AI Data Sovereignty Risk Assessment: Where Does Your Data Actually Go?
This free AI data sovereignty risk assessment scores your organization across eight dimensions that determine where AI data actually goes, not where a vendor's marketing page says it goes. It is built for IT directors, compliance leads, and security architects at manufacturers who handle export-controlled technical data, customer-confidential designs, or personal data inside AI workflows. Answer eight questions covering inference location, encryption key custody, subprocessor visibility, retention, and audit evidence, and get a scored risk band with prioritized recommendations. Most organizations discover the gap is not malicious, it is that nobody ever mapped where a public AI API actually routes a request once it leaves the browser.
1. Where does inference actually execute for your most sensitive AI workloads?
Marketing pages describe a region. Contracts and infrastructure diagrams describe reality.
2. Do you know which countries your AI vendor's subprocessors operate in?
3. Who holds the encryption keys protecting AI data at rest and in transit?
4. Can prompts or documents sent to an AI system physically leave your country?
5. Do you have a documented data flow map for every AI system in production?
6. What happens to prompts and outputs after a request completes?
7. Do your customer or regulatory contracts include data flow-down requirements, and do you apply them to AI vendors?
ITAR, GDPR, and customer-specific data handling clauses apply to an AI vendor exactly as they apply to any other subcontractor.
8. Can you produce evidence of data residency on demand for an auditor or customer?
Why data sovereignty breaks quietly
A sovereignty failure rarely looks dramatic. It looks like an engineer pasting a drawing into a chat tool that routes through three subprocessors across two continents, a vendor rotating encryption keys during an infrastructure migration nobody was told about, or a retention policy that defaults to indefinite unless someone finds the opt-out checkbox. None of this triggers an alert. It surfaces months later, during a customer audit, a proposal review, or an incident investigation, when someone finally asks the question a contract required you to already know the answer to.
- Cloud AI APIs frequently load-balance requests across regions for latency, even when the marketing page names a single region.
- Subprocessor lists change as vendors adopt new infrastructure partners, often without a proactive customer notice.
- Encryption key custody determines who can technically read your data, independent of where the data physically sits.
- Retention defaults in consumer and prosumer AI tools are usually far longer than teams assume.
The eight risks this assessment measures
Each question maps to a control that shows up in real audits: inference location, subprocessor transparency, key custody, cross-border transfer, data flow documentation, retention policy, contractual flow-down enforcement, and evidence production speed. These are not abstract compliance categories. They are the exact questions a defense prime's supplier security team, a customer's procurement counsel, or a CMMC assessor will ask when they learn AI touches your workflow, and the exact questions that determine whether an incident stays a contained internal matter or becomes a reportable breach.
How to read your score
A low score does not mean your AI program is reckless, it usually means sovereignty was never assigned as anyone's explicit responsibility while the program grew organically from a few pilots into production use. Treat the band verdict as a starting priority list rather than a grade. The fastest wins are almost always encryption key custody and data flow mapping, because both are entirely within your control regardless of which AI vendor you use, while subprocessor restrictions require contract renegotiation and take longer to close.
How Netray builds sovereign AI deployments
Netray designs on-prem and private AI infrastructure for aerospace, defense, and electronics manufacturers where data sovereignty is not negotiable. We deploy open-weight models entirely inside your network boundary, put encryption keys in infrastructure you control, and build the data flow documentation your customers and assessors will actually ask to see. For customers who need a hybrid posture, we help you draw the line precisely between what can safely leave the building and what cannot, backed by a defensible architecture rather than a hopeful assumption.
Frequently Asked Questions
Is running AI entirely on-prem the only way to guarantee data sovereignty?
It is the strongest guarantee, but not the only workable path. A contracted private cloud instance with customer-managed keys, restricted subprocessors, and enforced regional pinning can satisfy many sovereignty requirements. The right answer depends on your specific obligations: ITAR and classified work typically require full on-prem or air-gapped deployment, while general data residency clauses can often be satisfied with a well-contracted private cloud arrangement.
How do I find out what subprocessors an AI vendor actually uses?
Request their current subprocessor list directly, usually published as a data processing addendum exhibit or available on request from their trust or security page. Review it against your own restricted-country list and any customer flow-down clauses. Ask specifically whether the subprocessor list can change without prior notice, since many vendor contracts reserve that right, which quietly reopens a sovereignty question you thought you had closed.
Does customer-managed encryption actually stop a cloud vendor from reading my data?
It removes the vendor's ability to decrypt data at rest without your explicit key release, which closes a real risk around vendor staff access, subpoenas served on the vendor, and infrastructure compromise on their side. It does not protect data while the model is actively processing it in memory, which is why workload isolation and access logging around the compute layer still matter alongside key custody.
What is the fastest way to improve a low sovereignty score?
Start with the two controls entirely within your reach: build a data flow map for every AI system in production, and move encryption key custody for your most sensitive workload to keys you control. Both can typically be done in two to four weeks without vendor contract changes. Subprocessor restrictions and retention renegotiation take longer because they require the vendor's cooperation, so start those conversations in parallel rather than sequentially.
Get a data flow map and sovereignty gap analysis for every AI system currently touching your sensitive data.
Related Tools
ITAR AI Workload Compliance Assessment
Score your AI deployments across eight dimensions of ITAR exposure, from technical data classification and US persons access control to technology control plan coverage.
On-Prem AIAir-Gapped LLM Deployment Checklist
A practical control checklist for deploying and maintaining large language models in a fully air-gapped environment, from initial staging through ongoing patching and drift detection.
On-Prem AISovereign AI Readiness Assessment
Score your organization across eleven dimensions of sovereign AI readiness, from data residency and model provenance to cleared personnel and air-gapped operations.
Go Deeper
EU AI Act Implications for On-Prem AI Deployments
EU AI Act implications for on-prem deployments: risk tiers, high-risk obligations, and how self-hosted models simplify enterprise compliance.
ITAR and CMMC Handling of AI Workloads
How ITAR and CMMC apply to AI workloads: technical data boundaries, CUI handling, assessed environments, and where on-prem AI is the only option.
Securing Model Weights in the Enterprise
Secure model weights end to end: custody controls, encryption at rest, access policies, and exfiltration prevention for regulated AI deployments.