Answer first: Microsoft is moving the AI processing behind Microsoft 365 Copilot inside national borders — 15 countries by 2026. It confirms that "data sovereignty" is now mainstream, not just a bank-and-government concern. But "in-country processing" only answers where data is processed; it doesn't answer who controls it. For genuinely sensitive data — and for Vietnam's storage duties under the 2018 Cybersecurity Law + Decree 53/2022 — the highest level of control remains internal / on-premise AI: the model runs inside your own infrastructure and data never leaves your control.
TL;DR
- Anchor event: On 4 Nov 2025, Microsoft announced an expansion of in-country data processing for Microsoft 365 Copilot — Copilot interactions are processed in data centers located within a nation's borders.
- The numbers: 4 countries get it by end of 2025 (Australia, UK, India, Japan) + 11 more in 2026 = 15 total with in-country processing; Microsoft also offers in-country data residency in 27 countries.
- The trend: Gartner forecasts that by 2030, more than 75% of European and Middle Eastern enterprises will "geopatriate" their virtual workloads, up from less than 5% in 2025.
- Vietnam law: The 2018 Cybersecurity Law (Article 26) + Decree 53/2022 (effective 1 Oct 2022) require certain data on Vietnamese users to be stored in Vietnam for a minimum of 24 months.
- NAM Tech angle: "In-country" fixes where, not who controls. When sensitive data must never leave your perimeter, the definitive answer is internal / on-premise AI.
1. What Microsoft announced
On 4 November 2025, Microsoft announced an expansion of in-country data processing for Microsoft 365 Copilot. Per Microsoft, Copilot interactions "are processed, under normal operations, in data centers located within a nation's borders," giving customers more control over their data. In other words: the prompt you send and the model's response are kept and processed in-country.
Microsoft set out the rollout in two phases:
| Phase | Countries | List |
|---|---|---|
| Available by end of 2025 | 4 | Australia, UK, India, Japan |
| Added during 2026 | +11 | Canada, Germany, Italy, Malaysia, Poland, South Africa, Spain, Sweden, Switzerland, UAE, US |
| Total with in-country processing | 15 | — |
| Existing in-country data residency | 27 | — |
Source for Table 1: Microsoft 365 Blog, "Microsoft offers in-country data processing to 15 countries…", 4 Nov 2025.
2. Residency vs. processing
- Data residency means data is stored in-country. Microsoft says it offers this in 27 countries.
- In-country processing means the inference step (prompt → model → response) also stays inside the border, not just storage. This is the new expansion for Copilot, targeting 15 countries.
The key point: both are still run on the provider's infrastructure — not yours. They close the geographic gap, but the data still lives on the vendor's platform.
3. The bigger trend: data sovereignty goes mainstream
The fact that a hyperscaler like Microsoft has to "bring AI home" reflects industry-wide pressure. Gartner forecasts that by 2030, more than 75% of European and Middle Eastern enterprises will "geopatriate" their virtual workloads — moving them to options that reduce geopolitical risk (sovereign cloud, regional providers, or their own data centers) — up from less than 5% in 2025.
| Metric / Milestone | Value | Source |
|---|---|---|
| EU & Middle East enterprises "geopatriating" workloads by 2030 | >75% (vs <5% in 2025) | Gartner |
| Microsoft 365 Copilot — in-country processing (total) | 15 countries | Microsoft |
| Vietnam — Decree 53/2022/ND-CP effective | 1 Oct 2022 | lawlinkvn |
| Vietnam — minimum data storage period in Vietnam | 24 months | lawlinkvn |
| Vietnam — foreign firms must complete storage after a request | within 12 months | lawlinkvn |
| Vietnam — AI Law 2025 passed by National Assembly | 10 Dec 2025 | Bao Lam Dong |
| Vietnam — mandatory labeling of AI-generated content | from 1 Mar 2026 | Bao Lam Dong |
Sources: Gartner (Top Strategic Technology Trends 2026, via Help Net Security), Microsoft 365 Blog, lawlinkvn, Bao Lam Dong.
4. The Vietnam angle
Vietnam localized data even before the AI wave:
- The 2018 Cybersecurity Law (Article 26) sets the general storage requirement; Decree 53/2022/ND-CP provides the detail, effective 1 Oct 2022.
- Data that must be stored in Vietnam includes: personal information of Vietnamese users; user-generated data (account names, usage time, card details, email, IP, phone number); and data on users' relationships.
- Minimum storage is 24 months; in-scope foreign firms must set up a local branch/representative office and complete storage within 12 months of a written request from the Ministry of Public Security.
Scope note: this article does NOT advise on avoiding legal obligations or circumventing the 2018 Cybersecurity Law or Decree 147/2024/ND-CP on the management, provision and use of internet services and online information. The goal is to help enterprises comply better through the right data architecture.
5. When in-country isn't enough — the role of internal / on-premise AI
In-country processing fixes geography, but three questions remain:
- Who controls the keys and access? On a provider's service, ultimate operational control belongs to the provider, wherever the data center sits.
- Does data leave your infrastructure? With a public API, sensitive payloads still have to be sent out to be processed.
- Are you locked to one vendor? Vendor lock-in risk is one reason Gartner named "geopatriation" among its Top Strategic Technology Trends 2026 — trend #10.
For genuinely sensitive data (customer records, IP, data subject to mandatory residency), the definitive control is internal / on-premise AI: deploy an open model in your own data center or server cluster so data never leaves your perimeter. That is the strongest form of data sovereignty — and, by definition, a third party's "in-country" service does not reach it.
6. What Vietnamese enterprises should do
- Classify data first. Not everything needs on-premise. Separate mandatory-residency / sensitive data from the rest.
- Map legal obligations. Cross-check the 2018 Cybersecurity Law + Decree 53/2022 to see which data types must be stored in Vietnam for at least 24 months.
- Pick the right architecture layer. Public cloud for low-sensitivity tasks; in-country for location compliance; on-premise / internal AI for core data.
- Prepare for AI labeling. From 1 Mar 2026, AI-generated/edited content simulating real people or events must carry a clearly recognizable label under the AI Law 2025.
Frequently asked questions
Does Microsoft's "in-country data processing" mean my data never leaves the country?
Not automatically. The feature currently applies to the 15 countries Microsoft announced (Vietnam is not on the list), and even then, data still sits on Microsoft-operated infrastructure "under normal operations." To guarantee data never leaves your own infrastructure, you need internal / on-premise AI.
Are Vietnamese enterprises required to store data domestically?
Some data types, yes. Under the 2018 Cybersecurity Law (Article 26) and Decree 53/2022 (effective 1 Oct 2022), personal information, user-generated data, and users' relationship data for Vietnamese users must be stored in Vietnam for at least 24 months. Consult a lawyer for your specific case.
When does AI-generated content have to be labeled?
From 1 Mar 2026, under the AI Law 2025 (passed by the National Assembly on 10 Dec 2025). Audio/image/video content created or edited by AI to simulate real people or events must carry a clearly recognizable label; film and the arts apply it flexibly.
What is "geopatriation"?
Moving data and applications off the global public cloud toward domestic options (sovereign cloud, regional providers, or your own data center) to reduce geopolitical risk. Gartner forecasts more than 75% of European and Middle Eastern enterprises will do this by 2030.
Is internal AI always the right choice?
No. Classify your data: low-sensitivity tasks can use cloud/in-country for cost efficiency; only core/sensitive/mandatory-residency data really needs on-premise.
Keep data and prompts inside your organization
Namtech deploys internal AI running 100% on-site — the model and data never leave your firewall, keeping data sovereignty at a level a third party's "in-country" service cannot reach.
Book a free consultationThis article is informational, not legal advice. Enterprises should consult experts before making compliance decisions. Compiled from public sources as of 15 July 2026; subject to change.
- Microsoft 365 Blog — Microsoft offers in-country data processing to 15 countries… Microsoft 365 Copilot (4 Nov 2025)
- Help Net Security citing Gartner — Top Strategic Technology Trends 2026 (23 Oct 2025)
- LawLink Vietnam — Data storage obligations in Vietnam under Decree 53/2022/ND-CP
- Bao Lam Dong — AI Law 2025: mandatory labeling of AI-generated content from March 2026