MareNostrum 5 gets AI hardware for startups
EuroHPC signed a contract to upgrade MareNostrum 5 in the Barcelona AI Factory. What that means for European startups, SMEs and sector pilots with shared compute.
You must establish whether each AI workflow is suitable for shared supercomputing before committing data to it, and record that decision in writing with the controls you will operate. Shared compute lowers the cost of entry; it does not transfer your responsibility for audit, data handling or oversight.
The prompt is an analysis of 23 September 2026 of shared supercomputing infrastructure for AI pilots in Europe, which argues that a network of AI Factories across European member states now offers smaller organisations access to GPU capacity and technical support without requiring them to build their own data centres. The example is the upgrade of MareNostrum 5 in Barcelona with AI-optimised hardware and storage, managed by the Barcelona Supercomputing Center. In our assessment, this shifts the decision from whether to invest in infrastructure to which workflows are suitable for shared environments—a distinction that matters most in regulated sectors such as law, finance, energy and public administration, where data location, traceability and accountability carry operational weight.
Which workflows belong on shared compute?
Shared supercomputing is not a default. It suits bounded pilots where you can isolate the data, control the inputs and document the outputs. It does not suit workflows where you cannot justify why the data must leave your premises, or where regulatory requirements tie data to a specific location.
The practical test is straightforward: before you approach an AI Factory, select one workflow, establish whether it is genuinely suitable for shared compute, and write down your reasoning. That record becomes part of your audit trail. If you cannot articulate why shared compute is the right choice for that workflow, it probably is not.
What control questions must you answer before data enters a shared environment?
You should be able to answer these five questions concretely and in writing:
- Document the workflow and its lawful basis — which model does it use, what data does it touch, and what legal ground justifies processing that data on shared infrastructure rather than locally.
- Establish data minimisation — confirm that you are sending only the data strictly necessary for the task, and that you have removed or masked anything else.
- Record human oversight of AI decisions — demonstrate that a person reviews and approves each material decision the model supports, with a documented trail of who decided what and when.
- Keep personal data in embeddings controllable — even when personal information persists in derived or encoded form within model outputs, you must be able to identify it, retrieve it and delete it on request.
- Confirm exit and portability — establish in advance how you will retrieve your data, models and results if you need to leave the shared environment, and test that process before you depend on it.
These are not optional refinements. They are the minimum conditions under which you can later account for an AI-supported decision to a regulator, an auditor or a court.
What does the AI Factory network actually provide?
The European Commission has expanded the network to 19 facilities across 16 member states, supported by more than 2.6 billion euros in combined commitments from the EU and participating countries. Each AI Factory offers GPU resources, storage, training and technical expertise in sectors including law, finance, energy, media and public administration.
The support layer is what distinguishes this from raw cloud compute. Smaller organisations gain access not only to hardware but to people who understand how to set up workflows in those sectors. That expertise is valuable precisely because it helps you think through the control questions above before you start.
What stays your responsibility?
Shared infrastructure lowers the threshold to pilot AI in your organisation. It does not shift accountability for what happens in those pilots. You remain responsible for:
- Data minimisation and retention — you decide what enters the shared environment and how long it stays there.
- Audit trails and documentation — you must record which model ran, who approved its output, and what happened next.
- Compliance with sector rules — if you work in law, finance or healthcare, the regulatory obligations that bind you locally do not disappear because you use shared compute.
- Exit planning — you must be able to retrieve everything and leave without losing control of your data or your models.
- Human oversight of material decisions — no workflow can be fully automated if it affects a person's rights or interests, regardless of where the compute happens.
The concrete step is modest and testable. Select one bounded workflow, determine whether it is suitable for shared compute, and record the five control questions in writing beforehand. Only then does it make sense to contact an AI Factory about data access and support.
Tooling can help you manage these controls—version control for models, audit logging for access, encryption for data in transit and at rest. But no tool can answer the first question for you: whether this workflow belongs on shared infrastructure at all. That remains your professional judgement, and it must be documented before you act on it.
Sources: This article draws on reporting and guidance from European High-Performance Computing Joint Undertaking, European Commission and AI Summit Barcelona.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.