Skip to content
Business•October 7, 2026•5 min read

Location is not accountability

A cloud region says where capacity sits, and a transaction log says what happened. Neither names the legal entity that answers for it. On both questions, the people writing the rules are now looking past location to the legal person behind the machine.

Location is not accountability

Two questions now sit under every serious plan to put automated systems into regulated work. Which law can reach the system? And which legal entity answers for what the system does?

The market keeps answering both with a location. For compute, the answer is a cloud region. For transactions, it is an account, a wallet or a complete log. Each describes where something happened. Neither says who is answerable for it. In 2026, the people writing the rules on both questions are looking past location to the legal person behind the machine.

A region says where capacity sits

Europe's own sovereignty tests treat location as the floor. In the European Commission's Cloud Sovereignty Framework, where data is stored and processed is one factor inside an objective that carries 10% of the score. Supply chain alone carries 20%. When the Commission used the framework for its €180m sovereign-cloud tender in April 2026, the grades turned on control: three consortia reached the second-highest assurance level, and an EU-operated consortium built on US cloud technology won a contract one level below.

The proposed Cloud and AI Development Act, published on 3 June 2026, draws the same line in draft law. Its lowest assurance level asks for EU establishment and EU data location. Its higher levels ask whether the provider is "subject to the control of a third country or a legal entity established in a third-country". The act is still a proposal, but its direction is plain: location buys entry, and control earns the grade.

Germany's federal cyber-security agency was more direct. In its cloud autonomy catalogue of April 2026, data residency is a "service option" the customer selects, while effective control of the provider by EU companies is a requirement.

Foreign law reaches the operator, not the rack

The reason is legal. The US CLOUD Act requires a provider to disclose data within its "possession, custody, or control", whether that data is stored inside or outside the United States. The test follows the operator, not the building. A data centre can sit in Frankfurt and still answer to a court elsewhere if the company that controls it does.

The clearest statement came from a provider. Asked under oath at a French Senate inquiry in June 2025 whether French citizens' data held through public procurement could ever be passed to US authorities without the explicit consent of the French authorities, Microsoft France answered: "No, I cannot guarantee it." It added that no such request had occurred. That is the point. Nothing had gone wrong, and the region still could not rule it out.

No structure removes every exposure, and the rule cuts both ways. In 2024 an Ontario court ordered a French cloud provider to disclose subscriber data held in France. Sovereignty in the serious sense is a structure in which ownership, the operator's seat, its staff, the applicable law and the route to recourse all point at the same legal order. The honest claim for that structure is that fewer jurisdictions can reach the operator. It is never that the operator is immune.

The same gap, one layer up

Automation moves the question from the system to the act. A perfect record of a transaction can still leave its answerable party unnamed.

The law agrees that machine-made acts count. It is less settled on whose acts they are. UNCITRAL's Model Law on Automated Contracting attributes an automated system's action to "the person who uses the system for that purpose", unless the parties agreed otherwise, and leaves the legal consequences to other law. The EU withdrew its AI Liability Directive in 2025, so national contract and tort law still decides. Software has no legal personality, so liability has to land on a person. The law does not yet say which person in the chain.

Central banks now say so on the record. The Governor of the Bank of England wrote in July 2026 that the harder question "is working out where: one entity may have developed the model, another may have trained it, another may have integrated it into a particular system, and a regulated firm may then have deployed it in a client-facing context." In September, Federal Reserve Governor Christopher Waller put the payments version in one line: "Who is on the hook if an agent makes the wrong purchase?"

One supervisor has now given a firm answer, and it is about who, not where. On 7 October 2026 the Monetary Authority of Singapore finalised its AI risk guidelines: financial institutions "remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties". MAS expects firms to revisit their controls as more autonomous systems come into use. Accountability stays with a regulated legal entity. It does not move to the provider, and it does not move to the software.

A record is not an answer

This is why account-level evidence is too thin. An account can be delegated or automated. A wallet can sign. A server can send. Each signal is valid inside its own system, and each describes an instrument rather than a responsible party. A log can show that something happened and which key acted. It cannot show that a legal entity with authority to act allowed it, within limits a counterparty can check.

The identifier half of the answer already exists at scale. More than 3.1 million Legal Entity Identifiers were active at the end of June 2026, and US financial regulators adopted the LEI as their joint legal-entity identifier from 1 October 2026. Its verifiable form, the vLEI, is standardised as ISO 17442-3.

Carrying an entity's mandate with each automated act is the part that is not finished. GLEIF's September 2026 working paper on AI agents in payments proposes a mandate credential that states what an agent may do, its limits and its permitted counterparties, "creating an unbroken chain of accountability back to a verified individual within a verified organization". GLEIF presents it as a working paper, not an official position, and names a standard way for payment providers to verify that chain as "the critical adoption dependency". That is the right level of candour for the whole field. The standards case is strong. The deployment is still ahead.

Where the two questions meet

Jurisdiction and accountability fail independently, which is why they belong in one argument.

An organisation whose identity is perfectly known can still lose a service if the operator's home state orders it. A sovereign operator running automated processes with no entity-level mandate still leaves the loss with whoever signed the terms of service. Jurisdiction decides which state can compel the system. Legal identity decides which party answers for what the system did. Neither replaces the other.

They also share one dependency. Europe's sovereignty tests are tests of facts about legal entities: who owns the provider, who controls it, where its seat is. Attributing an automated act needs facts about legal entities too: who authorised it, in what role, within what mandate. Both need verifiable, current information about organisations. Both fail when that information sits in a back-office file instead of in the evidence a counterparty sees before value moves.

The fair objections

Sovereign infrastructure costs more, and some critics call the whole agenda protectionism. The cost is real. The protectionism reading fits the evidence less well. In its own tender, the Commission awarded a contract to a consortium running on Google Cloud technology, operated exclusively by EU companies. What is being graded is who operates a service and which law binds it, not the nationality of the code.

Customer-held encryption keys answer part of the problem. European data protection authorities accept encryption as a safeguard for transfers where the keys are kept beyond the reach of the relevant public authorities. Even then, keys protect data at rest. They do not stop an operator from suspending the service.

Existing agency law already binds principals to their agents' acts. That is true, and it supports the argument. Every one of those rules works only when the act can be traced to an identifiable principal. The question is whether that trace is available when the transaction happens, or only after a dispute.

Where LTIN stands

LTIN's sovereignty case rests on its ownership and its legal home, facts that were not chosen by a marketing decision and cannot be copied by one. LTIN is majority-owned by Telecom Liechtenstein. Liechtenstein is a member of the European Economic Area, shares a customs union with Switzerland, and has regulated token-based services under its Blockchain Act (TVTG) since 2020. DORA, the EU's digital operational resilience regulation, has applied in Liechtenstein since 1 February 2025.

LTIN has also announced that it is developing an organisational identity layer on Solana, using the Solana Attestation Service, designed to let applications confirm which named organisation stands behind a wallet. The service is in development, with testnet to follow.

Before value moves or a system acts, a counterparty should be able to answer two questions without opening a dispute: which legal order can reach the system, and which legal entity answers for the act. A region and a log are useful evidence for both. Neither is the answer.

What we do not claim

We do not claim that any operator, LTIN included, is beyond the reach of every foreign court. A sovereign structure reduces the number of jurisdictions that can reach an operator. It does not reduce that number to zero.

We do not claim that the organisational identity layer on Solana is in production. It is in development, with testnet to follow.

We do not claim that any regulator or standards body has endorsed LTIN's approach. The GLEIF mandate credential cited above is a proposal in a working paper, and the rules that would settle liability for automated transactions are still being written.

#SovereignCompute

Tags

SovereignCompute

Share this article