Loading the catalogue…
Loading the catalogue…
Microsoft is a US-domiciled, publicly listed technology company whose Phi family of small language models is released under the permissive MIT licence with detailed model cards and training-data summaries, enabling fully sovereign self-hosting inside the EEA. As a US-incorporated entity, Microsoft remains structurally subject to the CLOUD Act and FISA Section 702 regardless of its EU Data Boundary data-residency commitments, and the company's security track record includes multiple nation-state intrusions (Storm-0558, Midnight Blizzard, Storm-2949), a 2024 US Cyber Safety Review Board finding of 'inadequate' security culture, and a year-on-year doubling of critical CVEs in 2025 — all of which EU regulated-sector customers should weigh against its comparatively strong EU AI Act compliance posture (signed GPAI Code of Practice, dedicated AI Act Trust Center) and extensive ISO/SOC certification portfolio.
Microsoft is a US-incorporated entity fully subject to the CLOUD Act and FISA Section 702; US authorities can compel disclosure of data held anywhere globally, including EU data centres, notwithstanding the EU Data Boundary.
A new nation-state-style intrusion technique, Storm-2949, turned a single compromised identity into a cloud-wide breach without malware (disclosed May 2026), adding to a pattern of prior significant intrusions (Storm-0558, Midnight Blizzard/APT29).
Critical CVEs doubled year-on-year in 2025 (78 to 157), reversing a multi-year downward trend, per the BeyondTrust 2026 Microsoft Vulnerabilities Report.
Microsoft's CTO testified in May 2026 in the Musk v. OpenAI litigation regarding internal emails about OpenAI's transition from nonprofit to for-profit structure, raising scrutiny of Microsoft's due diligence and governance practices around its central AI partnership.
Microsoft's own EU Data Boundary FAQs acknowledge that customers cannot opt out of limited cross-border transfers for global cybersecurity purposes.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Phi-4-reasoning-vision-15B was released with full model weights, fine-tuning code, and benchmark evaluation logs under a permissive MIT licence, continuing Microsoft's pattern of detailed technical disclosure for open-weights releases.
Microsoft signed the full GPAI Code of Practice in August 2025 and maintains a dedicated EU AI Act Trust Center page, among the stronger EU AI Act compliance signals from a major model producer.
The Phi family continues active development and public release under the MIT licence through 2026, enabling fully sovereign EEA self-hosting without any dependency on a Microsoft-run inference endpoint.
Microsoft's Digital Crimes Unit disrupted the StealC and Amadey malware infrastructure in June 2026, and the company maintains a transparent public incident-response blog documenting attacker techniques and defensive recommendations.
Published safeguards & certifications