Knowledge baseAI

The CLOUD Act and your AI provider: what sovereignty does and does not mean

25 September 20267 min read

"Our AI runs in an EU region" appears in almost every quote for a language-model API, and the sentence reassures without guaranteeing anything. A region is a place on the map; jurisdiction is a matter of ownership. If you send prompts containing customer or patient data to an API, that distinction matters more than which model is running. This article explains how the CLOUD Act works, why the ground under transatlantic data transfers is shifting, what even a Dutch provider cannot promise, and which questions to ask. It follows on from what we wrote about NIS2 and the Dutch Cyber Security Act: supply-chain responsibility does not stop at your own rack.

An EU region is not EU jurisdiction

The US CLOUD Act of 2018 gives US authorities the power to request data from any US company, including its subsidiaries, that has "possession, custody or control" of that data. Where the disk sits is irrelevant. A German GmbH with a US parent is covered; so is a server in Amsterdam.

This is not theoretical. In June 2025, Microsoft France testified under oath in the French Senate that it cannot guarantee French data will not be handed over to US authorities. And the AWS European Sovereign Cloud, available in Brandenburg since January 2026, runs under a separate German entity, but with a US parent. A sovereign cloud from a US company moves the problem to a different legal entity; it does not solve it.

The misconception, then, is that data location and jurisdiction are the same thing. The right question is not "where is my data" but "who can be ordered to hand it over".

The Data Privacy Framework is under pressure

Since 2023, transfers to the US have rested on the EU-US Data Privacy Framework. On 3 September 2025 the General Court of the EU dismissed the Latombe challenge against it, but the appeal before the Court of Justice (C-703/25 P) is still pending. Meanwhile the PCLOB, the US oversight body that plays a role in the framework, has had no quorum since January 2025.

On FISA 702, the law governing collection at US service providers, you sometimes read that it "expired" in June 2026. In practice it did not: collection continues under an FISC certification until March 2027. Anyone building their data processing agreement on the assumption that 702 is gone is building on sand.

In July 2026 the Dutch cabinet tightened its cloud policy for central government, including a mandatory exit strategy. Not a ban for businesses, but a signal.

What a Dutch chain does not solve

Honesty is due here, from us too. A chain without a US company removes the legal route via the CLOUD Act. It does not remove the fact that:

  • EO 12333 continues — collection outside the US, for instance on traffic in transit, is independent of who delivers the service. "Protected from US surveillance" is a promise nobody can keep.
  • Dutch and European authorities have their own powers — the Wiv 2017, criminal procedure and the EU e-Evidence package. The difference is not whether someone can request data, but under which law and with what review.
  • The GDPR simply applies — your AI provider is a processor, you remain the controller. Prompts contain personal data more often than teams think, and a DPIA is usually needed for customer or patient data. The Dutch Data Protection Authority did not warn without reason about staff pasting such data into public chatbots.

Sovereignty is therefore not a shield but a choice: you lay down which law applies to your data and who can reach it. That is verifiable.

The chain is longer than the API

"Our inference runs in the Netherlands" can be true while the chain still has a US link. Look beyond the endpoint:

  • Owner of the hardware — who owns the cards the model runs on, and which law does that company fall under?
  • Data centre — who is the operator, and who is the parent?
  • Logs, backups and support — prompt logs going to a US monitoring service, or a support team working in a US ticketing system, make the chain American after all.
  • Licence and telemetry agents — software that phones home sends metadata somewhere. Ask where.

Which questions to ask your provider

A provider that has thought this through answers these questions without having to look anything up:

  1. Which legal entities are in the chain, from API to data centre to hardware owner, and does any of them have a parent outside the EU?
  2. Where are logs and backups kept, for how long, and who has access?
  3. Are prompts stored or used for training, and is the answer in the contract or only on the website?
  4. Which sub-processors are there, including monitoring, support and billing?
  5. What happens on a request from an authority: are you informed, and under which law is it reviewed?
  6. Can you leave without exit costs? From 12 January 2027 the Data Act requires switching costs and egress for cloud services to be zero, but ask now.

AI inference at Xyphen IT

With our AI inference the chain is Dutch: Xyphen IT, the BIT data centre in Ede and the owner of the hardware. There is no US company in it. That we do not train on your data and do not store your prompts is not written on a web page but in an addendum to the data processing agreement. How the API and the network options fit together technically is on the technical page. If you want the chain even shorter, you place your own servers next to it in GPU colocation or colocation at BIT, with a cross-connect or a private VRF on our EVPN fabric, so your prompts never see the public internet at all.

Want to put the six questions above to us? Get in touch or request a proposal.

Frequently asked questions

Frequently asked questions

My provider runs in an EU data centre, so the CLOUD Act does not apply, right?

The CLOUD Act does not look at where the server is but at who has control over the data. A US company, or a European subsidiary of one, can be served with an order for data it keeps in Frankfurt or Amsterdam. The data centre tells you nothing; the chain of ownership does.

Am I protected from US intelligence services with a Dutch provider?

No, and anyone who promises that is overstating it. Collection outside the US under Executive Order 12333, for instance on traffic in transit, is independent of who delivers the service. What a Dutch chain does remove is the legal route via an order served on a US company. That is a smaller difference, but a concrete and verifiable one.

So Dutch authorities cannot request data either?

They can. The Dutch Intelligence and Security Services Act (Wiv 2017), the Code of Criminal Procedure and the European e-Evidence package give Dutch and European authorities their own powers. The difference is that these fall under Dutch and European law, with review you know and can challenge. Sovereignty does not mean nobody can reach your data; it means you know which law applies.

Answer not found?

Ask an engineer directly — we usually respond within one business day.