Your Data Is in the UK. Is It Under UK Control?

hi Hi Human
On data sovereignty

For a clinic, those are two different questions. The gap between them is where the US CLOUD Act lives, and most healthcare AI sits right inside it.

Hi Human · 8 minute read

Ask almost any AI tool sold to clinics where your patient data is stored and you will hear a reassuring answer: a UK data centre, in the UK region, encrypted, GDPR aligned. All true, all important, and not the same thing as your data being under UK control.

Where something is stored is a question about geography. Who can be compelled to hand it over is a question about jurisdiction. They sound alike, so they get treated as one. They are not. A patient record can sit on a server in London and still be reachable by a foreign government, because the company that holds the keys answers to that government’s courts. For a GP surgery or a private clinic, that is the distinction that matters, and it is the one the marketing never quite reaches.

What the US CLOUD Act actually says

The CLOUD Act is a piece of US federal law passed in 2018. In plain terms, it lets US authorities compel a US-based technology company, through a warrant or subpoena, to produce data the company holds, regardless of where in the world that data is physically stored. London, Frankfurt, Dublin, it does not matter. If the provider is headquartered in the United States or has a substantial US presence, the data is within reach of a US court order.

This is not a fringe reading. It is the settled understanding of the law, and the providers themselves have said so. In June 2025, Microsoft’s French subsidiary confirmed under oath at a French Senate hearing that it could not guarantee data held in France would be shielded from US authorities, even under a product marketed as a sovereign French offering. The honest position from one of the largest cloud companies in the world was: we cannot promise this data is beyond US reach.

It is worth being precise about the mechanics, because precision is the whole point here. The US and UK signed a Data Access Agreement that has been in force since October 2022, designed to make cross-border data requests between the two governments faster and more predictable. That agreement is real, it is lawful, and it is part of why this is a live issue rather than a hypothetical one. The route exists, it is paved, and it is in regular use.

Why this lands on healthcare specifically

Here is the part most clinics have not been told. When a healthcare AI tool answers your phone, reads your messages or summarises a consultation, the call recording might be stored in a UK data centre, but the intelligence doing the work, the model itself, very often runs on a US-parented cloud platform. So even when the records sit in Britain, the brain that reads them sits under US jurisdiction.

That means the question is no longer just “where are the recordings kept?” It is “whose servers process the actual content of a patient conversation, and whose courts can reach those servers?” For most AI tools sold to clinics today, the answer to the second question is: an American company, under American law. The UK data centre on the brochure is true and is also not where the sensitive thinking happens.

The NHS risks becoming a publicly funded data generator for privately controlled intelligence platforms.
British Medical Association, on the risk to NHS data sovereignty, 2026

The BMA has said the quiet part out loud

This is not a vendor talking its own book. In 2026 the British Medical Association, the professional body for doctors in the UK, published a clear warning on exactly this risk. Their phrasing is worth reading directly: “under the US CLOUD Act, US-based companies can be required to provide data to US authorities even if that data is stored in the UK or Europe.” That is the BMA, not a cloud reseller, stating the jurisdiction problem in one sentence.

The BMA’s conclusion is a principle clinics can borrow wholesale: “Data generated through NHS care, including data derived and structured by AI, must remain under NHS stewardship.” They frame it not as a reason to reject private partners outright, but, in their words, as “an argument for choosing who we partner with carefully.” The control of the data layer, they argue, should not quietly transfer to a platform whose ultimate accountability lies in another country’s legal system.

Read that across to a private clinic and the logic holds without modification. Your patients did not consent to their health conversations becoming reachable by a foreign government because of where your software supplier happens to be incorporated. Stewardship of that data is part of the duty of care, and it does not stop at the encryption layer.

To be clear: this is about control, not legality

A point we will not blur

It is not illegal for patient data to leave the UK. Lawful international data transfers happen every day under UK GDPR, through recognised safeguards, and a great deal of excellent software relies on them. Anyone telling a clinic there is a flat statutory ban on data crossing the border is overselling, and we will not do that.

The real issue is narrower and more practical: risk, control and governance. Even a lawful arrangement can leave your patient data reachable by a foreign authority, outside your knowledge and outside your control. That is a risk to assess, a procurement preference to weigh, and a question your DSPT and DTAC governance will increasingly expect a clear answer to. It is a judgement call about who holds the keys, not a question of breaking the law.

So the right question for a clinic is not “is this allowed?” It usually is. The question is “do I want this?” Do you want patient conversations sitting under a jurisdiction you cannot see into, governed by a legal process you will never be told about, on the word of a contract that the supplier’s own lawyers have admitted they cannot fully honour? For administrative convenience, plenty of clinics will accept that. For the most sensitive clinical and personal data, many will not, and they are right to think hard about it.

Britain has decided this matters too

The clinic-level concern sits inside a national one. In April 2026 the UK government launched a £500 million Sovereign AI Fund, with the explicit aim of building homegrown AI capability and reducing reliance on foreign technology providers. The framing from government was blunt: Britain should be, in its own words, “an AI maker, not an AI taker.” When the state is putting half a billion pounds behind keeping critical AI capability domestic, a clinic asking the same question about its patient data is not being paranoid. It is being early.

The constructive answer: keep the intelligence inside the building

If the problem is that the brain sits somewhere you do not control, the cleanest solution is to move the brain. Not to a better-marketed cloud, not to a sovereign-branded region with the same parent company, but onto hardware that physically lives inside the clinic, where the data never has to leave the premises to be understood.

That is a real architectural choice, and it changes the jurisdiction question entirely. If the AI runs on-site and the patient data never travels to a third party’s servers to be processed, there is no foreign court order to worry about, because there is nothing reaching across a border in the first place. The cleanest way to keep data under your control is to make sure it never leaves your control to begin with.

A note on what we are building

Hannah Sovereign

We are building a version of Hannah, our AI receptionist, that runs entirely on-site, inside the clinic, fully offline. The intelligence lives on your premises and patient data never leaves the building to be processed. It is a bespoke, high-trust build for clinics that want this distinction settled in the architecture, not just the contract. It is early, and we are opening a waitlist rather than shipping it off the shelf.

Join the Hannah Sovereign waitlist

None of this means every clinic needs an on-site AI tomorrow, and we are not going to pretend it does. For a great many practices, well-governed UK-hosted software is exactly the right call, and our own platform serves clinics that way today. The point is simpler than a sales pitch: know the difference between where your data is stored and who can reach it, ask your suppliers the second question, and choose with your eyes open. The clinics that win their patients’ trust will be the ones who treated that question as part of the care, not a footnote to it.

Sources

  1. British Medical Association, “AI, private platforms, and the risk to NHS data sovereignty” (2026) – bma.org.uk
  2. US CLOUD Act, 2018 (US federal law on overseas data access); US-UK Data Access Agreement, in force since October 2022
  3. Microsoft France testimony to the French Senate on data sovereignty under US law (June 2025)
  4. UK Government, Sovereign AI Fund, £500m, launched April 2026 – gov.uk / sovereignai.gov.uk

Hi Human

always on, always helping · Built and hosted in the UK. Used by UK practices including ndu Clinic on Harley Street.

Share This Story, Choose Your Platform!

About the author : Andrej Godina

Leave A Comment