CLOUD Act Risk: Why UK Data Hosted by US Providers Isn't Sovereign

UK hosting does not put data beyond the US CLOUD Act, which follows corporate control rather than location. What the real exposure is and what reduces it.

A supplier assurance questionnaire comes back from a client's legal team with one item flagged for a written answer. The organisation has already told them that its AI knowledge platform keeps everything in a London data centre, and the client now wants to know whether that puts the content beyond the reach of US authorities. The chief information security officer (CISO) passes it to the data protection officer (DPO), who passes it to the vendor, and the reply that comes back describes the hosting region again in slightly different words.

The honest answer to the client's question is no, and the reason has nothing to do with where the servers are. The US CLOUD Act follows corporate control rather than data location, so a London region operated by a US-owned company sits inside its scope exactly as a Virginia one does. This is the single most commonly misunderstood point in UK AI procurement, and it survives every attempt to configure around it.

Worth stating our own position before the argument rather than after it: credible sovereignty is sold as a specific Enterprise tier, and AnswerVault is no exception. Its Starter, Pro and Business tiers sit within CLOUD Act scope, and the closing section sets out exactly what that means. A vendor writing about this subject while implying its whole product line escapes the statute would be committing the error the rest of this post describes.

What follows is what the statute actually reaches, what the realistic exposure looks like for a UK organisation, and which of the controls vendors offer make a difference. The wider regulatory and market picture sits in our guide to sovereign AI for UK organisations.

What the CLOUD Act actually does

The US CLOUD Act (2018) compels US-headquartered companies to produce customer data on demand regardless of where that data physically sits. Two features of that sentence do the work, and both are routinely lost when the point is summarised.

The obligation attaches to the company

A production order under the Act is served on a legal person, not on a building. The question a court asks is whether the company has possession, custody or control of the data, not which jurisdiction the disk is in. A US-incorporated provider that can retrieve your documents from its London region in the ordinary course of running its service has control of them for these purposes. Moving the workload between the provider's own regions changes the answer to a question nobody is asking.

It reaches through the corporate group

Because control rather than geography is the test, the reach extends from a US parent to the subsidiaries it owns and the data those subsidiaries hold. Contracting with a UK-registered subsidiary of a US group therefore does not place the arrangement outside the parent's obligations. This is why the entity that appears on your order form is a weaker signal than the entity that ultimately owns it.

Public statements have made the limit unusually explicit. Microsoft confirmed to the French Senate in June 2025 that it cannot guarantee EU data will never be accessed by US authorities. That is not a criticism of Microsoft. It is an accurate description of what any US-incorporated company is in a position to promise, and a more useful statement than most of what appears in vendor security documentation.

Why a UK region does not close the gap

Region selection is a placement setting inside a single provider's estate. It determines which of that provider's data centres holds the content and, usually, which of them runs the compute. It does not alter the provider's country of incorporation, its ownership, or the law its officers must obey. Treating region choice as a jurisdictional control mistakes a deployment option for a change of legal status.

There is a second, quieter problem. Storage and processing are separate facts. A platform can hold documents in London while sending the reasoning step that reads them somewhere else, and a hosting-region claim would disclose nothing about that. For an AI knowledge platform this matters more than it does for a file store, because the content has to be read in cleartext by whatever composes the answer. When assessing a supplier, the tier worth asking about is the one that processes the content, not the one that stores it.

Note also that compliance and jurisdiction are different tests. Chapter V of the GDPR governs transfers of personal data rather than corporate nationality, so a service can be entirely compliant on transfers and still sit within a foreign jurisdiction's reach. A completed transfer impact assessment is not an answer to the client's question above.

The CLOUD Act risk UK data holders are actually exposed to

It is worth being proportionate here, because overstatement has done real damage to these conversations. The exposure is not that US authorities are routinely reading British corporate documents. Requests are targeted, subject to process, comparatively rare, and in most cases irrelevant to an organisation's day-to-day operations.

The exposure is that you cannot give an unqualified assurance. Three situations turn that from a theoretical position into a practical one:

  • A client audit or supplier assurance review, where a customer with its own regulatory obligations asks precisely the question at the top of this post and will not accept a hosting answer.
  • A contractual warranty, where the organisation has committed to keeping certain material outside foreign jurisdictional reach, sometimes without anyone checking whether the platform supports the promise.
  • A sector rule or regulator enquiry, where concentration and jurisdiction of critical third parties are in scope. Financial services buyers meet this most directly, and the mechanics are set out in our guide to DORA Article 28 and AI knowledge platforms.

There is a further wrinkle specific to UK organisations. A bilateral data access agreement between the United Kingdom and the United States allows authorities in each country to seek certain data directly from providers in the other, subject to conditions and safeguards. It cuts in both directions, and it is a reason the position deserves describing accurately rather than dramatising: the point is not that one jurisdiction is untrustworthy, but that your assurance needs to name which ones can reach the content.

What actually reduces the exposure

Vendors offer a range of controls in this area, and they are not equivalent. Testing each against the specific question of legal reachability sorts them quickly.

Control offered Changes CLOUD Act reach? What it does give you
UK or EU region selection No Data residency: lower transfer-compliance friction, better latency, and a straightforward answer to a location question
UK contracting subsidiary of a US group No A local commercial relationship, local support and local invoicing; obligations still attach to the parent
Encryption at rest with provider-managed keys No Protection against infrastructure compromise, which is a different threat from legal compulsion
Customer-held keys the provider genuinely cannot decrypt Partly Reduces what can be produced in intelligible form, but the claim must be verified against the architecture, including the processing tier
Processing operated by a non-US-owned entity under non-US law Yes Control at the layer that decides the question, committed contractually rather than configured

The last row is the only one that answers the question outright, and it carries real costs: a smaller and less feature-mature supplier field, higher infrastructure cost, and a stricter failover posture than a mainstream platform offers. Those are sound trade-offs where a risk assessment has identified foreign-jurisdiction access as material, and poor ones where it has not. Most UK organisations are proportionately served by residency plus a defensible audit trail, a judgement we set out in our explainer on what sovereign AI means for enterprise buyers.

How AnswerVault handles jurisdiction

AnswerVault is a governed AI knowledge layer that connects an organisation's existing document sources, including SharePoint, Google Drive and Confluence, and answers from approved document sets through web chat, Microsoft Teams, Slack, CLI and API.

The position differs by tier, and stating that plainly is more useful than a single claim stretched across everything. The Starter, Pro and Business tiers run on mainstream cloud infrastructure with a commercially managed AI tier. Both of those are provided by US-headquartered companies, so the CLOUD Act applies to those tiers regardless of which region is selected, and they should be assessed on a data-residency basis rather than a sovereignty one. Region selection is available from Business upwards. Presenting any of this as placing content outside US jurisdiction would be the exact substitution this post argues against.

The Enterprise sovereign tier is the one built for the requirement above: non-US infrastructure, UK corporate control over the tier that processes content, no cross-jurisdiction model fallback, and a contractual commitment rather than a configuration setting. If your answer to a client questionnaire has to survive scrutiny, that is the tier the question is about.

AnswerVault is ISO 27001 aligned, G-Cloud listed, and ISO 42001 certification is underway. The subprocessor list, the attestations, audit rights and the identity of the certifying entity are published on our security and compliance page, which is the material a procurement team needs in order to test any of the above rather than take it on trust.

Where to go next

Before the next assurance questionnaire arrives, establish two things in writing for each platform holding material you would not want disclosed: which legal entity operates the tier that processes the content, and under which country's law that entity is incorporated. Those two facts settle the jurisdiction question. Everything else in a security pack describes something adjacent to it.

Then decide deliberately whether your own risk assessment justifies the cost of closing the gap, or whether residency and a strong audit trail are the proportionate answer. Both are defensible conclusions. Reaching one by accident is not. Our guide to sovereign AI for UK organisations covers the regulatory background, the UK and EU supplier landscape, and how jurisdiction interacts with governance and audit obligations.


AnswerVault is built by Catapult CX, an enterprise technology consultancy. The product was originally developed for a global pharmaceutical company with strict data governance requirements; the same architecture now powers the SaaS platform.

Frequently asked questions

Does hosting data in the UK protect it from the US CLOUD Act?

No. The CLOUD Act obliges US-headquartered companies to produce customer data regardless of where that data is stored. Because the duty attaches to the company rather than to the data centre, selecting a UK region from a US-owned provider changes the location of the data without changing who can be compelled to hand it over.

What is the CLOUD Act risk for a UK organisation in practice?

Chiefly an assurance and contractual risk rather than a day-to-day access risk. Requests are targeted and comparatively rare, but the organisation cannot truthfully tell a client, auditor or regulator that no foreign authority can compel disclosure. Where a contract or a sector rule requires that assurance, the gap becomes a live problem.

Does using a UK subsidiary of a US provider help?

Not for this purpose. Extraterritorial obligations attach to the ultimate parent company, and through the parent to the subsidiaries it controls. A UK contracting entity gives a local commercial relationship and local support, which are useful for other reasons, but it does not place the arrangement outside the parent's legal obligations.

Does encryption solve CLOUD Act exposure?

Only in specific architectures. Encryption at rest with keys the provider holds does not help, because a provider able to decrypt data in the ordinary course of business can be required to produce it in readable form. Arrangements where the customer holds the keys and the provider genuinely cannot decrypt reduce what can be produced, but the claim needs verifying against the architecture rather than the brochure.

What actually removes CLOUD Act reach?

Having the tier that processes the content operated by an entity that is not US-owned and not subject to US law, committed contractually rather than set as a configuration option. This costs more and narrows the supplier field, so it is worth doing where a risk assessment identifies foreign-jurisdiction access as material, and is disproportionate where it does not.
Try AnswerVault

Ready to put your documents to work?

Connect your document sources and start querying in minutes.