Skip to main content
Sign in See the demo
Sovereignty

Does the Cloud Act apply to the enterprise offerings of the major LLMs?

4 August 20262 min read

The foreign legal perimeter covers the entire territory: the law follows the provider, not the server.

In short.
The Cloud Act is a 2018 US law that allows US authorities to require providers subject to their jurisdiction to hand over data, including when that data is stored outside the United States. Does it apply to the enterprise offerings of the major generative AI providers? Yes, wherever the data is hosted. “Your data is not used to train our models” is a guarantee about use; it says nothing about jurisdiction, that is, about who can legally compel the provider.

Use and jurisdiction: the distinction the market keeps blurred

Enterprise offerings provide real guarantees: no training on your content, encryption, confidentiality commitments. But the jurisdictional question is of a different nature: which law is the provider subject to, and who can legally compel it? A US provider remains subject to US law, even for a French client whose data is hosted in Paris. Local hosting changes the latency, not the applicable law.

Acceptable risk or red line, depending on your sector

For many organisations, this risk is theoretical and acceptable. For others, it is a red line: defence, healthcare, the public sector, operators of vital importance, companies whose files contain industrial sovereignty information or data localisation clauses. For them, the only robust answer is structural: an operator subject to European law, data that does not pass through a provider under extraterritorial jurisdiction, deployment at the client’s premises or on a cloud with a sovereign qualification. The question to ask any AI provider: “Which jurisdiction are you subject to, and which are your inference subcontractors subject to?”. The answer should fit in one sentence.

The Optivalue.ai approach

Optivalue.ai is a European operator: a private AI for each client, deployed on-premise or on a sovereign cloud, with no transit through a provider subject to the Cloud Act, and guaranteed deletion of data at the end of the contract.


Is hosting in Europe enough to escape the Cloud Act?

No: the law follows the provider, not the server.

‍Are all companies affected to the same degree?
No: it is a sector-specific risk analysis; for some sectors, it is a contractual or regulatory red line.

Back to top

A quote is easier to discuss after a demonstration on your own documents.