# Why this project exists
A gateway concentrates every prompt an organisation sends to an AI model. We had to select one for a large European company under the constraint that the operator must not be subject to US law, and this page sets out the reasoning so the table can be read with the same questions in mind.
# 01
Using one model provider directly worked while there was one obvious model. That stopped being true.
The leading model for a task changes several times a year. A gateway lets a team swap a model or a provider behind one API without touching the applications that call it.
Fallback between providers, rate-limit spreading, caching and spend limits are applied once, at the gateway, rather than re-implemented in every service.
Keys, access control, logging, retention and observability sit at a single point. That is also why the gateway is the most sensitive component in the chain.
# 02
The gateway is the single point where all of an organisation's AI traffic converges.
Prompts, uploaded documents, retrieved context, model outputs, API keys and request logs all pass through the gateway. Whoever operates it has technical access to that flow, and the law that applies to the operator applies to that access. Where the servers stand is one factor. Who controls the company, and which courts and agencies can compel it, are the others.
For most organisations this makes the gateway more sensitive than any single model provider behind it, because a model provider sees one slice of traffic while the gateway sees all of it.
# 03
We did not set out to build a directory. We set out to make a purchasing decision.
In 2026 we had to select an AI gateway for a large company headquartered in the European Union. Its requirement was specific: the operator must not be an American provider subject to the CLOUD Act, and hosting in an EU region on its own would not satisfy that requirement, because the law follows the company rather than the server.
The comparisons we found did not answer the question. They treated “EU hosted” and “EU company” as the same thing, rarely named the legal entity behind a product, and ordered vendors by a score whose ingredients were not stated. So we did the research ourselves: registry filings, legal pages, public model endpoints and product documentation, one rule applied to every vendor. This site is that research, published so that others facing the same choice can reuse it and correct it.
# 04
Each authority below can apply to an American AI provider, or to the American infrastructure a provider relies on, independently of where a European customer's data is stored. Each entry links to the primary legal text.
18 U.S.C. § 2713; 18 U.S.C. §§ 2701–2713
50 U.S.C. § 1881a
18 U.S.C. § 2709
15 C.F.R. Parts 730–774
15 C.F.R. § 734.9
50 U.S.C. §§ 1701–1710; 31 C.F.R. Chapter V
E.O. 12333 (1981), as amended
Practical consequence for a strategic European company
Hosting data in France or elsewhere in the EU does not, by itself, eliminate exposure to US law where the AI provider or the infrastructure it relies on remains subject to US jurisdiction. The assessment therefore has to consider corporate control and legal jurisdiction, not only the physical location of the servers.
This page describes what United States law can require of a provider that is subject to it. It is general information, not legal advice, and it is not an allegation that any vendor in the dataset has disclosed customer data. Whether a given authority applies to a specific product depends on facts this dataset does not record, such as contractual terms and the full corporate structure behind it. The table records jurisdiction and ownership as facts, not as verdicts.
# 05
Each question the assessment forced on us became a separately sourced field, shown as a table column or in the expanded row. None is derived from another, and EU incorporation is never taken as evidence of EU processing.
Which company appears on the contract, and where is it incorporated?
Where it is recordedIs the operator controlled by a company in another jurisdiction? An acquisition changes the answer without changing the website.
Where it is recordedWhere does a request land first, and where are request and response logs stored?
Where it is recordedFor the models actually in use, where does inference run, and is EU processing the default, a setting or an enterprise-only option?
Where it is recordedIs content kept at all once the response has been returned, and for how long?
Where it is recordedCan the gateway run in the customer's own cloud or on-premise, so that no third party sits in the request path?
Where it is recordedThe residency attributes, and why a single “EU” label is not enough, are defined under methodology. The jurisdiction and EU residency filters above the table select the two populations separately for the same reason.