Public previewRAGSuite is open-source, self-hosted and EU-ready — and we build it in the open.See it live

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Sovereignty

The US CLOUD Act and your AI vendor: what DACH buyers should ask

The US CLOUD Act lets US authorities compel US-based providers to disclose data — wherever it's stored, including EU regions. What DACH buyers should ask.

SOVEREIGNTY §extraterritorial demand · blocked ragsuite.de
Jürgen Pietschmann
Jürgen Pietschmann AI Consultant
Published15 June 2026 Updated25 June 2026 Read2 min Sovereignty

The US CLOUD Act lets US authorities compel a US-headquartered provider to disclose data it controls — regardless of where that data is physically stored, including an EU data centre. For a DACH enterprise putting its knowledge into an AI platform, that is not a remote legal footnote; it is a line item in the risk assessment, and the reason “EU region” alone does not settle the sovereignty question.

What the CLOUD Act actually does

The Clarifying Lawful Overseas Use of Data Act gives US law enforcement a mechanism to require US-based providers to produce data in their possession, custody or control — even when the servers sit in Frankfurt or Dublin. The obligation follows the provider’s jurisdiction, not the data’s location. This sits in tension with the DSGVO, which restricts such transfers, and the enterprise customer inherits the uncertainty.

The questions to ask a vendor

Surface the real position

  • Who ultimately owns and controls the entity that processes our data, and under which jurisdiction?
  • Could a foreign authority compel disclosure of our data without our knowledge?
  • Can the platform run entirely within our own infrastructure, with no provider access at all?
  • If we go air-gapped, does the product still work?

A vendor that cannot give clean answers to the first two, and a “yes” to the last two, is offering convenience — not sovereignty.

How self-hosting removes the question

See What is sovereign enterprise AI? and data residency vs. sovereignty for the fuller framework. This is general information, not legal advice — assess your own exposure with qualified counsel.

Frequently asked questions

Does an EU subsidiary or 'EU cloud' brand solve it?

Not on its own. What matters is who ultimately controls the processing entity and under which jurisdiction it can be compelled. An EU-badged service with a US parent can still face an extraterritorial demand.

Is this only a banking problem?

No. It applies wherever you concentrate sensitive or regulated data — healthcare, public sector, KRITIS operators, and any enterprise where a data-transfer finding would matter in a risk assessment.

Sources & further reading

  1. US CLOUD Act — overview (US Department of Justice) — the mechanism and its reach
  2. EDPB–EDPS joint response on the CLOUD Act — the EU data-protection view
  3. Data residency vs. data sovereignty — why location isn't control

← All posts