Learn

    Explainer

    Can the US government access UK cloud data?

    How the US CLOUD Act reaches data stored in Britain, who's exposed, and how to remove the risk.

    By James Drayson

    In short

    Yes. Under the US CLOUD Act, US authorities can compel American cloud providers to hand over data they control, even when that data is stored in the UK. Because the obligation follows the provider, not the server location, a UK data centre operated by a US company does not, by itself, protect your data.

    Locai One with the side panel open

    What is the CLOUD Act?

    The US Clarifying Lawful Overseas Use of Data (CLOUD) Act lets US authorities require US-based providers to disclose data in their possession or control, regardless of where in the world it is physically stored. The trigger is the provider's nationality and control, not the data's location.

    Why a UK region doesn't protect you

    Storing data in a UK region of a US-owned cloud keeps it physically in Britain, but the operator remains a US company subject to US law. If compelled, it can be required to produce that data. Residency addresses location; it does not address jurisdiction or control, which is the heart of the issue.

    Who's exposed, and how to remove the risk

    • Most exposed: Government, finance, healthcare, and any holder of sensitive or regulated UK data on US-owned platforms.
    • Own the model: Running a model you own removes dependence on a foreign provider's control.
    • Stay in your perimeter: On-prem or air-gapped deployment means there is no foreign operator to compel.
    • UK jurisdiction: Use a genuinely UK-controlled provider and deployment.

    What this looks like with Locai

    Compliance is far easier to evidence when the machine, the model and the logs are all things you own, not things a vendor describes in a whitepaper.

    Locai Labs builds Locai One, an on-prem AI appliance. It is one machine that arrives with everything already in it: the hardware, our open-weight Locai Juno models, and Locai OS, the operating system that serves the models and handles users, access and monitoring. You plug it into a mains socket and your network, and your team is working in about 15 minutes. No cloud account, no per-token bill, and nothing leaving the building.

    The reason a data-centre-class model fits in a box on your floor is SPACE, our compression algorithm. Instead of asking how much of a model can be cut while keeping it broadly similar, SPACE asks what the model needs to be good at, preserves the subnetworks behind those capabilities and strips back the rest. The result is a smaller specialist rather than a shrunken generalist, tuned to the exact hardware it ships on.

    Locai One starts at £29,950 for a team, and Locai One Pro at £49,950 for an organisation, bought once and owned outright. Both run air-cooled on standard mains power and work fully air-gapped. Any compatible open-weight model runs alongside Juno, and if you need a model trained on your own proprietary data we can post-train one and deploy it on the same machine.

    Frequently asked questions

    What is the US CLOUD Act?

    A US law allowing American authorities to compel US-based providers to disclose data they control, wherever in the world it is stored.

    Does it apply to UK data?

    Yes. If a US-owned provider controls the data, the CLOUD Act can reach it even when it is stored in the UK.

    Does a UK data centre protect me?

    Not on its own. Physical location doesn't override the provider's US jurisdiction; the obligation follows the company, not the server.

    How do I avoid exposure?

    Own your model and run it inside your perimeter (on-prem or air-gapped) under genuine UK jurisdiction, so there is no foreign operator to compel.

    Book a sovereign AI briefing

    A 30-minute session on owning your model: deployment options, the data path, and a clear cost range for your use case.