I dont get the proposition, they want to build DCs in partnering countries to run GPT on? Who is this useful for, except for OpenAI to get lower latency connections to their customers?
How can one audit that the bytes going from a DC in country A to a DC in the US is not the user queries but some telemetry data for example? Presumably you don't get to look at the unencrypted packets
The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) explicitly gives US authorities the power to compel US-based companies to provide data stored on servers, regardless of where those servers are physically located. This effectively undermines any meaningful data sovereignty claims.
Consider the actual arrangement being proposed:
- OpenAI (US company) maintains control of the infrastructure
- OpenAI controls the models and their development
- OpenAI maintains the security protocols and access rights
- The data merely sits physically within national borders
This isn't sovereignty - it's a limited hosting arrangement that remains fully under US legal jurisdiction. US intelligence agencies can still access this data through legal mechanisms that bypass the host country's laws entirely.