AIonicOS · Technical assurance & procurement

Digital sovereignty starts with four questions you can verify.

Sovereignty follows from the implemented architecture, the agreed operating model, and the customer’s own accountability—not from a product label. This page separates AIonicOS mechanisms from contractual and organizational controls for IT, procurement, privacy, and business owners.

Three control domains, one shared review

Product configuration

Technical mechanisms present, enabled, and demonstrable in the AIonicOS configuration that is actually implemented.

Contract / procurement

Agreements covering hosting, support access, subprocessors, retention, export, and exit.

Company organization

Customer decisions on classification, roles, risk assessment, oversight, training, and legal responsibility.

AIonicOS / CONTROL MAP

Four questions for architecture, procurement, and accountability

Where do data and execution run?

The answer is a documented data flow covering source, storage, retrieval, model, tool, logging, backup, and support access.

Product configuration

Configuration

Depending on agreed scope, AIonicOS supports single-tenant operation and other deployment configurations. Available models, providers, regions, storage locations, and telemetry are described only for the configuration actually implemented.

Contract / procurement

Agreement

Hosting region, subprocessors, retention, backup, support and emergency access, export, and exit services belong in the procurement and data-protection documents.

Company organization

Accountability

The customer classifies data, approves permissible processing locations and provider paths, and assigns owners for sources, operations, and exceptions.

Evidence to inspect

  • Architecture and data-flow diagram
  • Configuration and provider inventory
  • DPA, support-access, and exit terms

Who can access, approve, and change an operation?

Sovereignty requires named identities, bounded rights, and a traceable change path—not merely a login to an interface.

Product configuration

Configuration

Agent and service identities, least-privilege access, policy controls, and human approvals can be bound to the relevant integration. Effective coverage depends on the source system and implementation.

Contract / procurement

Agreement

Support roles, time-bounded emergency access, approvals, logging, and the change process are agreed with owners and expected evidence.

Company organization

Accountability

The customer assigns roles, separates incompatible duties, recertifies permissions, and decides which business-critical or risk-sensitive actions require approval.

Evidence to inspect

  • Role and permission matrix
  • Approval and escalation rules
  • Change and access record

What does the run and cost record prove?

A technical run record shows what the configured operation captured. It supports review; it is not blanket proof of legal compliance.

Product configuration

Configuration

Available run data can assign source references, model and tool calls, approvals, outcomes, errors, and AI and cost categories to a run. Fields and granularity follow the supported configuration.

Contract / procurement

Agreement

Retention, access, export format, deletion, evidence delivery, and any audit rights are defined for the intended purpose.

Company organization

Accountability

Business, IT, and control owners review the available evidence, compare it with the intended business outcomes, and handle exceptions or incidents through the company’s own control system.

Evidence to inspect

  • Representative run record
  • Field and retention concept
  • Mapping to acceptance and control criteria

Which controls belong to product configuration, contract, and company organization?

No domain replaces another. Clear allocation prevents technical functions from being treated as legal promises or company duties from being delegated to software.

Product configuration

Configuration

AIonicOS provides the mechanisms implemented for the agreed operation: permissions, approvals, records, source and model selection, and observability.

Contract / procurement

Agreement

Scope, operating model, responsibility boundaries, service, subprocessors, privacy, evidence, change, and exit are documented for procurement and review.

Company organization

Accountability

Legal role and risk classification, a data-protection impact assessment where required, workforce participation, human oversight, training, and ongoing effectiveness checks remain with the accountable company.

Evidence to inspect

  • RACI for product, supplier, and customer
  • Risk and control register
  • Approval for operation and material changes

EU AI Act · official status

The timetable is phased—and currently in transition.

For procurement decisions, we separate milestones already in application from high-risk dates that are still moving. The applicable legal text, current official sources, and classification of the specific system remain decisive.

  1. Already applicable

    The European Commission states that prohibitions on certain AI practices and AI literacy provisions are in application.

  2. Already applicable

    The Commission states that governance rules and obligations for providers of general-purpose AI models are in application.

  3. General milestone

    The Commission identifies this date for the majority of rules and for transparency obligations. High-risk dates must be considered separately.

The Commission’s AI Act policy page, last updated on 7 July 2026, reports a political agreement reached on 7 May 2026 on the amending proposal: rules for systems in certain high-risk areas are to apply from 2 December 2027, and rules for systems integrated into regulated products from 2 August 2028. The AI Act Service Desk still displays the earlier high-risk dates while flagging the Digital Omnibus proposal. We therefore do not present those older dates as settled procurement deadlines. The political agreement, formal legal act, and current consolidated text should be checked again before a decision.

AIonicOS / NEXT REVIEW

Inspect the configuration, not the promise.

In a technical conversation, we map one operation, its data paths, roles, evidence, and contract questions. The AIonicOS overview provides the wider platform context.