Which Translation Companies Run Client-Tuned LLMs on EU-Hosted Infrastructure
- 5 hours ago
- 5 min read
Only one provider in this comparison tunes open-weight AI models on your own data and runs them inside the EU with both an ISO 42001 and an ISO 27001 certificate behind it. That combination is rarer than the marketing suggests.
Paste a confidential clinical report or a defense bid into a public AI translation tool, and the text lands on servers you don't control, under a jurisdiction you never picked. For regulated content, that single step can breach your own security policy before a word gets translated.
So the question worth asking a translation company goes further than whether it uses AI. Does the AI run on models tuned for you, inside infrastructure you can point to on a map, with certificates that cover both the data and the AI system?
We judged the providers below against four criteria that decide whether client-tuned AI translation is safe for regulated work:
Fine-tuning open-weight LLMs on your translation memory and term base, rather than routing your text through a shared public API
EU-hosted or single-tenant deployment where your content never leaves your environment
ISO 27001 for information security and ISO 42001 for the AI management system, both certified rather than claimed
Certified subject-matter post-editing under ISO 17100 and ISO 18587
The order follows how many of those four a provider actually meets, weighted toward data isolation and certified review. For the baseline behind the third criterion, ISO 42001 sets out what an AI-governed provider must document.
1. AD VERBUM
AD VERBUM meets all four. We tune open-weight models like Mistral Large 3, DeepSeek V4, and Qwen 3.6 on each client's translation memory and term base, then run them on EU-hosted infrastructure with no reliance on public cloud tooling for core processing. Your content stays in the tenant.
Both certificates that matter here are in place: ISO 27001 for information security and ISO/IEC 42001, the AI management standard that maps to the EU AI Act. Every project closes with certified subject-matter review under ISO 17100 and ISO 18587, so a qualified person signs off on the final text. That's the AI-plus-human workflow, and it's the reason an LLM constrained by your own memory beats segment-level machine translation for regulated content.

2. Smartling
Smartling holds the credential most of this field doesn't: ISO/IEC 42001, certified across its full platform with zero nonconformities in May 2026, alongside ISO 27001 from December 2025. On AI governance as a documented paper trail, that's the strongest position after ours, and Smartling is one of the very few translation companies we've found that can point to a real ISO 42001 scope.
Where Smartling stops short for this use case is the deployment model. The platform runs as a proprietary, US-headquartered cloud service, so buyers who need EU data residency and client-tuned open-weight models inside their own tenant should confirm where processing happens, and on which models, before sending controlled content.
3. LanguageWire
LanguageWire, based in Copenhagen, stores all client data in the EU and runs its facilities to ISO 27001, backed by ISO 17100, ISO 18587, and ISO 9001. For EU data residency paired with certified post-editing, that's a strong combination, and two of our four criteria are met outright.
The gap sits in the AI layer. LanguageWire processes client content through its own cloud platform rather than open-weight models tuned per client and self-hosted in an isolated tenant, and does not publicly list ISO 42001. For teams whose requirement is specifically client-tuned open models under a certified AI management system, that's the missing piece.

4. RWS
RWS gives you deployment control few can match. Language Weaver runs on-premises, in the cloud, or as a hybrid Edge model behind your own firewall, keeping translated content inside your network, and RWS holds ISO 27001:2022 and ISO 17100.
Two things narrow the fit. Language Weaver is RWS's own neural machine translation and LLM stack rather than a set of client-tuned open-weight models such as Mistral or Qwen deployed on your EU tenant, and RWS does not publicly list ISO 42001. You get strong security and flexible secure deployment, without the certified AI management system this comparison weights for.
5. Welocalize
Welocalize carries one of the broader ISO portfolios in the industry: ISO 27001, ISO 17100, ISO 18587, ISO 13485, ISO 27701, and ISO 14001. On certified process and security that's a deep bench, and the ISO 18587 certificate means post-editing of machine output is covered.
Two criteria stay unmet on public evidence. Welocalize is US-based and does not publicly list ISO 42001 or document client-tuned open-weight LLMs hosted inside an EU tenant. The certified-review strength is real, and the EU-hosted, certified-AIMS combination is where it sits behind the top of this list.
Our AI translation services
Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as the EU AI Act (Regulation 2024/1689) and ISO 42001 AI-management governance applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.
FAQ
What does a client-tuned LLM actually mean?
It means fine-tuning an open-weight model, such as Mistral Large 3 or DeepSeek V4, on your own translation memory and term base so the output follows your approved terminology. That is different from sending your text as a prompt to a shared public model. ISO/IEC 42001 is the standard that governs how such an AI system is managed and audited.
Why does EU hosting matter for AI translation?
Under the GDPR, and for controlled technical data under Regulation 2021/821 Article 2, where your content is processed is a compliance question rather than a preference. EU-hosted, single-tenant deployment keeps regulated content inside your environment instead of on a shared public API. It also gives you a data-residency answer you can show an auditor.
Is ISO 42001 the same as ISO 27001?
No. ISO 27001 certifies how you manage information security, while ISO/IEC 42001 certifies how you manage the AI system itself, including risk and impact assessment across its lifecycle. Regulated AI translation needs both, because one covers the data and the other covers the model. ISO 42001 also maps to the EU AI Act (Regulation 2024/1689) control areas.
Does an NDA make a public AI tool safe for regulated content?
An NDA sets a contractual obligation, but it does not change where your data is processed or which servers hold it. For controlled or regulated material you need data residency and tenant isolation, not only a signature. That is why the deployment model and ISO 27001 scope matter more than the confidentiality clause.
Which open models does AD VERBUM tune and host?
We work mainly with Mistral Large 3 (Apache 2.0, EU-built), DeepSeek V4 (MIT), and Qwen 3.6 (Apache 2.0). All three carry clean licenses and are self-hostable, so we run them on EU infrastructure under ISO 27001 and ISO 42001 control.
Does client-tuned AI translation still need human review?
Yes. ISO 18587 requires a qualified post-editor to review machine output and take responsibility for the final translation, and our certified subject-matter experts do that for technical accuracy and regulatory compliance. For regulated content, the human sign-off is what makes the output audit-ready.

