26 September 20269 min readGDPR & EU AI Act

Mapping local open-weight document models to PiTuKri's eleven control areas

TL;DR

  • PiTuKri is the Finnish cloud services security assessment criteria set published by Traficom, currently at version 1.1, organised into eleven control areas containing 41 requirement cards.
  • Requirement EE-02 on legislation-derived risks decides most AI document procurements, because it asks which actors can be legally compelled to access the data rather than where the data physically sits.
  • Running open-weight document models on infrastructure you control does not remove PiTuKri obligations; it moves them from a cloud provider you must trust to an environment you can inspect, with physical and operational security becoming your burden.
  • Finland has no data localisation law, and neither does the EU; demand for local processing comes from classification rules and procurement, not from a localisation statute.
  • Published benchmark scores for open document models are measured on English and Chinese corpora, so Finnish-language accuracy has to be measured on your own documents rather than assumed.

Questions people ask

Can an AI document processing pipeline pass a PiTuKri assessment?
It can be assessed, and whether it passes depends on the data classification, the processing environment and the responsible parties, not on the AI component in isolation. PiTuKri assesses a service and its operating environment against eleven control areas. An AI pipeline is simply part of that environment. The practical difficulty is usually requirement EE-02, which demands a full description of physical locations, subcontracting chains, applicable jurisdiction and every actor that could be legally compelled to access the data. Many cloud-hosted AI services cannot supply that description in a form that survives scrutiny.
Does running models on-premise make PiTuKri compliance automatic?
No. PiTuKri is an assessment framework applied by a competent authority or assessment body, not a certification anyone holds in advance, and no supplier can confer it on you. Local deployment changes which criteria apply and who is responsible for them. It generally helps with the prerequisites, communications and encryption areas, and it hands you the physical security and operational security areas in full. Security management, personnel security and change management stay yours either way. If your organisation cannot carry physical and operational security, local deployment makes the assessment harder rather than easier.
Is Finnish public sector data legally required to stay in Finland?
There is no general data localisation mandate in Finnish or EU law. Regulation (EU) 2018/1807 on the free flow of non-personal data points the other way, and PiTuKri itself cites it while noting that it does not apply to location requirements imposed on national security and preparedness grounds. Real restrictions come from classification rules under the Tiedonhallintalaki and the government decree on document classification, and from procurement requirements. For security-classified material the practical conditions can be strict, but they arise from classification, not from a localisation statute.
How accurate are open-weight document models on Finnish text?
Nobody can honestly tell you without measuring on your documents. The headline benchmark for document parsing, OmniDocBench v1.6, documents its language categories as English, Simplified Chinese and mixed English-Chinese, with no Nordic language represented. Finnish is absent, and Finnish is morphologically rich and compounds heavily, which is exactly the kind of text where extraction quality diverges from English results. Take 200 to 500 pages of your own material in the formats you actually receive, and measure field-level accuracy against a human-labelled ground truth. That measurement is the only evidence worth putting into a procurement document.
What volume makes on-premise document AI worth it in Finland?
Below roughly 250,000 pages a year, buying GPUs and standing up a controlled environment usually costs more than paying a cloud API, and the engineering overhead is not recovered. Above that the arithmetic starts favouring fixed-cost local processing. Classification overrides the arithmetic entirely: if the documents are turvallisuusluokitellut asiakirjat, page count is irrelevant and the question becomes whether the environment can satisfy the criteria at all. At that point a service where a foreign provider retains technical access to cleartext is unlikely to qualify at any price.
Is PiTuKri being replaced?
Yes. On 29 January 2026 the Ministry of Finance and Traficom announced work on joint national cloud security criteria that will supersede PiTuKri and the cloud services sections of Julkri, with a public comment period that closed in April 2026 and completion scheduled for autumn 2026. Version 1.1 remains the published criteria set today and is what assessments currently reference. If you are scoping a procurement that lands in 2027 or later, ask Traficom about the transition before you commit to a specific control mapping.

Want this worked out on your documents?

We will price a real sample against OpenAI or Anthropic and tell you whether Local document models or a local model on your hardware is the cheaper first step.