From Ritu Raj | Product & Market Analysis

AI Data Residency in 2026: Storage Is Solved, Inference Is Where Deals Die

On this page

Storage residency is close to table stakes. Inference residency is not. Ask a vendor where your prompt is processed rather than where it is stored, and the AI data residency conversation changes shape in one question. 51% of companies in a 320-firm survey rate data sovereignty as very important, and the gap between what buyers ask for and what vendors actually ship is now a deal event in regulated sectors.

Key takeaways

  • Storage residency and inference residency are separate products, sold separately. OpenAI offered data-at-rest residency across 10 markets before it documented in-region GPU inference, and that later commitment covers the United States and Europe only.
  • India's default is permissive and its exception is not. The DPDP Rules let personal data leave India unless the government orders otherwise. Significant data fiduciaries must keep government-specified categories, and the traffic data describing their flow, inside the country.
  • European demand is driven by procurement as much as by law. The European Commission built a scored sovereignty framework into its own tender and awarded 180 million euros of sovereign cloud in April 2026.
  • No United States headquartered vendor has closed the jurisdiction question. Microsoft France told the French Senate in June 2025 that it could not guarantee French data would never be handed to United States authorities.
51%Rate data sovereignty as very important, and 76% expect that importance to rise. Source: BARC, survey of 320 companies, May 2026.
70%Share of the European cloud market held by three United States hyperscalers. Source: Synergy Research, reported 2025.
€180mSovereign cloud contract the Commission awarded to 4 providers in April 2026. Source: European Commission, June 2026.

What "AI data residency" means once a model is in the path

Data residency is a promise about where information sits. That definition worked when the only question was which region held the database.

A model changes it. Your text is stored somewhere, processed somewhere, sometimes reviewed somewhere, and logged somewhere. Those four locations are governed by four separate commitments, and vendors do not always make all four.

Residency, localisation and sovereignty are three different claims

Buyers use the words interchangeably. Contracts should not.

Residency is a vendor commitment about geography, usually about data at rest. Localisation is a legal requirement that certain data stay inside a country, imposed by a regulator. Sovereignty is a claim about jurisdiction and control, which is a much larger promise, because it concerns who can compel access rather than where the disk spins.

A vendor can be fully compliant on residency and still fail a sovereignty test. That is not a gotcha. It is the structure of the market.

Map any AI purchase against four stages before you read a single compliance page. Storage at rest is the first stage and the easiest to guarantee. Inference is the second, and it is where the model executes your prompt. Safety and abuse review is the third, and it can move content out of your region by design. Logs, telemetry and traffic metadata are the fourth, and almost nobody asks about them.

One prompt, four locations, four separate promises Most published residency pages cover the first box. Deals are lost on the second and third. Storage at rest. Inference where the model runs. Safety review flagged content. Logs and metadata. Contractually in region on most enterprise plans. In region on some plans, some models, some regions. Can leave the region by design, under published policy.
Read left to right and ask which box each clause in your contract actually covers. Most cover only the first.

Storage residency and inference residency are different products

This is the single most useful distinction in the whole category, and it is barely present in vendor marketing.

What in-region storage buys, and what it does not

Storage residency keeps your uploads, prompts, outputs and workspace content at rest inside a named country or region. It answers the audit question most procurement teams write down.

It does not tell you where the model ran. When OpenAI expanded residency to India, the United Arab Emirates, Australia, the United Kingdom, Canada, Japan, South Korea and Singapore in November 2025, inference still defaulted to United States infrastructure. Analyst Akshat Tyagi described the mechanism plainly to Computerworld: the prompt is processed on United States infrastructure and the result is sent back.

That is a real compliance improvement. It is not the thing a regulated buyer thinks they bought.

Inference residency is the newer and thinner product

Processing commitments arrived later and cover less ground. OpenAI's own documentation now describes in-region GPU inference for eligible enterprise, education and healthcare customers in the United States or Europe, dated January 2026, and separate regional processing for European API projects through a European endpoint.

Notice what that list does not include. India has storage residency and no equivalent in-region inference commitment from the same vendor. A buyer in Mumbai and a buyer in Munich are being sold products with the same name and different contents.

What each vendor commits to, and where the commitment stops
ProviderStorage at rest in regionProcessing in regionThe stated exception
OpenAI enterprise plans and API.10 markets including India, the EU and the UK.United States or Europe only, added January 2026.Residency applies to new workspaces. Modified abuse monitoring and zero data retention need approval.
Microsoft 365 Copilot.In-country residency in 27 countries.EU and EFTA regional, in-country rolling out to 15 countries.Committed for normal operations. Timeline and scope were being refined again in April 2026.
Google Cloud, Gemini models.Regional data residency documented per service.Machine learning processing listed per model and per region.Model coverage moves version by version. A newer model can lack a region an older one had.
Anthropic, contracting directly.No European data residency option published.No European data zone for Claude models.Anthropic lists European support on Microsoft Foundry as coming during 2026, without a date.
Claude via a cloud marketplace.Achievable in EU regions of AWS or Google Cloud.Depends on the endpoint and deployment type chosen.The cloud contract governs hosting. The model provider still governs safety review.

Compiled from vendor documentation and reporting current to August 2026. Every row moves. Treat this as the shape of the market rather than as a live compliance matrix, and re-check the vendor page on the day you sign.

The same word, four different products Colour shows how complete the published commitment is, not how good the vendor is. Stored in region. Processed in region. India option. OpenAI Documented US and EU only Storage only. Microsoft 365 Copilot 27 countries Rolling out Announced. Google Cloud Documented Per model Listed. Anthropic direct Not published No EU zone Not published. Anthropic models can still be run in EU regions through AWS or Google Cloud, under those providers' terms.
The amber cells are where deals stall. They are not refusals, they are partial commitments that a compliance checklist reads as a yes.

What European buyers actually demand

European demand has three distinct sources, and only one of them is the law everyone quotes.

GDPR never required residency. Buyers ask anyway.

The regulation permits transfers to third countries under an adequacy decision or appropriate safeguards. Nothing in it says European personal data must physically remain in Europe.

Buyers still ask, for reasons that are commercial rather than statutory. The BARC data sovereignty study of 320 companies was fielded in February and March 2026. It found legal requirements cited by 61% as an external driver, but United States political developments cited by 54% and cloud provider dependency by 46%. Those are not compliance answers. They are risk answers.

The same study found companies with repatriation initiatives doubling from 8% to 16% in a year. That is still a minority, and it is the fastest moving number in the set.

Why buyers raise sovereignty, in their own words External drivers cited, 320 companies surveyed February and March 2026. Legal requirements 61% United States political developments 54% Cybersecurity incidents 49% Dependency on public cloud providers 46% Three of the four top drivers are risk judgements rather than statutory obligations. Source: BARC Data Sovereignty 2026.
If the demand were purely legal, the second and fourth bars would be near zero. They are not, which is why a GDPR argument rarely wins this meeting.

Procurement turned sovereignty into a score

The European Commission published a Cloud Sovereignty Framework with 48 criteria across eight objectives, including a specific data and AI objective. Providers are graded on Sovereignty Effectiveness Assurance Levels from 0 to 4, and the level works both as an eligibility threshold and as an award criterion.

In April 2026 the Commission awarded 180 million euros of sovereign cloud to four providers under that framework. Public buyers across member states now have a scoring rubric to copy, and they are copying it.

Supply moved with it. AWS launched its European Sovereign Cloud on 15 January 2026, with a first region in Brandenburg and more than 90 services. It sits under a German parent company with three subsidiaries and staff who are European Union citizens. Microsoft has committed to processing European Union and EFTA customer data inside its European Union Data Boundary.

Then there is the question that infrastructure cannot answer. In June 2025 a Microsoft France executive was asked under oath whether he could guarantee French citizens' data would never be transmitted to United States authorities without French authorisation. His answer was no. He also noted that such a demand had never been made. Both facts are true and they point in opposite directions.

My position is that this question is decisive for public sector and defence buyers and close to irrelevant for most commercial ones. If your risk register does not contain a scenario involving a foreign subpoena, do not let a vendor sell you a sovereignty tier to solve for it. The comparison of what model providers actually promise in their terms is a better use of the same hour.

What Indian buyers actually demand

India is routinely described as a data localisation market. That description is roughly ten years out of date, and it leads sellers to over-promise on the wrong axis.

The DPDP default is permissive. The exception is not.

The Digital Personal Data Protection Rules were notified in November 2025, with a phased schedule that puts core business obligations 18 months out, in May 2027. The general transfer rule permits personal data to move outside India, subject to whatever requirements the central government specifies by order. That is a blocklist model, not a localisation mandate.

The teeth are in the additional obligations for significant data fiduciaries. Such an entity must ensure that categories of personal data specified by the central government, and the traffic data pertaining to its flow, are not transferred outside India. It must also run an annual data protection impact assessment and audit, and exercise due diligence over algorithmic software.

Read that traffic data clause slowly. It reaches metadata about routing, which is exactly the layer a storage-only residency commitment leaves untouched. Penalties under the Act run to 2.5 billion rupees per breach, roughly 28 million dollars, as summarised in this compliance review of the notified rules.

Sector rules bite before DPDP does

If your Indian buyer is a bank, an insurer or a payments company, the binding constraint is older and stricter than DPDP.

The Reserve Bank of India's April 2018 circular on storage of payment system data requires the entire data relating to payment systems to be stored only in India. It explicitly extends to third party vendors and intermediaries engaged by the regulated entity. If you sell an AI feature into that stack, you are inside the scope of that circular, not adjacent to it.

The CERT-In directions of April 2022 add a second constraint. Information and communication technology system logs must be maintained for 180 days within Indian jurisdiction. A vendor whose observability stack ships every log to a United States region has a problem that no model-level residency toggle fixes.

The two markets ask different questions
The questionEuropean buyerIndian buyer
What drives the requirement.Procurement scoring, board risk appetite, and sector regulators.Sector regulators first, then the DPDP Rules from 2027.
Is general localisation mandated.No. Transfers are lawful with safeguards.No. Transfers are permitted unless restricted by order.
Where the hard requirement sits.Public sector tenders and regulated finance.Payments, banking and insurance, plus designated large fiduciaries.
What catches sellers out.Inference location and support access from outside the region.Log retention and traffic metadata, not just stored content.
What closes the deal.A written exception list and a named region for processing.Evidence of in-country storage plus in-country log retention.

Where the vendor claim and the technical reality diverge

Three divergences account for most of the disappointment I see in these deals.

The first is hosting versus processing. Claude models reached general availability on Microsoft Foundry in 2026, hosted on Azure, with an Anthropic-hosted deployment in Sweden. InfoQ reported that the deployment types available were global or data zone, that no European data zone exists for those models, and that global routing means inference can run on United States infrastructure. Hosted in Europe and processed in Europe are different sentences.

The second is safety review. Automated safeguards can flag content for a provider's trust and safety team, and that review path can sit outside the boundary your contract describes. This is published policy at most major labs rather than a hidden practice, which is precisely why it belongs in your data protection impact assessment instead of your complaints file.

The third is scope language. Microsoft's November 2025 commitment to in-country processing in 15 countries is written as applying under normal operations, and the same page carries an April 2026 note about refining the timeline and scope. That is candid disclosure. It also means the guarantee has an implicit exception clause and a moving date, both of which belong in your risk register rather than in a slide.

I would not sign a residency clause that does not name inference explicitly. A clause saying customer data is stored in the European Union is compatible with every prompt being processed in Virginia, and buyers discover this after go-live more often than before it. The same discipline applies to the contract clauses worth fighting for in an AI purchase.

Seven questions that settle a residency claim

Send these in writing and ask for written answers. A vendor who can answer all seven in one reply has built the capability. A vendor who routes you to a compliance portal has not.

The diligence list, and what a weak answer sounds like
Ask thisWhy it mattersA weak answer sounds like
In which region is inference executed for our tenant.Separates storage residency from processing residency.All customer data is stored in your region.
Which specific models carry that commitment.Coverage is documented model by model and version by version.Our platform is compliant.
What happens when content is flagged for safety review.Review can move content outside the boundary under published policy.Silence, or a link to a trust page.
Where are logs, telemetry and traffic metadata retained.India's rules reach traffic data and 180 day log retention.Logs are anonymised.
Can support staff outside the region access tenant data.Operational autonomy is scored separately from data location in EU procurement.Access is role based.
Is the commitment contractual or documentation only.A published page can change without notice. A schedule cannot.It is on our website.
What is the exception list, in writing.Every real commitment has one, and the honest vendors will name it.There are no exceptions.

Two of these are worth escalating if the answer is vague. The inference question decides whether the product is usable at all in a regulated deployment. The exception list tells you whether the vendor has actually read its own architecture, which is the same signal you are looking for in any production readiness review of an AI system.

Where this argument is weakest

I have argued that residency claims are thinner than they look. Here is the case against my own framing.

The strongest case against residency demands

Residency is a weak proxy for security. Encryption, key custody, access control and retention policy protect data more directly than geography does, and a determined attacker does not care which region holds the bucket.

There is also a real cost. Regional deployments run behind on model availability, they cost more, and they can leave a buyer on an older model for months. A team that insists on in-region inference in 2026 may be trading measurable capability for a control that mitigates a risk it cannot describe.

And the market pressure is not evenly distributed. Three United States hyperscalers hold about 70% of the European cloud market according to Synergy Research, and European providers have sat near 15% since 2022. Stated preference and revealed preference are far apart, which should make anyone cautious about survey-based demand signals, including the 51% headline at the top of this post.

Two things survive that critique. Sector regulators do not accept the argument that encryption beats geography, so in payments, banking and public sector work the question is settled before it starts. And the diligence list above costs a seller almost nothing. Answering seven questions honestly is cheap, while discovering after go-live that inference runs elsewhere is not, which is the same failure pattern documented in the analysis of what unmanaged AI use costs when it goes wrong.

Frequently asked questions

What is AI data residency?

AI data residency is a vendor commitment that your content stays in a named country or region. In practice it splits into separate promises about storage at rest, model inference, safety review and log retention. Most published residency pages cover storage only. Ask which of the four stages the commitment actually covers, because a product can be fully resident at rest while every prompt is processed on another continent.

Does GDPR require AI data to stay in the EU?

No. The regulation permits transfers to third countries under an adequacy decision or appropriate safeguards such as standard contractual clauses. European buyers still ask for residency for commercial and risk reasons rather than statutory ones. In a 2026 survey of 320 companies, 61% cited legal requirements as a driver, but 54% cited United States political developments and 46% cited dependency on public cloud providers.

Does India's DPDP Act require data localisation?

Not as a general rule. The DPDP Rules notified in November 2025 permit transfers outside India unless the central government restricts them by order. The exception applies to significant data fiduciaries, which must keep government-specified categories of personal data, and the traffic data describing their flow, inside India. Sector rules from the Reserve Bank of India and CERT-In impose stricter and older requirements on payments and log retention.

Which AI providers offer EU data residency?

OpenAI offers European storage residency and European regional processing for eligible enterprise and API customers. Microsoft commits to processing EU and EFTA customer data inside its EU Data Boundary. Google documents residency and machine learning processing per service and per model. Anthropic has not published a European data residency option for direct contracts, though its models can run in EU regions of AWS or Google Cloud.

What is the difference between data residency and data sovereignty?

Residency is about location. Sovereignty is about jurisdiction and control, including who can compel disclosure and who operates the infrastructure. A vendor can meet every residency requirement and still be subject to a foreign legal order. That gap is why the European Commission scores sovereignty across eight separate objectives rather than asking a single question about where servers sit.

Does the US CLOUD Act override EU data residency?

The statute can require United States headquartered providers to produce data they control regardless of where it is stored. Asked under oath in June 2025 whether French data would never be handed to United States authorities, a Microsoft France executive said he could not guarantee it, while noting that no such demand had been made. Treat this as a live jurisdictional risk, weighted by your sector.

Where to start this week

Pull the residency page of your three largest AI vendors and mark each of the four stages as covered, partial or unknown. The unknown column is your actual diligence list, and it usually has more entries than the team expects.

Then send the seven questions to whichever vendor is closest to a renewal. Ask for the answers in the order form or a schedule, not in an email. A commitment that lives only on a web page can be edited on a Tuesday, and you will not get a notification when it is.

Related on governance

Residency is one input to a wider control set. The comparison of enterprise governance controls across ChatGPT, Claude and Gemini covers the rest, and the EU AI Act transparency checklist covers what changes when the obligations land.

References

  1. BARC, Data Sovereignty 2026 study, published 6 May 2026, 320 companies surveyed February and March 2026. Used for all survey percentages.
  2. European Commission, Sovereign Cloud Framework explained, 1 June 2026. Used for the 48 criteria, eight objectives, SEAL levels and the 180 million euro award.
  3. Microsoft 365 Blog, In-country data processing for Microsoft 365 Copilot, 4 November 2025 with an April 2026 update. Used for the 15 and 27 country figures.
  4. Computerworld, OpenAI expands data residency for enterprise customers, 26 November 2025. Used for the residency market list and the inference default.
  5. InfoQ, Claude reaches GA on Microsoft Foundry, July 2026. Used for the deployment type and European data zone position.
  6. The Register, Microsoft exec admits it cannot guarantee data sovereignty, 25 July 2025. Used for the French Senate testimony of June 2025.
  7. India Briefing, Digital Personal Data Protection Rules 2025 notified, 2025. Used for the phased timeline, the fiduciary obligations and the penalty ceiling.
  8. Reserve Bank of India, Storage of Payment System Data, 6 April 2018. Used for the payments localisation requirement and its extension to vendors.

The weakest part of this source base is the vendor capability table. It is compiled from documentation pages that vendors revise without notice, and two of the entries rest on secondary reporting rather than a contractual document. The CERT-In log retention requirement is cited from the April 2022 directions by title and date rather than from a linked filing. Verify any row against the vendor's current terms before you rely on it in a contract.

ST
Ritu Raj
Contributing Analyst, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading