Microsoft's logo on its office in Israel
– Getty Images

Microsoft has doubled down on its efforts to address growing data sovereignty demands, unveiling a slew of new cloud capabilities as it faces increased scrutiny from lawmakers.

Among the changes introduced, the hyperscaler revealed that data processed by its AI services will remain within the EU. All customer data, whether at rest or in transit, will be stored and processed exclusively in the EU, unless a customer requests otherwise.

Microsoft’s new data processing rules also apply to its Copilot chatbot service, which is now firmly embedded across a wave of enterprise PCs following the recent Windows 10 support switch-off as devices move to Windows 11.

The hyperscaler said that 365 Copilot interactions will be processed in-country. By the end of 2025, this will also apply to 365 Copilot users in certain non-EU countries, including India, Japan, and the U.K.

Data processed when using AI systems and services is typically stored in cloud platforms, but the traditional reliance on centralized cloud infrastructure for AI data processing is facing increasing regulatory scrutiny across the globe.

Legislative frameworks like the EU’s Data Act or India’s Digital Personal Data Protection Act (DPDP), see AI service providers like Microsoft under increased pressure to ensure that user-specific data processed by AI systems is stored and governed in the jurisdiction where the user is located.

Upon unveiling its latest sovereignty commitments, Microsoft touted its sizable investment in digital infrastructure as the reason behind its ability to offer in-country processing.

It’s earmarked $80 billion to build AI data centers in 2025 alone, with many of the countries slated to provide localized Copilot processing either existing Microsoft data center locations or scheduled to host new ones. Add to that the news this week that the hyperscaler was spending some $60 billion in GPU leasing deals in recent months, with Bloomberg suggesting Nscale alone contributes $23 billion.

“With in-country processing, Copilot interactions are processed, under normal operations, in data centers located within a nation’s borders, giving customers greater control over their data,” Paul Lorimer, Microsoft’s corporate VP for Office 365 enterprise and cloud engineering, wrote in a blog post. “In-country data processing can also improve performance by reducing latency, delivering an even more responsive Copilot experience.”

Sovereignty compliance templates & Azure Local updates

Beyond in-country data processing, Microsoft also introduced the Sovereign Landing Zone (SLZ) foundation – a pre-configured Azure environment for sovereignty-savvy cloud customers.

Reworked from its prior SLZ offering, Microsoft cloud customers can now employ a compliance-ready cloud environment where data stays within specific geographic boundaries alongside extra security and compliance controls.

The hyperscaler touts the platform as a way for organizations in regulated areas like government or the public sector to employ sovereign cloud environments, rather than having to architect everything from scratch.

“By adopting Sovereign Landing Zones, customers can gain a prescriptive architecture that accelerates compliance with regional sovereignty requirements while reducing complexity in policy management,” Douglas Phillips, president and CTO for Microsoft Specialized Clouds, wrote in a blog post. “This approach also helps organizations confidently scale workloads across Azure regions without compromising on regulatory alignment or operational consistency.”

Also receiving sovereignty updates was Azure Local, Microsoft’s service that lets cloud-connected infrastructure be deployed both at physical and virtual locations.

The service now scales up to hundreds of servers, beyond the initially offered 16.

Detailed in a company post, Phillips wrote that the increased scale “means customers can support bigger, more complex workloads, scale their infrastructure with ease, and respond to evolving business needs all while aligning with the security and sovereignty required by European and global regulations.”

Azure Local now also supports Storage Area Network (SAN), a dedicated network offering providing servers with access to consolidated data storage. This means Microsoft’s cloud customers can connect their existing on-premises storage solutions to Azure Local – a key part of the EU’s Data Act, with cloud service providers now forced to make it easier to transfer data to rival providers.

Phillips wrote that European customers can gain that flexibility “without compromising on performance or control.”

Those updates add to SDN capabilities introduced to Azure Local back in July. Additions to the hyperconverged platform allowed users to configure network security rules on-premises. There are also newly added ways for users to implement consistent device naming for compatible network adapters, allowing for more predictable network interface identification.

More sovereignty services on the way

Microsoft’s latest batch of sovereignty-focused services looks to take advantage of the growing demand from users.

Recent survey results from Mimecast suggest that 87% of organizations, and 93% of large enterprises, consider both geopolitical factors and data sovereignty when choosing security providers. For cloud provider considerations, Fortune Business Insights projects the global sovereign cloud market to soar from $154 billion in 2025 to $823 billion by 2032, with Europe dominating projected demand.

Already, the likes of Cisco, Amazon Web Services (AWS), and Oracle have all launched sovereignty-centric services to meet that increased demand.

Microsoft already launched a Euro Sovereign Public Cloud offering to appease continental lawmakers, while also striking a controversial pay-as-you-go deal with a European trade association for cloud providers.

The hyperscaler has more in the works, too, with Phillips’s blog post referencing a ‘Sovereign Cloud roadmap’ that’s set to provide additional capabilities. Among them is something called Data Guardian, which the firm said will “provide transparency into operational sovereignty controls in our European public cloud environments.”

Also in the works are configurable policies and approval workflows set to provide users with explicit oversight of any changes propagating from the cloud to the edge, as well as disaster recovery tools for Azure Local.

Microsoft’s attempts to double down on data sovereignty came after comments from its French legal director caused unease earlier this year. Anton Carniaux told French lawmakers under oath that the hyperscale couldn’t guarantee citizens' data held through public contracts would remain protected from U.S. authorities without local consent.