Two US laws decide whether US authorities can reach your data, and neither cares where the server stands. They care who controls the provider. An EU region at a US cloud company therefore changes less than it sounds.
The CLOUD Act
The CLOUD Act of 2018 added 18 U.S.C. § 2713 to US law. It requires providers under US jurisdiction to disclose data in their possession or control, whether the data sits in the United States or abroad. The provider can be ordered to hand over what it holds, encrypted content included.
FISA 702
Section 702 of FISA allows surveillance of non-US persons outside the United States, with compelled help from US providers and without a court order for each person. The statute lapsed at midnight on 12 June 2026, the first time since it was enacted in 2008, after the House rejected a short extension by 198 votes to 218. But the certifications the FISA court approved in March 2026 remain valid until March 2027. In practice the surveillance continues at least until then, and Congress has until March 2027 to renew the law.
The EU region
Microsoft completed its EU Data Boundary on 26 February 2025: storage and processing of customer data inside the EU. On 10 June 2025, Anton Carniaux of Microsoft France was asked under oath in the French Senate whether he could guarantee that French citizens' data would never be handed to US authorities without French approval. His answer: "Non, je ne peux pas le garantir." Microsoft says it commits by contract to challenge unfounded demands. That is a promise to try, not a wall.
What it means for a Swedish firm
GDPR still applies, and a US cloud company can be a lawful choice. But in a supplier assessment the question is not only where the data sits. Ask three questions about every service that handles client material:
- Is the provider, or its parent, American, or does it operate in the United States?
- Where does the AI model run, and which company runs it?
- Which sub-processors handle the data, and who owns them?
The laws bind providers under US jurisdiction. A Swedish company with no US owner and no operations in the United States is as a rule not covered. That is the difference that matters, not the address of the data centre.
Quince AI builds Egen, an AI workspace on Swedish servers with no US company in the chain. The FISA 702 position is as of 24 September 2026 and will change when Congress acts; we will update this note then.