# The Cloud Act and generative AI: what is really exposed

> The Cloud Act comes up in almost every discussion about AI in business, rarely with precision. The law does not look at where your data is, but at who holds it and which jurisdiction that entity falls under. That criterion decides your exposure, flow by flow.

Source: https://smartagt.ai/en/ressources/cloud-act-ia/
Published: 2026-09-22
Publisher: SmartAGT (NERVIAL LABS)

---
## What the law actually says {#text}

The Clarifying Lawful Overseas Use of Data Act, known as the Cloud Act, is a US law enacted on 23 March 2018. Its core provision is codified at [Title 18 of the US Code, section 2713](https://www.law.cornell.edu/uscode/text/18/2713). It requires providers of electronic communication services and remote computing services to preserve, back up or disclose data within their “possession, custody, or control”, whether that data is located inside or outside the United States.

Three elements of that sentence decide everything:

- **Who the obligation falls on**: the service provider, not the customer, and not the data centre.
- **The test**: possession, custody or control of the data, not its location.
- **The framework**: the procedures of the US Stored Communications Act, in other words requests from authorities in a criminal law context.

The law also gives the provider a remedy: it can challenge a request where the person targeted is not a US person, does not reside in the United States, and disclosure would expose the provider to breaching the law of a foreign country. That remedy is reserved for countries that have concluded an executive agreement with the United States. According to the [European Commission](https://commission.europa.eu/law/cross-border-cases/judicial-cooperation/types-judicial-cooperation/e-evidence-cross-border-access-electronic-evidence_en), negotiations on an EU-US agreement on electronic evidence are ongoing.

> **Key point** The Cloud Act does not create open access to European data. It creates an obligation for certain operators to answer lawful US requests, including for data stored outside the United States.

## What is exposed: the operator, not the location {#exposed}

The practical consequence is simple to state: what counts is the jurisdiction of the entity that holds or controls your data. The address of the data centre offers no protection on its own.

- **Exposed** A service operated by a company subject to US jurisdiction, even when hosted in France. The question also arises for a European subsidiary whose parent company controls the data.
- **Not exposed under this law** A service operated by an entity outside US jurisdiction that has no control over data held elsewhere. Processing you run yourself, within your own perimeter.
- **To be checked** A European operator that subcontracts part of the service (support, monitoring, infrastructure) to a US company able to access the data.

*Exposure is judged on the chain of control over the data, down to the last subcontractor.*

The notion of control is what makes the analysis tricky. A European operator can be shielded for its own operations and exposed through a supplier with technical access. This is exactly what the French SecNumCloud scheme run by ANSSI targets: in version 3.2, it requires that a non-European subcontractor has no technical ability to obtain the data processed through the service, on top of conditions on the provider's registered office and shareholding.

## Applied to generative AI: the flows involved {#ai-flows}

For an AI project, the question arises for each flow, and there are more flows than it seems.

| Flow | Where it may sit | Exposed if |
| --- | --- | --- |
| Prompts and attachments | At the model provider, during processing and under its retention policy | The provider falls under US jurisdiction |
| Document context (RAG) | In every request sent to the model | Same: it travels with the prompt |
| Logs and history | At the platform vendor, at the model provider | Either of them falls under that jurisdiction |
| Vector indexes | In the database that stores them | That database is a cloud service run by a US company |
| Administration data | At the vendor, for support and monitoring | Support accesses data from an exposed entity |

One point is specific to generative AI: a model does not process encrypted data. Encryption at rest, even with keys you hold, protects storage; it does not protect the text that has to be given to the model in clear to produce an answer. If that model runs at an exposed operator, the prompt's content is exposed during processing too, and beyond if the provider retains it.

## What the GDPR offers, and its limits {#gdpr}

[Article 48 of the GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj) provides that a judgment or decision of a third-country court or authority requiring personal data to be disclosed is only recognised or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty. In their [joint assessment of 2019](https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_edps_joint_response_us_cloudact_coverletter.pdf), the European Data Protection Board and the European Data Protection Supervisor pointed out that a request from a foreign authority is not, on its own, a legal ground for a transfer.

This protection has a limit: it creates a conflict of laws for the operator, not a physical impossibility. A provider subject to both legal systems faces two contradictory obligations, and how it will resolve them is not in your hands.

The EU-US Data Privacy Framework, recognised by adequacy decision (EU) 2023/1795, and against which the EU General Court dismissed an action for annulment on 3 September 2025 (case T-553/23), governs transfers to certified US companies. It does not turn a US operator into one subject to European law alone.

## How to check your exposure {#check}

The check is done provider by provider, following the chain all the way up.

- **List the parties** For each flow in the table above: platform vendor, model provider, host, vector database, web search service, support provider.
- **Trace the ownership** For each one, get the contracting entity, its parent company and the ultimate parent. A French address says nothing about the chain of control.
- **List the sub-processors** Who has technical access to the data, from which country, and for which operation?
- **Read the retention terms** How long are prompts and answers kept, and for what purposes? Data that is not retained cannot be handed over later.
- **Decide by data class** Sensitive data goes to a local model or a verified operator; the rest can go elsewhere, possibly after pseudonymisation.

*A check that stops at the first-tier contract leaves out most of the exposure.*

For flows that still have to go to an exposed operator, removing personal data before sending reduces what can be handed over: that is the subject of the guide [Anonymise or pseudonymise before an LLM](~/ressources/anonymiser-donnees-llm/). The wider picture, beyond the Cloud Act alone, is in the guide [Data sovereignty and generative AI](~/ressources/souverainete-donnees-ia/).

## Common mistakes {#mistakes}

### Settling for a “Europe” region

Choosing a European hosting region at a US operator settles location, not jurisdiction. It is the most widespread case, and the one that most often gives a false sense of security.

### Forgetting subcontractors

A European operator that hands monitoring or support to a US supplier with technical access brings the exposure back in through the service entrance.

### Banning everything on principle

Not all flows are equal. A summary of a press article is not at the same stake as a medical file. Banning every non-European model often pushes users towards personal tools that are even less controlled.

## Frequently asked questions {#faq}

### Is my data hosted in France by a US company affected?

It can be. The Cloud Act targets data in the provider's possession, custody or control, wherever it is stored. What matters is the jurisdiction of the operator and its chain of control, not the address of the data centre.

### Is encryption enough to protect us?

It protects storage if you alone hold the keys. It does not protect data while a model is processing it, since the model has to read it in clear. For generative AI, encryption does not replace the choice of the operator running the model.

### Is a model run on our own servers exposed?

Not under the Cloud Act through a provider, since no provider holds the data. Do check, however, that the platform around the model sends no telemetry or logs to an exposed vendor, and that support has no uncontrolled remote access.

### Where SmartAGT fits
SmartAGT is deployed on-premise, within your perimeter. You choose the model provider: 100% local, with no outbound traffic at all, or a cloud provider you contract with directly, and the administrator can restrict the catalogue to European providers.
In hybrid mode, personal data is detected and reversibly pseudonymised, in a vault, before any outbound call. No raw prompt is stored. Details are on the [Security](~/security/) page.
