Your AI has already gone global. Your governance probably hasn’t.
Research from Harbr Data finds that most large UK organisations can’t fully explain how their sensitive data is used once AI processes it overseas, while their boards remain on the hook for the outcome.
The AI tidal wave has well and truly washed over UK enterprises in the last couple of years. Adoption is widespread, the volume of data now flowing through AI systems is vast, and for a third of large organisations, that data is leaving the country as often as daily.
What hasn’t spread as quickly is the ability to explain exactly where the data’s going, or how it’s being used when it gets there. New research from Harbr, surveying 250 senior IT and data leaders at large UK enterprises, finds that 61% cannot fully account for how their sensitive data is used once it’s processed by AI overseas — despite nearly three-quarters sending data overseas at least weekly. The problem underneath is structural: AI systems are global by design, but accountability stays national. A model can reach for data across borders, while the regulators, legal obligations and boards that answer for it can’t.
The TL;DR: what the research shows
- 61% can’t fully explain how their sensitive data is used once it’s processed by AI overseas.
- Nearly 75% see data processed by AI outside the UK at least weekly; 33% say daily.
- Confidence drops with distance: 70% feel confident managing AI-driven data in the UK, 62% in the EU/EEA, 31% in North America, and just 12% in Asia-Pacific.
- 47% don’t have enough qualified people to manage cross-border AI; 40%+ are unsure whether their systems fully comply with international regulations.
- 50% say limited visibility could lead to compliance breaches; 36% fear fines or investigations.
- Only 20% say the board is ultimately accountable, while 58% point to the CIO or CTO.
- 91% say data localisation laws have already shaped their AI architecture.
Adoption has quickly become routine, but visibility is thin, and the people carrying the legal risk aren’t the ones holding the controls.
You can’t govern what you can’t see
When 61% of organisations can’t explain how their data is used once AI processes it overseas, the consequences aren’t just organisational, they’re personal. Data leaders can no longer reliably answer basic questions about their own data — which systems accessed it, in which jurisdiction, for what purpose, and whether a copy now sits somewhere they’ll never see.
And the blind spot only widens the further data travels. Leaders feel confident close to home, (seven in ten say so within the UK) but that confidence falls away with distance: 62% in the EU/EEA, 31% in North America, and just 12% in Asia-Pacific. You can govern data you can see and whose rules you understand, but push it beyond that and both go with it. The problem isn’t the AI, it’s that the data underneath it has become much harder to follow.
Where to start: Start by mapping where sensitive data goes. That means understanding not just which vendors process data overseas, but which AI systems those vendors use, where those systems run, and what rights your agreements actually grant. The audit effort is real, but it’s the only way to identify where visibility has broken down and where it needs to be rebuilt.
The gap is operational
This problem lives in the day-to-day plumbing. Nearly half of organisations (47%) don’t have enough qualified people to manage cross-border AI. More than 40% aren’t sure whether their systems fully comply with international regulations; not that they know they don’t, but that they can’t confirm they do. And 38% say they struggle to audit AI-driven decisions that draw on data from multiple regions. If you can’t audit a decision, you can’t defend it later.
The instinct is to hire your way out, but specialists who understand the data and the regulation are in high demand, and cross-border AI is expanding faster than any hiring strategy (or budget). A governance model that depends on a few experts holding it in their heads doesn’t scale either, it just concentrates the risk. The key is shifting the burden from people to systems: compliance you can prove rather than assume, and an audit trail built in by default rather than reconstructed under pressure.
Where to start: Assign explicit ownership for cross-border AI governance, rather than leaving it spread across teams. That doesn’t mean creating a new function, but instead deciding who’s accountable, what they’re accountable for, and how they’ll track it. Alongside that, organisations need a way to manage external data access that’s requested, approved, enforced, and audited through a consistent process rather than handled case by case across disconnected systems. Without consistency, every new AI use case creates new uncontrolled exposure.
What’s at stake
Ask these leaders what limited visibility could cost them, and the answers come quickly. Half say it could lead to breaches of international compliance rules. A third (36%) point to potential fines or investigations, 35% flag strategic or geopolitical exposure, and 31% cite commercial or contractual disputes — the kind that crop up when a partner asks how their data was handled and can’t get a clear answer answer.
None of this needs a dramatic breach to bite. A regulator’s enquiry, a contractual clause about where data may be processed, or a routine customer audit can be enough on their own. The challenge isn’t necessarily that something actually went wrong; it’s the struggle to demonstrate that it didn’t.
Where to start: Treat cross-border AI data governance as a risk management issue, not a compliance checkbox. That means mapping the specific risks to your organisation: which jurisdictions carry the most exposure, which AI systems hold the most sensitive data, and which relationships have the least contractual protection. Scenario planning for regulatory enforcement actions and commercial disputes should be on the table for any team processing sensitive data through overseas AI systems at scale.
The people on the hook aren’t the ones holding the controls
Only 20% of respondents say the board is ultimately accountable for cross-border AI governance; 58% say it sits with the CIO or CTO. That looks sensible, seeing as it’s technical territory, but it isn’t how accountability works. Boards retain legal and fiduciary responsibility for the outcomes of AI-driven decisions, whether or not they’ve delegated the day-to-day. “The CTO owned that” won’t protect a board when a regulator comes knocking. What’s been delegated is the work, not the liability.
So a misalignment runs through a lot of large organisations: those carrying the ultimate risk are furthest from the controls, and those closest to the controls don’t carry the risk. Add the 28% reporting ownership spread across multiple teams, and accountability ends up technically everywhere — and practically nowhere.
Where to start: Cross-border AI governance needs to be visible at board level, not just managed at CIO level. That means translating technical exposure into language boards can act on: which regulations apply, what the consequences of non-compliance look like, where the gaps currently are, and what’s being done to close them. It also requires organisations to define who owns what (not just in the org chart, but in practice) so accountability doesn’t crack under pressure.
This isn’t a future problem
Data localisation laws have already influenced AI architecture for 91% of organisations, and geopolitical factors are already affecting cross-border data operations for 87%. These aren’t future risks to plan for; they’re currently shaping where systems are built, where data can travel, and which vendors make the shortlist.
As frameworks like the EU AI Act mature, international operators face closer scrutiny over governance and the movement of sensitive data between jurisdictions — part of why analysts expect more organisations to adopt region-specific AI platforms by 2027. Those treating localisation and geopolitics as design constraints now, rather than headaches to retrofit later, will be the ones that can move quickly when the rules tighten again.
Where to start: Factor data governance requirements into AI architecture decisions from the start, rather than retrofitting controls later. That means asking, before deploying any AI system that handles sensitive data, where the data will be processed, what governance mechanisms the vendor provides, whether those mechanisms meet your obligations, and how access will be tracked and audited on an ongoing basis. The organisations that have built these questions into procurement and architecture reviews early are better positioned than those trying to manage retrospectively.
Where this leaves us
For the varying pressures the research surfaces — thin visibility, stretched governance, misaligned accountability — one issue connects them. AI systems are global by design; accountability remains national, and that gap isn’t closing on its own.
Cross-border AI processing is fundamentally a question of how to govern data sharing. Organisations need a robust operating model for how sensitive data is accessed and used across systems, legal entities and borders. Without one, boards risk being caught off guard by compliance breaches, fines, or international disputes.
The organisations that manage this well won’t be those with the most sophisticated AI infrastructure, but those with a consistent, auditable approach to external data access — one that makes every request, approval and use visible and trackable, wherever it happens. Not centralising data, but centralising control.
Harbr works with organisations managing cross-border data ecosystems to build exactly that: a governed, repeatable approach to external data sharing that reduces the cost and risk of regulatory data access, and lets boards and data leaders be as confident about their data overseas as they are at home.
About the research
Harbr commissioned this research to understand how large UK organisations govern sensitive data as AI accelerates cross-border data flows. The survey covered 250 senior IT and data leaders (CIOs, CTOs, Heads of Data, Chief Data Officers and IT Directors) at UK organisations with 500+ employees and approximately £100m+ in annual revenue.