Your AI Assistant Is Being Watched: What the US CLOUD Act Means for Your Business Data
Let’s start with a question. You’re typing a prompt into ChatGPT, maybe drafting a proposal for a client, summarising a contract, or asking it to review some sensitive business data. You’re in the UK. Your data is probably also in the UK, or possibly the EU. You’re fully GDPR-aware. You’ve ticked all the boxes. You’re fine, right?
Well. Here’s the thing. If you’re using any AI tool owned by a US company, and that includes OpenAI (ChatGPT), Google (Gemini), Microsoft (Copilot), and yes, Anthropic (Claude), a little piece of American law called the CLOUD Act has a quiet but important say over your data. And it doesn’t much care where your servers are.
It’s not a conspiracy theory. It’s not scaremongering. It’s just the law. So let’s talk about it.
What on Earth is the CLOUD Act?
The Clarifying Lawful Overseas Use of Data Act (the CLOUD Act) was passed by the US Congress in 2018. Its core purpose: to allow US law enforcement to compel American technology companies to hand over data stored anywhere in the world, not just on US soil.
Before the CLOUD Act, the FBI hit a wall when it needed data stored overseas. The law hadn’t kept pace with cloud computing. The CLOUD Act fixed that, from Washington’s perspective, at least.
What this means in practice is stark: Microsoft, Google, Amazon, and OpenAI are all US companies. They are all subject to US law. And US law can require them to disclose customer data in response to a lawful order, even where that data is stored on servers in a UK data centre, and in some circumstances the company may be prohibited from notifying you that such an order has been made.
The key point: It doesn’t matter if your AWS, Azure, or Google Cloud instance is physically located in London, Manchester, or Edinburgh. If the company that owns the infrastructure is American, US authorities can potentially reach your data through the CLOUD Act.
So How Often Does This Actually Happen?
This is where it gets interesting, and where the data is genuinely illuminating.
Since the US–UK CLOUD Act agreement came into force in October 2022, the US government has made 63 requests to UK providers up to October 2024. The UK, meanwhile, has fired off 20,142 requests to US providers during the same period, primarily using it for intelligence gathering via wiretapping orders.
But here’s where it gets more nuanced, and more concerning for UK businesses. Those 63 US requests to UK providers were specifically for UK-based companies. The bigger risk for UK businesses is not the formal CLOUD Act agreement: it’s the underlying legal authority US agencies have over US-owned companies like AWS, Azure, and Google Cloud, regardless of where their servers sit.
Major cloud providers do push back on invalid requests. AWS has publicly stated that, as of mid-2025, it has had zero disclosures of enterprise data stored outside the US to the US government. Microsoft reported that in the second half of 2024, it received 173 global law enforcement requests for enterprise cloud data. But, and this is a significant “but”, these protections are built on trust, corporate policy, and ongoing legal challenge. They’re not a legal guarantee in the way GDPR is.
The uncomfortable reality is that, even if your organisation has never been affected by such a request, the legal mechanism exists. Under UK GDPR and EU GDPR, organisations must consider whether overseas legal powers could undermine the level of protection afforded to personal data when assessing international transfers. That doesn’t automatically make the use of US providers unlawful, but it does mean organisations should carry out an appropriate transfer risk assessment and consider whether additional safeguards are required.
Microsoft Said It Under Oath. That’s the Point.
In June 2025, Microsoft’s director of public and legal affairs, Anton Carniaux, appeared before a French Senate inquiry into public procurement and European digital sovereignty. The senators asked him a direct question: could he guarantee, under oath, that data on French citizens held on Microsoft servers could not be transmitted to the American government without the explicit agreement of the French government?
His answer was one word: “No.”
He followed it up with the now-famous qualification: “I cannot guarantee that, but, again, it has never happened before.”
Microsoft went on to explain that it has contractually committed to resisting unfounded requests, and that it tries hard to redirect US authorities to go directly to the customer instead. It has implemented technical environments to keep EU data within the EU. It fights back against poorly framed warrants. All of that is true, and worth acknowledging. But the fundamental answer, the one given under oath, in a Senate chamber, on the record, was: no guarantee.
Why this matters: Microsoft’s statements are those of a company acting in good faith within a difficult legal situation. But “we’ll try our best” is not the same as “this is legally impossible.” From a GDPR perspective, organisations need more than assurances of good intentions. The law requires organisations to assess whether personal data transferred internationally will continue to receive an essentially equivalent level of protection and, where necessary, implement appropriate supplementary safeguards.
Mark Boost, CEO at Civo, put it plainly in response to the testimony: “Microsoft has openly admitted what many have long known: under laws like the CLOUD Act, US authorities can compel access to data held by American cloud providers, regardless of where that data physically resides. UK or EU servers make no difference when jurisdiction lies elsewhere.”
OVHcloud’s spokesperson, responding to the same story, made a point worth noting: the debate now shows that cloud users need clarity on the Cloud Act, the Patriot Act, and FISA 702, and the conditions of their extraterritorial reach. Which brings us neatly to…
The CLOUD Act is Just the Start: Meet the Patriot Act and FISA 702
Most discussions of US data access focus on the CLOUD Act, and it’s the most relevant tool for law enforcement requests. But there’s a second, more shadowy layer of US legal authority that businesses should know about, and it’s arguably more concerning: FISA Section 702, expanded by the USA PATRIOT Act.
The USA PATRIOT Act significantly expanded surveillance and investigative powers under the existing Foreign Intelligence Surveillance Act (FISA), particularly in the years immediately following the September 11 attacks.
The USA PATRIOT Act, passed in the weeks after 9/11, dramatically expanded existing powers in the Foreign Intelligence Surveillance Act (FISA). The most controversial element was Section 215, which allowed the FBI to compel any organisation to hand over “any tangible things”, including records, documents, and data, if deemed relevant to a terrorism or counterintelligence investigation. This was the legal basis for the NSA’s mass telephone metadata collection programme revealed by Edward Snowden in 2013.
Section 215 in its bulk-collection form was eventually curtailed by the USA Freedom Act of 2015 and has since lapsed in parts. But the underlying FISA framework it expanded remains very much in force.
FISA Section 702: The Intelligence Community’s Broader Reach
Where the CLOUD Act is about law enforcement (the FBI, the DOJ, with a judge involved), FISA Section 702 is about intelligence agencies (the NSA, CIA, the FBI in its intelligence role) and it operates very differently.
The key differences are significant:
- No individual warrant is required. Intelligence agencies can target non-US persons outside the US without needing a court order for each case.
- US companies are compelled to provide all information, facilities, or assistance necessary and must do so secretly.
- The target company cannot inform its customers they have been targeted. A mandatory gag order applies.
- FISA 702 was further expanded in 2024 to cover any organisation or individual who has access to devices on which communications are stored, a remarkably broad definition.
And here’s the critical point for UK businesses: the Fourth Amendment of the US Constitution, which provides protections against unreasonable searches, applies to US citizens. It does not automatically protect non-US persons. If you are a UK business, your data stored with a US-owned provider has considerably fewer constitutional protections under US law than the data of an American citizen.
FISA Section 702 permits intelligence agencies to target non-US persons who are reasonably believed to be located outside the United States. In principle, this means that UK businesses and UK citizens fall within the category of individuals whose communications may be subject to collection under the statutory framework.
The layered picture: US law gives multiple agencies multiple routes into data held by US-owned companies. The CLOUD Act for law enforcement (judge required, probable cause needed). FISA 702 for intelligence agencies (no individual warrant, gag order mandatory). Broader executive orders for overseas surveillance. Each has different thresholds, different oversight, and different disclosure rules. None of them require telling you.
The GDPR Problem: A Square Peg in a Round Hole
The UK GDPR (which mirrors the EU version post-Brexit) is built on a foundational principle: personal data about UK residents must be protected, and transfers to third countries must only happen when adequate protections are in place.
These US laws sit uncomfortably against this. Under GDPR, data subjects have rights: the right to know their data is being accessed, the right to challenge it, the right to have it protected. The CLOUD Act, FISA 702, and the Patriot Act framework can override all of that. Requests can be made in secret, with the receiving company often prohibited from disclosing the request even to its own customer.
The Information Commissioner’s Office (ICO) expects organisations transferring personal data internationally to assess whether appropriate safeguards are in place. While the UK has established mechanisms that permit certain transfers to the US in specific circumstances, these do not remove an organisation’s obligation to assess the risks associated with overseas legal access powers. The Court of Justice of the European Union’s Schrems II decision highlighted these concerns by finding that certain US surveillance laws did not provide protections equivalent to those required under European data protection law. The EU’s Schrems II ruling in 2020 already invalidated the previous Privacy Shield framework specifically because FISA 702 surveillance was deemed disproportionate by European standards.
Importantly, neither the ICO nor European regulators prohibit organisations from using US cloud providers. Instead, they require organisations to understand the legal landscape, carry out appropriate transfer risk assessments and implement supplementary measures where necessary.
- GDPR fines can reach 4% of global annual turnover or £17.5 million, whichever is higher.
- Lack of awareness is not a defence under GDPR.
- “The data is in the UK” is not sufficient if the controller is subject to US law.
- “We haven’t been asked yet” is not a compliance strategy.
This isn’t about whether any particular US provider is acting in bad faith. Most are not. It’s about the fact that multiple layers of US legal framework allow access in ways that GDPR was specifically designed to prevent. And as Microsoft confirmed under oath: they cannot guarantee it won’t happen.
UK Data Centres: Location Matters, But Ownership Matters More
There’s a common misconception worth addressing head-on: many businesses believe that simply choosing a UK-based data centre ticks the data sovereignty box. It doesn’t, not by itself.
AWS has multiple UK data centres (the eu-west-2 region, based in London). Azure has UK South and UK West. Google Cloud has a UK region. All of these are physically in the UK. But physically being in the UK doesn’t change the fact that they’re owned and operated by US companies subject to US law.
Contrast this with a genuinely sovereign provider owned and operated within the UK or EU. In these cases, access to customer data is generally governed by UK and European legal processes rather than directly through US extraterritorial legislation such as the CLOUD Act. While no organisation is immune from lawful court orders within its own jurisdiction, this significantly changes the legal framework that applies to your data.
| Feature | US-Owned Providers | EU/UK-Sovereign Providers |
|---|---|---|
| Legal jurisdiction | US law alongside local law | UK / EU law |
| Gov. access to data | May be subject to US legal powers including the CLOUD Act | Not ordinarily subject to US extraterritorial legislation |
| Data location | Can often be configured to remain in the UK/EU | the UK/EUTypically hosted within the UK/EU |
| GDPR compliance | Requires appropriate transfer assessments and safeguards | Generally simpler from a sovereignty perspective |
| Notification of requests | May be restricted by applicable legal orders | Governed by local legal requirements |
| Examples (AI) | ChatGPT, Claude, Gemini, Copilot | ionosGPT, Mistral Le Chat, OVHcloud AI |
UK and EU-sovereign providers such as IONOS (Germany), OVHcloud (France), and Hetzner (Germany) operate entirely outside the reach of the CLOUD Act. Your data is primarily governed by UK and European legal frameworks and is not ordinarily subject to US extraterritorial legislation in the same way as services operated by US-owned providers.
It’s worth noting a nuance AWS raised: the CLOUD Act technically applies to any company doing business in the US, including some European providers with US operations. OVHcloud, for example, has confirmed that its US entity could be subject to CLOUD Act requests related to its US customers. But crucially, OVHcloud’s French entity and its European subsidiaries are explicitly not subject to the CLOUD Act, the Patriot Act, or FISA, because their ownership structure and operations are kept legally separate. That’s the kind of structural sovereignty that matters, and it’s what to look for.
But What About AI? It’s Different, Isn’t It?
AI tools present a specific and heightened version of this concern. When you use ChatGPT, Copilot, or Gemini, you’re not just storing data on a server somewhere. You’re actively sending it to an AI model hosted on US-company infrastructure, and receiving responses back.
The data flowing through these systems is often highly sensitive: business strategies, client information, contract details, internal communications, personnel data. This is exactly the category of data GDPR was designed to protect most carefully.
The good news? The European AI ecosystem has grown up considerably, and you have real, practical alternatives that don’t force you to choose between capability and compliance.
Option 1: ionosGPT, the Easy Compliant Route
IONOS, Europe’s largest hosting provider and one we know well as an IONOS Gold Partner, launched IONOS GPT in April 2025. Think ChatGPT, but built from the ground up on European values of data sovereignty.
- 100% European data processing, everything stays in German data centres
- Designed with GDPR compliance and European data sovereignty as core principles, not as an afterthought
- Built on open-source models (Llama, Mistral) with no proprietary black boxes
- Your prompts are never used to train the AI models
- Powered by 100% renewable energy
- Currently free to use
For businesses that want the convenience of a hosted AI assistant, the simplicity of just logging in and asking questions, without the compliance headache, IONOS GPT is the obvious starting point. It’s not yet at GPT-5 level for every task, but it handles the vast majority of business use cases competently and, crucially, legally.
Option 2: Other European AI Platforms
The European AI landscape has expanded rapidly. Several strong options exist for businesses needing a GDPR-compliant AI assistant:
- Mistral Le Chat: a French AI platform with excellent performance, hosted entirely in the EU
- Langdock: a German platform giving teams access to multiple AI models under one GDPR-compliant roof
- OVHcloud AI: AI services hosted on French infrastructure, built for European compliance
These platforms let you access powerful AI capabilities while keeping your data firmly within European legal boundaries.
Option 3: Self-Hosted AI for Total Control
For organisations with sensitive data and the technical capacity to manage it, self-hosting an AI model is the gold standard for data sovereignty. Tools like Ollama make it genuinely accessible to run models like Llama, Mistral, or Qwen on your own infrastructure.
The advantages are compelling:
- Your data never leaves your network, full stop
- No third-party access of any kind, legal or otherwise
- Complete customisation of the model for your specific use case
- No ongoing API costs once set up
The trade-off is that self-hosting requires technical expertise and ongoing maintenance. This is exactly the kind of work we do at Exe Squared, helping businesses deploy, configure, and maintain AI infrastructure that keeps them in complete control of their data. If you’re interested in exploring this route, get in touch.
The Bottom Line
AI has become an incredibly valuable business tool, and we’re certainly not suggesting organisations should avoid using it altogether. The productivity gains are undeniable. What matters is understanding the legal framework that sits behind the technology you choose.
For organisations handling personal data, confidential commercial information or sensitive client records, questions of jurisdiction and data sovereignty should form part of any procurement decision alongside functionality, price and security.
US providers continue to invest heavily in privacy protections and frequently challenge requests they believe are legally unjustified. However, as Microsoft’s own testimony demonstrated, no provider can offer an absolute legal guarantee that US authorities could never compel disclosure under applicable US law.
At the same time, European AI providers have matured significantly. Services such as ionosGPT, Mistral Le Chat and self-hosted open-source models now offer practical alternatives for many organisations seeking greater control over where their data is processed and under which legal framework it is governed.
Every organisation’s requirements are different. Some will decide that the capabilities offered by US providers justify the additional compliance work. Others may prefer solutions built around European data sovereignty from the outset. The important point is that the decision should be an informed one.
At Exe Squared, we help organisations understand those choices. Whether you’re assessing your current AI estate, exploring sovereign alternatives or considering a self-hosted solution, we’re always happy to have a conversation about what best fits your business and your compliance obligations.
Get in touch: info@exe-squared.co.uk • exe-squared.co.uk