← Back to Blog

The data residency fine print nobody's reading.

Part 1 of a series on data residency, by Kisa Brostrom, CTO at BoodleBox

Every RFP asks it: “Is my data stored in the United States?”

Every vendor answers yes.

Almost nobody asks the follow-up question that actually matters.

Because there are two very different promises hiding behind that one yes.

There’s a huge difference between saying our infrastructure is based in the United States and saying we can guarantee that your data will never be stored, processed, or touched outside the United States.

US-based means a provider’s infrastructure normally runs domestically.

US-bound is a contractual commitment that a specific workload cannot leave a defined geography, full stop.

Most vendors are selling you the first one. Most institutions think they bought the second.

And even that distinction is more complicated than it sounds, because “your data” is a lot bigger than the database you asked about.

It can touch the application layer, storage, logging, document processors, embeddings, model providers, moderation services, and every subprocessor underneath them. So when a vendor says your data is “in the US,” the next question should be: which parts of the system does that promise actually cover?

This used to be a relatively easy promise to make

For a long time, data residency requirements didn’t feel particularly consequential from an infrastructure perspective.

If an institution required US data residency, keeping its workloads on US infrastructure was generally a manageable constraint. There was enough domestic capacity that limiting a workload to US servers didn’t fundamentally change the economics of delivering the service.

AI is changing that.

We are entering an era where compute capacity itself is constrained. AI workloads are creating unprecedented demand for infrastructure around the world, while providers compete for access to the GPUs, data centers, power, and capacity required to serve them.

Suddenly, geography matters in a way it didn’t before.

A provider with access to global infrastructure has a much larger pool of compute to draw from. If capacity is constrained in one region, workloads can potentially be routed somewhere else with room to spare.

But the moment you contractually require a workload to remain in the United States, that flexibility disappears.

You haven’t just added a compliance requirement.

You’ve constrained the available supply.

"You can’t ask for maximum reliability and a hard geography lock in the same sentence."

Or, more precisely, you can — but there’s a tradeoff hiding inside that request. The tighter you constrain where a workload can run, the fewer resources a provider has available to serve it. And when the thing you’re constraining is already scarce, that constraint starts to have a real cost.

Geography now has a price

We’re already beginning to see that reflected in AI infrastructure pricing.

Anthropic prices US-only inference at 1.1x the cost of global inference. OpenAI applies a 10% uplift to regional processing.

And another inference provider we work with charges 50% more for US-only infrastructure.

That range matters.

The point isn’t that US data residency suddenly costs 10%, or 50%, or any other predictable number.

The point is that something procurement teams have historically treated as a relatively inexpensive compliance requirement is becoming a capacity constraint with a market price attached to it.

That changes the conversation.

As AI demand continues to put pressure on available compute, providers guaranteeing that workloads stay within a particular geography have a smaller pool of infrastructure available to them. They may need to reserve capacity, procure more expensive capacity, or give up the ability to route workloads wherever resources are available.

That can affect cost.

It can affect capacity.

And, depending on how the infrastructure is designed, it can affect reliability.

In the age of AI, geography is becoming a compute constraint

That doesn’t mean institutions should stop requiring US data residency. There are very real regulatory, contractual, security, and institutional reasons to require it.

But we should stop treating it like a free checkbox.

When an institution writes “US-only” into an RFP, it may not simply be making a compliance decision anymore. It may also be making an infrastructure decision — one with implications that procurement teams need to understand.

So the question to ask your vendor isn’t simply:

“Is my data in the US?”

It’s:

“Is this workload contractually bound to the US, what parts of the system does that guarantee cover, and what does that guarantee cost?”

Because in the age of AI, where your data has to stay increasingly determines where your compute can come from.

And compute is no longer something we can assume is unlimited.

About the author

Kisa Brostrom | Chief Technology Officer, BoodleBox

Kisa Brostrom leads AI systems architecture, data strategy, and platform governance at BoodleBox. With over a decade of experience in data engineering, applied machine learning, and distributed systems design, she has spent her career building scalable, privacy-aligned AI infrastructure in startup and growth-stage environments — the kind of environments where the gap between what technology can do and what people actually use it for is most visible.

At BoodleBox, Kisa has led the development of a privacy-first AI platform serving 100,000+ learners across 1,300+ institutions, including a sustainability-focused token-reduction architecture that makes equitable access to AI practical at institutional scale. She works daily at the intersection of what AI can do and what it should do for the people trying to learn with it.

The perspective in this piece is drawn from her work on AI security, compliance, and data governance at BoodleBox.

Not sure what your institution actually needs?

Every organization's data residency requirements are different. See our full security posture, then let's talk through yours.

Visit the Trust Center →

Book a free consultation and demo →

More in this series:

Want to see Kisa walk through this exact distinction? It starts around 2:30 in the recording below.

Find out what's in it for you.

Learn more about the ins and outs of the BoodleBox workspace from our team of experts.

Schedule a meeting

Looking for more information?