The US CLOUD Act obliges US providers to disclose data in their "possession, custody, or control", wherever it is stored.1 For AI this covers every prompt, uploaded file, embedding, log and fine-tuning set held by a US-owned model provider or cloud. An EU data centre does not change that. The operator's ownership does.

Summary

  1. The operator's owner decides. In June 2025 Microsoft France told the French Senate under oath that it could not guarantee French data would never reach US authorities.2
  2. It happens, rarely. In 2025 Microsoft gave US law enforcement the content of eight non-US enterprise customers whose data was stored outside the US. Two were located in the EU.3
  3. AI multiplies the data at stake. US AI APIs keep abuse logs for up to 30 days by default, and files, vector stores and fine-tuning data until deleted.19 Only an EU-controlled operator or own hardware removes the CLOUD Act route.

What is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act became US law on 23 March 2018. Congress passed it while the Supreme Court was hearing United States v Microsoft, in which Microsoft refused to hand over emails stored in Ireland. The Act ended that dispute by adding a new section to the Stored Communications Act, 18 U.S.C. 2713.

Section 2713 obliges providers of electronic communication or remote computing services to preserve and disclose customer data "regardless of whether" it is located inside or outside the United States.1 Cloud platforms and hosted AI APIs that store customer data typically fall under those definitions.

The Act has a second part. It lets the US sign executive agreements so that partner countries can serve orders on US providers directly. Only the United Kingdom and Australia have one.11 Orders still need US legal process: a warrant from a judge for content, a subpoena or court order for subscriber data.

Does the CLOUD Act apply to data stored in Europe?

Yes. The test is whether a provider under US jurisdiction controls the data. A US company that runs a data centre in Frankfurt controls what is stored there. Amazon, Microsoft and Google hold 70 percent of the European cloud market; European providers hold 15 percent.7

What did Microsoft tell the French Senate?

On 10 June 2025 a Senate inquiry into public procurement questioned Anton Carniaux, director of public and legal affairs at Microsoft France. Asked under oath whether French citizens' data would never be handed over after a US government injunction without explicit French consent, he answered: "Non, je ne peux pas le garantir" (No, I cannot guarantee it). He added that it had never happened.2

Microsoft completed its EU Data Boundary in February 2025, keeping core cloud data in the EU and EFTA.4 In April 2025 it committed to challenge any government demand for EU enterprise or public sector data where it has a legal basis, and to compensate customers if it discloses data in breach of EU law.5 Both measures are real. Neither removes the obligation in US law.

The same applies to new "sovereign" regions. The AWS European Sovereign Cloud opened in Brandenburg in January 2026, run by German legal entities and EU-resident staff.6 Its owner is still Amazon. Whether a US court could compel the parent to obtain data from such a subsidiary has not been tested.

How often do US authorities obtain European cloud data?

Rarely, on the only published figures. Microsoft reports law enforcement requests for enterprise customers twice a year. These are organisations with more than 50 seats. Requests from all countries number fewer than 200 per half year.

Four in ten enterprise requests end in disclosure

Of 697 requests from 2024 to 2025, Microsoft disclosed data in 281 cases. In 125 of them it handed over customer content.

Microsoft disclosed data in about four in ten law enforcement requests for enterprise customers.

Requests for enterprise customer data, by outcome, number of requests

Content disclosed Non-content disclosed Rejected, withdrawn or no data
0 50 100 150 200 166 173 168 190 H1 2024 H2 2024 H1 2025 H2 2025

1 Requests from law enforcement worldwide for accounts of enterprise customers (organisations with more than 50 seats). US national security orders are reported separately and excluded.

Source: Microsoft, Government Requests Report, enterprise disclosures to law enforcement, one-pagers for H1 2024, H2 2024, H1 2025 and H2 2025; accessed 1 October 2026

Most content went to US agencies: 31 of the 45 content disclosures in the second half of 2025.3 The CLOUD Act question is narrower. How often did the US obtain data of non-US customers stored outside the US? Microsoft reports that figure separately.

The cases are few, but the count is not zero. Microsoft's next two reports after the Senate hearing each list one customer located in the EU, one of them a US government contractor.

EU-located customers now appear in the figures

Fourteen non-US enterprise customers had content stored outside the US disclosed to US law enforcement in two years. Two were in the EU.

In 2025, content of two EU-located enterprise customers went to US law enforcement.

Non-US enterprise customers whose content, stored outside the US, went to US law enforcement, customers

Non-US customers, data stored outside the US Of which located in the EU
0 2 4 6 1 0 5 0 5 1 3 1 H1 2024 H2 2024 H1 2025¹ H2 2025

¹ Microsoft states that the EU-located customer in H1 2025 was a US government contractor.

Source: Microsoft, Government Requests Report, enterprise disclosures to law enforcement, H1 2024 to H2 2025; accessed 1 October 2026

These figures cover criminal law enforcement at one provider. US national security orders are reported only in bands of 500, and other providers publish less detail. Low frequency is no guarantee. A single case involving a client file or a patient record is enough to trigger a GDPR breach review.

How does the CLOUD Act clash with GDPR?

GDPR Article 48 says a foreign court order to transfer or disclose personal data "may only be recognised or enforceable" if it rests on an international agreement, such as a mutual legal assistance treaty.8 The EDPB and the EDPS found the CLOUD Act likely to bypass that treaty route.

Their assessment of July 2019 is blunt. Unless a CLOUD Act warrant is recognised through an international agreement, "the lawfulness of such processing cannot be ascertained".9 A US provider that complies may breach GDPR. One that refuses may breach US law.

US law offers a narrow exit. A provider may ask a court to quash an order within 14 days if the customer is not a US person and disclosure risks breaching the laws of a "qualifying foreign government".10 Only countries with an executive agreement qualify, and the EU has none. The EU e-Evidence Regulation has applied since 18 August 2026, yet an EU-US agreement is still outstanding.12

The legal exposure sits with the customer as well. The European organisation is the controller under GDPR. It chose the processor and must show that the processor can protect the data.

Is the EU-US Data Privacy Framework still valid in 2026?

Yes. The General Court rejected Philippe Latombe's challenge on 3 September 2025.13 He appealed on 31 October 2025, as case C-703/25 P.14 In June 2026 the Court of Justice admitted Microsoft as an intervener on the Commission's side.15 As of 1 October 2026 Lindstead found no hearing date, no Advocate General opinion and no judgment.

The framework rests on a US executive order, which a president can amend. In January 2025 the US administration removed three of the five members of the Privacy and Civil Liberties Oversight Board, one of the oversight bodies it relies on.16 The predecessors, Safe Harbor and Privacy Shield, both fell at the Court of Justice. A plan that depends on the framework needs a fallback.

One distinction matters for boards. The framework makes a transfer to a certified US company lawful. It does not limit what US law can compel that company to disclose.

What about FISA Section 702?

The CLOUD Act serves criminal investigations. Section 702 of the Foreign Intelligence Surveillance Act serves intelligence. It lets US agencies require US providers to help target non-US persons abroad, without an individual warrant. Europeans in Europe are exactly that group.

The statute lapsed on 12 June 2026 after Congress failed to renew it. Collection continues: the surveillance court approved certifications in March 2026 that remain valid until about March 2027.1718 At the Brennan Center's update of 17 September 2026, Congress had not passed a reauthorisation. For EU data held by US providers, the lapse has changed little so far.

What does the CLOUD Act mean for prompts, embeddings, logs and fine-tuning data?

AI services store more customer data, in more places, than most buyers assume. Taking OpenAI's published API terms as the reference:19

  • Prompts and outputs. Abuse monitoring logs are kept for up to 30 days by default. Zero data retention requires a separate agreement.
  • Files and embeddings. Uploaded files and vector stores are kept until deleted. Embeddings are not anonymous: researchers recovered 92 percent of 32-token inputs exactly from their embeddings.20
  • Fine-tuning data. Training files and job data stay until deleted. A fine-tuning set often contains the most sensitive examples an organisation owns.
  • Metadata. Even with EU data residency, account and system data may be processed outside the region.

Deletion settings can be overridden by US courts. In May 2025 a US magistrate judge ordered OpenAI to preserve output logs it would otherwise delete, for the New York Times copyright case. The order ran until 26 September 2025; logs already kept remain preserved.21 Data a provider holds can be reached; data it never stored cannot.

Encryption helps less for AI than for storage. Customer-held keys protect data at rest. A model must still read the prompt in plain text on the provider's GPU to answer it.

Which hosting options keep AI data out of CLOUD Act reach?

Exposure follows the operator's ownership. The table ranks the common options for running a model on sensitive data.

CLOUD Act and FISA 702 exposure by hosting option for AI workloads

Hosting option Operator CLOUD Act route FISA 702 route Examples
US AI API, US region US provider Yes Yes OpenAI, Anthropic, Google
US AI API, EU residency US provider Yes Yes OpenAI Europe region
US hyperscaler, EU region US provider Yes Yes Azure, Bedrock, Vertex AI
US-owned sovereign cloud EU unit of US group Contested Contested AWS European Sovereign Cloud
EU-run cloud, US technology EU company Low¹ Low¹ S3NS (Thales)
EU-owned GPU cloud EU provider No² No² Scaleway, OVHcloud, STACKIT
EU-owned model API EU provider No² No² Mistral AI
Own hardware or colocation The organisation No No Own servers, rented racks

No US route via the operator Reduced or contested US law can compel the operator

Sources: 18 U.S.C. 2713; Brennan Center on Section 702; AWS, OpenAI and Thales documentation; Lindstead classification, not legal advice. ¹ S3NS is a French company controlled by Thales that runs Google Cloud technology and holds SecNumCloud qualification since December 2025;22 check support and update access. ² Check US subsidiaries and subprocessors. Accessed 1 October 2026.

The top three rows differ only in residency; the same US law applies to each. An EU-owned GPU cloud running an open-weight model, or own hardware, removes the operator route entirely. The self-hosted LLM guide covers models and hardware. On-premise vs private cloud AI weighs owning against renting, and the European cloud GPU price index lists providers by owner.

Banks and insurers face this twice. GDPR governs the data, and DORA governs the supplier. In November 2025 the European supervisors designated 19 critical ICT third-party providers, including AWS, Google Cloud and Microsoft.23 See AI in financial services for the sector view.

What should a European organisation do now?

A ban on US services is rarely needed. Sorting data by sensitivity usually is.

  1. Map every AI data flow. List each tool, its operator's owner, and what it stores: prompts, files, embeddings, logs, fine-tuning sets.
  2. Classify the data. Special category data, client files, privileged documents and trade secrets go on the EU-controlled side. General drafting can stay on US services.
  3. Minimise what US providers hold. Use zero data retention where offered, delete files and vector stores, and avoid fine-tuning on sensitive sets.
  4. Run sensitive workloads on an EU-controlled stack. An open-weight model on an EU-owned GPU cloud or own hardware. Lindstead's AI deployment work builds this.
  5. Document the assessment. Record the CLOUD Act and Section 702 analysis in the DPIA and transfer impact assessment. Lindstead's AI governance and compliance work covers this.

The briefing Where should your AI run? shows how these rules interact with the AI Act, DORA and NIS2.

Frequently asked questions

  • A US law from March 2018. It obliges US cloud and communication providers to hand over data they control when served with a valid US warrant or order, wherever that data is stored. It also lets the US sign data-access agreements with other countries.

  • Yes, if a provider under US jurisdiction has possession, custody or control of it. The test is control by the provider. Data in a Frankfurt or Paris region of a US cloud is within reach.

  • Yes. GDPR Article 48 recognises a foreign court order only if it rests on an international agreement, such as a mutual legal assistance treaty. The EDPB and EDPS concluded in 2019 that a CLOUD Act warrant alone is not a lawful basis for disclosure. The provider can end up bound by both laws at once.

  • No. Residency fixes where data is stored and processed. The provider remains a US company that controls the data, so a US order can still reach it. Residency does help with GDPR transfer rules and reduces what leaves the EU in normal operation.

  • Yes, as of 1 October 2026. The General Court upheld it on 3 September 2025, and the appeal in case C-703/25 P is pending at the Court of Justice. The framework governs transfers; it does not stop a CLOUD Act order.

Next step: The AI sovereignty scan maps which AI tools hold sensitive data, which law can reach each one, and what to move first. Or schedule a meeting to discuss a specific use case.

Sources

  1. 18 U.S.C. 2713, Required preservation and disclosure of communications and records (CLOUD Act), Cornell Legal Information Institute. www.law.cornell.edu/uscode/text/18/2713
  2. Sénat, commission d'enquête sur la commande publique, hearing of Microsoft France (Anton Carniaux, Pierre Lagarde), 10 June 2025, verbatim record. www.senat.fr/compte-rendu-commissions/20250609/ce_commande_publique.html
  3. Microsoft, Government Requests Report: customer data, including the enterprise one-pagers for H1 2024 to H2 2025. www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data
  4. Microsoft, Microsoft completes landmark EU Data Boundary, 26 February 2025. blogs.microsoft.com/on-the-issues/2025/02/26/microsoft-completes-landmark-eu-data-boundary-offering-enhanced-data-residency-and-transparency/
  5. Microsoft, Microsoft announces new European digital commitments, 30 April 2025. blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/
  6. AWS News Blog, Opening the AWS European Sovereign Cloud, January 2026. aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud
  7. Synergy Research Group, European cloud providers' local market share now holds steady at 15%, 24 July 2025. www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15
  8. Regulation (EU) 2016/679 (GDPR), Article 48, EUR-Lex. eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  9. EDPB and EDPS, Initial legal assessment of the impact of the US CLOUD Act on the EU legal framework, annex to joint response to LIBE, 10 July 2019. www.edpb.europa.eu/sites/default/files/files/file2/edpb_edps_joint_response_us_cloudact_annex.pdf
  10. 18 U.S.C. 2703(h), Comity analysis and disclosure of information regarding legal process, Cornell Legal Information Institute. www.law.cornell.edu/uscode/text/18/2703
  11. US Department of Justice, CLOUD Act resources (executive agreements with the United Kingdom and Australia). www.justice.gov/criminal/cloud-act-resources
  12. Microsoft, e-Evidence: Europe leads the way to a modern era of lawful access, 18 August 2026. blogs.microsoft.com/eupolicy/2026/08/18/e-evidence-europe-leads-the-way-to-a-modern-era-of-lawful-access/
  13. General Court, Latombe v Commission, case T-553/23, judgment of 3 September 2025. curia.europa.eu/juris/liste.jsf?num=T-553/23
  14. Appeal in Latombe v Commission, case C-703/25 P, notice in the Official Journal, 22 December 2025. eur-lex.europa.eu/eli/C/2025/6610/oj/eng
  15. Microsoft, Protecting privacy as a fundamental right while supporting transatlantic data flows, 28 June 2026. blogs.microsoft.com/on-the-issues/2026/06/28/protecting-privacy-as-a-fundamental-right-while-supporting-transatlantic-data-flows/
  16. Center for Democracy and Technology, What the PCLOB firings mean for the EU-US Data Privacy Framework, 2025. cdt.org/insights/what-the-pclob-firings-mean-for-the-eu-us-data-privacy-framework/
  17. Brennan Center for Justice, Section 702 of FISA: 2026 resource page, updated 17 September 2026. www.brennancenter.org/our-work/research-reports/section-702-foreign-intelligence-surveillance-act-fisa-2026-resource-page
  18. NBC News, A key U.S. spying program expires Friday night. What does that mean?, 12 June 2026. www.nbcnews.com/politics/trump-administration/fisa-section-702-warrantless-foreign-surveillance-expire-congress-rcna349798
  19. OpenAI, Data controls in the OpenAI platform (retention, data residency, zero data retention). developers.openai.com/api/docs/guides/your-data
  20. Morris, Kuleshov, Shmatikov and Rush, Text embeddings reveal (almost) as much as text, EMNLP 2023, arXiv 2310.06816. arxiv.org/abs/2310.06816
  21. Engadget, OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions, 11 October 2025. www.engadget.com/ai/openai-no-longer-has-to-preserve-all-of-its-chatgpt-data-with-some-exceptions-192422093.html
  22. Thales, S3NS receives SecNumCloud qualification, December 2025. www.thalesgroup.com/en/news-centre/insights/group/s3ns-receives-secnumcloud-qualification-turning-point-trusted-cloud
  23. EIOPA, ESAs designate critical ICT third-party providers under DORA, 18 November 2025. www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en

Method: desk research of public primary sources, all accessed 1 October 2026. Figures are as published by the sources, not Lindstead measurements. This guide is not legal advice. Corrections: contact@lindstead.com.