Data Protection & Digital Sovereignty  ·  14 August 2026

The Adequacy Trap

Digital Isle of Man's latest AI case study talks about governance while quietly skipping the one question that actually decides it: where does the data go, and who can reach it once it's there.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

On August 12th 2026, Digital Isle of Man published a case study titled “Keeping People at the Centre of AI,” profiling Red5 Systems (a trading brand of ITEX (Isle of Man) Limited) and its Managing Director Alyson Hamilton Lacey. It is a well-written piece. It says the right things. Governance before technology. Phased rollout. Human judgement retained. A “horses-for-courses” mix of Microsoft Copilot and internal assistants, built out from a Microsoft Modern Workplace foundation the business already knew and trusted.

None of that is wrong. Red5 has spent years building a genuine on-Island hosting story: dual Isle of Man data centres, ISO-accredited facilities, an Isle of Man GDPR-compliant environment for its own Cloud Desktop and archiving products, developed in consultation with the Island’s own Information Commissioner and Financial Services Authority. That is a real, defensible sovereignty posture, and it is one this publication has no quarrel with.

What the piece never does, in nearly 1,500 words about governance, is answer the question that actually determines whether “governance” means anything in an AI deployment: where does the data go once it leaves the tenant, and under what law can someone else reach it there.

That is not a pedantic add-on to the governance conversation. It is the whole of it. Everything else — the phased rollout, the smaller pilot group, the role of human judgement — is process. Process without a jurisdictional answer underneath it is theatre.


What the EU Data Boundary Actually Covers, and What It Doesn’t

Microsoft’s EU Data Boundary is a real, meaningfully engineered commitment, completed in February 2025 after a multi-year build. It keeps customer data and pseudonymised personal data for core Microsoft 365, Dynamics 365, Power Platform and most Azure services stored and processed within a defined geography. That geography is EU member states plus three EFTA states: Iceland, Liechtenstein and Norway. Microsoft’s own documentation is explicit about the scope; it is EU and EFTA, nothing wider.

The Isle of Man is neither. It is a Crown Dependency with its own adequacy finding from the European Commission, made under the pre-GDPR Data Protection Directive on 28 April 2004 (Commission Decision 2004/411/EC, published in the Official Journal, OJ L 151, 30.4.2004, p. 48) and confirmed as maintained following the Commission’s first formal review of all such decisions in January 2024. That finding governs the lawfulness of transferring personal data between the Island and the EU. It says nothing about where a US-headquartered processor subsequently stores or processes that data once it has arrived on the processor’s own infrastructure. Adequacy is a transfer mechanism, decided under what is now Article 45 GDPR. The EU Data Boundary is a data-residency commitment, decided unilaterally by Microsoft as a product feature. They answer different questions, and treating one as a substitute for the other is a category error.

Practically, this means a Manx tenant of Microsoft 365 Copilot is not, by Microsoft’s own published scope, inside the EU Data Boundary at all, regardless of how “adequate” the Island’s own data protection law is judged to be. Where such a tenant’s data actually sits depends on the country selected at tenant creation and on whatever Advanced Data Residency or Multi-Geo commitments, paid, opt-in features, have subsequently been configured. Microsoft’s own November 2025 announcement confirms that even in-country AI data processing for the UK, the jurisdiction the Island is most often bundled with commercially, is not expected to go live until “by the end of 2026.” Whether Microsoft’s tenant-creation country list even offers “Isle of Man” as a distinct option, separate from “United Kingdom,” for residency purposes, is not something this publication has been able to confirm from public documentation. That is itself worth stating plainly: it is a fact any Manx business running Microsoft 365 Copilot should be able to get a straight answer to from their own tenant configuration or reseller, and this article cannot responsibly assert one way or the other without seeing it. Being found “adequate” under GDPR did not, on the evidence available, buy Red5’s clients a defined seat inside the residency boundary that actually governs where Copilot’s AI processing happens.


Flex Routing, the Anthropic Carve-Out, and Why Neither Is Quite What It First Looks Like

There are two further wrinkles worth being precise about, because getting them slightly wrong is easy and the imprecise version is doing the rounds.

The first is Flex Routing, introduced by Microsoft in April 2026. It allows Copilot’s large language model inferencing to be routed to infrastructure in the US, Canada or Australia during periods of peak demand, while data at rest nominally stays inside the EU Data Boundary. Per Microsoft’s own current documentation, it is on by default for eligible tenants created after 25 March 2026, and was switched on by default for existing eligible tenants from 17 April 2026 unless an administrator disabled it. The detail that matters for this piece: Flex Routing is explicitly scoped to “customers who are in scope for the EU Data Boundary.” A Manx tenant, not being in that scope to begin with, is not affected by Flex Routing at all — not because it is protected, but because it was never inside the boundary Flex Routing flexes out of. The feature is a red herring for Island businesses; the underlying question, where does a non-EU-Data-Boundary tenant’s Copilot processing happen by default, predates and sits outside this entire debate.

The second is Anthropic’s status as a Microsoft subprocessor, and here the record needs stating precisely. Microsoft’s own current documentation is specific: Anthropic models are enabled by default for most commercial cloud customers, but the EU, EFTA and UK are explicitly excluded from that default; for tenants in those regions, the setting is Off, and an administrator must actively opt in. This has been the case since Anthropic’s onboarding as a full Microsoft subprocessor on 7 January 2026, refined further by a dedicated EU/EFTA/UK opt-in control Microsoft added on 3 April 2026.

What Microsoft’s documentation does confirm, without ambiguity, is this: when Anthropic models are used, whether by an EU/EFTA/UK admin opting in or by default elsewhere, that processing is excluded from the EU Data Boundary and from any applicable in-country processing commitment. The protective default exists precisely because Microsoft itself treats this as a genuine residency gap for those markets, not a hypothetical one. A separate category again, “Preview models with Data Retention,” covering newer models such as Claude Fable 5 and Claude Mythos 5, remains default-off in every region regardless of the general Anthropic setting, and sits under Anthropic’s own commercial terms rather than Microsoft’s.

It is also worth being precise about retention, because vendor marketing material on this point tends to round up to “stateless” or “zero retention,” and the underlying documentation does not support that. For the standard Anthropic subprocessor path, Microsoft’s Product Terms and DPA apply, but Anthropic retains prompts and outputs for up to 30 days by default for abuse-detection purposes, extending to up to two years where its trust and safety systems flag a possible policy violation. Zero Data Retention is not offered on any Microsoft consumption path for these models — Copilot, Copilot Studio, Researcher, or Foundry alike. And the processing itself does not stay inside Microsoft’s own infrastructure: unlike Azure OpenAI, where OpenAI’s models run inside Microsoft’s own Azure estate, a request routed to an Anthropic model is transferred out to Anthropic’s own servers, hosted on AWS or GCP, located primarily in the United States. “It runs inside Microsoft Copilot” and “it runs inside Microsoft’s infrastructure” are not the same claim, and the case study elides that difference entirely.

None of this is a criticism of Anthropic specifically; the same structural point would apply to any third-party model Microsoft plugs into Copilot as a distinct subprocessor. It is simply a fact, sourced from Microsoft’s own current admin documentation, that “we use Microsoft Copilot” does not tell you which of several possible processing arrangements — each with a different residency footprint, retention period, and physical destination — a given interaction actually falls under. That depends on which agent handled the request, which subprocessor sits behind that agent, and what an administrator has, or has not, configured.

None of this granularity appears anywhere in the Digital Isle of Man piece. “Governance” as described there is entirely about internal process: who gets access first, what problem each tool solves, how confidence is built. It never once descends to the level of a subprocessor list, a residency setting, or a transfer impact assessment. That is the difference between governance as a word and governance as a control.


Adequacy Is Not Immunity, and Microsoft Says So Itself

Even where data genuinely stays inside the EU Data Boundary, a European data centre has never meant beyond US legal reach. Microsoft’s own February 2026 commentary on its cloud sovereignty position is unambiguous: there is still no law that repeals the extraterritorial effect of the US CLOUD Act, and Microsoft cannot give an absolute guarantee that EU-resident data will never be the subject of a US authority’s request. The CLOUD Act, passed in March 2018 in direct response to the United States v. Microsoft Dublin warrant case, exists specifically to establish that physical storage location does not put data beyond a US court order’s reach when the custodian is a US company. Readers wanting the fuller mechanics of that case, and of Section 702 FISA alongside it, will find them set out at length in Your Data in Dublin Isn’t as Irish as You Think; the short version is that the fight over Irish-held data did not produce a ruling protecting that data. It produced a law making it permanently accessible.

The legal architecture that currently makes routine US-EU commercial data transfers possible, the EU-US Data Privacy Framework, is itself mid-challenge at the Court of Justice of the European Union. Latombe v Commission (Case C-703/25 P) is a live appeal, with Microsoft granted intervener status in June 2026 specifically because the company has a direct stake in the outcome. The Framework replaced two predecessor arrangements, Safe Harbor and Privacy Shield, both struck down by the same court on broadly the same grounds: that US surveillance and access law does not, in the CJEU’s view, provide protections essentially equivalent to the GDPR. Whether this appeal produces a “Schrems III” outcome is genuinely unresolved. What is not unresolved is that relying on the current framework as a permanent settlement, rather than the third iteration of an arrangement with a documented history of collapsing, is a choice with a known failure mode.

None of this means Manx businesses should not use Microsoft 365 Copilot, Claude, or any other AI vendor operating out of US jurisdiction. It means that “we’re a well-regulated, GDPR-adequate Crown Dependency” is not, on its own, an answer to the question of where the data goes and who can compel access to it. Adequacy governs the Island’s relationship with the EU. It has no bearing on the US CLOUD Act’s reach into a US company’s infrastructure, wherever that infrastructure happens to sit, and no bearing on whether the EU-US transfer mechanism a Microsoft-hosted AI vendor is relying on will still be standing in two years.


The Inconsistency Red5’s Own Marketing Exposes

This is what makes the Digital Isle of Man piece a genuinely useful case study — not because it is unusually bad, but because the contradiction sits so close to the surface. Red5’s own commercial pitch for its Cloud Desktop and hosted server products is built explicitly on Isle of Man data centres and an Isle of Man GDPR-compliant environment, developed in direct consultation with the Island’s regulators. That is a genuine, defensible sovereignty story, and it is the correct way to sell hosting to a regulated Manx business.

The AI deployment described in the case study is a different animal entirely: a Microsoft 365 tenant plugged into Microsoft’s global Copilot infrastructure, with data residency, inferencing location and subprocessor routing determined by Microsoft’s product terms, tenant creation details and admin-centre configuration, not by anything under Red5’s or its clients’ direct control. The piece moves seamlessly from one sovereignty posture to the other without ever marking the transition. A reader who trusts Red5’s hosting story, reasonably, on the strength of its published track record, has no reason from this article to realise that the AI layer sitting on top of that hosting operates under an entirely different jurisdictional model, one that as of publication cannot even be confirmed to have a defined home for Manx tenants at all.


What “Governance” Would Actually Have to Include

None of the above is an argument against AI adoption. It is an argument against selling governance as a settled state rather than a live, checkable set of facts. A Manx business, or any regulated business anywhere, adopting Microsoft 365 Copilot, Claude, Gemini or any comparable tool responsibly would need to be able to answer, in writing, at minimum:

It is also worth being honest about what fixing any of this actually costs, because that is precisely where “governance” case studies tend to stop. Advanced Data Residency is not a targeted control an organisation switches on for whichever department handles sensitive data. Microsoft’s own documentation is explicit that ADR requires 100% coverage of every paid licence in the tenant to establish or maintain the commitment at all; there is no minimum seat count that qualifies on its own, and no way to buy it selectively. Priced per user per year on top of an existing E3 or E5 licence, that is a tenant-wide, recurring, five-figure commitment for many small and mid-sized organisations, bought against a risk that is invisible until it materialises, which is exactly the kind of line item that struggles to survive a CFO’s budget conversation next to something with a demonstrable, immediate return. And Microsoft’s own eligible-country list for ADR — Australia, Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Mexico, Poland, Qatar, South Korea, Norway, South Africa, Spain, Sweden, Switzerland, the UAE and the United Kingdom — does not include the Isle of Man. Whether a Manx tenant could purchase ADR at all depends on how its Default Geography is classified, a question this piece has already established the public record does not clearly answer. A governance conversation that never gets past process, in other words, may not simply be an oversight. The control that would actually answer the sovereignty question is expensive, all-or-nothing, and not confirmed to be available to the jurisdiction in question at any price.

A case study built around “governance, not technology” that cannot answer any of these has described a rollout plan. It has not described governance. Digital Isle of Man’s own National AI Office lists responsible use of AI and risk awareness among its stated first-year deliverables. Publishing this piece, under that banner, with none of the above addressed, is a small but clean example of the gap between the institutional claim and the operational reality it is supposed to be closing.

Crown Dependency status, and the adequacy finding that comes with it, is a genuine asset. It is not a force field. Selling it as one, even by omission, does a disservice to exactly the clients this kind of article is meant to reassure.


An Instrument Built for a Different Time

It is worth being precise about what Commission Decision 2004/411/EC was actually built to assess. It weighed the Isle of Man’s data protection law against Directive 95/46/EC, a framework written for file-based processing and identifiable transfers between named parties: a data controller in one place sends a defined dataset to a data controller in another place, and the question is whether that second place’s law offers equivalent protection. The concept only works if you can say where the data is and which law governs it once it arrives.

Nothing in that 2004 assessment, or the Directive it was measuring against, had any vocabulary for a prompt routed by a load-balancer to whichever of three continents has spare inferencing capacity that afternoon; for a subprocessor toggle an admin does not know exists, defaulting one way in some jurisdictions and the other way elsewhere, on a date set by a vendor’s product roadmap rather than a customer’s contract; or for a distinction between where the data sleeps and where it is briefly, repeatedly, put to work. Flex Routing, the Anthropic subprocessor carve-out, and the plain absence of Isle of Man from Microsoft’s own residency geography list are not edge cases the 2004 adequacy finding failed to anticipate in its detail. They are a different category of problem, one that did not exist yet in any form the instrument could have been built to see.

Citing a 2004 adequacy decision as though it settles a 2026 AI routing question is not really conflating two things that answer the same question differently. It is asking an instrument to adjudicate a category of risk it predates. That gap is the whole of the trick, and it is exactly the gap “governance, not technology” is supposed to close, not paper over.


Sources

European Commission, Commission Decision 2004/411/EC of 28 April 2004 on the adequate protection of personal data in the Isle of Man, OJ L 151, 30.4.2004, p. 48. EUR-Lex CELEX:32004D0411.

European Commission, Report on the first review of the functioning of the adequacy decisions adopted pursuant to Article 25(6) of Directive 95/46/EC, COM(2024) 7 final, January 2024. EUR-Lex CELEX:52024DC0007.

Microsoft Learn, “What is the EU Data Boundary?” — learn.microsoft.com/en-gb/privacy/eudb/eu-data-boundary-learn

Microsoft Learn, “Data, Privacy, and Security for Microsoft 365 Copilot” — learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy

Microsoft Learn, “Anthropic models in Microsoft Online Services” — learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor (last updated 22 July 2026)

Microsoft Learn, “Flex routing (EU and EFTA)” — learn.microsoft.com/en-us/microsoft-365/copilot/copilot-flex-routing

Microsoft Learn, “Overview of AI Subprocessors in Microsoft 365 Copilot” — learn.microsoft.com/en-us/microsoft-365/copilot/copilot-subprocessor-overview

Microsoft 365 Blog, “Microsoft offers in-country data processing to 15 countries to strengthen sovereign controls for Microsoft 365 Copilot,” 4 November 2025

Directions on Microsoft, “M365 Copilot Adds Choice (and Risk) with Anthropic’s Claude,” 20 January 2026

Directions on Microsoft, “What Is Advanced Data Residency?”

Microsoft Learn, “Advanced data residency in Microsoft 365” and “Advanced Data Residency Commitments” — learn.microsoft.com/en-us/microsoft-365/enterprise/advanced-data-residency, learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-commitments

FutureAbility, “Anthropic Claude Data Residency for Australian Organisations,” compliance briefing on Copilot, Copilot Studio, Claude for Work and Azure AI Foundry deployment paths

Digital Isle of Man, “Keeping People At The Centre of AI,” 12 August 2026 — digitalisleofman.com/news/keeping-people-at-the-centre-of-ai/

Red5 Systems / ITEX (Isle of Man) Limited, “About Us” and “Information Security” — red5.im/about-us/, red5.im/information-security/

TechCrunch, “Microsoft finalizes its EU sovereign cloud project,” 26 February 2026

The Register, “Microsoft to assist European Commission in defense of EU-US data-sharing agreement,” 29 June 2026

Databalance, “Microsoft Cloud sovereignty in 2026: ambition and reality,” 12 February 2026

Appleby, “Data Protection Guide 2023: Isle of Man”; ICLG, “Data Protection Laws and Regulations Report 2025-2026: Isle of Man”

Isle of Man Government / Digital Isle of Man, National AI Office launch materials, January 2026 — gov.im/news/2025/oct/16/digital-isle-of-man-to-lead-early-work-to-establish-national-ai-office/


Cross-reference: Your Data in Dublin Isn’t as Irish as You Think

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy -- with a particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly -- or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.