For (European) businesses, it's not the issue of safety, but the issue of compliance. If I (EU citizen) have personal data with EU company that stores said data on US-controlled servers, they are potentially viable for breach of data-protection laws. Since these laws are EU laws, it wouldn't be a problem if EU governments would read this data, since that's governed by the same set of laws.
It doesn't matter if clients are naive or not, it matters if they have a checkbook.
Well that's how it would seem, in the wake of the Snowden revelations.