Is your AI supplier within reach of the US CLOUD Act?
Seven questions about who owns your stack. About two minutes. No email address, no tracking, your answers stay in your browser.
In 2018 the United States enacted the CLOUD Act. It requires any provider subject to US jurisdiction to preserve and disclose data within its “possession, custody, or control”, and to do so “regardless of whether such communication, record, or other information is located within or outside of the United States” (18 U.S.C. § 2713). In plain terms: if the company can be compelled in a US court, the location of the servers does not settle the question. Data residency is about geography. The CLOUD Act is about what they keep about you.
This is not a theoretical reading of the statute. Asked before a French Senate commission of inquiry on 10 June 2025 whether he could guarantee that French citizens’ data would never be transmitted to the US authorities without the agreement of the French authorities, the director of public and legal affairs of Microsoft France answered, under oath: no, he could not guarantee it, adding that it had never happened. Both halves of that answer deserve to be taken seriously. This checker is about the first half: whether the legal route into your data exists at all.
Answer the questions below about the AI or cloud service your practice actually uses, including any unofficial ChatGPT habit, if that is the honest answer. If you don’t know an answer, say so. Not knowing is a finding in its own right, and the result will tell you exactly which questions to put to your supplier in writing.
Within direct reach.
On your answers, the company you contract with, or its parent, is subject to US jurisdiction. Under 18 U.S.C. § 2713, a provider subject to US jurisdiction must disclose data in its “possession, custody, or control... regardless of whether” that data “is located within or outside of the United States”. UK data residency does not close this route; it determines where your data sits, not who can be compelled to hand it over. To be equally clear about what this verdict is not: it is not a finding that your data has been accessed, that access is likely, or that using this supplier is unlawful. US authorities need a qualifying legal order, orders can be challenged, and the Microsoft executive who told the French Senate he could not guarantee non-disclosure also said it had never happened. The finding is narrower and more useful than alarm: the legal route exists, your contract and your hosting region do not remove it, and your DPIA should say so in those words rather than rely on “UK hosting” to answer a question it cannot answer.
What to do next
- Record the exposure in your DPIA by name, the CLOUD Act and the entity it attaches to, rather than under generic “third-country transfer” boilerplate.
- Decide deliberately which categories of text staff may put into the service, and write that down as practice policy. A dictated patient letter and a rota query are different decisions.
- Put the questions you could not answer from public pages to your supplier in writing: who owns the inference hardware, and which entities in the chain are subject to US legal process.
- Treat the answer as a procurement input at renewal, not necessarily an emergency today. The point of knowing is to decide on purpose.
- Ask your supplier to publish who owns the inference hardware and where content is processed. If it is good news, they should want to; if they decline, note that in your DPIA.
- Ask for one sentence in writing: “No company in our ownership or processing chain can be compelled to disclose your data under US law”, or their nearest honest alternative. File whichever sentence you receive.
- Your supplier’s written confirmation appears inconsistent with your other answers. Re-read what they actually signed, confirmations about “your data at rest in the UK” are not confirmations about jurisdiction.
Within reach through the supply chain.
Your supplier may well be UK- or EU-owned, but on your answers your content passes through US-owned hands, a model API, a cloud platform, or hardware operated by a US company. The CLOUD Act binds providers subject to US jurisdiction, and the question for your data is asked of every link that has possession, custody or control of it, not of the logo on the invoice. A UK company reselling a US model has moved the contract; it has not moved the jurisdiction. As with every verdict on this page, this is not a finding that anything has been accessed. It is a finding that the route exists one step down the chain, which is precisely where it is easiest for a DPIA to miss.
What to do next
- Ask your supplier for the complete sub-processor list in writing, with each entity’s country of incorporation and ultimate parent. Under UK GDPR Article 28 this is a reasonable request, not an awkward one.
- Ask specifically where inference happens and who owns those machines. “UK region” names a location, not an owner.
- Update your DPIA to assess the chain rather than the contracting party alone, and date the assessment.
- Ask your supplier to publish who owns the inference hardware and where content is processed. If it is good news, they should want to; if they decline, note that in your DPIA.
- Ask for one sentence in writing: “No company in our ownership or processing chain can be compelled to disclose your data under US law”, or their nearest honest alternative. File whichever sentence you receive.
- Your supplier’s written confirmation appears inconsistent with your other answers. Re-read what they actually signed, confirmations about “your data at rest in the UK” are not confirmations about jurisdiction.
Exposure unknown, which is itself a finding.
You could not answer one or more of the questions that determine whether a US legal route into your data exists. That is not a criticism. Most of this information is genuinely hard to find, and some suppliers prefer it that way. But it means your practice’s current position is “exposure undetermined”, and a DPIA that is silent on a question this basic is incomplete rather than reassuring. The useful news is that every gap on this page can be closed with one short letter, and a supplier’s speed and directness in answering it will tell you nearly as much as the answers themselves.
What to do next
- Send your supplier the unanswered questions in writing. The link below preserves your answers, so you can see exactly which ones are open.
- Ask for four things: the ultimate parent company and its country of incorporation; the entity you contract with and the governing law; the complete sub-processor list with countries of ownership; and who owns and operates the inference hardware.
- Diarise a reply deadline. A supplier that cannot answer ownership questions in writing within two weeks has answered a different question.
- Re-run this check when the letter comes back.
- Ask your supplier to publish who owns the inference hardware and where content is processed. If it is good news, they should want to; if they decline, note that in your DPIA.
- Ask for one sentence in writing: “No company in our ownership or processing chain can be compelled to disclose your data under US law”, or their nearest honest alternative. File whichever sentence you receive.
- Your supplier’s written confirmation appears inconsistent with your other answers. Re-read what they actually signed, confirmations about “your data at rest in the UK” are not confirmations about jurisdiction.
Outside direct reach, on your answers.
On what you have told us, no company in your AI supply chain is US-owned, US-contracted or running on US-operated hardware. If that is correct, the CLOUD Act has no direct route to your data: the statute binds providers subject to US jurisdiction, and on your answers there are none in the chain. Two honest caveats belong next to that. First, this page cannot verify your answers, only your supplier’s written confirmation can, and if you do not yet hold one, that is the next step. Second, “outside the CLOUD Act” does not mean “beyond all legal process”: US authorities can still seek data held in the UK through UK courts, by mutual legal assistance or under the UK, US Data Access Agreement in force since October 2022, and UK authorities have powers of their own. The difference is that those routes run through UK law and UK oversight, which is exactly why what they keep about you, not server location, were worth checking in the first place.
What to do next
- Keep a dated copy of this result with your DPIA as a record that the question was asked and answered.
- Re-check at contract renewal and on any acquisition or investment news. Ownership is a fact, and facts change.
- If a supplier in your chain is acquired by a US company, the analysis above changes on the day the deal closes, not when the privacy policy is updated.
- Ask your supplier to publish who owns the inference hardware and where content is processed. If it is good news, they should want to; if they decline, note that in your DPIA.
- Ask for one sentence in writing: “No company in our ownership or processing chain can be compelled to disclose your data under US law”, or their nearest honest alternative. File whichever sentence you receive.
- Your supplier’s written confirmation appears inconsistent with your other answers. Re-read what they actually signed, confirmations about “your data at rest in the UK” are not confirmations about jurisdiction.
Sources
- 18 U.S.C. § 2713, enacted 23 March 2018 by the CLOUD Act (H.R. 4943, Pub. L. 115-141, Div. V).
- French Senate commission of inquiry into public procurement and digital sovereignty, audition of Microsoft France, 10 June 2025 (video of the hearing).
- UK, US Data Access Agreement, in force 3 October 2022.
Frequently asked questions
What is the US CLOUD Act?
The CLOUD Act is a 2018 US law (18 U.S.C. § 2713) requiring any provider subject to US jurisdiction to disclose data in its possession, custody or control when lawfully ordered, regardless of whether that data is stored inside or outside the United States.
Does UK data residency protect my data from the US CLOUD Act?
No. Data residency is about where servers sit; the CLOUD Act is about who can be compelled. A US-owned company holding your data in a UK region still holds it within reach of a US order. Residency is geography; jurisdiction is the law it answers to.
How do I know if my AI tool is exposed to the CLOUD Act?
Answer seven questions about who owns your AI supplier and where it processes your data. This free checker computes the result in your browser, no email address, no tracking, and gives you a link you can share with your DPO.
Worried by your result? Get the 1-page CLOUD Act brief.
A plain-English brief you can forward to your DPO, plus how an alternative with no US parent removes the exposure. Free.
Get the brief, free →No email, no sign-up. Download it straight from our resources page, and we keep no conversations or documents.