Hello, this is Ryuta Hamamoto from TIMEWELL.
"It's encrypted, so we're fine." I have read that sentence in a lot of cloud review documents.
Encryption is table stakes. But there is a question that sentence does not answer. What happens when the provider holding your data is ordered by its own government to hand it over? If that provider holds the keys, it can produce plaintext.
This topic usually gets discussed on instinct. America is scary, China is out of the question, Japan is safe. I have heard all three said in meetings. Read the actual texts, though, and the picture changes. The regimes are not the same, and Japan's regulator has published country-by-country assessments of exactly this.
So this piece reads the US CLOUD Act, China's National Intelligence Law and two companion statutes, GDPR Article 48, and an answer given by Japan's cabinet in the Diet. On choosing a region in the first place, I wrote Can you actually run an LLM inside Japan. For a read on where your own organisation stands, there is a free AI readiness check.
One correction before we start. The EU AI Act is not a law that compels governments' access to data. It regulates AI systems. The provision that belongs in this conversation is GDPR Article 48, and it points the other way.
The United States: the statute says "regardless of where"
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) was enacted on 23 March 2018. What it did was add section 2713 to Title 18 of the US Code1:
A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.
The clause that matters is the last one. Regardless of whether the data sits inside or outside the United States.
So if data is within the "possession, custody, or control" of a US provider, it can be in scope even when it physically sits in a Tokyo data centre. "We chose the Tokyo region, so US law does not reach it" does not survive contact with this text.
Taken alone, the CLOUD Act is a criminal-process story. A disclosure order needs US criminal process, with limits on purpose and procedure. That much stays inside what most people would recognise as ordinary law enforcement.
The problem is that US collection abroad does not run on this track only.
The other track was built to target foreigners
Section 702 of the Foreign Intelligence Surveillance Act is a separate lineage. From the Congressional Research Service2:
Section 702 of the Foreign Intelligence Surveillance Act of 1978 (FISA) ... authorizes intelligence agencies to programmatically target non-U.S. persons reasonably believed to be outside the United States to acquire foreign intelligence information.
Non-US persons reasonably believed to be outside the United States, targeted programmatically. A Japanese company operating in Japan sits squarely inside that definition. Not on the protected side. On the collection side.
The same CRS piece describes what makes it distinct:
Section 702, which uniquely authorizes programmatic surveillance that does not require individual court orders for each target and acquisition.
No individual court order per target, per acquisition. Once a year the Attorney General and the Director of National Intelligence certify the procedures, and the Foreign Intelligence Surveillance Court approves those procedures. What gets approved is the method, not the people. That is a different animal from a warrant.
Beyond that, signals intelligence collected abroad under Executive Order 12333 sits outside this framework altogether.
This asymmetry is why I do not think Japanese companies should read their own regulator's country report as the whole story. Japan's Personal Information Protection Commission report on the United States mentions neither the CLOUD Act nor FISA. Absence from a report is not absence from the statute book.
The statute lapsed. The collection did not.
One more thing happened in 2026, and it belongs in this article.
Section 702 was automatically repealed on 12 June 2026. All of Title VII of FISA, sections 702 through 705, fell away under Public Law 119–87 when Congress could not agree on reauthorisation2.
Did the collection stop? The CRS explains:
Pursuant to transition procedures contained in the FAA, "any order, authorization, or directive issued" under Section 702 "shall continue in effect until the date of the expiration of such order, authorization, or directive."
Orders already issued run to their own expiry. The FISC authorised a year of activity in March 2026, and the executive branch may keep operating under those orders for up to a year. Which means the collection continues into roughly March 2027, with the authorising statute repealed.
I hesitated over including this, because it reads like scaremongering. I kept it because there is a practical lesson in it. Do not build your data governance on the current state of a foreign surveillance statute. It did not stop when the law lapsed, and it will return if the law is renewed. There is no reason to hand the design of infrastructure you will run for years to another country's legislative calendar.
China: Japan's regulator names three statutes
For China, Japan's Personal Information Protection Commission publishes an official assessment3. Article 28 of Japan's personal data protection act requires operators transferring personal data to a third party abroad to give the individual information about that country's regime, and the Commission publishes country reports as reference material.
The China report, updated 3 February 2025, lists three statutes as regimes imposing cooperation duties on operators that may seriously affect the rights and interests of individuals.
| Statute | As described by the Commission |
|---|---|
| Cybersecurity Law | Obliges network operators to provide technical support and assistance to public security and state security organs for safeguarding national security and investigating crime |
| Data Security Law | Obliges relevant organisations and individuals to cooperate with data examinations conducted by public security and state security organs |
| National Intelligence Law | Obliges relevant institutions, organisations and citizens to provide necessary support, assistance and cooperation for national intelligence work conducted by state security organs, the intelligence departments of public security organs and military intelligence departments |
Article 7 of the National Intelligence Law reads4:
第七条 任何组织和公民都应当依法支持、协助和配合国家情报工作,保守所知悉的国家情报工作秘密。
Any organisation and citizen shall, in accordance with law, support, assist and cooperate with national intelligence work, and keep secret any national intelligence work they become aware of. In force since 28 June 2017, amended in 2018.
Quoting statutes is easy. What makes the Commission's report worth reading is that it lists what is not there. For each of the three, it records the absence of provisions on: limits and procedures for conducting access; access confined to what is necessary for a purpose specified in law; approval by an independent body; restrictions and security controls on how acquired information is handled; and transparency.
Then the Commission states its own conclusion:
Under these laws, the state security organs and public security organs of the People's Republic of China are able, for the purpose of broad intelligence gathering and not merely national security or criminal investigation, to require enterprises and individuals to provide the various information they hold, including personal information, and to collect and monitor it.
That is a national regulator putting it in writing. The report also notes that China imposes data localisation, with cross-border transfer subject in some cases to passing a security assessment by the authorities.
Struggling with AI adoption?
We have prepared materials covering ZEROCK case studies and implementation methods.
Japan's regulator does not treat the two the same. Neither should you treat its report as the last word
Here is the part I most want to land.
The same Commission publishes a report on the United States5. Its entries read:
- Data localisation regimes that may seriously affect the rights and interests of individuals: –
- Regimes imposing cooperation duties with government information gathering that may seriously affect the rights and interests of individuals: –
None identified, in both cases. I searched the full PDF: the CLOUD Act, FISA and the Patriot Act do not appear in it once.
This does not mean the United States has no government access regime. Section 2713 plainly exists, as we saw. The report states its own limits: the survey covered only statutes that contractors identified as representative, the information dates from October 2021, and confirming a foreign regime is the operator's own responsibility with the Commission's material as an aid.
What remains as fact is a contrast. Japan's regulator named three Chinese statutes and recorded the absence of procedure, independent approval and transparency. For the United States, it named nothing under the same criteria.
I read that difference as being about whether limits, procedure, independent approval and transparency exist, rather than about whether a government can obtain data at all. Every country has investigators who will ask for data when they need it. The question is whether there are brakes, and whether anyone outside can see them.
But treating this one report as canon would be a mistake.
Another body examined the same US statutes and reached the opposite conclusion. In July 2020, in the judgment known as Schrems II, the Court of Justice of the European Union invalidated the EU-US Privacy Shield. Its reasons were that FISA Section 702 and Executive Order 12333 are too permissive to meet EU law's necessity and proportionality standards, and that EU data subjects have no effective redress against the US government6.
Japan's Commission wrote "none identified". Europe's highest court wrote "not adequate". On the same statutes.
I am not in a position to say which reading is correct. As a practitioner I can say this much: persuading your own organisation with "our regulator found no issue" is a weak argument to stand on, especially when that regulator writes in the same document that its survey was not exhaustive and the responsibility is yours.
The EU: a law that blocks foreign orders, not one that compels disclosure
People sometimes explain the EU position by pointing at the AI Act. Worth being precise here. The EU AI Act regulates AI systems. It does not compel disclosure of data to governments.
The provision that belongs here is GDPR Article 48, and it runs in the opposite direction7:
Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.
A third country's order to transfer or disclose personal data is recognisable and enforceable only where an international agreement, such as a mutual legal assistance treaty, is in force. This is not a rule that makes companies comply with foreign orders. It is a rule that stops those orders passing straight through.
Line them up and the structure is plain. US law says disclose regardless of location. EU law says a foreign order is unenforceable without a treaty. Those two collide head-on, and a US provider holding data inside the EU lives in that collision.
Japan: there is an answer on the record
So where does Japan sit? On this, the government has stated a position.
In June 2019 a written question was submitted to the House of Representatives on the US CLOUD Act and obligations under Japan's personal data protection act8. The question ran: the act exempts third-party provision where it is "based on laws and regulations"; is that limited to Japanese law? If it is, a Japanese company receiving a CLOUD Act demand breaches Japanese law by complying and breaches US law by refusing.
The cabinet's written answer, dated 25 June, says:
The "laws and regulations" referred to here are limited to the laws and regulations of our country.
It goes on to decline comment on foreign law, and states that operators are expected to "respond appropriately based on the act, according to the individual case". To the third question, which asked for remedial measures for the bind, the answer was that the government would "respond appropriately according to the individual circumstances".
The reading is not difficult. A foreign government's order is not an exemption under Japan's personal data protection act. The bind is unresolved, and the judgement is left with the company. The provision cited then, Article 23(1)(i), corresponds to Article 27(1)(i) after the subsequent amendment.
Which also means "Japanese law will protect us" deserves care as a phrase. Japanese law applies, certainly. But that means you must also comply with Japanese law, not that you are shielded when a foreign order arrives. Less protection than absence of an exit, in practice. What does differ, and differ materially, is how much a company can explain about a domestic process operating under judicial warrant versus a regime whose procedural provisions cannot be located at all.
Does holding your own keys solve it?
Back to encryption. If the provider holds the keys, it can produce plaintext. So hold the keys yourself. The instinct is right, and products exist.
AWS KMS External Key Store (XKS) keeps encryption keys outside AWS. From the AWS documentation9:
AWS KMS never interacts directly with your external key manager, and cannot create, view, manage, or delete your keys.
AWS KMS cannot decrypt any ciphertext encrypted by a KMS key in an external key store without access to your external keys via your external key store proxy.
AWS cannot touch the key material, and cannot decrypt without going through the external key manager. Permanently revoke access to the external key and remaining ciphertext is, in the documentation's words, effectively crypto-shredded. Data is double-encrypted, so neither AWS's key material nor your external key opens it alone.
For data at rest, then, you can construct a state where the provider genuinely cannot produce plaintext. That is a direct answer to everything above.
AWS attaches a strong caveat of its own:
The greater risk to availability and latency will, for most customers, exceed the perceived security benefits of external key stores.
A vendor writing that about its own feature is unusual, and I take it seriously. The responsibility boundary moves too: availability, durability and performance of the keys become yours. XKS is also not offered in the China (Beijing and Ningxia) regions.
And encryption at rest does nothing for inference
Here is the thing I most wanted to write down.
Encryption at rest does not protect LLM inference.
The reason is simple. A prompt has to be in plaintext to be processed. However carefully you hold your keys, the moment you send an inference request that text becomes plaintext in the memory of the serving system. Mechanisms that protect stored data do not reach there.
So the region question has to be split in two. For storage, holding your own keys creates a state where the provider cannot produce plaintext. For processing, where it happens is the jurisdiction question, directly. As covered in the earlier piece, most frontier models are not offered In-Region in Tokyo, and Google writes plainly that endpoints do not guarantee data residency or in-region ML processing.
The real stake is the technology sitting in research institutes
Everything above assumed corporate data. What actually worries me is elsewhere: the unpublished knowledge held in Japan's universities and research institutes.
Japan has a startling amount of quietly world-leading research. Materials, metrology, precision machining, biology. Corporate labs are the same. And most of the value is not in the published paper but in the part that never gets published. The conditions that failed. The knack that lifted yield. The adjustment made for one machine's quirks. What cannot be reproduced from the literature is exactly where the advantage lives.
In December 2025, Japan's Cabinet Office issued procedures for securing research security, aimed at preventing the outflow of critical technology while allowing international collaboration with like-minded partners on equal terms10. Institutions and researchers applying to designated R&D programmes are asked to work through a research security checklist.
This is where AI intersects. Generative AI is one of the highest-leverage tools a researcher can pick up: literature sweeps, experimental design, code, polishing an English manuscript. There is no reason not to use it, and I would use it too.
The question is what leaves in the process. Paste unpublished experimental conditions into a prompt and they go to the serving system. In Japan this is not only an information security matter. Article 25(1) of the Foreign Exchange and Foreign Trade Act requires a licence for transactions whose purpose is to provide controlled technology in a foreign country, and the same applies to providing it to a non-resident. Depending on the nature of the research data, sending it to an AI service can raise that question.
Answering this with "so researchers should not use AI" is the worst available option. Blocking use only lowers Japan's research output. Who benefits from a world where researchers everywhere use a tool and Japanese researchers alone may not?
What is needed is not prohibition but a place where it can be used safely. Processing that completes domestically, a regime you can name and explain, and the current models available on top of that. With those three, researchers get back to their actual work. They are not available together today, which is why the field keeps being forced to choose between using AI and protecting what it holds.
Where we stand
Now let me be direct about our position.
We are a Japanese company serving Japanese customers, and we take the view that an option to keep processing inside Japan needs to exist. No pretence of neutrality. But the grounds are the texts and public documents quoted above, not sentiment.
We do not claim Japan is a safe haven. As the Diet answer shows, Japanese companies remain caught in the middle and the government has not fixed that. Japan has investigators too, and they obtain data under warrants. "It cannot be seen in Japan" would be a lie.
The differences that do exist come down to three things.
First, whether the procedure can be verified. The list of absent provisions the Commission compiled for China's three statutes works as an assessment axis for any country: limits and procedures, purpose limitation, independent approval, restrictions on handling acquired information, transparency. Run your current platform through those five. The boxes you cannot fill are the risks you cannot explain.
Second, whether you sit on the protected side or the collected side. FISA Section 702 targeted "non-US persons reasonably believed to be outside the United States". Japanese users are inside that definition. The brakes the US system applies for its own citizens do not apply the same way to them. This is not an accusation against the United States; every country builds its rules around its own nationals first. Which is exactly why what can be kept under your own country's rules probably should be.
Third, whether there is anyone domestic to talk to. When a foreign authority serves an order on a provider, the Japanese customer is not even a party. In practice there is no way to learn it happened and no way to contest it. Keep processing at home and at least you know who to ask.
And then the trap in all of this, once more: encryption at rest does nothing for inference. Hold your own keys and stored data is protected. Inference cannot run without plaintext. So the only question left standing is where the processing happens.
What is happening right now is that the options for answering that last question are shrinking. Frontier models are largely not offered In-Region in Tokyo. Open-weight models have no in-region option at all on some platforms. Region pinning has acquired a price. The more you need domestic processing, the older the model or the higher the bill you are pushed toward.
We do not think that resolves itself if left alone. Domestic GPUs, and a real choice of models to run on them. If there is work for a Japanese company to do here, I think that is it.
Protecting and using are not opposites. Keeping the technology that sits in research institutes safe, while putting the researchers who hold it in the best position to benefit from AI. The people placed to aim at that are the ones operating here.
Start with your own current state. Run your platform through the five items above, and separate storage from processing. We work on enterprise AI architecture through ZEROCK, so if you want to talk through a specific setup, get in touch. Regional availability by provider is in Can you actually run an LLM inside Japan.
Footnotes
-
18 U.S. Code § 2713 — Required preservation and disclosure of communications and records. Added 23 March 2018 by Public Law 115–141 (the CLOUD Act). Text from Cornell Law School's Legal Information Institute. https://www.law.cornell.edu/uscode/text/18/2713 ↩
-
Congressional Research Service, Legal Sidebar "The Impact of FISA Section 702's Repeal", 22 June 2026 (LSB11444). Source for Section 702 authorising programmatic targeting of non-US persons abroad, not requiring individual court orders per target and acquisition, the automatic repeal of FISA Title VII (sections 702–705) on 12 June 2026 under Public Law 119–87, and the transition procedures under which existing orders continue to their expiry. https://www.congress.gov/crs-product/LSB11444 / PDF https://www.congress.gov/crs_external_products/LSB/PDF/LSB11444/LSB11444.1.pdf . On Section 702's structure see also CRS R48592. https://www.congress.gov/crs-product/R48592 ↩ ↩2
-
Personal Information Protection Commission of Japan, "Foreign regimes (People's Republic of China)", updated 3 February 2025. The descriptions of the Cybersecurity Law, Data Security Law and National Intelligence Law, the list of provisions found to be absent, and the quoted conclusion are from this report. English renderings here are the author's translation of the Japanese original. https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_china/ / PDF https://www.ppc.go.jp/files/pdf/china_report.pdf ↩
-
National Intelligence Law of the People's Republic of China, Article 7. Adopted 27 June 2017 by the Standing Committee of the 12th National People's Congress, in force 28 June 2017, amended 2018. Text from the National People's Congress website. http://www.npc.gov.cn/npc/c2/c30834/201905/t20190521_281475.html ↩
-
Personal Information Protection Commission of Japan, "Foreign regimes (United States of America)", updated 25 January 2022. The report states that the survey was limited to statutes identified as representative by contractors, is not exhaustive, reflects information as of October 2021, and that confirming foreign regimes is the operator's own responsibility. https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/ / PDF https://www.ppc.go.jp/files/pdf/USA_report.pdf ↩
-
Court of Justice of the European Union, judgment of 16 July 2020 in Case C-311/18 (Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, "Schrems II"). Statement of the European Data Protection Board https://www.edpb.europa.eu/news/news/2020/statement-court-justice-european-union-judgment-case-c-31118-data-protection_en / Case documents https://curia.europa.eu/juris/liste.jsf?num=C-311%2F18 ↩
-
Regulation (EU) 2016/679 (GDPR), Article 48 — Transfers or disclosures not authorised by Union law. https://gdpr-info.eu/art-48-gdpr/ ↩
-
House of Representatives of Japan, 198th Diet session, Written Question No. 227, "Written question on the US CLOUD Act and responses under the Act on the Protection of Personal Information" (submitted 13 June 2019 by Kōichi Matsudaira) https://www.shugiin.go.jp/internet/itdb_shitsumon.nsf/html/shitsumon/a198227.htm / Written Answer No. 227 (received 25 June 2019, Prime Minister Shinzō Abe) https://www.shugiin.go.jp/internet/itdb_shitsumon.nsf/html/shitsumon/b198227.htm . Translations are the author's. Article 23(1)(i) as cited in the question corresponds to Article 27(1)(i) following the 2020 amendment. ↩
-
Amazon Web Services, "External key stores", AWS Key Management Service Developer Guide. Source of the quoted statements on AWS KMS being unable to create, view, manage or delete external keys, being unable to decrypt without access to them, the availability and latency caveat, and non-availability in the China regions. https://docs.aws.amazon.com/kms/latest/developerguide/keystore-external.html ↩
-
Cabinet Office of Japan, "Procedures for efforts to ensure research security" (December 2025, Expert Panel on Ensuring Research Security and Research Integrity). Aimed at preventing outflow of critical technology while advancing international joint research with like-minded countries on equal terms; institutions and researchers applying to designated R&D programmes are asked to confirm their position using a research security checklist. https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf / Cabinet Office research integrity portal https://www8.cao.go.jp/cstp/kokusaiteki/integrity.html ↩






