visibus Blog
Made in Germany, owned in Delaware: What the Langdock case reveals about your AI

by Lubomira Schmid · June 29, 2026 · 5 min read
This month a story went around the AI industry that sounds technical at first glance and, on a second look, concerns every management team. The Swiss lawyer Martin Steiger went public with the fact that an AI service widely perceived as German - Langdock, with around 33,000 users across more than 7,000 companies - is wholly owned by an American parent company based in Delaware.
Let's say it up front, because it matters: this is not a scandal. A US parent company is nothing unusual for internationally funded start-ups - in this case a standard requirement from the investors. And Steiger, too, is explicitly not out to paint "the US as the villain" but to make a point about transparency: a service that is perceived as German should disclose who controls it.
The case is interesting nonetheless - because it exposes a thinking error we hear again and again in conversations with companies. One observer put it well: Langdock isn't a scandal, Langdock is a mirror. The case doesn't show that a vendor did something wrong. It shows that we all ask the same question far too rarely.
The Two Questions That Get Confused
When it comes to AI and data, the discussion usually settles quickly with three sentences: "The servers are in Europe." "They don't train on our data." "The service is GDPR-compliant." All three matter. And none of them answers the real question.
Because these are two different things. Compliance answers whether the data processing is organized cleanly in legal terms - contracts, hosting location, records of processing. Control asks something harder: who actually owns the vendor - and who decides when it gets sold tomorrow, relocates its headquarters, raises prices, or changes access?
An entry in the commercial register doesn't answer that. Nor does a data center in the EU. Both can be entirely clean while the decision-making power sits somewhere else entirely.
Why the Server Location Isn't the Whole Answer
That "stored in Europe" and "under European control" are not the same thing is something even Microsoft had to admit publicly in 2025. Before the French Senate, the company was asked under oath whether it could guarantee that data stored in the EU would be kept from US authorities. The answer was no - it could not guarantee it.
The reason is the ownership and legal chain behind it. Steiger frames this carefully in legal terms for the Langdock case: a US parent alone does not mean an automatic outflow of data to the US. What matters is whether the parent company can legally or technically compel the subsidiary to hand over access to user data - the "possession, custody, or control" criteria. That is exactly why the ownership question is not a formality but the core: it decides who has the upper hand when it counts.
Sovereignty Doesn't Mean Doing Without - and Here It Gets Honest
This is where the debate often tips into the unrealistic: "sovereign" gets equated with "just no US vendor, no US model anymore." That sounds consistent, but it's usually expensive, technically demanding, and costs exactly the quality you introduce AI for in the first place. The industry association Bitkom puts it well: sovereignty means self-determination, not autarky - the ability to choose between alternatives, not the obligation to build everything yourself.
And because we don't want to fool anyone: this applies to us too. visibus also uses leading AI models, many of which come from the US and are accessed through an interface. Anyone who claims that this dependency simply disappears with them is setting exactly the trap this is all about. The honest question isn't "does someone use US models?" - it's "do you keep control and the choice?"
Where visibus Actually Takes a Different Approach
That's exactly where visibus Chat comes in - starting with us, not just with the model:
- With the vendor. visibus is a Swiss GmbH in the hands of its founders, with no foreign parent company that could sell, relocate, or change access tomorrow. That's the question the Langdock case raises - and we answer it about ourselves first.
- With the environment. Your instance runs in the EU or Switzerland, separated per customer and with no training on your data, contractually agreed. We evaluate usage and budget in aggregate - the conversations themselves are yours.
- With the power to switch. Which model does the computing today is secondary. What matters is that you're not tied to a single provider that can change prices, access, or availability overnight. The models are interchangeable - a strong model for quality today, a European one or, on request, a local one as a fallback lane.
- With the infrastructure, if needed. Anyone who wants full authority over operations runs visibus Chat on their own environment.
That doesn't make the individual AI call to a US model "sovereign" - that would be exactly the mislabeling game the Langdock case exposes. But it shifts control to where you actually need it: to ownership, location, data storage, and the freedom to switch at any time.
The Test for Your AI Vendor
If you ask only two questions of your AI tool, ask these: Who owns the vendor behind it - and how quickly could we get out again if we had to?
The answer isn't in the privacy notice. It's in the ownership and the architecture. An EU label is a good start. It just isn't the whole answer.
These questions can be answered - best of all on a concrete use case from your own company. We'd be glad to show you how visibus Chat solves it: who owns what, where your data sits, and how quickly you could switch models. Write to us and we'll look at it together.