industry · product
AI Data Residency: Where Do Your Customer Conversations Live?
Most businesses buy an AI agent without asking which country their customer messages land in. Here is why that question got urgent in 2026, and the eight things to ask a vendor before you sign.

AI data residency is the question of which countries your customer messages are stored and processed in, and which governments can reach them there. It stopped being a paperwork question this year. In a February 2026 survey of 203 enterprise IT decision-makers, 58% said data residency concerns had already delayed or scaled back an AI initiative, and Gartner expects sovereign cloud infrastructure spending to reach $80 billion in 2026, up 35.6% year over year. A single customer message handled by an AI agent passes through four separate organizations before the reply comes back, mapped below. Most buyers have never asked which ones.
What does AI data residency actually mean?
Three words get used interchangeably and mean different things. Separating them is most of the work.
| Term | The question it answers | Worked example |
|---|---|---|
| Residency | Where is the data physically stored? | Your customer transcripts sit on disks in a Frankfurt data centre. |
| Sovereignty | Whose laws can reach it? | Those Frankfurt disks are operated by a US-headquartered company, so US legal process may still apply. |
| Localization | Does a law require it to stay in-country? | Several jurisdictions require certain categories of personal or health data to remain onshore. |
Residency and sovereignty come apart, and that gap is the entire argument. A data centre inside the EU does not by itself put the data outside the reach of a non-EU government. Conversely, a well-drafted transfer mechanism can make a cross-border flow lawful without moving a single byte.
The backdrop is that this is now near-universal regulation, not a European quirk. As of the IAPP's January 2025 directory update, data protection and privacy laws were in effect in 144 countries. If you sell across borders, you are already inside several of them.
Why did this get urgent in 2026?
Because the main legal bridge between the EU and the US developed a visible crack.
On 29 June 2026, the US Supreme Court decided Trump v. Slaughter, overruling Humphrey's Executor and holding that FTC commissioners are removable by the president at will. That matters for data transfers because the European Commission's 2023 adequacy decision, the legal basis of the EU-US Data Privacy Framework, leaned explicitly on the FTC being an independent supervisory authority whose commissioners could be removed only for "inefficiency, neglect of duty, or malfeasance in office."
The European Data Protection Board noticed. On 31 July 2026, EDPB Chair Anu Talus wrote to Commissioner Michael McGrath asking the Commission to "closely assess" how the ruling affects the FTC's ability to uphold DPF commitments. Max Schrems, who killed the framework's two predecessors, told the IAPP "the deal is done" and confirmed noyb is working on a fresh case for the Court of Justice.
Here is the part that gets lost in the headlines. Nothing is illegal today.
| When | What happened or is expected |
|---|---|
| 3 Sept 2025 | The EU General Court dismissed the Latombe challenge and upheld the DPF (Case T-553/23). |
| 29 June 2026 | Trump v. Slaughter removes the FTC's for-cause removal protections. |
| 31 July 2026 | The EDPB formally asks the Commission to reassess the DPF. |
| Today | The adequacy decision remains in force. It has not been suspended or withdrawn. |
| Early to mid 2027 | The Court of Justice is expected to rule on the Latombe appeal. |
Skadden's read is the practical one: there is "at minimum a reasonable possibility" the Court strikes the decision down when asked, and companies should review their fallback arrangements now rather than after. Standard contractual clauses and binding corporate rules remain valid either way, which is why most careful vendors run both.
None of this is happening in isolation. In a separate Gartner survey fielded between May and July 2025, 61% of Western European CIOs and IT leaders said they were increasing their reliance on local or regional cloud providers for geopolitical reasons. Buyers moved before the courts did.
Where does a customer message actually go?
When a customer sends a WhatsApp message and an AI agent answers the DM, the text typically passes through four different organizations:
- The channel platform. Meta, Telegram, or your own website host receives and relays the message under its own terms.
- The AI platform. Your vendor stores the conversation, the contact record, and any media.
- The model provider. The text (and sometimes an image or voice note) is sent to a large language model for the actual reply.
- Sub-processors. Transcription, object storage, email delivery, analytics, error monitoring. This is the layer nobody reads.
Your exposure is set by the weakest link, not the strongest. A vendor's DPA is worth exactly what its own agreements with its sub-processors are worth, which is why the sub-processor list is the document to ask for first.
This is not an enterprise-only problem. Entagl's own Response Velocity Study covered 32,581 conversations drawn from businesses in nine countries: the United States, Türkiye, the UAE, Saudi Arabia, Egypt, Spain, Canada, Greece, and Peru. A ten-person clinic answering DMs can touch several legal regimes in a single week without anyone deciding that it should.
What should you ask an AI vendor about data residency?
Eight questions. Ask them in writing, before signing, and treat a vague answer as an answer.
| Ask this | Why it matters | A bad sign |
|---|---|---|
| In which countries is conversation data stored at rest? | Establishes actual residency, not marketing geography. | "Globally distributed" with no list. |
| Which model providers see customer text, and under what agreement? | The model call is the hop buyers forget. | They cannot name the providers. |
| Is our data used to train models? | The single highest-consequence answer on this list. | "We may use aggregated data to improve our services." |
| Can we see the full sub-processor list, and are we notified of changes? | Your exposure runs through it. | No list, or no change notice. |
| Which transfer mechanism do you rely on, and what is the fallback? | Post-Slaughter, DPF-only is thin. | DPF with no SCCs behind it. |
| How is data encrypted at rest, and who holds the keys? | Often does more real work than residency. | Encryption mentioned without a cipher or key model. |
| What is the retention period, and can we delete on request? | Data you no longer hold cannot leak or be compelled. | Indefinite retention "for quality." |
| Can we bring our own model API key? | Moves the model call into your own contract. | Not supported, no roadmap. |
If you are in healthcare, finance, or another regulated sector, pair this with the specific control requirements in our guide to compliant AI for regulated businesses. The transparency duties that apply when a bot answers a customer are a separate matter again, covered in what the EU AI Act means for AI chatbots.
Does moving data closer actually reduce risk?
Honestly, less than the conference talks suggest, and this part is genuinely unsettled.
In the Cloudian survey, 91% of respondents said they would choose on-premises, private, or hybrid infrastructure for AI involving sensitive company data. That is a preference, not evidence of a better outcome. Residency is a location control. It does very little against the failure modes that actually produce incidents: an over-broad access grant, an employee pasting a customer record into a consumer chatbot, a retention policy nobody enforced, a forgotten sub-processor.
Two controls usually buy more real protection per unit of effort than a map pin.
- A binding no-training commitment plus short retention. Data that was never retained cannot be subpoenaed, breached, or memorized.
- Encryption at rest with a clear key model, and access control that a human reviews. Boring, and it survives a change of venue.
Pulling everything in-house also moves risk rather than deleting it. You now own the patching, the key rotation, and the uptime. For a 40-person business that trade is usually bad. The governance gap that actually bites most companies is the one we covered in shadow AI, and no data centre fixes it.
Residency still matters. It is just the third question, not the first.
How Entagl handles this
Plainly, and with the limits stated:
- Encryption. Messages, media, and personal data are encrypted at rest with AES-256-GCM, and in transit with TLS.
- Signed agreements down the chain. BAAs with AWS, OpenAI (with zero data retention enabled), and Google Cloud for Vertex AI. DPAs in place for GDPR.
- Model routing by compliance posture. Workspaces with HIPAA enabled send their model traffic to Vertex AI under the BAA, and PHI access is written to an audit log. One retrieval surface, Google's File Search store, runs only on the Gemini Developer API and sits outside that BAA today. We will walk you through that carve-out rather than let you find it later.
- Export and deletion. Export is self-service for a workspace owner and arrives as a downloadable package. Deletion runs through a verified request, alongside in-app contact and account deletion.
- Bring your own key. You can supply your own OpenAI or Gemini API key, which moves the model call onto your own contract with that provider. This pairs with the argument for staying model-agnostic rather than locked to one lab.
Now the residency answer itself, stated rather than buried. Conversation data (databases, message storage, media storage) runs on AWS in the United States, in us-east-1. Realtime voice calls are the one exception: they can be routed to an EU media region in Milan (eu-south-1), with the model call on Vertex AI in europe-west8. If your procurement requires EU-only or in-country storage for conversation data, raise it on the call. We would rather scope that honestly than let you assume it.
Bring your sub-processor questions and your legal team's list. Book a 30-minute demo and we will walk the actual data path for your channels, end to end, before you commit to anything.
FAQ
Is data residency the same thing as GDPR compliance?
No. GDPR does not require personal data to stay in the EU. It requires a lawful basis for processing and a valid mechanism for any transfer outside the EEA, such as an adequacy decision, standard contractual clauses, or binding corporate rules. You can be fully compliant while processing data in the US, and you can be non-compliant while keeping everything in Frankfurt.
Does the EU-US Data Privacy Framework still work in 2026?
Yes, as of today. The European Commission's 2023 adequacy decision has not been suspended or withdrawn, and the EU General Court upheld it in September 2025. What changed is the risk profile: after Trump v. Slaughter, the EDPB has asked the Commission to reassess it, noyb is preparing a new challenge, and the Court of Justice is expected to rule on the Latombe appeal in 2027. Most law firms advising on this now recommend keeping standard contractual clauses in place as a backstop.
Do I need an EU data centre to serve EU customers?
Usually not. What you need is a lawful transfer mechanism, a transfer impact assessment, and a vendor who can tell you where the data goes. In-country storage becomes genuinely mandatory in narrower cases, typically specific categories of health, financial, or public-sector data under a national localization rule. Check the rule that applies to your sector before you buy infrastructure to solve it.
What is BYOK, and does it change where my data goes?
Bring Your Own Key means the AI platform calls the model using your API key rather than its own. The request still travels to that model provider, so the geography may not change. What changes is the contractual relationship: the terms, retention settings, and data processing commitments are the ones you negotiated directly with the provider, and the usage appears in your account.
Which question should I ask first if I only get one?
"Is our customer data used to train models, and can you put that in the contract?" It is the answer with the longest half-life. Storage locations can be migrated later. Training is not reversible.
Sources: Cloudian / Centiment, Enterprise AI Infrastructure Survey 2026 (n=203, February 2026); Gartner via Fierce Network, February 2026; IAPP Global Privacy Law and DPA Directory; Skadden, July 2026; IAPP, 3 August 2026. Legal position stated as of September 2026 and is not legal advice.