Two different questions
Data residency asks where data is physically stored and processed. Data sovereignty asks whose laws apply to it and who can compel access. Data held in an Australian region of a global cloud provider meets residency requirements, but the provider's home-country laws may still reach it. The United States CLOUD Act of 2018, for example, allows US authorities to seek data held by US providers regardless of where it is stored, subject to legal process.
Why it matters more with AI
- AI assistants often see the most sensitive content an organisation has: contracts, health records, personnel files and strategy.
- Prompts, retrieved documents and outputs can be logged by services in ways that are easy to overlook.
- Some services may use customer data to improve models unless their terms say otherwise.
A spectrum of control
| Option | Residency | Control | Typical use |
|---|---|---|---|
| Public AI tools | Often offshore | Low | Non-sensitive drafting |
| Enterprise AI service, Australian region | Australia | Medium | Most business content |
| Models in your own cloud tenancy | Australia | High | Regulated and confidential data |
| Open-weight models on-premise or offline | Your premises | Highest | Classified, health and critical infrastructure |
Questions to ask any AI provider
- Where are prompts, documents and outputs stored and processed, including backups and logs?
- Are inputs used to train or improve models?
- Which legal entity holds the data, and under which jurisdiction?
- How long is data retained, and can we delete it on request?
- Which subprocessors are involved?
Choose by sensitivity, not by default
Classify the information each AI use case touches, then pick the least complex hosting option that meets its obligations. Most organisations end up with a mix: enterprise services for general work and private deployments for their most sensitive knowledge.
