· AI  · 7 min read

Residency Is Not Jurisdiction

Data "stored in the EU" sounds like protection from US access. It is not, automatically. What the CLOUD Act and FISA 702 mean, and when it matters for your company.

Data "stored in the EU" sounds like protection from US access. It is not, automatically. What the CLOUD Act and FISA 702 mean, and when it matters for your company.

Residency is not jurisdiction.

Where a server sits does not decide who can legally demand access to its data. Microsoft’s EU Data Boundary governs location. The CLOUD Act and FISA Section 702 govern access, and both attach to the company, not the server’s location. For most mid-market workloads, that is an insurance question. For critical infrastructure, public sector clients, and heavily regulated industries, it is a real criterion.

At the former Checkpoint Charlie in Berlin, a replica of the old sign still stands: “You are entering the American sector.” Back then, American law visibly ended at a line on the street.

With cloud data, that line no longer exists, even though many IT departments plan as if it still does. The setting in the admin center reads reassuringly: “EU Data Boundary, active.” All Copilot data, it says, sits in Frankfurt and Amsterdam. One follow-up question stays open anyway: what happens to the data in Frankfurt if a US authority asks for it?

The honest answer does not fit on a marketing slide.

What the EU Data Boundary Actually Governs

The EU Data Boundary is real. Microsoft keeps M365 and Copilot customer data within the EU and EFTA for storage and most processing steps. That is a contractual and technical commitment, not a marketing claim, and it satisfies most data protection questions.

It answers one question: where does the data sit? It does not answer a second, often more important one: who can demand its release?

The Question Residency Does Not Answer

Access rights do not follow the server. They follow the company. Microsoft, Google, and AWS are US companies. Two US laws require them to hand over data, regardless of where that data sits:

The CLOUD Act of 2018 requires US providers to hand over data in their possession or control. Server location plays no role. FISA Section 702 lets US authorities monitor communications of people outside the US when a US provider is involved. Again: company status decides, not server location.

One provider admitted this publicly. Anton Carniaux, general counsel of Microsoft France, testified under oath before the French Senate on June 10, 2025. Microsoft could not guarantee the protection of French citizens’ data from US access, not without local consent. He added that Microsoft resists unfounded requests. Such a compelled disclosure has not happened yet. He could not rule it out structurally, though.

How the CLOUD Act and FISA 702 Apply in Detail

Both laws work through the company, not the location:

  • CLOUD Act: applies once data is in the “possession, custody, or control” of a US company. An EU subsidiary changes nothing as long as the US parent has legal access.
  • FISA 702: targets non-US persons outside the US, but covers any “electronic communication service provider” subject to US law. Again: company status, not server location.
  • GDPR Article 48: a foreign court order alone is not valid legal grounds to transfer personal data out of the EU. A US provider that complies with a CLOUD Act order risks conflicting with GDPR. That is an unresolved legal conflict, not a closed loophole.

The three frameworks contradict each other, and courts have not resolved that contradiction yet. That alone is why providers choose their words carefully on this question.

Where the Picture Lies

The obvious analogy: your files sit in a safe deposit box at a US bank’s Frankfurt branch. The bank is headquartered in the US, so a US authority could theoretically reach the box.

Here the picture lies, and not in your favor. A real safe deposit box requires physical access, often a legal assistance order recognized in Germany, and usually the bank or even the customer finds out. A CLOUD Act request needs none of that. It is an electronic request to US headquarters. It can come with a gag order. Neither you nor a German authority has to find out. The safe-deposit-box image suggests friction that often does not exist in practice.

The old Checkpoint Charlie sign was more honest about this than today’s legal reality: at least it marked the boundary.

What This Means For Your Company

For most mid-market workloads, this is not a purchasing decision. Internal collaboration, standard emails, meeting notes: if a hypothetical US access poses no real risk here, the EU Data Boundary is enough. It is insurance, not a reason to switch providers.

The question gets concrete on two criteria, and you should answer both yourself:

  1. Do you process data whose disclosure to a foreign authority would be regulatorily prohibited or existential for your business? This typically applies to critical infrastructure operators, public sector clients, and industries with strict confidentiality obligations.
  2. Would a silent disclosure to a foreign authority, one you are never notified about, cause real regulatory or contractual damage?

Two no’s, and your current setup is probably fine. One yes, and it is worth looking at EU-operated providers (IONOS, StackIT, or OVH, for example) or your own cloud account with model hosting under your own control.

One clarification often misstated in this context: Microsoft’s enterprise contracts exclude training its models on customer data. That is a separate question from jurisdiction, and the two should not get mixed up.

What You Can Do Now

You can now tell the difference between what a provider means when it advertises “your data stays in the EU,” and what that claim leaves open. The one line worth keeping: residency says where the data sits. Jurisdiction says who can demand it.

The more common data leak in daily business is a different one anyway. Employees use personal ChatGPT or Gemini accounts because no approved tool is available. They paste company data into consumer products that train on input by default. That is a bigger and more everyday risk than the CLOUD Act, and it is fixable without touching the jurisdiction question at all.

One more gap stays open here: how many of the AI licenses a company already pays for actually get used. More on that in one of the next posts in this series.

Frequently Asked Questions

What does data residency mean for AI services like Microsoft 365 Copilot? Data residency describes where data is physically stored and processed. Microsoft’s EU Data Boundary keeps customer data within the EU and EFTA for most processing steps. That is a real, contractually guaranteed boundary, but it only answers where the data sits, not who can compel its release.

Why does the EU Data Boundary not protect against US government access? The CLOUD Act and FISA Section 702 do not attach to where a server sits. They attach to the company that runs it. If the provider is a US company, a US authority can demand data regardless of whether it sits in Frankfurt or Virginia. Microsoft France confirmed this under oath before the French Senate on June 10, 2025.

When does the jurisdiction question actually matter for mid-sized companies? For most workloads at a typical mid-sized company, it is an insurance question, not a purchase criterion. It becomes concrete for critical infrastructure operators, public sector clients, and heavily regulated industries. There, EU-operated providers or your own cloud account are worth a look.


Related: Hosting or Renting Your Own AI Models and Why ChatGPT Does Not Know Your Company Knowledge.

Back to Blog

Related Posts

View All Posts »
The Quality Gap in Open AI Models, Honestly Quantified

The Quality Gap in Open AI Models, Honestly Quantified

In June an open model cracked 50 points on the leading independent AI benchmark for the first time; six weeks later a second one came within three points of the frontier. Why the average number is still almost irrelevant for your own decision.

What Happens When Your AI Vendor Disappears

What Happens When Your AI Vendor Disappears

An AI vendor can disappear no matter how big it was. Three questions decide whether that means a migration for your company or a rebuild from zero, and they belong before the contract, not after.

Paid Per Seat, Used Per Task

Paid Per Seat, Used Per Task

300 paid Copilot seats are not 300 users. What Microsoft's own reports count as "active," what the widely cited 20-30 percent figure actually measures, and why it likely understates the gap rather than overstates it.