AI Discovery

Does Your AI Keep Your Business Data in the UK?

IT Club Editorial14 minutes read29 August 2026
WhatsAppEmail
Does Your AI Keep Your Business Data in the UK?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

Business AI has several data locations, not one. Storage at rest, prompt processing, model inference, interaction history, safety records and connector services can follow different routes. This dated, vendor-neutral guide helps UK businesses test the exact residency requirement they have and verify the product, plan, model, endpoint and contract before relying on a regional promise.

A business wants an AI assistant to summarise a customer email, search a SharePoint library, draft a proposal or analyse a spreadsheet. Someone asks the sensible question: “Will our data stay in the UK?”

The honest answer is usually more precise than yes or no. Modern AI services have several data paths. The customer content might be stored in one place, the prompt processed in another, the model inference run somewhere else, interaction history and safety records retained under separate rules, and a connector or web-search service given a further copy.

The Quick Answer

A UK storage promise is not automatically a UK-only processing promise. Before approving a business AI workflow, identify which data must stay in the UK and ask the supplier to answer separately for storage, processing, inference, logs, safety data, support access and third-party services.

  • Microsoft 365 has UK data-location options for covered services, but Microsoft says Copilot model calls can use other regions when capacity is needed.
  • OpenAI distinguishes customer content at rest from inference residency. Eligible ChatGPT Enterprise and Edu workspaces have documented UK options, while product and feature eligibility still matter.
  • ChatGPT Business, commercial Claude and Gemini for Workspace have useful business privacy controls, but do not assume those controls are a universal UK-only hosting or processing commitment.
  • A connector, web search, agent tool, cloud deployment or support route can become the escape hatch that moves data outside the boundary you thought you had selected.
  • The right result is a dated, evidence-backed answer for one product and one workflow — not a blanket claim that a vendor is always UK-compliant.

Checked: 29 August 2026. Product features, model availability, regional options, terms and regulatory guidance change quickly. Verify the current supplier documentation and contract before relying on a specific control. This is general information for UK businesses, not legal advice.

The five locations hiding behind one question

“Where is the AI data?” is too broad to produce a useful answer. Separate the data into named paths. A supplier may make a strong commitment for one path and a limited or conditional commitment for another.

Data pathWhat it meansWhat to verify
Customer content at restPrompts, uploaded files, conversations, outputs, indexes or artifacts stored on disk or in a persistent serviceWhich content is covered, in which product and plan, in which region, and whether replicas and backups follow the same rule
Processing and inferenceThe computation that reads the input, invokes a model and produces an outputWhere the request runs for this model, endpoint, deployment type and capacity condition; whether regional processing is actually offered
Logs and metadataAccount details, usage, timestamps, diagnostics, billing, audit records and service telemetryWhether residency applies, how long records remain, which support or abuse systems can access them and where they are processed
Safety and abuse dataSignals used for abuse prevention, security investigation, content safety, fraud detection or legal obligationsWhether prompts, files or outputs can be retained for review and whether safety processing has a separate region or exception
Third-party servicesConnectors, web search, cloud platforms, plugins, apps, MCP servers, subprocessors and agent toolsWhat leaves the primary service, under whose terms, with which identity, and where the other service stores, processes and logs it

“Stored in the UK” answers only the at-rest question unless the supplier explicitly defines a wider boundary. Do not silently upgrade a storage statement into an inference, support, log or connector statement.

Data Location Map

Use this map when someone says “the data stays in the UK”. Each arrow is a separate question, not a footnote to the first one.

A five-path map for a business AI request

StageTypical routeResidency status to record
1. InputEmployee or application → AI prompt, file or connected recordWhat data entered the boundary, from which identity and under which purpose?
2. At restAI service → content store, conversation history, index, file or backupUK / Europe / global / not stated — name the covered content and replicas
3. InferencePrompt + retrieved context → model endpoint → outputUK / regional / closest available / global / conditional — name the model and endpoint
4. RecordsRequest → usage, diagnostic, safety, abuse, billing or support systemsCovered / separate policy / exception / not stated — record retention and access
5. Escape hatchAI service → web search, connector, cloud host, app, MCP server or agent toolDestination, supplier, identity, permissions, logs and revocation route

The map is deliberately boring. That is its value. A residency review should be able to point at each arrow and say “covered”, “conditional”, “not offered” or “we have not established this yet”.

Start with the requirement, not the vendor badge

A client may ask for UK hosting. A regulated workflow may require a particular transfer arrangement. An internal policy may say that personal data must not leave a chosen region. These can be sensible requirements, but they are not interchangeable.

RequirementMinimum questionLikely answer label
UK storage at restAre the specified prompts, files, outputs, indexes, backups and replicas stored in the UK?POSSIBLE, subject to product, plan and configuration
UK processingDoes the service process the request and retrieved context only in UK infrastructure?DEPENDS; check model, endpoint, failover and capacity routing
UK model inferenceDoes the selected model execute in the UK rather than merely store the result there?LIMITED or DEPENDS; often only selected plans and regions
UK logs and supportAre telemetry, abuse review, support access and billing records also confined to the UK?VERIFY WITH SUPPLIER; often separate from content residency
No onward disclosureCan connectors, search, agents, subprocessors and cloud hosts receive or retain the information?DEPENDS; map each external route

Write the requirement as a sentence with a subject and a boundary: “For customer contract summaries, prompt content and retrieved documents must be stored and processed in the UK; operational metadata may follow the supplier's documented transfer safeguards; no web search or external connector is permitted.” That can be tested. “We need a UK-compliant AI” cannot.

What the main business AI routes currently say

The following comparison was checked on 29 August 2026 against public vendor documentation. “Not a promise” means exactly that: it is not evidence that a product is unsuitable. It means the public statement does not answer the whole residency question for every workflow.

Product routeAt-rest positionProcessing / inference positionOverall reading
Microsoft 365 CopilotMicrosoft 365 has UK local-region geography for covered services. Copilot interaction content is stored and managed with Microsoft 365 commitments.Microsoft says Copilot calls to the LLM use the closest regional data centres but can use other regions when capacity is needed. Web-search queries go to Bing and are a separate path.DEPENDS. Useful Microsoft 365 boundary and controls, but not an automatic UK-only inference promise.
ChatGPT BusinessOpenAI says business workspace data is not used to train models by default. Published residency controls are plan- and eligibility-specific; do not assume Enterprise residency controls apply to Business.Do not infer UK processing from the no-training commitment or from a business plan name. Confirm the current workspace, features, apps, retention and contract.LIMITED / VERIFY WITH SUPPLIER for a UK-only requirement.
ChatGPT Enterprise / EduEligible workspaces can be configured for at-rest data residency, including the UK, covering documented customer content such as conversations and files.OpenAI's current ChatGPT documentation lists UK inference residency for eligible Enterprise and Edu customers with data residency enabled. Feature, model, connector and support boundaries still need checking.DEPENDS. The strongest documented ChatGPT route, but it is eligibility- and configuration-based.
Claude commercial / EnterpriseAnthropic's commercial privacy position says commercial inputs and outputs are not used to train models by default. That is not a universal UK storage statement.A Claude deployment may use Anthropic infrastructure or a cloud platform such as Google Cloud, with different regional controls. Public documentation does not justify a blanket UK-only claim for every commercial route.LIMITED / VERIFY WITH SUPPLIER for UK storage, inference, logs and subprocessors.
Gemini for Google WorkspaceWorkspace Data Regions can apply to covered Workspace data, with documented choices such as the United States or Europe. Europe is not the same as the United Kingdom.The exact Gemini feature, prompt route, model and advanced capability determine what is covered. Do not turn a Workspace Europe setting into a UK-only inference claim.DEPENDS. Check Workspace edition, Data Regions policy and Gemini feature coverage.
Gemini / models on Google CloudGoogle Cloud offers regional resources and UK locations for some services, but the selected project, resource, model and endpoint determine the boundary.Regional endpoints can help, but global endpoints, unsupported models, tools and third-party services may have different behaviour. Google documents that endpoints do not automatically guarantee residency.DEPENDS. A useful engineering route only when the exact deployment is documented and tested.
Azure OpenAI / AI FoundryAzure's deployment geography and data-processing documentation can support a regional design for selected deployments and supported features.Global, batch, preview, model-specific and connected features can have different processing locations. The Azure region alone is not a universal claim for every model or tool.QUALIFIED OPTION. Verify model, deployment type, region, logging and every connected service.

Microsoft 365 Copilot: a Microsoft 365 boundary is not a UK-only model boundary

Microsoft's current Copilot privacy documentation says prompts, retrieved data and generated responses are processed and stored in line with the contractual commitments for the organisation's Microsoft 365 content. It also says interaction content is stored, can be managed through Microsoft Purview and is not used to train foundation large language models.

That is useful, but location has another layer. Microsoft says Copilot calls to the LLM are routed to the closest data centres in the region and can also call into other regions when capacity is especially high. For a strict UK-processing requirement, that sentence matters more than a general statement that Microsoft 365 has a UK local region.

Copilot can also send generated search queries to Bing when web search is used. A plugin, connector, agent or third-party model may add further terms and destinations. A Microsoft 365 tenant can therefore have strong identity and compliance controls while a particular AI request still has a wider route.

Microsoft 365 Copilot: record UK at-rest coverage and UK inference separately. If web search, a third-party model or an external connector is enabled, record that as a new data path rather than assuming it inherits the tenant's location.

ChatGPT Business versus ChatGPT Enterprise and Edu

OpenAI's business-data position is not the same thing as a residency position. OpenAI says ChatGPT Business, Enterprise and Edu workspace data is not used to train or improve models by default. That answers an important data-use question, but it does not by itself say where content, inference, system metadata or app activity is handled.

OpenAI's current ChatGPT data-residency documentation describes at-rest residency for eligible Enterprise and Edu workspaces and lists the United Kingdom among supported inference-residency regions. That is a meaningful distinction from simply buying a business-labelled plan: the workspace must be eligible, configured and using a supported route.

Keep the boundary visible. Conversations, files, custom GPTs, memory, image-generation artifacts, code-interpreter artifacts, apps, support access and safety handling may not all have identical coverage. Read the current residency page and contract for the workspace rather than treating “Enterprise” as a magic suffix.

Claude: privacy defaults are not a UK location guarantee

Anthropic's commercial privacy documentation says inputs and outputs from commercial products are not used to train models by default, subject to its stated terms and exceptions. That is relevant to training and data use. It does not establish that every commercial or Enterprise Claude request is stored, inferred, logged and supported only in the UK.

Claude may be used through Anthropic's own service or through a cloud platform. A model served on Google Cloud, for example, brings the selected cloud project, region, endpoint, logging and provider terms into the map. The business should ask Anthropic or its cloud supplier for a written answer covering the exact plan, model, deployment, retention, subprocessors and support route.

Claude commercial privacy: NOT CURRENTLY OFFERED as a universal public UK-only promise in this guide. That label does not mean a suitable regional design is impossible; it means the buyer must establish it for the actual route.

Gemini: Google Workspace and Google Cloud are different decisions

Google Workspace Data Regions can help administrators choose a location for covered Workspace data and, for eligible editions and settings, some data processing. The documented choices are generally United States, Europe or no preference. Europe may be the relevant transfer boundary for some organisations, but it is not a promise that data is stored and processed in the United Kingdom.

Google Cloud is a different engineering route. A project can use a supported UK region or regional endpoint for some AI services, but model availability, global endpoints, tools, indexes, safety systems and third-party services vary. Google's own location documentation warns that an endpoint does not automatically guarantee data residency.

Ask which Gemini product is being purchased: Gemini in Workspace, the standalone Gemini app, Gemini Enterprise, Vertex AI or another Google Cloud feature. Similar names do not imply identical data paths, terms or administrative controls.

Azure OpenAI and AI Foundry: a qualified regional option

Azure can support a more explicit regional architecture because the customer chooses a deployment region and Microsoft documents data-processing and privacy behaviour for Azure OpenAI. That can be useful when a business needs a UK-hosted application and has engineering control over the model endpoint.

It is still a qualified option, not an automatic answer. Global and batch deployment types, preview features, model-specific availability, content filtering, monitoring, prompt-flow tools, application logs and external storage can have different boundaries. Record the exact deployment type and test the route rather than relying on the Azure brand.

The connector escape hatch

A connector changes the residency question from “Where does this AI service run?” to “Where does every service in this workflow run?” A search assistant connected to SharePoint, Google Drive, a CRM, email, accounting or a support system may retrieve information that was never manually pasted into a chat.

  1. 1Map the information: list the files, messages, records, attachments and personal data the connector can reach.
  2. 2Map the identity: establish whether the connector acts as the employee, a shared account, an administrator or an application identity.
  3. 3Map the destination: identify the AI provider, search provider, app, cloud host, plugin, MCP server and every relevant subprocessor.
  4. 4Map the location: establish where retrieval, indexing, inference, caching, logs, backups and support access occur.
  5. 5Map the action: distinguish read-only search from drafting, changing records, sending messages, deleting data or initiating payment.
  6. 6Map the evidence: identify access logs, prompt logs, output records, admin events, retention settings and the people who can review them.
  7. 7Map the stop button: test how quickly an administrator can revoke a token, disable an app, remove a user and prevent cached or indexed access.

Connector location is not inherited automatically. A UK setting on the main AI service cannot make a separate CRM, web-search provider, cloud index or agent tool UK-only.

AI agents make location harder to prove

A chatbot may process one prompt and return one answer. An agent can search several systems, call a model more than once, write temporary files, ask a tool to fetch a web page, hand work to another model and take an action. Each step can have its own service boundary and retention rule.

  • Begin with read-only access and synthetic or low-sensitivity data.
  • Keep the agent's retrieved context, prompts and outputs inside an approved route where possible.
  • Require human approval before external messages, record changes, deletion, payment or other hard-to-reverse actions.
  • Give every tool a named owner, narrow permission, expiry or review date and a tested disable route.
  • Log which tool was called, with which identity, what data it received, what it returned and what action followed.
  • Do not call an agent UK-resident until every model, tool, index, log and support route in its plan has been checked.

The AI residency checklist

Use this checklist for a real purchase or workflow review. If an answer is unavailable, label it rather than filling the gap with a supplier logo or a hopeful assumption.

  • What is the exact product, plan, tenant, project, model, endpoint and deployment type?
  • Which data must stay in the UK: prompts, files, outputs, indexes, backups, logs, safety records, support access or all of them?
  • Is the promise about data at rest, processing, model inference, access from support teams or a combination?
  • Which customer content is covered, and are replicas, caches, backups and temporary files included?
  • Can requests be routed to another region for capacity, failover, abuse review, support or model availability?
  • What interaction history, telemetry, usage, billing, audit and safety data is retained, for how long and where?
  • Are prompts and outputs used for training or improvement by default, and can the setting change?
  • Which connectors, web searches, plugins, apps, MCP servers, cloud hosts and subprocessors can receive the data?
  • Does the connector use the employee's identity or a broader service identity?
  • What happens to data when an agent retries, caches, indexes, drafts, acts or hands work to another service?
  • Which contract, DPA, product terms and subprocessor list contain the relevant commitment?
  • What audit evidence can the supplier provide, and how will the business detect a material routing or product change?
  • Can the business revoke access, delete data and preserve evidence without waiting for an informal support request?
  • Who owns the decision, the workflow, the incident route and the next review date?

The practical proof and review step

A residency page is useful evidence, but it is not the whole proof pack. Save the page and the date you checked it, then capture the configuration that makes the statement relevant to your business. A setting that is available but not enabled is not a control.

  1. 1Write the requirement and classify the information before testing the product.
  2. 2Record the product, plan, workspace or project, model, endpoint, deployment region and enabled features.
  3. 3Read the supplier's residency, privacy, retention, security, subprocessor and contract documents together.
  4. 4Ask the supplier to answer separately for at-rest content, inference, logs, safety data, support access and third parties.
  5. 5Run a controlled test with a harmless marker in the prompt and a connector record. Review the available audit events and export evidence where the product supports it.
  6. 6Disable web search and unnecessary connectors for the initial approved workflow. Add them only when their locations and terms are understood.
  7. 7Set a review owner and date. Re-check after a new model, agent, connector, region, contract or material product change.

The operational heartbeat

Residency is not a one-time procurement checkbox. Review the boundary at least quarterly and sooner after a material change.

  • Approved products, plans, models, endpoints and deployment regions
  • Data-residency settings, retention and training/data-sharing defaults
  • New connectors, web-search routes, agents, tools and subprocessors
  • User, application and service identities, permissions and leavers
  • Logs, safety records, support-access evidence and deletion requests
  • Supplier documentation, contract terms and regional availability changes
  • Real test evidence, unexpected routes, incidents, incorrect outputs and human approvals
  • Whether staff guidance still matches what people are actually using

What this does — and does not — say about UK GDPR

The ICO's AI and data-protection guidance emphasises familiar principles including purpose limitation, data minimisation, security, accountability and understanding the processing carried out by third parties. Its contracts guidance recommends identifying the distinct processing operations, decision makers and controller or processor responsibilities.

That does not create a universal rule that every business AI request must run in the UK. The relevant requirement may come from the information, a customer contract, sector expectations, an internal policy or a transfer assessment. UK data protection duties also depend on the facts of the processing. Get specialist legal advice where the consequences or transfer questions warrant it.

This article is therefore not a certification of Microsoft, OpenAI, Anthropic, Google, Azure or any other provider. It is a method for turning a broad location question into a testable, documented decision.

Read next: AI Privacy Is Becoming a Competitive Advantage

Read next: Your AI Agent Did Something Illegal. Who Is Responsible?

Sources and further reading

Primary sources below were checked on 29 August 2026. Product pages and terms can change; open the current source and verify the exact plan, model, region and feature before relying on it.

Microsoft Learn — Microsoft 365 Copilot privacy and data residency

Microsoft Learn — Microsoft 365 data locations

Microsoft Learn — Copilot Studio data locations and external services

Microsoft Learn — Azure OpenAI data privacy and security

OpenAI — Data residency and inference residency for ChatGPT

OpenAI — Business data privacy, security and compliance

OpenAI API — Your data and data residency

Anthropic — How do you handle data from commercial services?

Anthropic — Claude on Google Cloud

Google Workspace — Control over data location with Google Workspace

Google Cloud — Generative AI data residency

Google Cloud — UK Data Boundary

ICO — Guidance on AI and data protection

ICO — Contracts and third parties

GOV.UK — UK GDPR international data transfers guidance

Plain-English Takeaway

Do not ask only whether an AI provider offers UK data residency. Ask which content is covered, where it is stored, where prompts and inference are processed, what logs and safety data are retained, which connectors receive a copy and what the contract actually promises for the exact product, plan, model and endpoint.

Follow The IT Club Briefing on WhatsApp

Tap to follow The IT Club Briefing on WhatsApp.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor