AI Insights

Relying on US AI is a risk you do not control

Eric6 July 202610 min read
Relying on US AI is a risk you do not control

In one sentence: Relying on US-hosted AI puts your data, your pricing, and your day-to-day access under US law and politics that a UK or EU business cannot vote on or predict, so any company handling sensitive work should keep a sovereign option, run locally or inside the EU, for anything it cannot afford to lose.

Most businesses reach for ChatGPT, Claude, or Microsoft Copilot without asking one basic question: what happens to your operation the day that service says no? Not because the technology fails, but because a sanction, a policy change, or a terms-of-service decision made in Washington reaches down and switches it off. It sounds far-fetched until you look at what happened in 2025.

At Northern Codes we build automation on the best tool for each job, and US models are often the best tool. We also build a local or EU-hosted alternative for the work that actually matters. This is not an anti-American argument. It is a continuity argument, and the facts behind it are worth two minutes of your time. If you are still getting to grips with what these tools are, our plain-English guide to AI agents is a gentler place to start.

What are the real risks of building your business on US AI?

Three risks stack on top of each other. Access: a US provider can suspend your account for legal or political reasons you do not control. Data: US law can compel that provider to hand over your data, even when it sits in Europe. Continuity: the models, prices, and terms change on the provider's schedule, not yours. None of these are hypothetical any more.

  • Access risk: your service can be withdrawn by sanction, account suspension, or a change in which countries the provider will serve.

  • Data risk: where your data physically lives stops mattering once the company holding it answers to a US court.

  • Continuity risk: a model you built a workflow around gets deprecated, repriced, or rate-limited, and you rebuild on their timeline.

Can a US provider actually cut off your access?

Yes, and it already happened at the highest level. In May 2025, Microsoft blocked the email account of the International Criminal Court's chief prosecutor, Karim Khan, after the US government sanctioned the court. He was forced to move to Swiss provider Proton. If access can be pulled from an international court, a supplier switch is well within reach for an ordinary business.

The lesson is not that Microsoft is uniquely at fault. It is that any US provider sits under US jurisdiction and has to comply when its own government orders it to. Export controls, sanctions lists, and terms-of-service suspensions all point the same way: the switch is not in your hand.

Who can legally read your data on US AI?

Under the US CLOUD Act, American authorities can compel any US provider to produce data in its control, whether that data sits in a Frankfurt, Dublin, or London data centre. Choosing an EU region does not put the data beyond reach if the company holding it is American. This is the part most buyers get wrong.

You do not have to take our word for it. In 2025, Microsoft France's own legal director conceded under oath that the company could not guarantee French citizens' data would never be passed to US authorities. That is the vendor admitting the exposure, not a critic claiming it. For the legal detail, see the European Data Protection Board's assessment of the CLOUD Act.

Is sending EU data to US AI even legally settled?

No, and it has never stayed settled. The EU has already struck down two US data-transfer frameworks: Safe Harbor in 2015 and Privacy Shield in 2020, both over US surveillance powers. The current EU-US Data Privacy Framework survived its first court challenge in September 2025, but it is now under appeal at the EU's top court. Companies relying on it have short-term cover and no long-term certainty.

For a business, that means the legal basis for feeding EU personal data into a US AI tool could be pulled out from under you with limited notice, exactly as it was twice before. Building a core workflow on that footing is building on sand.

How dependent on US AI is Europe right now?

Heavily, and the numbers are stark. Amazon, Microsoft, and Google control more than 70% of the European cloud market, while home-grown European providers hold about 15% (Synergy Research Group, 2025). Around 70% of the world's foundational AI models are built in the United States (EuroStack, 2025). That concentration is the whole reason digital sovereignty moved from a fringe idea to EU policy.

The EU now has its first technology sovereignty commissioner and a growing push, sometimes called EuroStack, to build European chips, cloud, and AI. As one German MEP put it, Europe can no longer assume it has a reliable US partner. When policymakers plan a decade-long exit from a dependency, that is a signal for businesses too.

Are other businesses already moving to local and open-source AI?

Yes, and it has become mainstream rather than niche. In a 2025 survey of more than 700 technology leaders across 41 countries by McKinsey, the Mozilla Foundation, and the Patrick J. McGovern Foundation, over half of organisations already used open-source AI in their stack, and more than three-quarters expected to increase that use. The firms that treat AI as a competitive advantage are the most likely to adopt it.

The reasons line up exactly with the risks above: control over data, lower long-term cost, the freedom to fine-tune, and no single vendor holding the switch. Larger enterprises lead the way, frequently running open models such as Llama, Mistral, or Qwen on their own infrastructure for security and compliance. Many now run several models at once specifically to avoid being locked to one provider. Moving sensitive work to a local or EU-hosted open model is no longer the cautious outlier, it is where the market is heading.

Should you ban US AI? No, and here is why.

US models are frequently the most capable and the cheapest way to ship a low-risk automation. Banning them outright costs you speed and quality for no good reason. The smart move is to match the tool to the risk: US AI for public, low-sensitivity work, and a sovereign option for anything involving customer data, intellectual property, or operational continuity you cannot afford to lose.

That is the practical position, and it is the one we take on client projects. Sovereignty is not about purity. It is about making sure the parts of your business that must keep running are not sitting on a switch you do not own.

What are your sovereign AI options?

There are three practical routes, and they combine well. The right mix depends on how sensitive the data is and how much control you need.

Self-hosted or on-premise AI

  • Where your data sits: your own servers, in your building or a private EU host.

  • Who can compel access: you alone.

  • Best for: maximum control and sensitive intellectual property.

  • Trade-off: higher effort and cost up front.

EU-hosted inference

  • Where your data sits: an EU data centre, under EU law.

  • Who can compel access: EU authorities only, not a US court.

  • Best for: regulated data that must stay in the EU.

  • Trade-off: moderate setup, strong compliance fit.

US cloud AI, used deliberately

  • Where your data sits: US-controlled infrastructure.

  • Who can compel access: US authorities under the CLOUD Act.

  • Best for: public, low-sensitivity tasks where speed matters most.

  • Trade-off: lowest effort, but the least control and a contested legal basis for EU data.

Open models have closed most of the quality gap. For summarising documents, answering staff questions, drafting replies, extracting data, and routing tickets, a well-configured open model running in the EU or on your own kit does the job, and your data never leaves a jurisdiction you trust.

How Northern Codes builds sovereign AI that still performs

We start by mapping which of your workflows touch sensitive data and which do not. Low-risk tasks can stay on the fastest US model. Everything else runs on a self-hosted open model or EU-hosted inference, with a private knowledge base that never leaves your control. You get the automation without the exposure. Much of the work is connecting the systems you already use so data moves without leaving a jurisdiction you trust.

In practice that means a single automation setup where a customer-facing chatbot, an internal policy assistant, and your document search all run on infrastructure you can point to on a map. When a client asks where their data goes, you have a straight answer. When the transatlantic legal weather changes again, your operation does not flinch. If you are weighing up what to automate first, sovereignty is one more reason to start with the workflow that matters most.

Sovereign AI FAQ

Q: Is US AI illegal to use in the UK or EU?

No. US AI tools are legal to use in the UK and EU today. The issue is not legality, it is exposure and certainty: US law can reach your data, and the legal framework for EU-US data transfers has been struck down twice and is under challenge again. For sensitive work, a sovereign option removes that uncertainty.

Q: Are open-source AI models as good as ChatGPT?

For most business tasks, yes. Open models now handle summarising, drafting, data extraction, classification, and question answering to a standard that suits real workflows. The very largest US models still lead on the hardest reasoning, which is why a mixed approach, US models for low-risk work and open models for sensitive work, makes sense.

Q: Does self-hosted AI mean I need my own servers?

Not necessarily. Self-hosting can run on hardware in your office, or on a private server you rent inside the EU. The point is control: the model and your data sit in an environment governed by your rules and EU law, not by a US provider's terms. We size the setup to your budget and workload.

Q: What is the CLOUD Act in plain English?

The US CLOUD Act is a 2018 law that lets US authorities compel American technology companies to hand over data they control, regardless of whether that data is stored inside or outside the United States. So an EU data centre run by a US company does not put your data beyond US reach, which is the core problem for data residency.

Q: Will the EU AI Act affect which AI I can use?

The EU AI Act, in force since August 2024 with general-purpose AI rules from August 2025 and most obligations from August 2026, adds transparency and risk duties rather than banning specific providers. Running AI on infrastructure you control makes proving compliance and data handling far simpler, which is a growing reason UK and EU firms choose sovereign setups.

Q: Can I keep using ChatGPT and still be sovereign?

Yes. A pragmatic sovereign approach keeps US models for public, low-sensitivity tasks and routes anything involving customer data, IP, or critical continuity to a local or EU-hosted model. You keep the speed and quality of the best US tools where the risk is low, and remove the exposure where it counts.

Where to start

You do not need a sovereignty strategy on day one. You need to know which of your workflows are sitting on a switch you do not own, and to move those first. Everything else can wait.

If you want help working that out, that is what we do at Northern Codes. We map where your AI actually runs, show you what is exposed, and build a sovereign path for the parts that matter. Book a strategy call and we will start with the workflow you cannot afford to lose.

AI SovereigntyData SovereigntySovereign AIEU AIGDPROpen Source AISelf-Hosted AI

Ready to Automate?

Let's discuss how AI automation can transform your business operations.

Let's Talk

We use cookies

We use analytics cookies to understand how visitors use our site and improve your experience. No data is shared for advertising. Learn more