A US court order means your deleted ChatGPT chats are kept
What if every chat your team ever "deleted" in ChatGPT was being stored in a U.S. evidence locker? This isn't a hypothetical. It's the new reality for a 800 million users.¹
Here's why: The New York Times is suing OpenAI for massive copyright infringement. Their lawyers argued that user chats are a key source of evidence, potentially showing the AI regenerating their work verbatim.
A federal judge agreed.
The court then ordered OpenAI to preserve everything. This order is not narrow; it impacts services from the free ChatGPT app to most API usage.²
This isn't just a distant legal battle. It's a live demonstration of what happens when your provider's business model collides with US law.
And in that collision, your provider lost control of the delete button.
For European leaders, this confirms a critical vulnerability. It proves that data stored with a U.S. provider, even on EU servers, remains subject to US jurisdiction. This is a direct conflict with the principles of GDPR and the spirit of the EU AI Act.
This situation forces a strategic choice, based on your data's risk profile. You have three clear paths.
Path 1: The Sovereign Stack (Self-Hosted) This is the maximum-control option, reserved for your most sensitive and critical data. You host powerful open-weight models on your own infrastructure.
The trade-off is higher operational complexity and cost, but in return, you get guaranteed, absolute data sovereignty.
Path 2: The Close-By Stack (EU-Hosted) This is the strategic middle ground for sensitive corporate data. You partner with a European provider like Mistral, Germany's T-Systems and IONOS, or France's Scaleway and OVHcloud.
They offer managed services for leading (opensource) AI models under the EU legal framework, resolving the core jurisdictional conflict.
Path 3: The Contractual Shield (US Provider) This path requires a granular risk assessment.
-Low-Sensitivity Data: For tasks involving public information or non-critical drafts, using a US provider can be an acceptable business risk.
-Medium-High Sensitivity Data: For internal corporate data, client data, PII, or trade secrets, this is a high-stakes gamble. If you need a unique capability and for some reason cannot wait for European solutions, a ZDR agreement is not a feature—it is a critical, board-level risk mitigation.
So this is the moment to ask the hard questions in the boardroom:
Is our AI strategy dependent on the outcome of a foreign lawsuit? Is our most sensitive data governed by another country's laws? Do we truly control our most critical digital assets?
This forces the conversation to evolve. We must look past the initial promise of 'artificial intelligence' and begin asking harder questions about the fundamental resilience of our entire operation.
Sources:¹ PYMNTS. (2025, April 13). Sam Altman: OpenAI Has Reached Roughly 800 Million Users.² U.S. Magistrate Judge Ona Wang, Southern District of New York. (2025, May 13). Order Granting Motion for Preservation.
Sources
- 1: PYMNTS. (2025, April 13). Sam Altman: OpenAI Has Reached Roughly 800 Million Users.
- 2: U.S. Magistrate Judge Ona Wang, Southern District of New York. (2025, May 13). Order Granting Motion for Preservation.