Vai al contenuto
Guide

Assessing CLOUD Act exposure for AI services

How US disclosure orders reach data stored in the EU, where the Data Privacy Framework stands, and a four-factor assessment with worked examples.

Ultima verifica
23 September 2026
Tempo di lettura
6 min
Risk assessment
Scarica in Markdown

A Sluis guide for privacy, legal and security teams. Last checked 23 September 2026.

When an AI provider is controlled from the United States, US authorities can in principle order it to hand over your data, wherever that data is stored. This guide explains how that works, where the EU-US Data Privacy Framework stands, how to assess the exposure for a specific AI use, and which measures actually reduce it.

In short

  • The US CLOUD Act (18 U.S.C. § 2713) lets US authorities require a provider to disclose data in its possession, custody or control, regardless of where it is stored. What matters is who controls the provider, not where the servers are.
  • Transfers to US providers certified under the Data Privacy Framework are lawful today. The EU General Court upheld the framework on 3 September 2025; an appeal is pending before the Court of Justice.
  • The practical risk depends on four things: how sensitive the data is, who controls the provider, what the provider can actually read, and what the contract obliges it to do when an order arrives.
  • The most effective measure is to send less. Data the provider never receives cannot be disclosed.
  • Separate EU subsidiaries of US groups, such as the AWS European Sovereign Cloud, reduce the practical exposure. Whether they remove it in law has not been tested in court.

How the exposure arises

The CLOUD Act of 2018 added section 2713 to the US Stored Communications Act. It confirms that a provider subject to US jurisdiction must comply with a lawful US order for data it controls, even when the data sits outside the US. The provider can ask a court to set the order aside in limited circumstances, for example where it conflicts with the law of a country that has an agreement with the US under the Act.

A separate US instrument, section 702 of the Foreign Intelligence Surveillance Act, allows targeted collection of foreign intelligence from US providers. It was central to the Court of Justice's Schrems II judgment in 2020, which struck down the previous transfer framework, Privacy Shield.

For an AI service, the data in scope is everything the provider holds: prompts and outputs while they are processed, logs, abuse-monitoring copies, stored files and conversation history, and anything kept for training or evaluation.

Where the Data Privacy Framework stands

  • On 3 September 2025 the General Court dismissed the action brought by the French MP Philippe Latombe (Case T-553/23) and upheld the Commission's 2023 adequacy decision.
  • The General Court assessed the position as it stood when the decision was adopted in 2023. Later developments in the US redress mechanism were not before it.
  • Latombe appealed on 31 October 2025 (Case C-703/25 P). An appeal to the Court of Justice is limited to points of law. We found no hearing date as of September 2026.
  • The Court of Justice struck down both of the framework's predecessors, Safe Harbor in 2015 and Privacy Shield in 2020.

For planning purposes: the transfer basis is valid today, and its future depends on a court's timetable. Design your AI set-up so that you could change provider within a few months if you had to.

Assessing a specific use

Rate each use of AI on four factors.

FactorLower exposureHigher exposure
1. Sensitivity of the dataNo personal data; public or marketing contentSpecial category data, HR cases, legal privilege, trade secrets
2. Who controls the providerEU-owned and EU-controlledUS-controlled, whatever the region
3. What the provider can readPseudonymised text; no retentionPersonal data in clear; stored conversation history
4. Contract and processCommitment to challenge orders and notify you; published request statisticsStandard terms only

Worked examples

UseProviderMeasuresExposureReasoning
Drafting marketing copyUS provider, EU regionNoneLowNothing of value to disclose
Answering support tickets containing names, e-mail addresses and order historiesUS provider, EU regionNoneMedium to highPersonal data in clear, at volume, possibly retained
The same support ticketsUS provider, EU regionNames and identifiers replaced by placeholders before sending; mapping kept in the EU; zero retentionLow to mediumWhat the provider holds is hard to link to a person
HR case notes, including sickness absenceUS provider, EU regionAnyHighSpecial category data; a leak or disclosure is serious whatever its likelihood
HR case notesEU-owned provider, EU regionZero retention, EU-only failoverLow to mediumThe CLOUD Act route is removed; ordinary processor risk remains
Internal code assistant working on source codeUS provider, EU subsidiary structureCustomer-managed keys where availableMediumReduced practical exposure; the legal effect of the structure is untested

What reduces exposure, in order of effect

  1. Send less. Replace identifiers with placeholders before prompts leave your environment, and keep the mapping yourself. Our guide on personal data in prompts covers how well this works.
  2. Route by data class. Use US providers for what is low-risk, and an EU-owned provider, or no external model, for sensitive categories. This can be a rule enforced per request rather than a policy document.
  3. Turn off retention. Data that is not stored cannot be ordered later. Get zero retention in the contract where you can.
  4. Use the contract. Require the provider to challenge unfounded orders, to notify you where the law allows, and to disclose no more than the order requires.
  5. Keep an exit route. Use an interface that lets you switch providers without rewriting applications, and test the switch once.

The other side of the argument

A balanced assessment includes the reasons the risk may be smaller than it looks.

  • Frequency. No publicly confirmed case has shown US authorities using the CLOUD Act to obtain an EU company's enterprise data from a major cloud or AI provider. Microsoft's chief legal officer in France told the French Senate in July 2025 that it had not happened to Microsoft.
  • Resistance. Large providers have commercial reasons to challenge orders, and several publish transparency reports on the requests they receive.
  • European law has access powers too. EU member states and the UK can compel providers under their own laws. Choosing an EU provider changes which government could ask; it does not mean none can.
  • Smaller providers have their own risks. Concentration, financial durability and changes of ownership are real risks, as the reported 2026 acquisition of Aleph Alpha by Cohere showed.

The exposure is real but narrow. It matters most for sensitive data sent in clear, and least for pseudonymised or non-personal data.

Where regulation is heading

  • France gave SecNumCloud 3.2 binding force for much of its central public sector with a decree of 12 August 2026. It requires EU control of the provider and immunity from non-EU law.
  • The EU's Cloud and AI Development Act, proposed on 3 June 2026, would introduce sovereignty and immunity criteria in EU law, after member states failed to agree them in the EU cloud certification scheme (EUCS).
  • For French central government buyers this already applies: SecNumCloud asks who controls the provider, as well as where the data is stored.

Checklist

  • Each AI use rated on the four factors
  • Transfer basis recorded for every non-EU-controlled provider
  • Sensitive categories routed to an EU-controlled provider or kept out of external models
  • Identifiers replaced before prompts leave your environment
  • Zero retention agreed where available
  • Contract covers challenging orders, notification and data minimisation
  • Provider switch tested once; time to switch known
  • Assessment reviewed when the Court of Justice rules on the DPF appeal

Sources

Tutte le guide
Guida successivaChoosing an EU AI inference provider: a scorecard