kontinent / compliance index
EU LLM Provider Compliance Ranking
The EU inference providers in the Kontinent catalog, rated by publicly verifiable compliance facts. Methodology v2.0, open and auditable.
View methodologyAzure OpenAI (EU Data Zone), Infercom, and TensorX lead with 100/100. Followed by AKI.IO and Google Vertex AI (EU).
AKI.IO, Nebul, and Scaleway lead with 100/100. Followed by OVHcloud and Regolo.ai (Seeweb S.r.l.).
AKI.IO, Google Vertex AI (EU), and Inceptron lead with 100/100. Followed by Mistral and Scaleway.
Nebius Token Factory leads with 100/100. Followed by AWS Bedrock (EU) and Azure OpenAI (EU Data Zone).
AWS Bedrock (EU), Azure OpenAI (EU Data Zone), and Mistral lead with 100/100. Followed by Google Vertex AI (EU) and TensorX.
AKI.IODE
ScalewayFR
NebulNL
OVHcloudFR
TensorXIE
IONOS AI Model HubDE
Regolo.ai (Seeweb S.r.l.)IT
Azure OpenAI (EU Data Zone)IE
Google Vertex AI (EU)IE
InfercomLU
MistralFR
InceptronSE
AWS Bedrock (EU)LU
Nebius Token FactoryNL
Route these providers through one EU API
Kontinent fronts the catalog with a single EU-hosted gateway: one key, one bill, and the compliance facts above enforced at the edge — not left as a spreadsheet.
Under review
Aleph Alpha / PhariaAI
DEDue diligence in progress, rating to follow.Telekom AI Foundation Services
DEDue diligence in progress, rating to follow.Telekom Industrial AI Cloud
DEDue diligence in progress, rating to follow.Key definitions
Tier (A–E)+
Overall tier from the weighted average of the six dimension scores: A ≥ 85, B ≥ 70, C ≥ 55, D ≥ 40, otherwise E. Hard gates can cap the tier further.
Hard gates+
Without a documented DPA under GDPR Art. 28, tier D is the maximum achievable, or tier C with a partial DPA; without contractually guaranteed EU hosting, tier C is the maximum, or tier B with partial hosting, regardless of score.
Points only for what's documented+
Only what can be substantiated by contract clauses, certificates, or written commitments is scored. If no evidence exists, it counts as "no verifiable commitment" (0 points). This is not a confirmed violation.
Zero Data Retention (ZDR)+
A contractual commitment that prompts and responses are not stored after processing. "Partial" means documented exceptions, such as abuse logs or batch buffers.
DPA (GDPR Art. 28)+
A Data Processing Agreement between customer and provider that governs instructions, sub-processors, technical measures, and deletion. A baseline requirement for GDPR-compliant use.
Standard Contractual Clauses (SCCs)+
EU Standard Contractual Clauses safeguarding data transfers to third countries. "Yes" means SCCs are in place or no third-country transfer occurs.
Incident reporting deadline+
The contractual deadline by which the provider must report security incidents. A specific deadline (e.g. 72 hours) scores better than the formula "without undue delay".
Certifications (ISO 27001, SOC 2, C5)+
Security certifications and attestations, counted only if their scope actually covers the inference service, not just the general infrastructure.
GPAI Code of Practice+
A voluntary EU code of conduct for providers of general-purpose AI models. Pure deployers generally cannot sign it.
Under review+
Providers whose due diligence is still in progress. They appear without a rating until verifiable facts are fully available.