"Our AI runs in an EU region" appears in almost every quote for a language-model API, and the sentence reassures without guaranteeing anything. A region is a place on the map; jurisdiction is a matter of ownership. If you send prompts containing customer or patient data to an API, that distinction matters more than which model is running. This article explains how the CLOUD Act works, why the ground under transatlantic data transfers is shifting, what even a Dutch provider cannot promise, and which questions to ask. It follows on from what we wrote about NIS2 and the Dutch Cyber Security Act: supply-chain responsibility does not stop at your own rack.
An EU region is not EU jurisdiction
The US CLOUD Act of 2018 gives US authorities the power to request data from any US company, including its subsidiaries, that has "possession, custody or control" of that data. Where the disk sits is irrelevant. A German GmbH with a US parent is covered; so is a server in Amsterdam.
This is not theoretical. In June 2025, Microsoft France testified under oath in the French Senate that it cannot guarantee French data will not be handed over to US authorities. And the AWS European Sovereign Cloud, available in Brandenburg since January 2026, runs under a separate German entity, but with a US parent. A sovereign cloud from a US company moves the problem to a different legal entity; it does not solve it.
The misconception, then, is that data location and jurisdiction are the same thing. The right question is not "where is my data" but "who can be ordered to hand it over".
The Data Privacy Framework is under pressure
Since 2023, transfers to the US have rested on the EU-US Data Privacy Framework. On 3 September 2025 the General Court of the EU dismissed the Latombe challenge against it, but the appeal before the Court of Justice (C-703/25 P) is still pending. Meanwhile the PCLOB, the US oversight body that plays a role in the framework, has had no quorum since January 2025.
On FISA 702, the law governing collection at US service providers, you sometimes read that it "expired" in June 2026. In practice it did not: collection continues under an FISC certification until March 2027. Anyone building their data processing agreement on the assumption that 702 is gone is building on sand.
In July 2026 the Dutch cabinet tightened its cloud policy for central government, including a mandatory exit strategy. Not a ban for businesses, but a signal.
What a Dutch chain does not solve
Honesty is due here, from us too. A chain without a US company removes the legal route via the CLOUD Act. It does not remove the fact that:
- EO 12333 continues — collection outside the US, for instance on traffic in transit, is independent of who delivers the service. "Protected from US surveillance" is a promise nobody can keep.
- Dutch and European authorities have their own powers — the Wiv 2017, criminal procedure and the EU e-Evidence package. The difference is not whether someone can request data, but under which law and with what review.
- The GDPR simply applies — your AI provider is a processor, you remain the controller. Prompts contain personal data more often than teams think, and a DPIA is usually needed for customer or patient data. The Dutch Data Protection Authority did not warn without reason about staff pasting such data into public chatbots.
Sovereignty is therefore not a shield but a choice: you lay down which law applies to your data and who can reach it. That is verifiable.
The chain is longer than the API
"Our inference runs in the Netherlands" can be true while the chain still has a US link. Look beyond the endpoint:
- Owner of the hardware — who owns the cards the model runs on, and which law does that company fall under?
- Data centre — who is the operator, and who is the parent?
- Logs, backups and support — prompt logs going to a US monitoring service, or a support team working in a US ticketing system, make the chain American after all.
- Licence and telemetry agents — software that phones home sends metadata somewhere. Ask where.
Which questions to ask your provider
A provider that has thought this through answers these questions without having to look anything up:
- Which legal entities are in the chain, from API to data centre to hardware owner, and does any of them have a parent outside the EU?
- Where are logs and backups kept, for how long, and who has access?
- Are prompts stored or used for training, and is the answer in the contract or only on the website?
- Which sub-processors are there, including monitoring, support and billing?
- What happens on a request from an authority: are you informed, and under which law is it reviewed?
- Can you leave without exit costs? From 12 January 2027 the Data Act requires switching costs and egress for cloud services to be zero, but ask now.
AI inference at Xyphen IT
With our AI inference the chain is Dutch: Xyphen IT, the BIT data centre in Ede and the owner of the hardware. There is no US company in it. That we do not train on your data and do not store your prompts is not written on a web page but in an addendum to the data processing agreement. How the API and the network options fit together technically is on the technical page. If you want the chain even shorter, you place your own servers next to it in GPU colocation or colocation at BIT, with a cross-connect or a private VRF on our EVPN fabric, so your prompts never see the public internet at all.
Want to put the six questions above to us? Get in touch or request a proposal.