Souverainete numerique + AI on ERP
AI for ERP in France: Souverainete and SecNumCloud-Aligned Architecture
Short answer
French manufacturers, especially in the aerospace and defense supply chain around Toulouse, add AI to SAP, Infor LN, or Sage X3 by keeping the model and the data it touches inside France or the EU, aligned to SecNumCloud principles and reviewable under RGPD by the DSI and the DPO together. That answers the souverainete question directly instead of arguing about a US cloud vendor's contractual promises after the fact.
- ERP
- SAP S/4HANA, Infor LN, Sage X3
- Industries
- Aerospace, Defense, Manufacturing
- Written for
- DSI (CIO)
Souverainete numerique is not an abstract policy debate in French manufacturing, it is a procurement requirement that shows up in supplier questionnaires, security addenda, and sometimes in the DGA's own supply chain expectations for defense programs. A DSI evaluating AI for ERP in this context has to answer where the model runs and where the data goes before any conversation about features.
SecNumCloud, the ANSSI qualification for cloud service providers, sets a high bar: French or EU legal entity, protection from extraterritorial laws like the US CLOUD Act, and specific technical and organizational controls. Very few AI model providers meet it today, which is exactly why the practical answer for AI on ERP in France is usually on-prem or a private deployment on infrastructure that is SecNumCloud-qualified or architected to the same principles, rather than a public LLM API.
The French aerospace and defense supply chain around Toulouse works under an additional layer of scrutiny: prime contractors and their tier-1 integrators run their own supplier security assessments, and a supplier that can show its AI tooling never sends technical data outside a controlled boundary has a much easier conversation than one that has to explain a US-hosted SaaS dependency. Netray does not claim relationships with any specific prime or integrator; the architecture is built to satisfy the general class of requirement this supply chain applies to its suppliers.
RGPD (the French application of GDPR) and CNIL guidance add a second, related constraint on top of souverainete: any personal data processed by an AI layer - HR, customer, supplier contacts - needs a documented lawful basis and, for anything novel, a DPIA (analyse d'impact relative a la protection des donnees). An architecture that keeps processing inside France or the EU simplifies both the souverainete and the RGPD conversation at the same time, because they point to the same answer.
What usually gets in the way
The problems we hear most from dsi (cio) teams running SAP S/4HANA.
Souverainete requirements in supplier questionnaires
Prime contractors and defense customers increasingly ask suppliers directly where their tools, including AI, process data, and a US-hosted LLM API is a difficult answer to defend in that conversation.
Very few AI vendors are SecNumCloud-qualified
The ANSSI qualification process is demanding and slow, so most AI infrastructure a French manufacturer could buy off the shelf simply is not qualified, forcing a choice between waiting, compromising, or building on infrastructure architected to the same principles.
Mixed ERP landscape across sites
French manufacturers, particularly in aerospace supply chains, often run SAP at one site, Sage X3 at another after an acquisition, and sometimes Infor LN in an engineer-to-order division, which makes a single AI layer harder to design than a single-ERP shop.
RGPD and CNIL scrutiny of automated processing
CNIL has been active on AI-specific guidance, and any AI system touching customer, supplier, or HR data in an ERP needs a clear lawful basis and, in many cases, a DPIA before go-live, not as an afterthought.
Export control overlay on top of data protection
Where products or technical data fall under French or EU dual-use export control rules, the AI layer has to respect the same access segregation the company already applies to that data in the ERP, not create a new path around it.
Where AI earns its place in SAP S/4HANA
Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.
Quality nonconformance and 8D drafting
Drafts nonconformance reports and 8D structures from a quality engineer's description, pulling part, batch, and supplier history from SAP QM or the equivalent Sage X3 quality function.
Touches: SAP QM notifications, Sage X3 nonconformance functions, batch and vendor master data
Outcome: cuts the time to a usable first draft from most of a day to under an hour for routine defects
Production order exception triage
Surfaces the production orders that actually need attention today across MRP or scheduling exceptions, instead of a planner reviewing every open order line by line.
Touches: SAP MD04, Sage X3 GESSOP production order functions, Infor LN whinh work order sessions
Outcome: planners work the real exception list in a fraction of the time spent scanning full order lists
Purchase order follow-up
Handles routine supplier confirmation follow-up automatically and escalates only genuine delays or missing confirmations to the buyer.
Touches: SAP ME2N open PO reports, Sage X3 purchase order functions, vendor confirmations
Outcome: buyers spend follow-up time on real exceptions instead of routine status chasing
Engineering change impact assessment
Given an ECO/ECN, lists the open orders, affected BOMs, and routings it touches across the ERP so engineering and production can sequence the change without a manual cross-check.
Touches: BOM and routing tables, open sales and production orders, ECO/ECN records
Outcome: cuts the manual cross-check time for a change's downstream impact from hours to minutes for routine changes
Natural-language reporting across sites
Lets a plant or program manager ask a question once and get an answer grounded in whichever ERP that site runs, without needing to know the underlying transaction codes or table names.
Touches: SAP CDS views, Sage X3 BI cubes and Crystal Reports, Infor LN Business Object Documents
Outcome: fewer one-off report requests land on a stretched central reporting team
Traceability and lot genealogy queries
Answers 'where did this part go' or 'what batch was used in this shipset' questions instantly, pulling lot and serial genealogy that would otherwise take a manual trace across modules.
Touches: batch/lot records, serial number tracking, shipment and delivery data
Outcome: cuts trace-and-recall research time from hours to minutes for a typical genealogy question
Export control access review support
Helps compliance staff review who has access to controlled technical data in the ERP against the roles that should hold it, flagging discrepancies for human review rather than auto-remediating.
Touches: ERP role and authorization assignments, document classification metadata
Outcome: a faster, more consistent periodic access review that a small compliance team can actually keep up with
Reference architecture
The architecture is built around one principle: nothing about the model, the retrieval index, or the ERP connectors requires data to leave France or the EU, and every layer is documented in terms a DSI can present to an ANSSI-minded security reviewer.
- 1
ERP connectors
OData/BAPI/IDoc for SAP, the Sage X3 Web Services API or direct database views for Sage X3, and ION API or BODs for Infor LN, each read-only by default.
- 2
Data and semantic layer
A unified semantic layer that normalizes terms across the different ERPs a multi-site company runs, plus a document index over quality manuals and technical instructions kept in the same boundary.
- 3
Model serving
An open-weight model served on GPUs the company owns or on infrastructure in France or the EU architected to SecNumCloud's principles, with no default path to a non-EU model API.
- 4
Retrieval and agents
RAG grounds answers in current ERP and document data; agents that propose a write, such as a PO follow-up, wait for human confirmation before anything touches the ERP.
- 5
Governance and audit
Query and response logs mapped to ERP roles support both the RGPD registre des activites de traitement and any supply chain security review a customer requests.
Integration notes for your ERP team
- SAP: OData services via SAP Gateway, BAPI/RFC, and IDoc, read-only by default, write-back only with human approval per transaction.
- Sage X3: the Web Services / Syracuse API layer for transactional access, or direct read access to X3 database views for reporting-style use cases.
- Infor LN: ION API and Business Object Documents (BODs) for transactional and event data, consistent with how LN already exposes data to other integrations.
- A shared identity layer maps each user's existing ERP role to what the assistant can see, so a Sage X3 buyer and an SAP buyer at a different site each see only their own scope.
- All model inference and retrieval indexes are hosted in France or the EU; there is no default outbound call to a non-EU API for any part of the pipeline.
- Document sources (quality manuals, work instructions, technical specifications) are indexed in the same boundary as the ERP data, not in a separate SaaS tool outside the company's control.
Deployment options
Air-gapped on-prem
Defense-adjacent suppliers and sites handling export-controlled technical data
The full stack runs inside the company's own network boundary in France with no outbound internet path, matching the strictest supplier security addenda without relying on a third party's attestation.
Private, France or EU-hosted cloud
Manufacturers without in-house GPU operations who still need to satisfy souverainete requirements
A dedicated instance on infrastructure located in France or the EU and architected to SecNumCloud principles, avoiding both non-EU jurisdiction exposure and the capital cost of owning GPU hardware.
Hybrid across sites
Multi-site groups running SAP at one plant and Sage X3 or Infor LN at another
A shared governance and model-serving layer with site-specific connectors, so each site's ERP is read through its native interface while the AI experience and audit trail stay consistent group-wide.
Compliance and data control
How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.
SecNumCloud principles (ANSSI)
The architecture avoids non-EU processors by design and is built to be evaluated against SecNumCloud's technical and organizational criteria, even where full formal qualification of every component is not yet in place.
RGPD / CNIL guidance
A documented lawful basis and, where the use case is novel, a DPIA are prepared before go-live, and the audit log doubles as input to the registre des activites de traitement.
French and EU dual-use export control
Access to controlled technical data through the AI layer mirrors the ERP's own role-based restrictions rather than creating a new, broader access path.
DGA supply chain expectations
For defense-program suppliers, the on-prem or in-France deployment model and full audit trail are designed to be presentable in a customer security review without relying on a third-party vendor's own certifications as the only evidence.
Where Netray fits
ERPray
For a multi-site group running SAP, Sage X3, and possibly Infor LN, ERPray's connector-based, read-only question-answering model is the fastest way to give a consistent AI experience across different ERPs.
DataRay
Where technical documentation, quality manuals, and file shares sit outside the ERP but need to be searchable alongside it, DataRay extends the same on-prem, France/EU-hosted approach to those sources.
Custom build
Site-specific workflows like the engineering change impact assessment often need custom logic tailored to how a given plant's ERP and PLM are configured.
How an engagement runs
Phase 1 . 2-3 weeks
Discovery
- -Inventory of which ERP each site runs and how it exposes data today
- -Souverainete and export-control requirements gathered from security and compliance stakeholders
- -Use case shortlist ranked by effort and impact per site
- -Deployment sizing for on-prem GPU or France/EU private cloud
Phase 2 . 6-8 weeks
Pilot
- -One use case live in read-only mode at a single site
- -Model evaluation against real ERP and document data from that site
- -Draft DPIA and registre des activites de traitement entry for the pilot
- -Security review package prepared for internal or customer supplier assessment
Phase 3 . 6-10 weeks
Production
- -Hardened deployment with role-based access tied to each site's ERP roles
- -Full audit logging integrated with existing security monitoring
- -Finalized DPIA and compliance documentation
- -Runbook covering model updates and incident response inside the France/EU boundary
Phase 4 . Ongoing
Scale
- -Rollout to additional sites, including different ERPs under the shared governance layer
- -Additional use cases from the original shortlist
- -Periodic access review process handed to the compliance team
- -Quarterly review of model options as the open-weight landscape evolves
Questions to ask any vendor, including us
A short list that separates real SAP S/4HANA AI work from a chatbot demo.
- Where exactly does the model run, and can that location be confirmed in writing, not just claimed in a sales deck?
- Is the infrastructure SecNumCloud-qualified, or architected to the same principles without formal qualification, and what is the difference in practice?
- Does any part of the pipeline call a non-EU API by default, even for a secondary function like embeddings?
- Can we produce a DPIA and registre des activites de traitement entry from the vendor's own documentation of the system?
- How does the tool respect our existing export control access segregation rather than creating a new access path?
- If we run this across SAP, Sage X3, and Infor LN sites, is the governance and audit experience the same across all three?
- What happens to our data and configuration if we end the engagement?
Frequently asked questions
What does souverainete numerique actually require from an AI system on our ERP?
There is no single legal definition, but in practice it means the model, the data it processes, and the infrastructure it runs on stay under French or EU jurisdiction, free from foreign laws like the US CLOUD Act that could compel disclosure. The practical way to satisfy it is on-prem deployment or a private instance hosted in France or the EU using an open-weight model, rather than a public API from a non-EU provider.
Is SecNumCloud qualification required to sell AI tooling to French manufacturers?
Formal SecNumCloud qualification is only mandatory for specific public-sector and some defense procurements, but many private manufacturers, especially in the aerospace supply chain, treat it as a strong signal of trust even when not contractually required. Architecture that follows SecNumCloud's principles, EU-only processing, no extraterritorial exposure, strong access control, is worth building to even before or without formal qualification.
Can this work across SAP, Sage X3, and Infor LN if we run different ERPs at different sites?
Yes. Each ERP is read through its own native interface, SAP via OData/BAPI, Sage X3 via its Web Services API, Infor LN via ION API and BODs, and a shared semantic and governance layer sits on top so users get a consistent experience regardless of which ERP their site runs.
Do we need a DPIA before deploying AI on our ERP data?
If the AI system processes personal data in a way that is novel for the organization, which most first AI-on-ERP deployments are, RGPD generally expects a DPIA (analyse d'impact relative a la protection des donnees) before go-live. Keeping processing inside France or the EU and logging exactly what the system accesses makes that DPIA considerably easier to write and defend.
How does this help with export-controlled technical data?
The AI layer mirrors the access restrictions already configured in the ERP rather than introducing a new, broader path to the same data. A user who cannot see certain technical data or documents in SAP or Sage X3 today cannot see them through the assistant either, and access reviews can use the same audit log for both.
Is this realistic for a mid-size tier-2 or tier-3 aerospace supplier, not just a prime contractor?
Yes, and the sizing question usually matters more than the company's tier in the supply chain. A single-site, single-ERP supplier can run a modest on-prem GPU setup or a small private-cloud instance; the architecture principles, EU-only processing, read-only by default, human approval on writes, scale down as easily as they scale up.
Does using a US-founded open-weight model like Llama conflict with souverainete goals?
No, provided the model weights are downloaded and run entirely on infrastructure you control in France or the EU, with no outbound calls to the model provider. Souverainete is about where processing happens and who can compel access to it, not about the nationality of the organization that originally trained the model.
Related guides
AI for ERP in UK Defence Manufacturing: On-Prem, DEFCON 658-Aware
On-prem AI for ERP built for UK defence suppliers: aligned to DEFCON 658, Cyber Essentials Plus, UK GDPR, and JOSCAR accreditation expectations.
European defence supply chain AIOn-Prem AI for European Defence and NATO Supply Chain Manufacturers
AI grounded on SAP, IFS, or Infor LN for NATO and EDF supply chain manufacturers, kept inside the accredited network boundary your ERP already sits in.
EU AI Act + ERP AI systemsEU AI Act Compliance for AI Built on Your ERP
How the EU AI Act's risk classes, documentation, and timeline apply to AI copilots and agents on ERP systems, and what compliance officers need in place.
GDPR + AI on ERP dataBuilding GDPR-Compliant AI on Top of Your ERP
Design AI on ERP data that satisfies GDPR: lawful basis, DPIA, data minimisation, and an on-prem architecture that avoids the Schrems II transfer problem.
SAP S/4HANA + private AIAI for SAP S/4HANA, Running On-Prem or in Your Private Cloud
Run AI on SAP S/4HANA without sending ERP data to a public API. On-prem and private-cloud architecture, CDS views, OData, and honest deployment trade-offs.
Sage X3 + private AIAI for Sage X3, Grounded in Your Own Ledgers and Stock Data
Add AI to Sage X3 finance and stock data without exporting it to a public model. On-prem and private-cloud LLMs for Sage X3 in the UK and France.
Plan it with numbers
Sovereign AI Readiness Assessment
Score your organization across eleven dimensions of sovereign AI readiness, from data residency and model provenance to cleared personnel and air-gapped operations.
Free ToolAir-Gapped AI Readiness Assessment
A 10-question assessment that scores how prepared your organization is to deploy and operate LLMs inside an air-gapped or classified enclave.
Free ToolAI Data Sovereignty Risk Assessment
Score your organization across eight dimensions of AI data sovereignty risk, from inference location and encryption key custody to subprocessor visibility and audit readiness.
GuideEU AI Act Implications for On-Prem AI Deployments
EU AI Act implications for on-prem deployments: risk tiers, high-risk obligations, and how self-hosted models simplify enterprise compliance.
GuideERP GDPR Data Protection Compliance Guide
Achieve GDPR compliance in ERP systems with data mapping, consent management, right-to-erasure implementation, and data protection impact assessments.
GuideAI Governance for Export-Controlled Data (ITAR/EAR)
AI governance for export-controlled data: policies, access controls, and audit trails that keep ITAR and EAR data out of public LLMs and off foreign servers.
Talk it through with an engineer who knows SAP S/4HANA
Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.