Weekly digest

Who is exposed when GPAI enforcement starts in August?

GPAI enforcement nears, CADA reframes cloud sovereignty, and Cohere ships Apache-2.0 weights; LLM Radar flags EU deployment exposure.

Three changes matter this week. LLM Radar added no new model or provider entries between 2026-06-02 and 2026-06-09, but the deployment context moved: GPAI enforcement is now close enough to affect vendor review, CADA reframes cloud sovereignty, and Cohere has put a permissive coding model into the open-weight lane.

LLM Radar's read is simple: August is not only a frontier-lab problem. The exposed parties include API providers, European wrappers around upstream models, and regulated teams treating open-weight deployment as automatically sovereign.

What's new

No new LLM Radar model entries, provider entries or formal re-reviews landed in the 2026-06-02 to 2026-06-09 window. The editorial lead is therefore outside the database: the Commission moved cloud sovereignty from procurement language into proposed legislation, while Cohere Labs released North Mini Code, a permissive open-weight coding model that deserves a licence and hosting read before tracker inclusion.

Cohere Labs described North Mini Code on 2026-06-09 as a 30B-parameter MoE coding model with 3B active parameters for agentic software engineering, released on Hugging Face under Apache 2.0. The licence posture is the easy part. Apache 2.0 is permissive and clean enough for most commercial engineering teams to understand without a special negotiation.

The verdict here is Conditional until deployment paths are mapped. A permissive licence does not decide hosting jurisdiction, log retention, subprocessors, DPA availability or whether personal data leaves the EEA. For teams already using Cohere API, the relevant question is not only model quality. It is whether the runtime path is Canadian, US, EU or self-hosted, and whether the processor chain is defensible for European personal data.

Comparable deployment paths to check once North Mini Code is packaged include self-hosting, Hugging Face Inference Endpoints with EU region controls, and EU infrastructure providers able to run weights without third-country transfer. LLM Radar will not treat open-weight as automatically EU-ready. Open weights help licence clarity; they do not replace evidence on jurisdiction and operations.

Re-reviewed this week

No LLM Radar verdict changed in the supplied data for 2026-06-02 to 2026-06-09. That said, the soft re-review queue is now obvious: cloud-hosted providers should be checked against the Commission's proposed sovereignty assurance model under the Cloud and AI Development Act.

The defensible editorial move is to treat CADA as context, not yet as a hard verdict rule. As of 2026-06-09, it is still a proposal, and Parliament and Council negotiations may change the operating text. We do not require readers to agree with that caution; we require that both sides are visible. The counter-argument is that sensitive-sector buyers will start using the proposed language immediately in procurement, even before formal adoption.

For LLM Radar, the next review pass should test whether existing claims map to the emerging framework:

ProviderCurrent review pressureLLM Radar read
Scaleway Generative APIsEU hosting and sovereignty claims need mapping to CADA languagePotentially EU-ready where contracting, runtime and subprocessors remain inside a defensible EU posture
OVHcloud AI EndpointsSame question: EU location, control, dependency and supply chainStrong candidate for re-review once assurance levels become clearer
Mistral APINatural EU baseline for provider headquarters, infrastructure posture and AI Act obligationsDefensible comparison point for non-EU hyperscaler routes

The important distinction is between data location and control. EU location alone may satisfy a basic residency screen. It does not answer foreign control, operational dependency, software supply-chain transparency or incident response.

Outside LLM Radar

The Commission proposed the Tech Sovereignty Package on 2026-06-03, including the Cloud and AI Development Act, Chips Act 2.0 and an EU Open Source Strategy. CADA proposes a single EU-wide framework to assess cloud and AI sovereignty and sets a target to at least triple EU data-centre capacity within five to seven years.

The key LLM Radar angle is jurisdictional evidence. A provider saying "hosted in EU" is no longer enough for sensitive deployment if the buyer must also assess control, operational dependency and supply-chain transparency. That strengthens EU-ready verdicts where providers can prove EU infrastructure, accountable EU contracting and clear subprocessors. It weakens purely contractual sovereignty claims where runtime location and control remain vague.

The EU Open Source Strategy matters for open-weight models. Permissive licences become sovereignty assets only when European teams can inspect, run and maintain the stack without a foreign API dependency. North Mini Code is a useful example: Apache 2.0 supports deployment flexibility, but regulated teams still need evidence on hosting, logs, provenance and security controls.

On 2026-06-08, the Commission also welcomed a G7 cybersecurity declaration that explicitly connects LLMs and generative AI to model poisoning, data breaches, AI-assisted vulnerability discovery and AI software bills of materials. That gives security teams a public-source basis for asking vendors about model lineage, fine-tune provenance, vulnerability handling and incident response.

LLM Radar's read: the review surface is widening. GDPR paperwork still matters, but provider assessment is moving toward resilience, control and operational evidence.

Looking ahead

The next hard date is 2026-08-02. The Commission's AI Office FAQ says enforcement of full GPAI obligations with fines starts then, while models already on the market before 2025-08-02 have a separate compliance deadline of 2027-08-02.

The first exposure category is non-EU model providers serving EU customers through APIs without clear Article 53 documentation, training-data summary posture or EU-facing representative arrangements where required. The second is downstream European providers wrapping third-party models and presenting them as product infrastructure. Their GDPR posture may be documented, while upstream AI Act model documentation remains thin.

The third exposure category is open-weight deployment in regulated sectors. Permissive licensing helps, but it does not answer data residency, security controls, model provenance or post-deployment monitoring. A self-hosted model can still be Conditional if the team cannot document source, weights, fine-tune history, monitoring and incident handling.

The verdict frame for August should be strict. EU-ready only where hosting jurisdiction, GDPR posture, AI Act documentation and licence clarity are all defensible. Conditional where one dimension is documented but immature. Blocked where European personal data leaves the EU without a credible transfer, subprocessor and control posture.

Sources