Loading the catalogue…
Loading the catalogue…
NVIDIA Corporation is a US-incorporated, publicly listed technology company headquartered in Santa Clara, California, that designs AI accelerators and publishes AI models — including the open-weights Nemotron family — under a mix of custom NVIDIA licences and proprietary terms via its NIM microservices stack. As a US entity it is fully exposed to CLOUD Act and FISA Section 702 compelled-disclosure obligations, and hosted inference through build.nvidia.com routes through US infrastructure, though NVIDIA does publish a Cloud Services DPA incorporating EU Standard Contractual Clauses and holds ISO 27001/27017/27018 and SOC certifications. EU regulated-sector customers should note ongoing antitrust scrutiny from the US DOJ, French competition authority, and US senators over recent chip-supply deals, alongside an unconfirmed EU AI Act Code of Practice signatory status.
NVIDIA is US-incorporated and headquartered, making it fully subject to CLOUD Act and FISA Section 702 compelled-disclosure obligations; data processed via NVIDIA-hosted AI services (build.nvidia.com, DGX Cloud) is potentially accessible to US authorities.
Active, concurrent antitrust scrutiny across the US (DOJ subpoenas since 2024), France (Autorité de la Concurrence investigation following a 2023 raid and a 2024 dominance-abuse finding), and recent US Senate questions (March 2026) about a chip-supply deal with Groq possibly structured to avoid antitrust review.
NVIDIA's GPAI Code of Practice signatory status could not be confirmed; if not a signatory, it must demonstrate EU AI Act compliance via alternative means ahead of full enforcement from August 2026.
2022 LAPSUS$ ransomware breach resulted in exfiltration of approximately 1 TB of internal data, including employee credentials and proprietary source code — a historical but material incident.
NVIDIA uses custom, non-standard licences (NVIDIA Open Model License) for most open-weights models, and production NIM microservice deployment requires a commercial NVIDIA AI Enterprise licence, creating commercial dependencies for regulated-sector deployers.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
NVIDIA's AI Trust Center confirms ISO 27001, ISO 27017, ISO 27018, ISO 50001, SOC (SSAE 18), SIG Lite, and TISAX certifications, updated as recently as June 2026.
NVIDIA publishes a Cloud Services Data Processing Addendum incorporating EU Standard Contractual Clauses and UK IDTA for cross-border data transfers.
NVIDIA operates an active, coordinated Vulnerability Disclosure Program via the Intigriti platform (launched October 2025), supplementing its PSIRT.
NVIDIA publishes open model weights, model cards, and training data descriptions for the Nemotron family on its HuggingFace organisation page.
NVIDIA has exceptional leadership continuity, with CEO Jensen Huang having held the role continuously since co-founding the company in 1993.
Published safeguards & certifications