Artificial Intelligence Expansion Drives Data Repatriation and Localization Debates Worldwide

The IDC survey covered 763 technology and business decision-makers across the United States, Saudi Arabia, Germany, India, China, Japan and South Korea, and identified examples including hospitals retrieving old X-rays, telecom companies analyzing historical usage records and governments digitizing decades-old physical files for AI use.
Cashfree Payments says it keeps sensitive payment information within its own systems and in India rather than sharing it with third-party AI models, while using role-based access controls to prevent an agent serving one merchant from accessing another merchant’s data.
Cashfree cofounder Reeju Datta argued that the entity offering an AI agent should remain responsible for its actions, with autonomy calibrated to risk: low-risk tasks could receive limited oversight, while transactions moving money out of a merchant account may require explicit approval.
Anthropic India Managing Director Irina Ghose said the company views “safety and capability” as “two sides of the same coin,” and that security, privacy and governance are considered when its models are built and distributed.
Ghose said major system integrators, including Deloitte, TCS and Infosys, are rethinking their operating playbooks to become AI-native as financial-sector organizations expand their use of artificial intelligence.
Artificial intelligence is forcing companies worldwide to dig up old data they buried years ago. IDC found that 75.9% of organizations are retrieving cold-tier data — files stored cheaply and forgotten — to power AI systems. Nearly 95% say AI has made their old data more valuable. But this shift is raising urgent questions about where data lives, who controls it, and what happens when AI agents make their own decisions about money.
In India, the boom in autonomous AI agents that can buy things and move payments is exposing cracks in data rules written before such technology existed. Cashfree Payments and AI companies like Anthropic are pushing back, arguing that enterprises need stronger guardrails built into AI from day one — not bolted on later. Financial institutions and fintech firms say the stakes are too high to wing it.
For years, companies treated old data like basement archives — cheap to store, rarely touched. IDC surveyed 763 decision-makers across seven countries and found hospitals are now pulling decades-old X-rays from storage, telecom firms are mining historical call logs, and governments are digitizing physical records that had been gathering dust. The reason: AI models train better on larger datasets. But moving that data online costs money and creates security headaches.
The shift is massive. Nearly all organizations — 95% — say their historical data now matters more than ever because AI can extract hidden patterns from it. IDC found 75.9% are actively bringing sleeping data back to life. The catch: old data wasn't designed for real-time use. It was protected like a vault. Now it has to move fast.
India's rules say financial data must stay in India. But those rules were written in a world without AI agents — software that can make purchases and payments on your behalf. Cashfree Payments co-founder Reeju Datta warned at the Global Fintech Fest 2026 that credentials stored overseas create a dangerous gray area. If an agent has access to your payment details in another country, whose rules apply? Who is liable if something goes wrong?
Datta argued that the company providing the AI agent should bear responsibility for its actions. Autonomy should match risk: buying a coffee? Let the agent decide. Moving money out of a merchant's account? Get human approval first. Cashfree itself keeps sensitive payment data locked in India, inside its own servers, never shared with outside AI models. It uses role-based controls so an agent for one merchant cannot peek at another's ledger.
Anthropic India Managing Director Irina Ghose said the company treats safety and capability as "two sides of the same coin." That means security, privacy, and governance must be woven into AI models when they're built — not patched on after. Major consulting firms like Deloitte, TCS, and Infosys are rethinking how they help financial clients use AI, redesigning workflows to lock down data and limit agent actions.
Ghose emphasized that data residency and privacy are now baseline demands from enterprises. Anthropic distributes models with these guardrails already in place, rather than leaving it to users to figure out. The shift signals a fundamental change: AI safety is no longer optional or an afterthought — it's a core feature that vendors must prove from day one.
Regulators worldwide are scrambling to catch up. Existing data-localization rules don't address autonomous agents or cross-border credential storage. Businesses are asking: If an AI agent moves money or makes a purchase, can it do so across borders? Who gets sued if it breaks the law? India, which has strict financial data rules, must now decide whether those rules cover AI agents operating partially outside the country.
Industry players say the answer is clear: entities providing AI agents should stay liable for what those agents do. They should calibrate autonomy to risk and embed privacy controls into the system's DNA. Without clearer rules and stronger controls, the boom in agentic AI could outpace governance — leaving consumers, merchants, and regulators holding the bag when something breaks.
Publishers
60
Articles
98
Reach
158