Where should your Information Live?

On-premise, public cloud, sovereign cloud, or all of the above — rethinking data location in 2026

Does data residency matter more than data sovereignty?


In 2023, when we last wrote about where best to hold a company’s information, there was a straight choice: on-premise or in the cloud. The risk picture has changed dramatically since then. Today, the decision that matters is about location: where your data and information physically sit, and, critically, whose laws can reach them. Data residency is about where the bytes are stored. Data sovereignty is about which country’s legal system governs access to them. A dataset can be resident in Frankfurt and still be sovereign to the United States. That distinction is fundamental to managing data risk, and technology choices.

Who Can Reach Your Data Overseas? | Flare

Who can reach your data overseas?

A guide to the extraterritorial data-access powers governments have given themselves — and where they stop.

In 2018 Microsoft refused a US warrant for emails held on its Dublin servers, arguing US law stopped at the border. Congress disagreed: within weeks it passed the CLOUD Act, rewriting the rules so a US order reaches data anywhere a US-linked provider holds it. The EU, UK, Australia and others have since built their own — sometimes broader — versions. Explore each regime below, and see whether it only bites companies with a local office, or reaches anyone simply doing business in the market. Click a point on the line, or a row in the table, for the detail on that law.
Requires a local subsidiary or established presence Being active in the market is enough
RegimeReach triggerPresence needed?Key penalty
Select a regime above to see the powers taken, whether a local subsidiary matters, and the penalty for refusing.

Two things people sometimes get wrong

“GDPR does this too”GDPR’s Article 3 is genuinely extraterritorial, but it governs how personal data must be processed — it is not a law-enforcement access power, and it explicitly excludes law-enforcement/national-security processing from its scope. It cannot be used to compel production of data the way the CLOUD Act or e-Evidence can.
Canada & standalone Germany/France powersCanada has no extraterritorial production order yet — cross-border requests still rely on mutual legal assistance treaties, though a CLOUD Act-style agreement has been under negotiation since March 2022 and remains unconcluded. Germany and France rely on the EU e-Evidence framework rather than a separate extraterritorial production power of their own — though both also have older national blocking statutes (France’s modernised in 2022) restricting disclosure of evidence to foreign authorities; that’s a different, defensive mechanism, not a rival production power.

Market forces are moving data local


Several pressures now push data toward staying local and regional. Operationally, data gravity has become the dominant design principle. Large datasets are slow and expensive to move; egress fees alone account for an estimated 10 – 15% of the typical cloud bill1, and shifting a large AI training set between regions can cost as much as the compute itself. So the architectural pattern has flipped: rather than moving data to where the compute is, organisations increasingly move the compute to where the data already lives.

Deloitte’s 2026 outlook2 describes exactly this shift from cloud-first to hybrid models organised around where data resides, with cloud for elasticity, on-premise for compliance and cost control, and edge for immediacy. Gartner expects the share of enterprises running AI workloads locally to rise from under 2% in early 2025 to more than 20% by 2028.3

Oil & Gas Data Sovereignty — who really controls the geology

Oil & Gas Data Sovereignty: Who Really Controls the Geology

Many countries make operators report seismic and well data to a national database — that alone doesn’t restrict the data. This orbit separates the jurisdictions that genuinely control, own, or classify oil & gas geological data from those that merely require reporting.
Click a country to see the law, the mechanism, and the consequence.

Genuine export / ownership control
State secrecy classification
Reporting duty only — no restriction
Documented penalty/case
No published penalty figure
🔥

Select a country from the orbit to see its law, what it actually controls, and the consequence for breaching it.

Illustrative summary of publicly available regulatory sources, current as of July 2026, independently fact-checked against primary/near-primary sources. Not legal advice — consult local counsel before making compliance decisions. Where a source did not publish a concrete penalty figure, or a mechanism is contractual/reversion-based rather than a live export control, this is stated explicitly rather than estimated. Other jurisdictions with partial or unconfirmed evidence (e.g. Saudi Arabia, Kuwait) were reviewed but not included; standard confidential/”tight-hole” well-data filing delays (e.g. Alberta, Texas) were treated as trade-secret mechanisms similar to the reporting-only group, not sovereignty regimes. Created using Claude, by Anthropic. AIs can make mistakes – please let us know of any errors.

AI has added a whole new cost to control


The rise of large language models and AI agents has introduced a cost that barely existed three years ago: the token. Every AI query consumes tokens, and agentic workflows can consume 5 to 30 times more per task than a simple chatbot request. Enterprise spend on AI inference now makes up the large majority of AI budgets, and industry analysis suggests that 40–60% of that token spend is waste: redundant context, repeated retrieval and runaway agent loops.4 When AI runs on a metered public API, those costs are open-ended. Running inference on owned hardware turns an unpredictable operating expense into a fixed, capped one, which is exactly why on-premise GPU deployment is being reconsidered even by organisations that were firmly cloud-first.

Capex is a consideration


The accounting has also shifted. IFRS IAS38 clarified that cloud spending is typically operating expenditure, and not eligible for the capital allowances that many businesses can claim, particularly in capital-intensive industries such as oil and gas. Where a company has capital budget available and a workload that runs predictably around the clock, buying the hardware can be both cheaper over its life and more favourable on the balance sheet. The old assumption that “no upfront cost” always wins no longer survives contact with a multi-year total-cost-of-ownership calculation, or the variability of token budget management.

Sovereignty is now a boardroom issue


Data sovereignty pushes in the same direction. Regulations in many markets restrict where regulated data may sit and how it may cross borders, and operational sovereignty risks act in the same way. Airbus announced in late 2025 that it will move around 900 applications onto a European sovereign cloud.5 Operational sovereignty risk cuts that way too: in June 2026, a US export-control order temporarily barred non-US organisations from using Anthropic’s newly launched Fable 5 and Mythos 5 models, a reminder that a government can restrict access to a critical AI capability on political or national-security grounds alone, regardless of contract or data location.6

The operational case and the compliance case now largely agree: keep sensitive, heavy, always-on data close to home. The judgement challenge appears only where efficiency would tempt you to consolidate everything into one giant hyperscaler region, which is exactly what sovereignty resists.

Keep data local

Operational and sovereignty pressures converge on the same answer: keep data local and regional.

Does ‘edge’ deliver sovereignty?


One architectural solution attempts ‘cakeism’: using hyperscaler services, but hosted within an on-premise environment. These edge services (AWS Outposts, Google Distributed Cloud, Azure Stack, etc.) aim to deliver the on-premise benefits of local processing, low latency, and data residency while maintaining access to the operational efficiencies and technical benefits of working in a hyperscaler environment.

For data sovereignty, though, this needs care. Laws such as the US CLOUD Act, the UK’s Investigatory Powers Act, and the forthcoming EU e-Evidence Regulation attach to the nationality of the provider, or the market they serve, and not simply to the location of the server7. In principle a CLOUD Act or EPOC request can require data to be handed over even when the hardware it sits on is in your own data centre, in a third country. Edge therefore solves data residency, but it does not by itself deliver data sovereignty. Genuine sovereignty needs a next layer of data security, such as customer-held encryption keys so that any compelled disclosure yields only ciphertext, or use of a provider not subject to the foreign law in the first place.

The middle ground: cloud, in a country you trust


This is where a third option has matured, and for many organisations it may be the most practical answer: not on-premise, and not the global public cloud, but a sovereign cloud operated within a jurisdiction you trust. The clearest example arrived in early 2026, when AWS launched its European Sovereign Cloud,8 with its first region in Brandenburg, Germany9. It is run by a separate EU-incorporated subsidiary, staffed and operated exclusively by EU-resident personnel, physically and operationally separated from AWS’s other regions and designed to keep running even if cut off from the United States.

Microsoft and Google offer comparable sovereign options, and European-owned providers such as Scaleway (the provider Airbus has chosen) and OVHcloud sit further along the spectrum again, because a European-owned company is not exposed to US corporate-nationality law at all. The EU established the SEAL framework specifically to ease identification of cloud services that sit outside the reach of US authorities.11

Overall, sovereignty is best seen a risk assessment, not a switch. Even a US provider’s ‘sovereign’ EU cloud attracts debate over whether an American subsidiary can ever be fully insulated from American law. The right question is therefore not ‘is it sovereign?’ but ‘sovereign enough for this particular data, against this particular risk and compliance objective?’

sovereignty spectrum

A sovereignty spectrum: residency is solved long before true sovereignty is.

Does the EU AI Act help?


Bluntly, no. The EU AI Act mostly adds a layer rather than removing one. It is not a data-location law: it classifies AI systems by risk and, for high-risk systems, requires activity logging, documented risk assessment, data-governance controls and human oversight, with high-risk obligations now commencing from December 2027, not August 2026 as originally intended10.

Those requirements reach into the data pipeline, not just the storage layer. Organisations must be able to show where regulated data flows and how a model uses it. Set against continuing uncertainty over data transfer arrangements between the EU and the US (and the UK via the relevant adequacy arrangements), the effect is to push AI processing toward infrastructure you can fully account for and, often, keep in-jurisdiction. So the Act neither straightforwardly helps nor hinders, but instead, raises the compliance bar for everyone. In doing so, it reinforces the same direction of travel, towards controllable, auditable, local-where-it-matters deployment.

How Flare Solutions helps you decide


The real question is no longer on-premise or cloud; it is which information belongs where, for what purpose, and under whose law. Flare Solutions helps you to separate residency from sovereignty, to classify your information by internal sensitivity, legal obligation, and operational purpose, and to situate each workload accordingly, whether public cloud where it is compliant and efficient, sovereign cloud where jurisdiction matters, or on-premise where performance, residency, cost control or sovereignty risks demand it.

If you are revisiting decisions made a few years ago that may no longer fit today’s risks, contact us today and we’ll be happy to talk.

References

1.  Cloud data-egress costs estimated at 10–15% of the typical cloud bill (Gartner), reported in VDURA, “Data Gravity and AI Momentum,” Dec 2025.  https://www.vdura.com/2025/12/02/data-gravity-and-ai-momentum-from-storage-to-story/

2.  Shift from cloud-first to hybrid models organised around where data resides (Deloitte, Tech Trends 2026); see also SUSE, “The Data Gravity Problem.”  https://www.suse.com/c/the-data-gravity-problem-moving-data-to-ai-vs-moving-ai-to-data/

3.  Enterprises running AI workloads locally to exceed 20% by 2028, up from under 2% in early 2025 (Gartner), reported in VDURA.  https://www.vdura.com/2025/12/02/data-gravity-and-ai-momentum-from-storage-to-story/

4.  Is that AI agent worth it? Agentic economics and the modern operating model. McKinsey. https://www.mckinsey.com/capabilities/quantumblack/our-insights/is-that-ai-agent-worth-it-agentic-economics-and-the-modern-operating-model

5.  Airbus to move ~900 applications off AWS to French sovereign cloud Scaleway (announced late 2025; migration now beginning). The Register, Jul 2026; The Next Web.  https://www.theregister.com/columnists/2026/07/20/airbus-takes-flight-from-aws-what-happens-next-is-critical/

6.  US export-control order (Jun 2026) temporarily restricted non-US access to Anthropic’s newly launched Fable 5 and Mythos 5 models amid a security dispute; restrictions partially lifted weeks later. Forbes, Jun 2026; CBS News, Jun 2026.  https://www.forbes.com/sites/anishasircar/2026/06/16/anthropic-disabled-fable-5-and-mythos-5-after-a-us-export-control-order-heres-what-happened/

7.  US CLOUD Act attaches to provider nationality, not server location; edge appliances solve residency, not sovereignty. Eliatra, “The Sovereignty Illusion”; Kiteworks.  https://eliatra.com/blog/the-sovereignty-illusion-why-awss-european-cloud-cannot-escape-us/

8.  AWS European Sovereign Cloud governance: EU-incorporated subsidiary, EU-resident personnel, operationally separated, severable from the US. Amazon EU newsroom.  https://www.aboutamazon.eu/news/aws/built-operated-controlled-and-secured-in-europe-aws-unveils-new-sovereign-controls-and-governance-structure-for-the-aws-european-sovereign-cloud

9.  AWS to invest €7.8bn in the European Sovereign Cloud; first region in Brandenburg, Germany. Data Center Dynamics.  https://www.datacenterdynamics.com/en/news/aws-to-invest-78bn-in-european-sovereign-cloud/

10.  EU AI Act high-risk obligations (logging, risk assessment, data governance, human oversight); high-risk deadlines deferred from August 2026 to 2 December 2027 (Annex III, standalone systems) and 2 August 2028 (Annex I, AI embedded in regulated products) under the AI Act simplification package agreed by the Council and Parliament in June 2026. Gibson Dunn; see also Devoteam, Travers Smith.  https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

11. EU Sovereign Cloud Framework explained: https://commission.europa.eu/news-and-media/news/sovereign-cloud-framework-explained-2026-06-01_en

Want to know more? Contact us today.