Sovereign-ish: Google Cloud keeps AI data in UK, but not the support
- Reference: 1752144313
- News link: https://www.theregister.co.uk/2025/07/10/google_uk_data_sovereignty/
- Source link:
The option is an acknowledgment of local data (if perhaps not operational) sovereignty and compliance needs. Having data heading offshore for AI is a big no-no for many sectors, such as financial services. However, UK support calls will be routed to Google's global support personnel, while EU customers can receive support from personnel located in the bloc.
Just how sovereign is "sovereign," really? Yes, a customer can select Google Cloud's UK region (europe-west2) when using Gemini 2.5 Flash to store data in that region. Yes, machine learning computations (the "processing") for Gemini 2.5 Flash can be limited to within the UK region.
[1]
However, for data to unequivocally never leave the UK's jurisdictional boundary, support would theoretically also need to take place in the UK. Veteran Linux vendor SUSE this week, for example, [2]highlighted the risk of data crossing a boundary in the name of customer support.
[3]
[4]
One solution from Google is customers keeping their own encryption keys, ensuring their data remains safe from prying eyes. It would therefore be up to the customer to decide if those keys need to be given up. That said, according to Hayete Gallot, Google's customer experience boss, support generally involves troubleshooting why a virtual machine (VM) has failed or analyzing log files.
[5]Alternatives include Google Cloud Airgapped, where open source versions of it's software reside on servers fully disconnected from the internet, or Google Cloud Dedicated, where the software is run by a "trusted partner". However, the latter service is only available in Germany and France at present.
[6]
Mark Boost, CEO of UK cloud vendor Civo, expressed concern about Google's ties to the US. Also noting [7]plans to upskill UK civil servants in Google's technology , he said: "This new partnership positions Google Cloud at the heart of the UK's digital infrastructure, despite being governed by the US CLOUD Act.
"Under this legislation, government data, even if data is hosted in the UK, could still be accessed by US authorities if stored on Google's platform."
[8]SUSE launching region-locked support for the sovereignty-conscious
[9]EU rattles its purse and AI datacenter builders come running
[10]Cloud lobby warns EU: Clamp down on water rules and we'll evaporate
[11]What if Microsoft just turned you off? Security pro counts the cost of dependency
He added: "What's missing from the announcement is any confirmation that safeguards are in place to prevent overseas access to data stored on Google Cloud. When you're dealing with highly sensitive information, especially NHS health records, the legal framework around data access shouldn't be vague or implied. It should be made crystal clear to the public, whose private information is at stake. Right now, we don't have that assurance."
We asked Google about demands for data access from, for example, the US authorities. A spokesperson directed us to the company's [12]whitepaper [PDF] on dealing with government requests. The spokesperson went on to say that Google's processes "meet international best practices for responding to government requests, which we evaluate on a case-by-case basis for adherence to applicable laws and regulations."
"In the event of a government request, our policy is to redirect the request to the customer in question."
[13]
Or there's always the option of encrypting data. The spokesperson added: "Google Cloud offers customer-managed encryption capabilities for GCP and Workspace that give customers complete control of the keys used to encrypt and decrypt their data. This enables customers to deny decryption of their data by any party, including Google Cloud." ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aG_jlsYkbqJeug_c3eMzpwAAAUk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2025/07/08/suse_sovereign_support/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aG_jlsYkbqJeug_c3eMzpwAAAUk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aG_jlsYkbqJeug_c3eMzpwAAAUk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/05/21/google_sovereign_cloud_updates/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aG_jlsYkbqJeug_c3eMzpwAAAUk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2025/07/09/google_cloud_civil_service/
[8] https://www.theregister.com/2025/07/08/suse_sovereign_support/
[9] https://www.theregister.com/2025/07/01/eu_shakes_its_purse_and/
[10] https://www.theregister.com/2025/06/30/cispe_eu_water_resilience/
[11] https://www.theregister.com/2025/06/26/cost_of_microsoft_dependency/
[12] https://services.google.com/fh/files/misc/google_cloud_governmentrequestsfor_cloud_customer_data_v2_1018.pdf
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aG_jlsYkbqJeug_c3eMzpwAAAUk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
We don’t have the decryption keys?
“One solution from Google is customers keeping their own encryption keys, ensuring their data remains safe from prying eyes. It would therefore be up to the customer to decide if those keys need to be given up”
Interesting - wonder how long that’s going to work before the UK Government’s Home Office issues a technical capability notice requiring Google to decrypt the data (a la Apple and the ADP farce) and they are forced into a u turn.
Wouldn’t trust either with my data …
Theatre
Data residency isn’t data sovereignty when the provider is governed by the CLOUD Act. You can store it in a London bunker, process it on British soil, and wrap it in Union Jacks - but if Google gets the knock from Washington, your encryption keys better not be in the room.
This isn’t digital autonomy. It’s regulatory cosplay designed to calm regulators while leaving the jurisdictional backdoor wide open. Until the legal control matches the physical location, UK data on US platforms remains US-accessible - no matter how local the datacentre smells.
Don't forget about National Security Letters
If the US TLAs decide they want your data - hosted anywhere in the world by a US company - in theory, there's a legal review required for access under the CLOUD act.
However, if the demand for the data is delivered to the US company via a National Security Letter, there's no legal review and you will never even know that your data was lifted by Uncle Sam.
US computing services? No thanks.
Re: Don't forget about National Security Letters
that your data was lifted by Uncle Sam.
and today also by Uncle Putin.
It is all just smoke and mirrors
Designed to appear to make it look safe so that the "data is safe" box can be ticked while the auditors check with their eyes tightly shut.
Read the cloud act, Google will have to give the data up if the USA government asks for it. Do you really trust a government headed by Trump to not grab it on some whim of his ?