# What this story covers amazee.io and amazee.ai will highlight shadow AI and sovereign infrastructure at DrupalCon Rotterdam. Their session, From Shadow AI to Sovereign AI Infrastructure, features Thomas Schröpfer (amazee.ai) and Hank VanZile (Tag1). The companies are framing AI as an infrastructure problem once organisations need to track data flows, control which models are used, and manage spending.
# Why Drupal teams care Organisations that move beyond proof-of-concept AI face practical questions: where does organisational data go, which model versions are approved, how are costs monitored, and who retains control when AI is embedded in production workflows? Katy Walsh, marketing lead at amazee.io, says privacy, compliance, cost management, and observability are rising priorities as Drupal users adopt AI beyond simple content generation.
# The proposed control point: a private AI gateway amazee.ai describes a private gateway that acts as a single, managed layer between applications and multiple model providers. Key features documented by amazee.ai include:
- An OpenAI-compatible API that exposes multiple third-party models so applications don't need separate integrations for each provider.
- API keys tied to a workspace and a region, enabling budget and spending controls scoped by workspace, region, user, and key.
- Regional endpoints (examples listed: Switzerland, Germany, United States, Australia, United Kingdom) to help organisations align requests with regional data requirements.
These elements are presented as characteristics of amazee.ai's platform, not as universal guarantees for every deployment.
# What a gateway does and does not solve A gateway reduces the number of integration points and provides centralised controls for access and spending. It can make it easier to enforce which models are available to teams and to restrict regional paths for requests.
However, a gateway alone does not remove all governance responsibilities. Organisations still need to: assess the model provider's policies and practices, confirm contractual controls, verify data paths through client applications and any intermediary systems, and determine whether the provider's non-retention claims meet compliance requirements.
# Shadow AI as the starting problem Thomas Schröpfer frames shadow AI as unsanctioned or unmonitored AI tooling adopted inside organisations without standard governance. He warns this can create uncertainty about data leaving the organisation, which services are being used, and uncontrolled costs. The session will use the private gateway concept to show one way to regain visibility and control.
# Why this matters at DrupalCon
# Practical next steps for teams
- Inventory where teams are already using AI and which tools are unsanctioned.
- Map data flows to see where prompts and responses traverse external services.
- Evaluate gateways or centralised access layers for unified billing, regional endpoints, and audit logs.
- Review contracts and provider retention policies to confirm compliance for your jurisdiction.
# Session details From Shadow AI to Sovereign AI Infrastructure — Open Stage, 29 September, 14:25–15:10 CEST.