Fundamentals7 min read

Is Your Data Safe With American AI Providers?

Yes, with conditions. Sending personal data to a US AI is a transfer outside the EU. The GDPR, the Data Privacy Framework, and the fix.

By Pierre de ONYRI

The short answer: yes, but with conditions. Most leading AI is American. ChatGPT, Gemini, Claude. For a user in France, sending them personal data is a transfer of data outside the European Union. The GDPR governs that transfer. Since July 2023, the EU-US Data Privacy Framework allows it to certified US companies. That framework remains contested after the Schrems II ruling. The safest method: anonymise your data before you send. With no personal data in the prompt, there is no transfer to govern.

Sending data to a US AI is a transfer outside the EU

Let's set the scene. Most consumer AI models are hosted in the United States. When you paste text into ChatGPT, your data travels to US servers. If that text holds personal data, it is an international data transfer. The GDPR (General Data Protection Regulation) covers this in its Chapter V. A transfer outside the EU is lawful only on a valid legal basis. This is not an administrative detail. It is a condition of legality.

What the GDPR requires for a transfer

Chapter V of the GDPR sets out several legal bases. You cannot transfer data outside the EU without one of them. Here are the main ones.

  • An adequacy decision by the European Commission. It recognises that a country offers an equivalent level of protection.
  • Standard contractual clauses (SCCs), signed between the data exporter and importer.
  • Binding corporate rules (BCRs), for transfers within a single corporate group.

For the United States, the simplest route is the adequacy decision. It has existed since 2023, but it is conditional. Let's see what it actually covers.

The Data Privacy Framework, after Schrems II

On 10 July 2023, the European Commission adopted an adequacy decision. It rests on the EU-US Data Privacy Framework (DPF). In practice, a US company can receive personal data from the EU with no extra formality. On one condition: being certified under the DPF. Certification is voluntary. The company must commit, then appear on the list kept by the US Department of Commerce. Not every US company joins. So an AI provider is covered only if it has certified.

The DPF replaces the Privacy Shield. The Court of Justice of the European Union struck that down in July 2020. This is the ruling known as “Schrems II”. The Court then judged US law insufficient against surveillance programmes. Before it, the Safe Harbor had already fallen in 2015.

Where do things stand today? The DPF is in force. It passed a first test: the General Court of the European Union dismissed a challenge in September 2025. But the framework stays contested. The group noyb, led by Max Schrems, has flagged possible further challenges. Political questions have also touched US oversight bodies. So treat it as neither settled for good, nor fallen.

The CLOUD Act and digital sovereignty

Another point feeds the European concern. Some US laws, such as the CLOUD Act, can compel a provider under US jurisdiction. It may have to hand data to the authorities. Even when that data is stored outside the United States. This is one driver of the debate on digital sovereignty. The idea is simple: keep control of your data, without depending on foreign law. For many French companies, it has become a selection criterion.

European alternatives exist

You are not limited to US AI. European players are growing fast. Mistral AI, a French company, is one example. According to its documentation, Mistral hosts data in Europe by default. The company says it is natively subject to the GDPR. Still per Mistral, its API inputs and outputs are kept 30 days to fight abuse, then deleted. They would not be used to train its models, absent explicit consent. These policies change: check them directly with Mistral before you decide.

RouteWhat it means
US AI certified under the DPFTransfer allowed by the adequacy decision, but the framework is contested
US AI not certifiedTransfer to be framed by standard contractual clauses
European alternative (e.g. Mistral)Data hosted in the EU per the provider, no transfer outside the EU
Anonymise before you sendNo personal data in the prompt, so no transfer to frame
Four routes to use AI without losing control of your personal data.

The fix: anonymise before you send

There is a robust solution, whatever AI you choose. Anonymise your text before you send it. The logic is simple. With no personal data in the prompt, there is no personal-data transfer to frame. Your sensitive data stays under your control, in the browser. This is not a legal exemption certified by any authority. It is risk reduction, at the root.

Two-part diagram: at top, a personal-data record in amber chips crosses an ocean via a transfer arrow to a distant server (US cloud); at bottom, the same record anonymized into cobalt token chips with a checkmark stays on the left shore, no transfer crosses the ocean.
After the CNIL on transfers to the United States, the European Commission on the Data Privacy Framework, and the GDPR (Chapter V, EUR-Lex).

AI keeps all its usefulness. It reasons about the shape of your request. It never sees the real values. You then restore the real data, locally. Here is the method, step by step.

  1. 1Spot the personal data in your text: name, address, email, identifiers.
  2. 2Replace it with reversible tokens, in the browser.
  3. 3Send only the anonymized text to the AI, US or not.
  4. 4Restore the real values in the reply, locally.

That's what ONYRI Sanitize is for. The engine detects sensitive data — name, address, email, API key — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. Whether the AI is American or European, it finds only tokens. You keep control of your data, without giving up the power of the leading models.

Frequently asked questions

Is your data safe with American AI providers?
Yes, but with conditions. Sending personal data to a US AI is a transfer outside the EU. The GDPR allows it if the company is certified under the Data Privacy Framework, or via standard contractual clauses. That framework has stayed contested since the Schrems II ruling. The safest method is to anonymise your data before you send: with no personal data in the prompt, there is no transfer to frame.
Is the Data Privacy Framework reliable today?
It has been in force since July 2023 and survived a first challenge. The General Court of the European Union dismissed it in September 2025. But it stays contested: the group noyb, led by Max Schrems, has flagged possible new challenges. So stay cautious. Do not treat the DPF as settled for good, nor as fallen. Anonymising your data cuts your dependence on its resilience.
Should you drop ChatGPT for a European AI?
Not necessarily. European alternatives exist, such as Mistral, which says it hosts data in the EU. But you can also keep US AI under full control. Just anonymise your text before you send it. With no personal data in the prompt, the choice of provider weighs far less on your compliance.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next