Six years ago, on 16 July 2020, the Court of Justice of the European Union handed down the ruling everyone calls Schrems II. It struck down the Privacy Shield, the arrangement that had let companies move personal data from the EU to the United States, and it did so because US surveillance law gave European citizens no real way to object. That decision still shapes every transatlantic data flow, including the ones hiding inside your AI tools.

A quick recap for people who tuned out

The court's problem was never really with any single company. It was with the mismatch between EU data protection law and US national security law. Programmes operating under authorities like FISA Section 702 let US agencies reach data held by US providers, and a European whose data got swept up had no equivalent of a court to complain to. That gap is why Privacy Shield fell, and why its predecessor Safe Harbor fell before it.

After Schrems II, companies leaned on Standard Contractual Clauses plus so-called supplementary measures, and everyone had to run a transfer impact assessment to check whether the destination country actually offered adequate protection. It was a lot of paperwork for something that, deep down, the paperwork could not fully fix.

The Data Privacy Framework, and why people are nervous

In July 2023 the Commission adopted a new adequacy decision, the EU to US Data Privacy Framework, which restored a legal basis for transfers to certified US companies. Useful, and a relief for a lot of businesses. But it sits on the same fault line as the two arrangements that came before it, and the same activist who brought down the first two has said he expects this one to end up back in Luxembourg.

Through 2025 and into 2026 the framework has been under real pressure, including questions about the independence of the US oversight body it relies on. Nobody sensible is treating it as settled. If your compliance plan assumes the Data Privacy Framework will still be standing in three years, you are making a bet, not a plan.

Here is the thing about transfer risk. Every mechanism in this area, Privacy Shield, SCCs, the Data Privacy Framework, is a way of managing the consequences of your data leaving the EU. None of them changes the underlying fact that it left. The only move that removes the risk rather than managing it is not transferring the data at all.

Where AI quietly reintroduces the problem

Most companies spent years getting their transfer house in order, and then rolled out AI tools that undo a lot of it in a single procurement. A cloud assistant sends prompts, documents and context to a provider that is very often US-controlled, which pulls you straight back into the Schrems II world of adequacy decisions and transfer assessments. The AI did not create a new legal category. It just poured new data into the old one.

This is the least glamorous argument for running models locally, and maybe the strongest. When the inference happens on a server in your building, there is no transfer to assess, no adequacy decision to depend on, and no activist lawsuit that can change your legal exposure overnight. The data that would have crossed the Atlantic never leaves the room. The European Data Protection Board keeps publishing guidance on transfers, and it is worth reading, but the shortest compliant path is the one where the guidance does not apply to your workload because nothing crossed a border.

None of this is legal advice. International transfer rules are intricate and moving, and your DPO and counsel should map your specific flows. The general point stands on its own though. Data that stays home is data you never have to defend at the border.