From today, a prosecutor in one Member State can send a production order straight to your cloud or AI vendor in another, and the vendor has ten days to hand over the data. Eight hours if the case is an emergency.
No mutual legal assistance, no court in your country, and quite possibly no call to you.
What the production order changes today
A production order is not a request. It is a mutual recognition instrument, which means the receiving provider is expected to execute it rather than negotiate with it.
The e-Evidence Regulation, Regulation (EU) 2023/1543, became applicable on 18 August 2026 after a three-year transition. Its companion, Directive (EU) 2023/1544, had a transposition deadline of 18 February 2026.
Together they create two instruments. A European Production Order compels a service provider to hand over electronic evidence. A European Preservation Order compels it to keep specific data intact while a further request takes shape. The preservation order buys time; the production order does the work.
The speed is the story. A production order runs on ten days, or eight hours in an emergency. The Commission contrasts that with up to 120 days under a European Investigation Order and an average of ten months under mutual legal assistance.
Every provider in scope needs an EU address
The Directive obliges every service provider offering services in the Union to designate an establishment or appoint a legal representative inside the EU, specifically to receive and act on these orders.
That obligation ignores where the company keeps its headquarters. A provider in California serving EU users needs an EU addressee. Once it has one, a production order can land there.
Why this reaches your AI stack
Here is the part that has been missed in the AI governance conversation.
Electronic evidence is defined as data stored by or on behalf of a service provider. On behalf of. Your vendor holds prompts, outputs, logs and account records that belong to your organisation, and that data sits inside the definition.
The scope covers electronic communications services, internet domain and IP services, plus other information society services that let users communicate or store and process data. A hosted AI assistant that retains conversations is squarely in that description. So is the cloud platform underneath it.
The categories reached
Orders can seek subscriber data, data used to identify a user, traffic data and content data. Content data is the interesting one, because for an AI deployment content means prompts and generated output. A production order reaching content reaches the substance of what your staff typed.
Financial services sit outside the scope, as do services offered exclusively within a single Member State.
The notification you may not get
The issuing authority must inform the person whose data is sought, as a rule without undue delay. That duty can be postponed where telling them would endanger the investigation.
Read that carefully against your vendor contracts. Your standard law enforcement clause probably promises notification wherever legally permitted. Under a production order, the word permitted is doing more work than it used to.
Where governance actually bites
None of this is exotic. It is the same dependency question that vendor risk work has been circling for two years, arriving with a deadline attached.
Your organisation may not be the addressee
Most deployers are not service providers under this Regulation. You run AI internally, you do not offer a communications or storage service to the public, so a production order goes to your supplier rather than to you.
That sounds like relief. It is closer to the opposite. Being outside scope means you have no procedural role. No standing in the process, no visibility of the request, no opportunity to argue that the data is commercially sensitive. Your supplier decides how to respond, on a clock measured in days.
Four production order questions for your vendor review
- Who is your provider’s designated establishment or legal representative in the EU, and in which Member State? That answer determines which national authorities sit closest to your data.
- What does your contract promise about notification, and does it commit the vendor to tell you at the earliest lawful moment rather than merely when convenient?
- Which of your AI workloads retain content, and for how long? Retention you never needed is now exposure you did not price.
- Does your incident process have a lane for a lawful access request against a third party, or only for a breach? A production order is neither a breach nor an audit, and most playbooks have nowhere to put it.
The AI angle that is genuinely new
Prompts are a new category of business record and nobody has classified them yet.
An engineer pasting a contract into an assistant to summarise it has created content data held by a third party. So has a manager drafting a redundancy note. Two years ago that material lived in a document management system inside the perimeter. Today it sits with a supplier that can receive a production order with a ten day clock on it.
That is not an argument against using the tools. It is an argument for knowing what they keep.
Fold it into the work you are already doing
If you mapped your AI systems for the AI Act, you already hold most of the inventory this needs. What is missing is a retention column, plus a note on where each vendor’s EU addressee sits. Both take an afternoon.
Doing both at once is the efficient move, and it is the same discipline: knowing which obligations attach to you, which attach to your supplier, then what happens in the gap between them. Organisations working through that mapping will find the Future Prep Applied AIGP course covers exactly this territory, because value chain responsibility is where it starts.