Cross-border & Sovereignty
The model an agent runs on is trained in one place, hosted in another, and run wherever its provider puts it. A user’s data moves between those places, under whatever law holds in each. Government and user both have a stake in those locations, for different reasons. A government weighs them for national security and for the control it keeps over its own systems: a service built on a model another state can reach into is a dependency it cannot fully govern. A user mostly wants the task done, and the legal exposure behind the agent is neither shown to them nor easy to understand.
Neither party can read those locations off the interaction. Nothing in the exchange declares where the model runs, and supply chains run through layers of subprocessors. Even a full declaration would not settle the question, because an onshore host can be required to hand data to a foreign government. Agents calling tools across borders add further steps no one sees. Once a user’s benefits or health data has moved under another jurisdiction, the protection it had does not travel with it, and nothing the user does brings it back.
Policy challenge
When a user interacts with a government service through an AI agent, the model behind that agent may sit beyond the user's legal protection in several distinct ways: hosted in another country, operated by a foreign company, or subject to foreign legal compulsion even when hosted onshore. The user usually cannot see this, and the agency often cannot tell which legal regime governs the data and the interaction.
As agent-mediated contact becomes routine, that uncertainty determines whose data-protection law applies, who can compel access to a user's information, and how much sovereign control the government keeps over the dependency.
Design challenge
Make plain, to both the agency and the user's agent, where the model behind a service runs, where its data is processed, and what its supply chain depends on.
Provide these as machine-readable signals.
Match the level of sovereignty required to the sensitivity of the interaction, and check it before a user's data moves, not after.
Tell the user when these facts change their legal protections, in terms they can act on rather than click past.
Let them switch to another model where one exists.
Keep a path open for the user who can't weigh the legal detail, or for whom no compliant alternative exists, so sovereignty doesn't shut them out of the service.