AI · · ⏱ 6 min read

Lumo and sovereign AI

Proton's AI assistant proposes another way to build AI: no mass collection, no centralised infrastructures, and European sovereignty.

In a context where artificial intelligence generates fascination and, often, deep algorithmic distrust, the appearance of Lumo, Proton’s AI assistant, offers a clear alternative and a new design paradigm centred on the user and digital autonomy. It shows that it is possible to develop intelligence without sacrificing privacy, without depending on centralised external infrastructures and without mass collection of user data, directly addressing the algorithmic trust crisis.

Far from competing on power or spectacle, Lumo positions itself as a model of technological sobriety, centred on principles that today are differential: privacy by design, digital sovereignty and local control. And although it still has limitations, its approach could set the direction for a new generation of European AI services, laying the foundations for ethical AI frameworks.

A small hilltop fortress with an open door
A fortress does not protect only what it encloses: it protects what it lets in.

What is Lumo? An ephemeral and sovereign AI architecture

Launched in July 2025 by Proton, the Swiss company known for Proton Mail and Drive, Lumo is a conversational assistant based on open-source Large Language Models (LLMs) like Mistral or LLaMA, hosted entirely in European data centres.

Its features distinguish it, embodying fundamental tech-ethical principles:

Ghost Mode (data transience) — Conversations are not stored (free version) or are deleted after the session (paid version). This principle of data transience is a direct response to the digital right to be forgotten and data minimisation, ensuring user information has a defined and limited useful life, minimising the risk of long-term exposure.

Zero-Access Encryption — Not even Proton can access the messages. This refers to a secure communication system where only the users communicating can read the messages, and decryption keys are under the user’s exclusive control, not the service provider’s. It is a fundamental pillar of data autonomy and confidentiality.

European infrastructure — No transfer to US or China servers. Data residency in Europe and infrastructure sovereignty ensure regulatory alignment with GDPR and AI Act, avoiding extraterritorial jurisdiction and protecting data under European laws.

Integration with Mail and Drive — Without leaving the secure environment. This contextual integration promotes efficiency without compromising security, keeping user control over their data within a trust ecosystem.

Hybrid model — Open source + local training. Combines the flexibility and transparency of open source with the adaptation and customisation of local training, optimising performance without externalising sensitive data management.

Why it matters: Lumo as a case study in ethical AI

Lumo represents a strategic vision of ethical AI in regulated contexts and is a case study in the application of ethical principles in a productive environment. Its appearance coincides with the implementation of AI Act, Data Act, DORA and NIS2, demonstrating the viability of effective algorithmic governance.

Algorithmic governance: the set of policies, standards and mechanisms to supervise and regulate the design, development and deployment of artificial intelligence systems, ensuring their responsibility, transparency and alignment with ethical and legal values.

It shows that privacy is not incompatible with AI. And it does so in real production, with active users, setting a precedent for the practical implementation of ethics by design.

Lumo vs. ChatGPT: tech-ethical implications

AspectLumo (Proton)ChatGPT (OpenAI)
ApproachPrivacy and sovereigntyVersatility and power
ModelsOpen sourceProprietary (GPT-3.5/4)
HostingEurope (own data centres)US (Azure)
StorageGhost Mode / limited (7 days)Saved by default
Data usageNot used for trainingUsed unless opted out
CostLimited free / Plus versionFree / Plus / Enterprise

This comparison highlights not only technical differences but also the deep tech-ethical implications of each approach. While ChatGPT prioritises versatility and power through proprietary models and centralised infrastructure (with the consequent risks of data centralisation and algorithmic biases inherent in opacity), Lumo emphasises privacy resilience and the democratisation of AI access through open-source models and distributed architecture.

Critiques and challenges from tech ethics

Even when Lumo strictly complies with the European framework, it is crucial to address its critiques and challenges from a tech-ethical perspective to foster continuous improvement and transparency.

Lack of transparency about complete architecture — Although Lumo uses open-source models, the complete system architecture may not be fully transparent. This algorithmic opacity raises challenges for external auditability and developer responsibility. From a tech-ethical perspective, the lack of complete visibility makes it difficult for third parties to verify the absence of hidden biases or security vulnerabilities.

Zero-Access ≠ real E2E encryption — The “Zero-Access” claim is powerful, but the distinction with “real” E2E encryption (where keys are managed exclusively by the user) is fundamental. If Proton retains any access capability under certain conditions (even remote or theoretical), this could create a trust gap.

History in the free version (7 days) — Although limited, storing history for 7 days slightly contradicts the “Ghost Mode” no-storage principle. Every data retention decision must be justified and communicated with complete clarity.

Lower fluency and creativity vs. GPT-4 — An inherent challenge to prioritising privacy and using local resources. It is a dilemma between algorithmic utility and data protection, where Lumo opts for a compromise that favours ethics.

Partially closed stack — Despite being based on open-source models, if the underlying stack is partially closed, this could introduce vendor dependency and limit the community’s ability to inspect and contribute to its development.

Digital sovereignty as opportunity

Europe drives technological sovereignty with auditable models, distributed infrastructures and ethical data management. Lumo is a clear example that AI can be useful without being intrusive.

Digital sovereignty is not just a matter of control, but of trust construction, promotion of ethical competition and protection of fundamental digital rights, laying the foundations for a fairer digital social contract.

Recommendations for engineers and developers

For those seeking to build responsible AI systems, Lumo offers valuable lessons and a path to follow in ethical software engineering:

Integrate LLMs in local containers (Docker, MCP) — Deploy language models in controlled and isolated environments to guarantee data residency and minimise exposure to external infrastructures.

Build data copilots working on local schemas — Develop AI assistants that process and analyse data directly on the device or on local servers, ensuring privacy by design.

Apply Ghost Mode-style anonymisation logic — Implement anonymisation and data transience techniques to limit the useful life of personal information.

Use vector databases like Qdrant or ClickHouse for private semantics — Employ vector databases optimised for semantic search in local environments.

Design systems aligned with AI Act, GDPR and NIS2 — Integrate algorithmic governance principles and European regulatory requirements from the design phase.

A new contract with intelligence and human dignity

Lumo is not just an assistant; it is a production model of how ethical and sovereign AI can be built. Instead of capturing attention and data, Lumo proposes an AI that serves without invading, redefining the digital social contract between the user and technology.

Building systems that respect people is not a utopia, but a fundamental design decision. And Proton has shown that it is possible, marking a path towards a more equitable and dignity-respecting digital future, where technology serves society without compromising its autonomy.