FISA 702 Gives the US Government Your AI Queries. No Warrant Required.
What the 2024 Reauthorization Means for Every Non-US Organization Using US AI
---
A EU company's data protection officer completes a transfer impact assessment for the organization's primary AI provider. She documents that FISA Section 702 — which authorizes US intelligence agencies to collect non-US persons' communications without a warrant — applies to every query the company's employees send to that provider. She recommends against proceeding with the deployment. She is overruled. The tool is deployed. The TIA sits in the compliance file, documenting a problem that nobody solved.
That scenario repeats in organizations across Europe every quarter. The gap between the legal analysis in the TIA and the decision made above it is where the enforcement risk lives.
---
What FISA 702 Actually Says
Section 702 of the Foreign Intelligence Surveillance Act authorizes US intelligence agencies to collect communications of persons reasonably believed to be located outside the United States. No individual warrant. No notification to the subject. No recourse mechanism for the person whose communications were collected. The collection authority is granted through a bulk authorization, renewed annually, without court review of specific targets.
Every query a non-US organization sends to a US AI provider is a communication from a person outside the United States, transmitted through a US provider. That is precisely the category of communication this law was written to cover. FISA 702 was not designed to incidentally affect European business communications — collecting foreign intelligence communications is its stated purpose.
The law was reauthorized in March 2024. The 2024 reauthorization did not restrict scope. It expanded it, adding new collection authorities that were specifically debated in Congress. The direction of this law's trajectory, across every reauthorization, is toward more access, not less. Organizations that assessed their US AI exposure against the pre-2024 framework need to revisit that assessment.
One additional feature of FISA 702 that enterprise agreements cannot address: it includes a gag requirement. When a US AI provider receives a FISA 702 order, they cannot disclose it to affected users. They cannot confirm whether a specific query was collected. They cannot publish aggregate statistics about orders received. The disclosure that would allow an organization to assess actual impact is legally prohibited.
---
Why Your Data Protection Agreement Does Not Help
Legal teams at EU organizations frequently point to their enterprise AI agreements as protection against FISA 702 exposure. The agreements contain data processing addenda restricting commercial use, Standard Contractual Clauses establishing safeguards, and confidentiality provisions the provider is contractually obligated to honor.
These mechanisms operate in commercial law. FISA 702 operates in federal law. Federal law preempts commercial agreements. When a US intelligence agency serves a valid FISA 702 order on a US AI provider, the provider's legal obligation to comply with US federal law supersedes its contractual obligation to commercial customers. The provider cannot breach federal law to honor a commercial contract. At the exact moment the data protection agreement would be most valuable, it becomes unenforceable.
The European Court of Justice reached this conclusion in 2020. The Schrems II ruling invalidated the EU-US Privacy Shield framework — the legal mechanism that allowed EU personal data to flow to US companies — specifically because FISA 702 and related surveillance laws made adequate protection structurally impossible for EU data in US systems. The Court found that Standard Contractual Clauses, on their own, cannot provide adequate protection when the receiving country's law authorizes the collection SCCs are meant to prevent.
Four years after Schrems II, FISA 702 was reauthorized and expanded. The legal problem the ECJ identified in 2020 is larger in 2026 than it was then.
---
What GDPR Transfer Impact Assessments Are Actually Saying
When a EU organization conducts a GDPR transfer impact assessment for a US AI provider and documents FISA 702 inadequacy, it is creating a legal record with specific implications. The document says: we know this transfer does not meet the adequacy standard. It often then says: we are proceeding with compensating controls. The compensating controls — encryption in transit, access limitations, additional contractual clauses — do not address the FISA 702 authority, because that authority operates after the data reaches the US provider, not before.
The contrarian position, and the accurate one: TIAs that acknowledge FISA 702 inadequacy and then approve the transfer are legal documentation of a problem, not legal resolution of it. They protect the organization's compliance team from a claim of ignorance. They do not protect the organization from the enforcement finding that it proceeded with a transfer it documented as inadequate.
The TikTok €530M fine issued by the Irish Data Protection Authority in May 2025 was specifically for cross-border data transfers without adequate protection mechanisms. The structural failure was identical: data transferred to a jurisdiction where the receiving entity was subject to legal authorities the transfer safeguards could not override. The same structure applies to EU organizations transferring AI query data to US providers under FISA 702 authority.
---
The Enforcement Trajectory
GDPR enforcement on inadequate US data transfers is accelerating. The TikTok fine was the largest data protection fine of 2025. The EDPB's guidance on US data transfers consistently identifies FISA 702 as an adequacy barrier. EU national data protection authorities have been systematically reviewing US data transfer arrangements since Schrems II, and the AI channel — high-volume, often client-specific, frequently not covered by legacy transfer mechanisms — is an obvious target.
EU AI Act Article 26 adds a second liability layer. It places compliance responsibility on the organization deploying AI, not on the model provider. An EU company whose AI deployment routes client data through a US provider subject to FISA 702 is, under EU law, accountable for what happens to that data — including collection under legal authorities the organization cannot audit, cannot document, and cannot prevent.
The compound risk is specific: FISA 702 collection authority, GDPR Article 44–49 transfer restrictions, EU AI Act Article 26 deployer liability, and national data protection law all apply simultaneously. A DPA audit that finds TIAs acknowledging FISA 702 inadequacy, with three years of client data transfers documented afterward, is not looking at a theoretical violation. It is looking at a documented pattern.
---
The Architectural Exit
There is no contractual resolution to a statutory authority. No clause, no addendum, no SCC addition addresses a law that preempts commercial contracts. The only complete resolution to FISA 702 exposure is an architecture where no query reaches a US provider.
EU-jurisdiction infrastructure — EU-headquartered AI on EU servers, operating under EU law — eliminates the transfer entirely. No transfer, no TIA required. No US provider receives the query, so no FISA 702 order can compel its production. The compliance question changes from "how do we manage an inadequate transfer?" to "is there a transfer?" The answer is no.
The SIA standard's Data Residency principle addresses this directly: data never leaves customer infrastructure. EU-based open model deployment — Mistral on OVHcloud, for example, or on-premises open weights in the organization's own data center — achieves AI capability without US jurisdiction exposure. Model Sovereignty requires open weights deployable in any jurisdiction, specifically to enable this architectural independence from US AI infrastructure.
The DPO who documented the FISA 702 problem, recommended against the deployment, and was overruled is not vindicated by a better TIA. She is vindicated by an architecture where the TIA is not required. The gap between her recommendation and the organizational decision closes when the tool is replaced by one whose data never transits US infrastructure.
---
The Question That Ends the TIA Problem
Ask your current US AI provider for a written commitment that they will refuse any FISA 702 order involving your organization's data. No US AI provider can make that commitment — honoring it would require them to violate US federal law. The absence of that commitment is not a negotiating failure. It is the accurate description of the legal environment.
The enforcement actions that are coming will distinguish organizations that documented the FISA 702 problem and then resolved it architecturally from those that documented it and proceeded anyway. The first group has a compliance story. The second group has a compliance file.
No warrant. No notification. No recourse. No disclosure from your provider. And no clause in any enterprise agreement that changes any of those four facts.
The organizations that deploy EU-jurisdiction AI before their next TIA review cycle close the gap architecturally. The organizations that conduct another TIA review cycle and reach the same conclusion as the last one continue accumulating the exposure they documented.