Data residency and AI
Enterprise AI With Data Kept in Türkiye
Using enterprise AI does not require sending company data to AI services outside Türkiye.
Last updated: September 2026
Using AI while keeping data in Türkiye means running every component of the AI architecture on infrastructure inside the country. What decides it is not only where data is stored but where embedding, vector search, model inference and the application layer run. Data residency is therefore assessed across data at rest, data in transit and processing location together.
Large language model (LLM), retrieval-augmented generation (RAG), machine learning and AI agent workloads can run in an organization's own data centre, in a private cloud, or on suitable cloud infrastructure located in Türkiye.
In such an architecture it is not only where data is stored that stays under control, but also where it is processed, where the AI model runs, and the infrastructure through which enterprise knowledge reaches the model.
The Kauzas Data & AI Platform is Kubernetes-based, so data and AI workloads run inside the infrastructure boundary the organization sets.
Where data leaves the country
When an organization uses a public generative AI service the process usually looks simple: the user asks, the service answers. In enterprise use the architecture is broader and made of several components.
- Enterprise data
- Data processing
- Embedding
- Vector search
- Model inference
- Application
If any one of these components runs on infrastructure abroad, the data — or information derived from it — may move outside the geographic boundary the organization has set.
“Our database is in Türkiye” is therefore not enough on its own; the whole AI architecture has to be assessed.
The components that can run in Türkiye
With the right architecture, every core component of an AI system can run inside Türkiye.
- Data
- Retrieval
- AI model
- Agent
- Application
The whole chain can be built inside the environment the organization controls.
Enterprise data
ERP, CRM, data warehouse, data lake, document systems, operational databases and other sources.
Data lakehouse
Lets structured and unstructured enterprise data be used from a shared data layer by AI and analytics workloads alike.
Embedding
Turning documents and other enterprise knowledge into representations AI can search over can happen on the organization's own infrastructure.
Vector database
The vector data used in RAG applications can be held on infrastructure the organization sets.
Large language model
Suitable LLMs can run on the organization's own infrastructure or on suitable infrastructure in Türkiye.
RAG
Retrieval, context assembly and model inference can all happen within the same infrastructure boundary.
AI agents
The models, tools and enterprise data connections an agent uses can be governed under the same security and data policy.
Where the data sits, where the model sits
Organizations often make one assumption: “our data is in Türkiye, so our AI architecture is in Türkiye too.” That is not always true.
Enterprise data may sit in a database or object store in Türkiye while prompts, or the pieces of data relevant to them, are sent for inference to an AI service running abroad.
Data residency therefore has to be assessed across data at rest, data in transit and processing location together — not data at rest alone. Where the model runs matters for exactly this reason.
Where data sits is half the question; the other half is where it is processed.
Data control with an on-premise LLM
Suitable open-source models, or models the organization selects, can run on on-premise infrastructure. The flow then happens inside the organization's own environment:
- Enterprise data
- RAG
- LLM
- Answer
Inference no longer requires sending data to an external API.
This offers an alternative architecture, particularly for organizations that want to use generative AI over sensitive enterprise data.
A private AI architecture in Türkiye
Private AI is the approach of running AI systems in an environment controlled according to the organization's data, security and infrastructure policy.
A private AI architecture can be built on on-premise infrastructure or on suitable private or public cloud infrastructure located in Türkiye.
What matters is not whether cloud is used, but which physical and logical boundaries the AI workload runs within.
AI on the AWS Local Zone in Istanbul
AWS Local Zones are infrastructure extensions that place certain AWS services geographically closer to end users. There is an AWS Local Zone in Istanbul.
Thanks to its Kubernetes-based architecture, Kauzas can be used to build architectures that run Data & AI workloads on the AWS Local Zone in Istanbul where the scenario suits it.
- Corporate Systems
- Kauzas Data Platform
- Lakehouse
- AI / ML
- RAG / Agents
- Enterprise Applications
Deployment: AWS Local Zone Istanbul
This is worth considering for organizations that want the cloud operating model while placing certain workloads inside Türkiye.
Data and AI inside the same boundary
One of the important differences here is that Kauzas does not treat the AI layer as separate from enterprise data. These layers can be positioned together within one platform architecture:
- Data Integration
- Data Lakehouse
- Catalog & Governance
- Analytics / ML
- Generative AI
- RAG & AI Agents
Architectures can therefore be designed that avoid creating uncontrolled copies of data purely to feed AI applications.
User and AI agent authorization
In enterprise use of generative AI, where the data sits is not enough on its own; who can reach which data matters too.
As AI agents spread, the question widens: which user and which agent can reach which data?
In the Kauzas governance approach, user and agent access is handled alongside enterprise data policy. Rather than an AI application showing every user everything it can technically reach, data access is designed together with the organization's existing authorization policy.
KVKK and artificial intelligence
Under KVKK, transferring personal data abroad is subject to conditions. Amendments that took effect in 2024 established a new system covering adequacy decisions, appropriate safeguards and certain exceptional cases.
A blanket statement that “data can never leave the country when using AI” is therefore not accurate. Organizations instead need to assess the nature of the data, the AI services used, where processing happens, the legal transfer mechanisms available and their own security policy together.
By letting AI and data workloads run inside the infrastructure the organization sets, Kauzas supports building architectures that fit data residency requirements.
Choosing a deployment model
The Kauzas approach does not make any one of these compulsory. Each workload can run in the environment that suits its data and security requirements.
| Architecture | Data location | AI model | Use |
|---|---|---|---|
| On-premise | Your data centre | Local | Maximum infrastructure control |
| Private cloud | A defined environment | Local / private | A controlled cloud model |
| Cloud infrastructure in Türkiye | Türkiye | Local / private | Local workloads |
| Hybrid | More than one environment | Varies | Distributed by workload |
Frequently asked questions
- Does using AI require data to leave the country?
- No. With a suitable model and infrastructure, LLM, RAG and other AI components can run on the organization's own infrastructure or on suitable infrastructure located in Türkiye.
- Can a ChatGPT-like application run in Türkiye?
- Yes. LLMs that fit the organization's needs can run on infrastructure in Türkiye to build conversational AI and enterprise knowledge assistants. That does not mean installing the ChatGPT service itself locally.
- Does data leave the country when RAG is used?
- It depends on the architecture. Where embedding, the vector database, retrieval and the LLM service each run has to be assessed separately. With every component running locally, the RAG process can be kept inside the infrastructure boundary the organization sets.
- Can we use AWS and still keep data in Türkiye?
- Certain workloads can run on infrastructure located in Türkiye, such as the AWS Local Zone in Istanbul. But it should not be assumed that every AWS service used sits in the same location; the architecture has to be assessed service by service.
- Can Kauzas run in Türkiye?
- Yes. With its Kubernetes-based architecture, Kauzas can run in an organization's own data centre and on suitable infrastructure located in Türkiye.
Let your AI run wherever your data stays
Building AI on your enterprise data does not mean moving that data to an environment outside your control. Let's test a real AI use case running on your own infrastructure, on the Kauzas Data & AI Platform.