Streamline your contract management needs
Start today with GAIA - your new standard for legal management and get legal tasks done efficiently!
Introducing: GAIA Agentic AI Contract Extractions
Read moreEU data residency and EU data sovereignty aren't the same thing. Under the US CLOUD Act, who controls your LLM provider — not where its servers sit — decides who can reach your contract data. A practical guide for in-house legal teams, plus the honest trade-off of going fully European.
Most legal teams evaluating AI can tell you where their data is stored. Far fewer can tell you whose law can reach it. Why this matters: Under the US CLOUD Act, exposure follows who controls the provider, not which city the servers sit in, which is why EU data residency and EU data sovereignty are not the same thing. This piece unpacks the legal conflict beneath that distinction, why a European provider can offer something a US provider with EU data centres cannot fully match, and the honest trade-off if you go fully European.
A practical guide for in-house legal teams choosing the AI that reads their contracts.
When a legal team evaluates an AI tool for contract work, the first question is almost always: where is our data hosted? It feels like the responsible question, and vendors are ready for it. "Data stays in the EU." "Frankfurt region." "Sovereign cloud." These sound like reassuring answers, but hide an important distinction you should know about.
The harder question is whose law can reach your data? And that is a question about the provider's nationality, not the server's postcode. For contract data specifically — among the most sensitive commercial information a company holds, and routinely subject to strict confidentiality obligations — getting this distinction right enables an informed decision.
Two bodies of law collide here, and the collision has never been cleanly resolved.
On the European side, the GDPR treats any transfer of personal data outside the EU as something you may only do under defined conditions (Chapter V, Articles 44–49), the baseline principle being that the data may leave the EU only if it will enjoy protection essentially equivalent to European standards. Contracts are full of personal data — signatories, employees, beneficial owners, counterparties — so almost any contract workflow touches this. The cleanest way to satisfy that rule is an adequacy decision: a formal finding by the European Commission (under Article 45 GDPR) that a particular country protects personal data well enough for it to flow there freely, without each company having to put its own extra safeguards in place. The mechanism that currently supplies that finding for the United States is the EU-US Data Privacy Framework, the adequacy decision the Commission adopted in 2023.
The problem is that the Framework is standing on shaky ground. It is the third attempt at a transatlantic data deal; its two predecessors were both struck down by the Court of Justice of the European Union — Safe Harbor in 2015 (Schrems I, Case C-362/14) and Privacy Shield in 2020 (Schrems II, Case C-311/18). In both cases the Court reached the same conclusion:
US surveillance law let government agencies reach Europeans' data too broadly, and EU individuals had no effective way to challenge it in a US court. So the protection on offer was not "essentially equivalent" to the GDPR's.
It cleared its first legal test in September 2025 — the EU's General Court dismissed the challenge and upheld the adequacy decision in full — but the Court judged it only on the situation as it stood in 2023, expressly declining to weigh later developments, and that narrow framing is now the strongest ground of the appeal pending before the CJEU (Case C-703/25 P). The US foundations underneath have kept shifting since: the oversight body the Commission had relied on lost its quorum, and Section 702 of FISA — the surveillance authority at the centre of the dispute — lapsed in mid-2026 without reauthorization, with only existing court certifications keeping collection running into 2027. Privacy campaigners have already signalled the next challenge — the one commentators are calling "Schrems III." Nobody serious treats the current Framework as permanent.
On the US side sits the CLOUD Act. Passed in 2018, it lets US authorities compel a US-based provider to hand over data it controls — regardless of where that data is physically stored. Its reach follows corporate control, not geography. A legal demand served on a US company's headquarters can compel production of data sitting on its servers in Frankfurt, Amsterdam, or Dublin. The data centre's location is legally irrelevant; what matters is that the entity holding it answers to US law.

Complying with a CLOUD Act order can put a company in breach of GDPR Article 48. That article says a judgment or order from a third-country court or authority is not, on its own, a valid basis to transfer or disclose EU personal data — it can be recognised or enforced only where it rests on an international agreement between that country and the EU or a member state, such as a mutual legal assistance treaty (MLAT). A CLOUD Act warrant is exactly the kind of unilateral foreign order the article is meant to catch, so unless it runs through an MLAT or is backed by another lawful basis under the GDPR, complying with it means making an unlawful disclosure. This isn't just a literal reading of the text: in a 2019 joint assessment with the EDPS — since reaffirmed in the EDPB's dedicated Guidelines 02/2024 on Article 48 — the European Data Protection Board took the view that a CLOUD Act warrant cannot, by itself, make such a transfer lawful. The result is a genuine conflict of laws that leaves US providers and their European subsidiaries in an impossible position: comply with the US order and breach the GDPR, or refuse and breach US law. For a European company, that may be a dilemma it isn't willing to accept — and either way, the point is to make the choice knowingly, rather than discover it after a warrant has already landed.
This is where the marketing and the law part ways.
A US hyperscaler or AI provider can truthfully tell you your data lives in an EU region. That genuinely reduces some risks: lower latency, cleaner data-residency posture, fewer cross-border transfer headaches in day-to-day operation. It is not nothing.
But it does not remove US jurisdiction. If the provider is a US entity, or is ultimately controlled by one, the CLOUD Act still reaches the data — Frankfurt or not. "Sovereign cloud" branding does not change who the company answers to when a US order lands. Data sovereignty, in other words, cannot be delivered by a contractual promise or a hosting region alone; it is a function of which legal system the provider sits inside.
That is the real reason a European team might prefer a European provider over a US provider with EU data centres. It isn't a preference for European companies as such, and it isn't flag-waving. It's that a provider outside US jurisdiction addresses the CLOUD Act exposure at its root rather than merely managing it. Everything else — encryption, EU hosting, strong contracts, no-training guarantees — mitigates the risk; a provider with little or no US jurisdictional hook reduces it structurally. That isn't an absolute: the CLOUD Act reaches any provider subject to US jurisdiction, so a European company with US subsidiaries, staff, or substantial US business is not automatically beyond reach, and the statute has a comity mechanism for conflicting foreign law. The point is that jurisdiction is the lever that actually moves this risk — not the server's location.
For most workloads, mitigation is fine. For your most sensitive contracts — M&A, litigation-adjacent agreements, anything strategically explosive if disclosed — the difference between merely mitigating the exposure and removing its root cause is exactly the kind of distinction a GC is paid to notice.
So the clean answer is "use a European model like Mistral for everything," right?
Not so fast — and any vendor who tells you it's that simple is selling, not advising.
A genuinely European provider like Mistral gives you real advantages beyond jurisdiction: European data residency by default, open-weight models — many released under permissive licences — that you can self-host whenever you want full control rather than only in the most regulated corner cases, strong multilingual coverage across EU languages, and typically lower cost per token. For a European legal team, that's a serious package.
The trade-off is capability. On published reasoning and long-context benchmarks, the frontier US labs — Anthropic's Claude, OpenAI's GPT — have tended to hold a lead on the hardest tasks, which matters most precisely where contract review is unforgiving, since a confidently wrong extraction is worse than no extraction at all. But the gap has narrowed sharply — on general tasks a European model like Mistral is now competitive — and "narrowed" is not "closed."
So the real decision isn't European or American. It's a spectrum of positions, each with a different balance of capability and sovereignty:
The uncomfortable truth is that there is no single correct model for a legal team. There is a correct framework: know which jurisdiction each option sits in, know what each one can and can't reach, and route each type of contract to the option whose risk profile fits.
That's the logic behind keeping the model choice open rather than locking your team to whatever a single vendor happened to build on. GAIA works with most of the leading AI providers — including the major US models through their European-based data centres, as well as Mistral as a fully European option — so an organisation can align the model behind its contract work with its own risk appetite. And because that choice carries real compliance weight, it sits where it belongs: as an organisation-level decision owned by the people accountable for data governance, not something left to chance.
Ask your AI vendor a simple question: if a US court ordered it, could your provider be compelled to produce our contract data — yes or no? If the honest answer is yes, EU hosting hasn't solved your problem. It has postponed it until someone asks the right question.
GAIA works with most of the leading AI providers — including the major US models through their European-based data centres, as well as Mistral as a fully European option — so your organisation can align the model behind its contract work with its own balance of capability and data sovereignty.
Written by
Simona Sopova
on
August 25, 2026