Wondering whether a company AI assistant means your data ends up on servers in the US? The short answer: it doesn't have to. It depends on how the assistant is built, where the bridge to your data runs, and what actually leaves the company when someone asks a question.
Why companies keep putting AI off
It looks much the same in a lot of companies. Someone in sales pays for a personal subscription, pastes a customer contract into the window and asks for a summary. The accountant drops in an export from Pohoda. Nobody knows where that text went, who can see it, or how long it stays there.
The managing director finds out by accident and does the one sensible thing within reach: bans it. AI gets pushed to next year. The work it could have removed stays with people. Digging through mail, retyping numbers between systems, writing Monday meeting summaries by hand.
I don't mind that it can answer. I mind that I don't know who we just sent this to.
— A management meeting, paraphrased
What actually applies to data in the US
Transfers of personal data outside the EU are governed by Chapter V of the GDPR. In 2020 the Court of Justice of the EU struck down the earlier Privacy Shield in its Schrems II ruling. Since 10 July 2023 a new European Commission adequacy decision has applied: the EU-US Data Privacy Framework. A US company certified under it can receive personal data from the EU without additional contractual clauses. In September 2025 the framework held up at the EU General Court, though further rounds in court can't be ruled out.
The practical takeaway for a company is simple. Legally, transfers to the US are workable today. But leadership is really asking something else: how much data has to leave at all, and who stays in control of it. That is decided by architecture, not by contract alone.
What building it on your own infrastructure means
An AI assistant has two parts. The model, Anthropic's Claude, which reads, writes and reasons. And everything else: where your data sits, who may touch it, what gets logged and which route a question takes. That second part can live entirely with you.
Here is how we set it up. Small MCP servers run on your cloud, one per system: accounting, CRM, shared drive, mail. When an employee asks something, the server uses that person's own sign-in and permissions and sends Claude only the excerpt the answer needs. Nothing is copied into a third-party index, and the whole route is written to an audit trail on your side. The model itself is called in a region you choose, for example EU data centres at your cloud provider.
Concretely: Pohoda, Raynet and the company drive
Take a manufacturer with forty people (an illustrative example). Accounting runs in Pohoda, sales in Raynet, contracts on a shared Microsoft 365 drive. None of that changes. We add three bridges and one place that records who asked what.
- The Pohoda bridge reads balances and invoices only for people who can access that account in Pohoda.
- The Raynet bridge returns a customer's history according to the individual salesperson's rights, not the whole database.
- The drive bridge searches contracts the asker is allowed to open and cites the exact document.
- Every question and every read is written to an audit log on your infrastructure.
A salesperson asks first thing in the morning: how is customer Novák doing on payments, and what did we promise them in the last contract? The answer arrives in moments, with a link to the invoice and the contract clause. Before, that meant opening three systems and messaging accounting. Only the few lines the answer needed ever left the company.
What this won't do, and why that's good
It won't make you a lawyer. Whether a given processing activity needs an impact assessment, how to update your records of processing, or whether Data Privacy Framework certification is enough: that is for your data protection officer or counsel. We supply the evidence they need, meaning where data flows, what gets stored and where.
And it won't route around permissions. Anyone who can't reach the data today won't reach it through the assistant either. For leadership, that is exactly the reason to trust it. The rules stay where you already keep them, and you can trace afterwards who asked and what they got.
What it would take
Not a year-long project. You start with the one system that matters most, usually accounting or CRM. We deploy the bridge on your cloud, connect it to your sign-in, and you pick the region where the model is called. Once that works, the next system follows, and teams save the routines they repeat every week into the skills library.
What's left
The question of a company AI assistant versus US servers is rarely settled by a ban or by blind trust. It's settled by deciding how much data may leave and who stays in control. The model isn't the bottleneck. The bottleneck is the gap between Claude and the data your company already has, and how you bridge it.
If you'd like to see what this would look like for you, write to us. On a short call we'll go through the systems you use, where the bridge would sit and what would leave the company. No commitment, no hour-long pitch.
