Sovereignty & jurisdiction of AI data
The CLOUD Act allows U.S. authorities to access the data of your AI systems hosted with U.S. providers — even when the servers are in Europe. This page explains why, how, and what regulated organizations need to do.
Key points for executives
If your AI systems process sensitive data (health, finance, legal, defense) and your cloud provider is American, your data is potentially accessible to U.S. authorities without your consent or notification. The CLOUD Act applies to communication and cloud service providers subject to U.S. jurisdiction, wherever the data is stored. It is a legal, regulatory, and reputational risk.
Impact: choice of cloud provider, compliance strategy, DORA/NIS2 exposure.
Text of the CLOUD Act (H.R. 4943), enacted in the Consolidated Appropriations Act, 2018 — U.S. CongressDefinition
Sovereign AI infrastructure
A sovereign AI infrastructure is a set of compute, storage, and data processing resources operated exclusively under European jurisdiction, with no technical or legal dependency on entities subject to the extraterritorial law of third countries (notably the U.S. CLOUD Act, FISA Section 702, or China's National Intelligence Law). It is designed so that the entire processing chain — from input data to outputs and audit trails — remains under the exclusive legal control of the European Union.
Enacted in March 2018, the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) allows U.S. authorities, by warrant or court order, to require communication and cloud service providers subject to U.S. law to disclose the data they hold — regardless of the country where the data is physically stored.
In practice, if your AI system is hosted on AWS, Azure, or Google Cloud — even in a European data center — the U.S. government can lawfully request access to:
The U.S. cloud provider is under no obligation to notify you of such an access request. It may even be prohibited from doing so (gag order).
| Criterion | U.S. cloud (AWS, Azure, GCP) | KOREV — Sovereign infrastructure |
|---|---|---|
| Applicable jurisdiction | U.S. law (CLOUD Act, FISA 702, EO 12333) | Exclusively European law (GDPR, AI Act) |
| Access by foreign authorities | Possible without notifying the customer | Governed by European law and mutual legal assistance agreements |
| Data location | Servers in the EU, but U.S. jurisdiction | Servers in the EU, EU jurisdiction |
| Data transfers outside the EU | Possible under a U.S. court order | No transfers outside the EU in sovereign configurations |
| GDPR Article 48 compliance | Risk of conflict with the CLOUD Act | Designed to avoid conflicts of jurisdiction |
| DORA compliance (financial sector) | Identified critical ICT provider risk | Processing chain under EU jurisdiction |
| NIS2 compliance | Dependency on an extraterritorial provider | Supply chain under EU jurisdiction |
| Code transparency | Proprietary, not auditable | Architecture auditable by the customer |
| AI audit trails | Accessible to U.S. authorities | Under the customer's exclusive control |
Three European texts converge on the same requirement — control over critical digital infrastructure:
The AI Act requires traceability, documentation, and auditability of AI systems. If foreign authorities can demand audit trails through the CLOUD Act, control over them becomes harder to demonstrate. Article 15 requires robustness and cybersecurity — uncontrolled extraterritorial access is a risk to assess.
AI Act Article 15 — Accuracy, robustness and cybersecurityThe Digital Operational Resilience Act requires financial institutions to control the risks arising from third-party ICT service providers. Cloud providers subject to the CLOUD Act represent a concentration risk and a jurisdictional risk that DORA explicitly identifies. Financial institutions must assess this risk and demonstrate that they have alternatives.
DORA Regulation — Official textThe NIS2 Directive requires securing the entire digital supply chain. A cloud provider subject to the CLOUD Act introduces an uncontrolled access vector into that chain. Essential and important entities must identify and mitigate this risk.
NIS2 Directive — Official textHigh-risk AI systems process your organization's most sensitive data: medical records, financial data, legal evidence, citizen data, trade secrets.
Medical records processed by diagnostic AI are protected health data. Disclosing them to a foreign authority outside the cases provided for in GDPR Article 48 may breach GDPR and the French Data Protection Act (loi Informatique et Libertés).
Risk analyses, credit scoring, and fraud detection involve critical financial data. DORA requires that this data be protected against any unauthorized access.
Litigation strategies, case law analyses, and attorney-client communications processed by AI are covered by professional secrecy. The CLOUD Act does not recognize this privilege.
Citizen data processed by government AI (benefits, taxation, security) is sovereign by nature. Exposing it to a foreign jurisdiction is unacceptable.
European hosting: data centers, subcontractors, and providers selected outside the scope of the CLOUD Act, according to the level of external dependency defined by the organization.
No data transfers outside the EU in sovereign configurations: prompts, outputs, and audit trails remain under European jurisdiction.
AI models operated in Europe: no dependency on OpenAI, Google, or Anthropic APIs for processing sensitive data.
Audit trails under customer control: decision logs belong to the customer, not the provider.
Auditable architecture: the customer can verify the entire processing chain.
Combined GDPR + AI Act + DORA + NIS2 requirements: a single infrastructure designed to make these frameworks easier to implement, depending on the system and its use.
Operational summary
The essential checks to assess how exposed your AI systems are to the CLOUD Act.
Your AI decisions, your data, your jurisdiction. See how KOREV lets you keep your AI data and decisions within the environment you define.