top of page

Artificial Intelligence: How Data Sovereignty Is Redrawing the Map of Global Expansion

  • Writer: Intrust Associates
    Intrust Associates
  • 4 days ago
  • 6 min read

For years, data was the one thing that moved without a passport. A company in São Paulo could store customer records in Virginia, run analytics out of Dublin, and train a model on servers in Singapore, all before lunch, and no customs officer ever asked a question. That version of globalization is ending — not with a tariff notice or a shipping delay, but with a regulatory resolution published quietly on a government website, a fine issued by a privacy authority, or a cloud contract renegotiated at the last minute because the data, it turns out, was never allowed to leave the country.


Something similar happened to trade a few years ago. Tariffs and export controls forced executives to ask "who can we still trust?" before asking "where is it cheapest?" The same reordering is now arriving in a second currency: data. Where information is stored, who can access it, and under whose law it is governed have become conditions of market entry as binding as any tariff schedule — and considerably harder to see coming, because they are written into privacy statutes and AI regulations rather than trade agreements.


The paradox is sharp. Artificial intelligence and cloud computing were supposed to be the most borderless technologies ever built. Instead, they are the ones most rapidly acquiring borders. For any company expanding internationally, especially in software, AI, and digital services, that paradox is no longer a legal footnote. It is a strategic variable that belongs in the same conversation as market size and unit economics.

What Actually Changed Since Artificial Intelligence Creation?


The scale of the shift is easy to understate because it happened law by law rather than in a single dramatic announcement. Data protection statutes modeled on the EU's GDPR are now in effect in roughly 144 countries, according to the International Association of Privacy Professionals — a near-universal baseline that barely existed a decade ago. Layered on top of that baseline is a newer, more consequential trend: rules that do not just protect data but dictate where it must physically sit, who may access it, and under which country's legal authority.


Artificial intelligence has accelerated this from a compliance matter into a board-level one. The European Union's AI Act begins applying its requirements for high-risk systems on August 2, 2026, covering AI used in hiring, credit scoring, education, and essential services — and it reaches far beyond EU borders. A U.S. company with no European office can still fall under the law simply because its AI system's output affects people in the EU, whether through a SaaS platform with European users or an API embedded in a partner's product, according to legal analysis from Holland & Knight. The old test for whether a foreign regulation applied to you was physical presence. The new test is impact, and impact is much harder to avoid.


What makes this genuinely new, rather than simply GDPR with an AI label on it, is the entanglement of privacy law and industrial policy. Regulators are no longer only asking whether data is protected. They are asking whether a foreign government could compel access to it — a question that turns data infrastructure into a matter of national resilience, not just consumer rights. That question is precisely what pulled Germany, Brazil, and a Chinese-owned social media platform into three very different outcomes over the past year.



Three Outcomes, Three Lessons


Germany shows what it looks like to treat sovereignty as an infrastructure decision made early, not a compliance patch applied late. SAP's Delos Cloud, a joint venture built specifically to satisfy German government cloud requirements, is now the foundation for "OpenAI for Germany," a partnership announced to deliver sovereign AI services to the German public sector by combining OpenAI's models with Delos Cloud and Microsoft Azure infrastructure, backed by an initial buildout of 4,000 GPUs on German soil. Notably, the underlying legal tension has not disappeared — no law repeals the extraterritorial reach of the U.S. CLOUD Act, so even sovereign-branded infrastructure cannot offer an absolute guarantee that data will never be requested by American authorities. The lesson is not that sovereignty problems can be fully solved. It is that building visible, dedicated infrastructure ahead of the requirement is what lets a company keep selling into a market that has grown wary of foreign-controlled data.


Brazil shows the opposite trajectory: a country turning regulatory credibility into a competitive asset. On January 27, 2026, Brazil and the European Union announced mutual recognition of data protection adequacy — the European Commission's formal conclusion, under Article 45 of the GDPR, that Brazil's LGPD offers protection "essentially equivalent" to EU law. It is Brazil's first-ever adequacy decision and the broadest one the EU has granted to date, covering public and private sectors simultaneously and placing Brazil among a select group of roughly seventeen jurisdictions worldwide with that status. For companies already operating in Brazil, or weighing whether to, the practical effect is immediate: personal data can now move between Brazil and the EU without the standard contractual clauses, binding corporate rules, or case-by-case approvals that still burden transfers to most of the world. Brazil did not win this by being the cheapest place to process data. It won it by building a regulatory track record credible enough for Brussels to trust without a side agreement.


TikTok illustrates what happens when a company treats data location as a communications problem rather than an operational one. In May 2025, Ireland's Data Protection Commission fined TikTok €530 million and ordered it to bring its data practices into compliance within six months, after finding that the company had transferred EEA user data to China without demonstrating protection equivalent to EU standards, and had failed to adequately disclose this to users. The case took a sharper turn when TikTok subsequently informed the regulator that, contrary to evidence it had previously given the inquiry, some EEA user data had in fact been stored on Chinese servers — turning a transfer violation into a credibility problem. The fine was significant. The disclosure failure was worse, because it signaled to every regulator watching that the company's account of its own data flows could not be trusted.



What This Means for Decision-Makers?


Three lessons emerge, and none of them are really about data at all — they are about how expansion decisions get made. First, data location has quietly joined tax structure and entity formation as a question that has to be settled before a company enters a market, not after a regulator asks about it. Treating it as a technical detail owned by an IT team, rather than a strategic one owned by the leadership steering the expansion, is how companies end up explaining themselves to a regulator instead of a customer.


Second, regulatory credibility is now a competitive input, not a compliance cost. Brazil's adequacy decision did not just remove friction for companies already established there; it made Brazil a more attractive place to route data for anyone doing business across Latin America and Europe simultaneously. Executives evaluating where to place a regional hub should weigh a jurisdiction's trajectory on data governance with the same seriousness as its tax treaties or logistics infrastructure — because that trajectory determines how easily the company can operate across borders for years afterward.


Third, and most uncomfortable for lean organizations expanding quickly: transparency about data flows has become non-negotiable, and getting caught misrepresenting them is more damaging than any technical violation. Regulators increasingly behave like they assume companies do not fully know where their own data lives — because, in sprawling multi-vendor cloud environments, many genuinely do not. The operational discipline required to answer that question accurately, before a regulator forces the answer, is now a basic cost of entry into any serious market.

The Takeaway


For a decade, the winning question in international expansion was some version of "where can we operate most efficiently?" That question still matters, but a second one now sits beside it with equal weight: "where is our data allowed to exist, and can we prove it?"


The companies coming out ahead — building sovereign infrastructure before it is mandated, entering markets whose regulatory credibility is rising rather than falling — are not necessarily the most technically sophisticated. They are the ones that stopped treating data governance as paperwork and started treating it as a condition of market access, decided at the same table where the expansion strategy itself gets built.


In a world where borders now run through server racks as much as through customs checkpoints, foresight alone is not the advantage. Knowing, precisely and provably, where your data lives is.

Sources:

Comments


Start Your Global Expansion

Please complete the form to apply for a position with us.

Business Field:
How did you find us?
bottom of page