4 minute read

Where does the AI run? The first question to ask your CTRM vendor

Every CTRM vendor now claims AI. We’ll be asking a few vital questions about those claims, starting with the most important.

Most Commodity Trade and Risk Management (CTRM) platforms now come with an AI story. Demonstrations are easy to arrange and the features look similar from the outside: document reading, faster capture, assistants in the workflow. What separates the platforms sits underneath, in architecture a demonstration never shows.

Over the coming weeks we are publishing questions that surface that architecture. Each one can be put to a vendor in a meeting. Each has answers that tell you more than the feature list does. This is question one, and the rest of the series depends on it.

Why this question comes first

AI in commodity trading is only useful if it can read the data that matters: contracts, prices, positions, P&L, counterparties and internal workflows. That data is the commercial edge. So before any discussion of accuracy, features or roadmap, one architectural fact sets the terms of everything else.

Where does the model run?

The answer determines who else can reach your data, which jurisdiction applies to it and whether your access to the tool is a decision your firm makes or one made for it. The Fable 5 shutdown in June made that last risk visible: a working model, withdrawn worldwide by a policy decision in one country. Firms whose AI runs on infrastructure they control were unaffected.

When you ask the question, you will hear one of three answers.

“On our cloud platform”

The most common answer, and the most honest of the weak ones. Your data leaves your perimeter, is processed on the vendor's infrastructure and sits under the vendor's jurisdiction. The contract will promise segregation and no training. The architecture still places your commercial edge on systems someone else owns, governed by law you did not choose.

Worth pressing: where is the data physically processed, who holds the encryption keys and what, exactly, leaves your environment on each request?

“On a hyperscaler, in your region”

This answer sounds like sovereignty. A named provider (AWS, Azure or GCP), servers in your country, a regional data residency commitment.

Physical location and legal jurisdiction are different things. A US-headquartered provider can be compelled to disclose data held in European data centres under US legal orders, whatever the servers' postcode. For a trading firm operating across regulated markets, that gap between where the data sits and which law reaches it belongs in the risk register, next to counterparty and settlement exposure.

Worth pressing: which legal entity operates the infrastructure, and under which jurisdiction could disclosure be compelled?

“Inside your environment”

The third answer reverses the flow. The AI comes to the data.

This is the answer Euclid gives. Euclid deploys on client-owned infrastructure or inside Euclid's private Swiss data centre, connected directly to the CTRM, with no US hyperscaler dependency. The model runs where the data already lives.

Inside that environment, Euclid AI does three things today. It processes trading documents: drop a contract, invoice or confirmation into the integrated chat and the AI returns structured, populated fields for review, cutting an eight minute manual entry to under ten seconds. It ingests market data, parsing high, low and mean prices from daily PDF reports for automatic database updates. And it provides contextual platform support, answering questions from the platform's technical documentation so new users get up to speed faster.

Every step is traceable and a person commits every trade. The intelligence accelerates the work while the data stays inside the perimeter.

What a clear answer sounds like

A vendor that has thought about this question can name where the model runs, who owns the hardware, which jurisdiction applies and what leaves your environment. The answer takes thirty seconds and survives a follow-up.

A vague answer (”secure cloud”, “enterprise-grade infrastructure”) tells you the architecture was designed around the vendor's convenience. Your control came second. That is an answer too.

Question two follows next week.

Request a sovereign AI walkthrough.

Ready to regain control and value?

Join the trading firms moving to a smarter, sovereign platform.

Ready to regain control and value?

Join the trading firms moving to a smarter, sovereign platform.