Simor
Data residency laws are tightening globally: a compliance timeline

Data residency laws are tightening globally: a compliance timeline

Simor Consulting | 03 Oct, 2026 | 04 Mins read

Data residency requirements are multiplying. In the past six months, nine countries have enacted or strengthened laws that restrict where certain categories of data can be stored and processed. Five more have draft legislation moving through their legislative processes. The direction is unambiguous: governments want data about their citizens and their industries to stay within their borders, and they are writing laws that make it expensive and risky to do otherwise.

For data teams running AI systems that process data across borders, this is not a theoretical concern. It is a constraint that is already affecting architecture decisions and will affect more of them over the next 18 months. The teams that plan for it now will avoid expensive rearchitecting later. The teams that assume the current permissive environment will continue will find themselves scrambling when enforcement actions begin.

The regulatory landscape by region

The European Union’s GDPR remains the most comprehensive data residency framework, but its enforcement is tightening. Recent guidance from the European Data Protection Board has clarified that AI model training on EU citizen data constitutes processing under GDPR, which means the training must either occur within the EU or under an adequacy framework that many non-EU countries do not satisfy. This has direct implications for companies that train models on data that includes EU citizen records.

China’s data localisation requirements have expanded to cover AI training data explicitly. Companies that train models on data containing Chinese citizen information must store the training data within China and must not transfer it outside the country without government approval. The practical effect is that any company serving the Chinese market with AI features must maintain separate training infrastructure within China.

India’s Digital Personal Data Protection Act, which took full effect this year, requires that personal data be stored and processed within India for specified categories, with limited exceptions. The law is less restrictive than China’s but more restrictive than the pre-2026 framework. Companies that have been processing Indian data in global data centres need to evaluate whether their current architecture complies.

Brazil, South Korea, Indonesia, Nigeria, and Saudi Arabia have all enacted or strengthened data residency laws in the past 12 months. The specifics vary, but the direction is consistent: more data must stay within national borders, and the penalties for non-compliance are increasing.

This diagram requires JavaScript.

Enable JavaScript in your browser to use this feature.

What this means for AI architecture

The core architectural implication is that you cannot assume a single global deployment for AI systems that process data from multiple jurisdictions. You need jurisdiction-aware data routing that directs data to processing infrastructure within the appropriate jurisdiction, and you need model serving infrastructure that can operate in multiple jurisdictions.

For training, the implications are more complex. If your training data includes records from jurisdictions with strict residency requirements, you may need to train separate model instances on data from different jurisdictions. This is operationally expensive but may be legally necessary. Alternatively, you can train on jurisdiction-specific data subsets and combine the resulting models through ensemble or routing approaches that keep the raw data within jurisdictional boundaries.

For inference, the challenge is simpler but still significant. When a user in India sends a query that includes personal data, the inference must happen on infrastructure within India, or under a data transfer mechanism that satisfies Indian law. This means deploying inference infrastructure in each jurisdiction where you have users who send personal data through your AI system. For companies with global user bases, this means inference infrastructure in multiple regions.

The cost implications are real. Running inference infrastructure in multiple regions costs more than running it in a single region, because you cannot share capacity across regions. Each region needs enough capacity to handle its own peak load, which means total capacity across regions exceeds what a single centralised deployment would need. The overhead varies by workload pattern but is typically 30 to 60 percent more than centralised deployment.

A practical compliance approach

Start with a data inventory. For each category of data your AI systems process, document where it comes from, where it is stored, where it is processed, and which jurisdictions’ laws apply. This inventory will be incomplete on the first pass. That is acceptable. The goal is to identify the categories that carry the highest residency risk, not to achieve comprehensive coverage immediately.

Next, map your AI workloads against the data inventory. For each workload (training, fine-tuning, inference, evaluation) identify which data categories it uses and whether current processing locations comply with applicable residency requirements. Flag workloads where compliance is unclear or where current processing locations are in jurisdictions that do not satisfy the data source jurisdiction’s requirements.

Then, prioritise remediation based on enforcement risk. Jurisdictions with active enforcement and significant penalties should be addressed first. Jurisdictions with enacted but not yet enforced laws should be addressed on a timeline that aligns with expected enforcement dates. Jurisdictions with draft legislation should be monitored but not yet remediated.

For architecture decisions, adopt a jurisdiction-first design principle. When designing new AI systems, determine data residency requirements before choosing infrastructure. Do not choose infrastructure and then try to retrofit compliance. The retrofit is always more expensive and more fragile than the original design.

The bounded recommendation

Conduct a data residency audit of your AI workloads within the next 90 days. Identify the three highest-risk jurisdiction combinations in your current architecture. For each, determine whether a deployment within the appropriate jurisdiction is technically and economically feasible. If it is not feasible for any of the three, escalate to legal and executive leadership, because the enforcement risk is real and growing.

Shipping a production AI system?

Find where your AI spend leaks and where quality slips. Take the AI Production Scorecard for a fast baseline across the seven layers, or book a free AI cost review and we will turn it into a plan.

Similar Articles

Human-in-the-Loop AI: When to Keep Humans in the Loop and How
Human-in-the-Loop AI: When to Keep Humans in the Loop and How
01 Oct, 2026 | 14 Mins read

Human-in-the-loop has become a catchphrase that means everything and nothing. Systems are described as having human-in-the-loop when a human reviews an AI output, when a human approves an AI decision,

AI Contract Management: Automating Review and Risk Assessment
AI Contract Management: Automating Review and Risk Assessment
18 Aug, 2026 | 17 Mins read

Legal review scales poorly. A contracts team can process a certain volume per person per week. When the business grows, the team either grows proportionally or contracts queue up behind review capacit

Anatomy of an AI Incident: Post-Mortem of a Model Provider Outage
Anatomy of an AI Incident: Post-Mortem of a Model Provider Outage
19 Jun, 2026 | 09 Mins read

On a Tuesday at 2:14 PM, a major model provider began returning elevated error rates for a specific model endpoint. By 2:31 PM, a customer support platform that depended on that endpoint was producing

Agent Guardrails: Containing What an Agent Can Do in Production
Agent Guardrails: Containing What an Agent Can Do in Production
25 Jun, 2026 | 09 Mins read

Input guardrails check whether a user prompt is safe. Output guardrails check whether a model response is appropriate. Agent guardrails check whether the actions an agent takes are within bounds. Thes

EU AI Act enforcement begins: what data teams must do now
EU AI Act enforcement begins: what data teams must do now
25 Apr, 2026 | 04 Mins read

The first enforcement window of the EU AI Act opened in February 2026, and the grace periods that protected early movers are expiring on a rolling schedule through 2027. This is no longer a policy dis

The open-source LLM landscape just shifted: again
The open-source LLM landscape just shifted: again
02 May, 2026 | 03 Mins read

Three releases in the last six weeks have redrawn the open-source LLM map. Meta shipped Llama 4 with a mixture-of-experts architecture that narrows the gap with proprietary frontier models. Mistral re

Why every cloud provider launched an AI operating system this year
Why every cloud provider launched an AI operating system this year
09 May, 2026 | 03 Mins read

AWS announced Bedrock Studio. Google shipped Vertex AI Platform as a unified surface. Azure consolidated its AI offerings under a single "AI Foundry" brand. Databricks, Snowflake, and even Cloudflare

The A2A protocol and what it means for enterprise AI
The A2A protocol and what it means for enterprise AI
16 May, 2026 | 03 Mins read

Google published the Agent-to-Agent (A2A) protocol specification in late 2025 and, as of this quarter, has secured endorsement from over fifty technology companies including Salesforce, SAP, ServiceNo

Conference report: key takeaways from Data Council 2026
Conference report: key takeaways from Data Council 2026
23 May, 2026 | 04 Mins read

Data Council 2026 wrapped in Austin last week, and the signal-to-noise ratio was higher than in recent years. The conference has historically been the venue where data infrastructure practitioners (no

AI spending is up 300%: where is it actually going?
AI spending is up 300%: where is it actually going?
27 May, 2026 | 03 Mins read

Enterprise AI spending increased roughly 300% year-over-year according to multiple industry surveys released this quarter. The headline number gets attention, but the breakdown is where the actionable

The great model commoditisation: what happens when everyone has GPT-5
The great model commoditisation: what happens when everyone has GPT-5
30 May, 2026 | 03 Mins read

OpenAI shipped GPT-5. Anthropic shipped Claude 4. Google shipped Gemini Ultra 2. Within six weeks of each other, the three leading model providers released frontier models that are, by most benchmarks

A compliance-first AI rollout in financial services
A compliance-first AI rollout in financial services
03 Jun, 2026 | 05 Mins read

A regional bank with $12 billion in assets wanted to use machine learning to improve its commercial loan underwriting process. The existing process was manual, relying on credit analysts who spent fou

Regulators are coming for your training data: are you ready?
Regulators are coming for your training data: are you ready?
06 Jun, 2026 | 03 Mins read

The regulatory focus on AI is narrowing from the models themselves to the data that trains them. The EU AI Act requires documentation of training data provenance and composition. The US Copyright Offi

How to audit your AI pipeline for bias: step by step
How to audit your AI pipeline for bias: step by step
07 Jun, 2026 | 06 Mins read

Bias in AI systems is not a theoretical risk. It is a measurable property that can be detected, quantified, and mitigated at every stage of the pipeline. The teams that treat bias as an audit problem

Why 'AI engineer' is the fastest-growing job title (and what it means)
Why 'AI engineer' is the fastest-growing job title (and what it means)
17 Jun, 2026 | 04 Mins read

LinkedIn's latest workforce report shows "AI engineer" as the fastest-growing job title for the third consecutive quarter. Job postings containing the title increased 280% year-over-year. The growth r

The death of the dashboard: what replaces BI?
The death of the dashboard: what replaces BI?
20 Jun, 2026 | 03 Mins read

The traditional BI dashboard, a grid of charts that a business user opens every morning to check KPIs, is losing its grip on how organisations consume data. The decline is not dramatic. No one declare

Designing guardrails: a practical architecture guide
Designing guardrails: a practical architecture guide
21 Jun, 2026 | 06 Mins read

The guardrail problem in AI is a tension between two failure modes. Too few guardrails and the system produces harmful, inaccurate, or brand-damaging outputs. Too many guardrails and the system refuse

Sovereign AI: why countries are building their own models
Sovereign AI: why countries are building their own models
27 Jun, 2026 | 03 Mins read

France released a fully open-source large language model trained on curated French-language data. India announced a multilingual model covering 22 scheduled languages. The UAE expanded its Falcon mode

The hidden environmental cost of your RAG pipeline
The hidden environmental cost of your RAG pipeline
04 Jul, 2026 | 03 Mins read

Retrieval-augmented generation is the default architecture for enterprise AI applications that need to ground model outputs in organisational data. The standard RAG pipeline ingests documents, chunks

The GDPR audit that reshaped our entire ML pipeline
The GDPR audit that reshaped our entire ML pipeline
07 Jul, 2026 | 05 Mins read

A European fintech with twelve million customers received a GDPR audit notice from their national data protection authority. The audit focused on the company's machine learning pipeline, which powered

Why your AI strategy needs a data strategy (not the other way around)
Why your AI strategy needs a data strategy (not the other way around)
11 Jul, 2026 | 03 Mins read

The majority of enterprise AI strategies are built on an implicit assumption: that the organisation's data is ready to support AI workloads. The assumption is almost always wrong. Data that is adequat

How to write an AI incident response plan
How to write an AI incident response plan
12 Jul, 2026 | 07 Mins read

AI systems fail differently than traditional software. A traditional software bug produces incorrect output deterministically. The same input always produces the same wrong output, and a fix eliminate

How a healthcare org deployed LLMs without violating HIPAA
How a healthcare org deployed LLMs without violating HIPAA
14 Jul, 2026 | 05 Mins read

A hospital system with twelve facilities and 14,000 clinical staff wanted to use large language models to assist with clinical documentation. Physicians spent an average of two hours per day on docume

Agentic AI in production: hype vs reality check
Agentic AI in production: hype vs reality check
18 Jul, 2026 | 03 Mins read

Agentic AI (systems where language models plan, execute multi-step tasks, and use tools autonomously) is the dominant topic at every AI conference, vendor pitch, and engineering blog. The hype is inte

The $100B AI infrastructure buildout: who benefits?
The $100B AI infrastructure buildout: who benefits?
25 Jul, 2026 | 03 Mins read

The combined AI infrastructure capital expenditure of the four largest cloud providers exceeded $100 billion in the trailing twelve months. Microsoft, Google, Amazon, and Meta are building data centre

Building trust in AI recommendations: the change management story
Building trust in AI recommendations: the change management story
28 Jul, 2026 | 06 Mins read

A consumer goods company built an AI system that recommended reorder quantities for 12,000 SKUs across 340 distribution points. The system optimised for a multi-objective function that balanced invent

The procurement checklist for AI vendors
The procurement checklist for AI vendors
26 Jul, 2026 | 07 Mins read

AI vendor procurement is where organisations make binding commitments that are expensive to unwind. A three-year contract with a model provider locks you into their pricing, their rate limits, their m

AI safety regulation roundup: US, EU, UK, and Asia compared
AI safety regulation roundup: US, EU, UK, and Asia compared
01 Aug, 2026 | 04 Mins read

The regulatory landscape for AI safety has fractured along jurisdictional lines. The EU has taken a prescriptive, risk-based approach. The US has taken a sector-specific, agency-led approach. The UK h

When the model was right but nobody believed it
When the model was right but nobody believed it
04 Aug, 2026 | 05 Mins read

An agriculture technology company built a crop yield prediction model that combined satellite imagery, soil sensor data, weather forecasts, and historical yield records. The model predicted per-field

Why every tech company is now a data company
Why every tech company is now a data company
05 Aug, 2026 | 03 Mins read

Five years ago, "data company" described a specific type of organisation: a business whose primary product was data or data services: Snowflake, Databricks, Palantir, Bloomberg. Today, the distinction

The talent war: what AI engineers actually want in 2026
The talent war: what AI engineers actually want in 2026
08 Aug, 2026 | 03 Mins read

The market for AI engineers is the tightest it has been since the deep learning boom of 2017. Demand has grown 280% year-over-year for the "AI engineer" title, and the supply of experienced practition

Web scraping legality update: what changed this quarter
Web scraping legality update: what changed this quarter
15 Aug, 2026 | 03 Mins read

The legal landscape for web scraping shifted twice this quarter, and the changes affect any organisation that scrapes web data for AI training, RAG pipelines, or market intelligence. First, a US fede

From copilot to autopilot: the autonomy spectrum debate
From copilot to autopilot: the autonomy spectrum debate
22 Aug, 2026 | 04 Mins read

The framing of AI systems as either "copilots" (human-in-the-loop, AI assists) or "autopilots" (human-out-of-the-loop, AI acts independently) has dominated the conversation about AI autonomy for two y

Metadata Management for AI Governance
Metadata Management for AI Governance
24 May, 2024 | 03 Mins read

# Metadata Management for AI Governance AI systems in production require metadata management to support compliance, auditing, and model oversight. Without systematic tracking of model lineage, traini

The consolidation wave: 5 AI acquisitions that reshaped the market this quarter
The consolidation wave: 5 AI acquisitions that reshaped the market this quarter
02 Sep, 2026 | 04 Mins read

The acquisition wave in AI this quarter was not random. Five deals, each above the billion-dollar threshold, closed within weeks of each other, and they share a common logic: the companies being acqui

Why enterprises are repatriating from managed AI services
Why enterprises are repatriating from managed AI services
05 Sep, 2026 | 04 Mins read

A quiet but significant trend has emerged over the past two quarters: enterprises are moving AI workloads off managed services and back onto infrastructure they control. The pattern is not universal,

The rise of vertical AI: industry-specific models outperform generalists
The rise of vertical AI: industry-specific models outperform generalists
12 Sep, 2026 | 04 Mins read

The benchmark results from the past quarter are hard to ignore. On tasks spanning legal document analysis, medical coding, financial risk assessment, and manufacturing quality inspection, vertical AI

AI chip wars: NVIDIA, AMD, Intel, and custom silicon: who wins?
AI chip wars: NVIDIA, AMD, Intel, and custom silicon: who wins?
19 Sep, 2026 | 04 Mins read

NVIDIA still dominates AI inference and training hardware, but the dominance is no longer absolute in the way it was 18 months ago. AMD has shipped competitive alternatives at lower price points. Inte

What the latest partnership announcements mean for enterprise buyers
What the latest partnership announcements mean for enterprise buyers
26 Sep, 2026 | 04 Mins read

Partnership announcements in AI have become a quarterly ritual. Two companies issue press releases about a strategic alliance, exchange compliments about each other's technology, and promise integrati

The carbon footprint of training frontier models: what the latest research shows
The carbon footprint of training frontier models: what the latest research shows
10 Oct, 2026 | 04 Mins read

The energy consumption numbers for training frontier AI models have crossed a threshold that makes them difficult to ignore. Training a single large language model now consumes between 50 and 100 giga

2025 Year-in-Review & 2026 Trends in Data & AI Architecture
2025 Year-in-Review & 2026 Trends in Data & AI Architecture
19 Dec, 2025 | 03 Mins read

2025 was the year AI moved from experimentation to industrialisation. While 2024 saw the explosion of generative AI capabilities, 2025 was about making those capabilities production-ready, cost-effect

The Governance Layer: Managing AI Risk, Compliance, and Audit
The Governance Layer: Managing AI Risk, Compliance, and Audit
07 Feb, 2026 | 13 Mins read

A healthcare system deployed an AI triage assistant. It worked well in testing. In production, it started routing patients with chest pain to low-priority queues. The error was subtle and infrequent.

Responsible AI by Design: Integrating Ethics into AI Architecture
Responsible AI by Design: Integrating Ethics into AI Architecture
02 Jun, 2026 | 09 Mins read

Responsible AI is not a checklist you complete before deployment. It is a set of architectural decisions that you make throughout the design process, each of which involves trade-offs that are real an

RAG vs Fine-Tuning: Choosing the Right Approach for Your Use Case
RAG vs Fine-Tuning: Choosing the Right Approach for Your Use Case
10 Jul, 2026 | 09 Mins read

Your team has a real use case. Maybe it is a support assistant that answers from your knowledge base, a contracts reviewer that applies your house clause library, or an ops copilot that understands yo

Why Small Businesses Need AI Now: A 2026 Practitioner's Guide
Why Small Businesses Need AI Now: A 2026 Practitioner's Guide
10 Jul, 2026 | 11 Mins read

If you run a small business, you have heard the AI pitch a hundred times. Most of it is aimed at enterprises with data teams, seven-figure budgets, and a CIO to translate. That framing is now out of d