Skip to main content
Sovereign AI refers to a nation’s or region’s ability to develop, deploy, and control artificial intelligence systems within its own borders, using local infrastructure and under local regulatory frameworks. As AI becomes critical infrastructure, governments and enterprises increasingly require that AI workloads (including the data they process) remain within specific geographic and jurisdictional boundaries. OpenRouter offers fully in-region routing in the EU and the US on the Business and Enterprise plans. There is no setting to turn on: you choose the region for each request by sending it to that region’s base URL. Organization admins can upgrade to Business in Settings > Manage plan; for Enterprise, contact our enterprise team.

Drivers of sovereign AI

Sovereign AI is driven by two converging forces:

Regulatory Compliance

Regulations like the EU AI Act, GDPR, and sector-specific rules (healthcare, finance, defense) impose strict requirements on where data can be processed and stored. Organizations operating across jurisdictions need infrastructure that respects these boundaries.

Data Residency and Privacy

Sensitive data (whether personal, financial, or classified) may not legally or ethically leave a particular jurisdiction. Sovereign AI ensures that prompts and completions are processed entirely within a designated region, with no cross-border data transfers.

How OpenRouter Enables Sovereign AI

OpenRouter provides several features that enable sovereign AI deployments today, allowing enterprises to maintain control over where their AI workloads are processed.

In-Region Routing

For Business and Enterprise customers, OpenRouter supports in-region routing in the EU and the US. When you send a request to a regional base URL, the request is decrypted within the designated region and routed only to provider endpoints in that region. Server tools and plugin engines run on a regional domain only when they have a backend resident in that region; a request that uses any other tool or engine fails instead of falling back to global infrastructure. See Privacy and regional availability for each tool’s regional availability. Choosing a regional base URL per request is the first step. To guarantee that every request in a workspace stays in-region regardless of how a client is configured, restrict the allowed data regions in a guardrail. The guardrail’s allowed_data_regions setting (global, europe, us) lists the OpenRouter domains that governed requests must arrive through; requests through any other domain are rejected with a 403 before processing. Setting it on the workspace default guardrail enforces the policy for all keys and members in that workspace, and per-member or per-key guardrails can narrow it further. See Enforcing In-Region Routing with Guardrails. To use in-region routing, send API requests through the region-specific base URL:
In-region models listTo see which models are available for in-region routing, you can:
In-region routing (EU or US) is available on the Business and Enterprise plans. Organization admins can upgrade to Business in Settings > Manage plan, or contact our enterprise team for Enterprise. For full details on how requests are routed, which features are available on regional domains, and how BYOK works with regional routing, see the In-Region Routing guide.

Zero Data Retention (ZDR)

When Zero Data Retention is enforced, OpenRouter routes model inference only to provider endpoints that have a Zero Data Retention policy. ZDR enforcement does not apply to plugins, server tools, or their backends, which follow their own retention policies. See Privacy and regional availability for each server tool’s execution path and backend policy. ZDR can be enforced per model group (Anthropic, OpenAI, Google, SpaceXAI, and all other models) in your privacy settings, via guardrails, or per-request:

Data Collection Controls

Control whether providers can collect your data with the data_collection parameter:
When set to "deny", your requests are only routed to providers that do not collect user data. This can also be configured as an account-wide default in your privacy settings.

Building a Sovereign AI Stack with OpenRouter

Combining these features, you can build a fully sovereign AI deployment:
  1. Send requests to a regional base URL (eu.openrouter.ai or us.openrouter.ai) to keep model inference and supported tools within the EU or the US
  2. Enforce ZDR to route inference only to provider endpoints with a Zero Data Retention policy
  3. Deny data collection to prevent training on your data
This gives you a single API with unified billing while maintaining full control over data residency, privacy, and compliance, without the complexity of managing relationships with individual providers in each region.

Getting Started

Sovereign AI features are available to all OpenRouter users, with in-region routing (EU or US) available on the Business and Enterprise plans. To get started: For a complete enterprise setup guide, see the Enterprise Quickstart.