AI in defense and security: the unclassified layer, done properly
The boundary first: what PrivatAI cannot do
Classified material is out. Even the lowest German classification level — VS-NfD — requires BSI-approved products and procedures in the IT system used; the company needs industrial security accreditation through the Federal Ministry for Economic Affairs, and staff need a security clearance under the SÜG. For VS-VERTRAULICH, GEHEIM or NATO classifications that applies all the more. PrivatAI does not meet these requirements.
Anyone promising you otherwise at this point either does not know the rules or is hoping you don't. The honest statement is: for classified content you need an approved environment. For everything else you need a provider that stores nothing and does not sit in a foreign jurisdiction.
And "everything else" is the larger part. A supplier spends the working day on quotes, bills of material, inspection records, complaints and supplier emails. None of that is classified. All of it is confidential enough that it does not belong in a public chatbot.
Why jurisdiction matters here, not server region
With US providers, "hosted in the EU" is a statement about where data sits, not about who can reach it. The CLOUD Act obliges US companies to hand over data in their custody — including data held on European servers. That is precisely the tension that led the CJEU to strike down the Privacy Shield in Schrems II (C-311/18).
In defense supply work this is rarely an abstract discussion. Customers, framework agreements and group security policies routinely rule out US access for particular project documents. A provider with a US parent company cannot structurally meet that condition, regardless of which data centre the data sits in. A European provider can meet it — and evidence it.
Added to that is the regulatory pressure from NIS2: operators of essential and important entities have to assess supply-chain risk systematically. A tool that stores your documents in a third-country jurisdiction is a line item you will have to explain in that assessment.
The second problem: when the model refuses the work
Security work brings an obstacle that has nothing to do with data protection: the large commercial models refuse precisely the tasks in question. Malware analysis, understanding an exploit, working through attack logs — as input, none of that is distinguishable from someone preparing an attack. The guardrails cannot separate the defender from the attacker, so they block both.
We wrote this up in detail: when HuggingFace investigated a real incident, the commercial frontier model refused to help; the analysis only became possible with an open model on their own infrastructure. PrivatAI runs open models — the same class of tool, without the server cabinet.
The practical point: a tool you are not allowed to use in an emergency, and that refuses to answer during one, is not a tool. Both questions have to be settled beforehand, not at 3 a.m.
What you can actually use AI for
- Quotes and tenders: structuring responses to specifications, quote texts from bullet points, drafting queries back to the customer.
- Technical documentation: manufacturing and inspection instructions, change notices, deviation reports, manual sections — from notes to complete drafts.
- Quality and audit work: QM documents, audit preparation, corrective action plans, supplier assessments.
- Cyber defense and IT security: log analysis, incident reports, pentest documentation, hardening guidance — covered in depth on the IT security page.
- NIS2 and supply-chain compliance: policies, evidence documentation, questionnaires to sub-suppliers, internal training material.
- Translations for international programmes — without technical documents leaving the building or the EU.
Not included: classified content at any level. That boundary is drawn organisationally — through a short, binding usage policy that names what may go into the tool and what may not.
How PrivatAI meets the requirements
PrivatAI stores nothing: inputs and responses are processed and discarded — not logged, never used for training. No body of data arises that could be caught up in an incident or a request. Provider and processing are both European: the application in Germany (Hetzner), the AI processing in France (Scaleway) — no US parent company, no CLOUD Act access. Contractually secured through the data processing agreement under Art. 28 GDPR with documented technical and organisational measures; the full sub-processor chain is public, and therefore reviewable for your supply-chain assessment.
Where the place of processing is itself a requirement, there is an Enterprise setup with AI inference in Germany. That is still not an approval for classified material — it moves the place of processing, not the classification.
If you are an IT service provider building this kind of solution for your own clients, the partner page is the better starting point.
PrivatAI (privatai.com) — AI chat & API from Germany. No content logs, no training on your data, GDPR-compliant.
PrivatAI compared
| Criterion | PrivatAI | US frontier API ("EU region") | Self-hosted local model |
|---|---|---|---|
| Storage of inputs | None — processed and discarded | Usually 30-day retention | None (if configured correctly) |
| Provider jurisdiction | EU (German company) | USA (CLOUD Act) | Not applicable |
| Refuses security work | No (open models) | Frequently | No |
| Place of processing | EU (DE/FR); Enterprise: DE | EU server region, US parent | Your premises |
| Suitable for classified material | No | No | Only in an approved environment |
| Supply-chain evidence (NIS2) | DPA, TOMs, sub-processors public | Partial | Your own responsibility |
| Time to start | Minutes | Minutes | Weeks |