, hosted in the EU, with workspaces and an audit. Models can still be chosen per job. The room, the files, and the offboarding have to be yours.
Does a DPA fix consumer ChatGPT at work?
No. A DPA is about a vendor relationship you actually have. Consumer ChatGPT on a personal email is usually not that relationship. The paste still happened. The client file still left the matter folder.
How do you keep company AI data in the EU?
Host the company workspace in the EU. Put the files there. Run the threads there. Issue and revoke accounts in admin. Stop using consumer chats as the place the file meets the model. Policy without a room will lose.