Skip to content

Data residency and AI

Enterprise AI With Data Kept in Türkiye

Using enterprise AI does not require sending company data to AI services outside Türkiye.

Last updated: September 2026

Using AI while keeping data in Türkiye means running every component of the AI architecture on infrastructure inside the country. What decides it is not only where data is stored but where embedding, vector search, model inference and the application layer run. Data residency is therefore assessed across data at rest, data in transit and processing location together.

Large language model (LLM), retrieval-augmented generation (RAG), machine learning and AI agent workloads can run in an organization's own data centre, in a private cloud, or on suitable cloud infrastructure located in Türkiye.

In such an architecture it is not only where data is stored that stays under control, but also where it is processed, where the AI model runs, and the infrastructure through which enterprise knowledge reaches the model.

The Kauzas Data & AI Platform is Kubernetes-based, so data and AI workloads run inside the infrastructure boundary the organization sets.

Where data leaves the country

When an organization uses a public generative AI service the process usually looks simple: the user asks, the service answers. In enterprise use the architecture is broader and made of several components.

  1. Enterprise data
  2. Data processing
  3. Embedding
  4. Vector search
  5. Model inference
  6. Application

If any one of these components runs on infrastructure abroad, the data — or information derived from it — may move outside the geographic boundary the organization has set.

“Our database is in Türkiye” is therefore not enough on its own; the whole AI architecture has to be assessed.

The components that can run in Türkiye

With the right architecture, every core component of an AI system can run inside Türkiye.

  1. Data
  2. Retrieval
  3. AI model
  4. Agent
  5. Application

The whole chain can be built inside the environment the organization controls.

Enterprise data

ERP, CRM, data warehouse, data lake, document systems, operational databases and other sources.

Data lakehouse

Lets structured and unstructured enterprise data be used from a shared data layer by AI and analytics workloads alike.

Embedding

Turning documents and other enterprise knowledge into representations AI can search over can happen on the organization's own infrastructure.

Vector database

The vector data used in RAG applications can be held on infrastructure the organization sets.

Large language model

Suitable LLMs can run on the organization's own infrastructure or on suitable infrastructure in Türkiye.

RAG

Retrieval, context assembly and model inference can all happen within the same infrastructure boundary.

AI agents

The models, tools and enterprise data connections an agent uses can be governed under the same security and data policy.

Where the data sits, where the model sits

Organizations often make one assumption: “our data is in Türkiye, so our AI architecture is in Türkiye too.” That is not always true.

Enterprise data may sit in a database or object store in Türkiye while prompts, or the pieces of data relevant to them, are sent for inference to an AI service running abroad.

Data residency therefore has to be assessed across data at rest, data in transit and processing location together — not data at rest alone. Where the model runs matters for exactly this reason.

Where data sits is half the question; the other half is where it is processed.

What data sovereignty means end to end

Data control with an on-premise LLM

Suitable open-source models, or models the organization selects, can run on on-premise infrastructure. The flow then happens inside the organization's own environment:

  1. Enterprise data
  2. RAG
  3. LLM
  4. Answer

Inference no longer requires sending data to an external API.

This offers an alternative architecture, particularly for organizations that want to use generative AI over sensitive enterprise data.

The on-premise AI platform architecture

A private AI architecture in Türkiye

Private AI is the approach of running AI systems in an environment controlled according to the organization's data, security and infrastructure policy.

A private AI architecture can be built on on-premise infrastructure or on suitable private or public cloud infrastructure located in Türkiye.

What matters is not whether cloud is used, but which physical and logical boundaries the AI workload runs within.

AI on the AWS Local Zone in Istanbul

AWS Local Zones are infrastructure extensions that place certain AWS services geographically closer to end users. There is an AWS Local Zone in Istanbul.

Thanks to its Kubernetes-based architecture, Kauzas can be used to build architectures that run Data & AI workloads on the AWS Local Zone in Istanbul where the scenario suits it.

  1. Corporate Systems
  2. Kauzas Data Platform
  3. Lakehouse
  4. AI / ML
  5. RAG / Agents
  6. Enterprise Applications

Deployment: AWS Local Zone Istanbul

This is worth considering for organizations that want the cloud operating model while placing certain workloads inside Türkiye.

Deployment options

Data and AI inside the same boundary

One of the important differences here is that Kauzas does not treat the AI layer as separate from enterprise data. These layers can be positioned together within one platform architecture:

  1. Data Integration
  2. Data Lakehouse
  3. Catalog & Governance
  4. Analytics / ML
  5. Generative AI
  6. RAG & AI Agents

Architectures can therefore be designed that avoid creating uncontrolled copies of data purely to feed AI applications.

User and AI agent authorization

In enterprise use of generative AI, where the data sits is not enough on its own; who can reach which data matters too.

As AI agents spread, the question widens: which user and which agent can reach which data?

In the Kauzas governance approach, user and agent access is handled alongside enterprise data policy. Rather than an AI application showing every user everything it can technically reach, data access is designed together with the organization's existing authorization policy.

Carrying permissions through to the data source

KVKK and artificial intelligence

Under KVKK, transferring personal data abroad is subject to conditions. Amendments that took effect in 2024 established a new system covering adequacy decisions, appropriate safeguards and certain exceptional cases.

A blanket statement that “data can never leave the country when using AI” is therefore not accurate. Organizations instead need to assess the nature of the data, the AI services used, where processing happens, the legal transfer mechanisms available and their own security policy together.

By letting AI and data workloads run inside the infrastructure the organization sets, Kauzas supports building architectures that fit data residency requirements.

Choosing a deployment model

The Kauzas approach does not make any one of these compulsory. Each workload can run in the environment that suits its data and security requirements.

ArchitectureData locationAI modelUse
On-premiseYour data centreLocalMaximum infrastructure control
Private cloudA defined environmentLocal / privateA controlled cloud model
Cloud infrastructure in TürkiyeTürkiyeLocal / privateLocal workloads
HybridMore than one environmentVariesDistributed by workload

Frequently asked questions

Does using AI require data to leave the country?
No. With a suitable model and infrastructure, LLM, RAG and other AI components can run on the organization's own infrastructure or on suitable infrastructure located in Türkiye.
Can a ChatGPT-like application run in Türkiye?
Yes. LLMs that fit the organization's needs can run on infrastructure in Türkiye to build conversational AI and enterprise knowledge assistants. That does not mean installing the ChatGPT service itself locally.
Does data leave the country when RAG is used?
It depends on the architecture. Where embedding, the vector database, retrieval and the LLM service each run has to be assessed separately. With every component running locally, the RAG process can be kept inside the infrastructure boundary the organization sets.
Can we use AWS and still keep data in Türkiye?
Certain workloads can run on infrastructure located in Türkiye, such as the AWS Local Zone in Istanbul. But it should not be assumed that every AWS service used sits in the same location; the architecture has to be assessed service by service.
Can Kauzas run in Türkiye?
Yes. With its Kubernetes-based architecture, Kauzas can run in an organization's own data centre and on suitable infrastructure located in Türkiye.

Let your AI run wherever your data stays

Building AI on your enterprise data does not mean moving that data to an environment outside your control. Let's test a real AI use case running on your own infrastructure, on the Kauzas Data & AI Platform.