Buying guides

What AI providers' data terms allow. Choose the deployment, then the model.

  • Choose the deployment before the model. The same model can be safe for health records through one route and off-limits through another.
  • Business terms stop training on your content, not logging. Sensitive data needs more: zero retention with in-region processing, your own cloud account, or your own servers.
  • A region on a provider account may describe storage, not processing, and a BAA covers only the features it lists.
  • Every route to the top level, self-hosting included, needs a written sovereignty assessment.

We think the first question about any AI service is which deployment you use, not which model, because the contract, the processing region and the operator change with the route.

We map seven kinds of deployment to the six AI Data Levels from our companion post, Data licenses for AI:

  • ADL-0 is public data, and ADL-1 is internal data with no personal data.
  • ADL-2 is ordinary personal data, and ADL-3 is sensitive data such as health records or ID numbers.
  • ADL-4 is data a sector law ties to a signed agreement, such as patient data under HIPAA, the US health privacy law.
  • ADL-5 is data that must stay under one jurisdiction's control.

We read the vendor terms below on 10 October 2026, and they change often. Nothing here is legal advice.

Seven deployments against the six levels

ADL-0 publicADL-1 internalADL-2 personalADL-3 sensitiveADL-4 sector lawADL-5 one jurisdiction
Consumer appNone beyond the source license (yes)nonononono
Business API on standard termsyesyesNo training on your content, plus a DPA for personal data (yes)nonono
Zero data retentionyesyesyesProcessing stays in the labelled region (yes)nono
Region-pinned endpointyesyesyesZero retention as well, or the model is called through your own cloud account (yes)nono
BAA-covered featureyesyesyesyesOnly the features the BAA lists (yes)no
Self-hosted open-weight modelyesyesyesyesyesServers, keys, logs and admin access inside the jurisdiction, plus a sovereignty assessment (yes)
Sovereign cloudyesyesyesyesyesInside the jurisdiction, with a written sovereignty assessment (yes)
  • ADL-0 public

    Consumer app
    None beyond the source license (yes)
    Business API on standard terms
    yes
    Zero data retention
    yes
    Region-pinned endpoint
    yes
    BAA-covered feature
    yes
    Self-hosted open-weight model
    yes
    Sovereign cloud
    yes
  • ADL-1 internal

    Consumer app
    no
    Business API on standard terms
    yes
    Zero data retention
    yes
    Region-pinned endpoint
    yes
    BAA-covered feature
    yes
    Self-hosted open-weight model
    yes
    Sovereign cloud
    yes
  • ADL-2 personal

    Consumer app
    no
    Business API on standard terms
    No training on your content, plus a DPA for personal data (yes)
    Zero data retention
    yes
    Region-pinned endpoint
    yes
    BAA-covered feature
    yes
    Self-hosted open-weight model
    yes
    Sovereign cloud
    yes
  • ADL-3 sensitive

    Consumer app
    no
    Business API on standard terms
    no
    Zero data retention
    Processing stays in the labelled region (yes)
    Region-pinned endpoint
    Zero retention as well, or the model is called through your own cloud account (yes)
    BAA-covered feature
    yes
    Self-hosted open-weight model
    yes
    Sovereign cloud
    yes
  • ADL-4 sector law

    Consumer app
    no
    Business API on standard terms
    no
    Zero data retention
    no
    Region-pinned endpoint
    no
    BAA-covered feature
    Only the features the BAA lists (yes)
    Self-hosted open-weight model
    yes
    Sovereign cloud
    yes
  • ADL-5 one jurisdiction

    Consumer app
    no
    Business API on standard terms
    no
    Zero data retention
    no
    Region-pinned endpoint
    no
    BAA-covered feature
    no
    Self-hosted open-weight model
    Servers, keys, logs and admin access inside the jurisdiction, plus a sovereignty assessment (yes)
    Sovereign cloud
    Inside the jurisdiction, with a written sovereignty assessment (yes)

Each deployment clears every level up to its highest one, under the condition written beside that level.

Consumer apps take public data only

A consumer app is the wrong place for anything above ADL-0, even with training switched off, because the training choice belongs to each user, and a company cannot audit it. OpenAI says it may train on content from services such as ChatGPT unless the user opts out. Anthropic uses consumer chats to improve its models when the user allows it, and flagged chats to improve its safety systems.

Business APIs stop training, not logging

Business terms are the floor for company data, not a pass for sensitive data. They exclude customer content from training by default, which clears ADL-1.

What each provider's business terms say

OpenAIAnthropicGoogle CloudMicrosoft AzureAmazon Bedrock
Training on your contentExcluded by defaultExcluded by defaultExcluded by defaultExcluded by defaultModel providers have no access to the accounts that run their models, or to customer prompts
Where processing happensTen storage regions, but in-region processing only in the United States, Europe and the United Arab Emirates, not in India or the United KingdomInference geo is US or global, and workspace geo is currently US onlyRequests to global endpoints "may be processed in any Google Cloud location around the world"Global deployments may process prompts in any geography where the model is deployed; DataZone deployments stay in the United States or the EUInference profiles keep inference inside a geography such as the EU; global profiles can use any commercial AWS Region
Business associate agreementOffered for its APIOffered for its HIPAA-ready servicesLists generative AI on its Agent Platform as coveredSigned for its enterprise cloud servicesOn AWS's HIPAA eligible list

Inference is the step where a model processes a prompt and returns an answer. Vendor terms read on 10 October 2026.

Personal data at ADL-2 also needs a data processing agreement, or DPA, which GDPR requires with every vendor that processes personal data for you, plus a lawful transfer mechanism if the data leaves its home jurisdiction.

The same terms keep logs. OpenAI keeps abuse-monitoring logs for up to 30 days, and Anthropic deletes API data within 30 days by default, which suits support tickets at ADL-2 but not health records at ADL-3.

Zero data retention still has exceptions

Zero data retention, or ZDR, is the contract term under which the provider keeps no prompts or outputs, apart from listed exceptions. OpenAI and Anthropic grant ZDR by approval, and Google takes requests for an exception to its abuse-monitoring logs.

Anthropic keeps User Safety classifier results, and says certain Covered Models require 30-day retention and are not available with ZDR unless it authorizes an exception. OpenAI may make a model ineligible for ZDR when needed to investigate or prevent severe risk. Write the exceptions you accept into the label.

Regional storage is not regional processing

A region on a provider account can describe where data is stored, where it is processed, or both. From ADL-3 up, only in-region processing counts, and providers draw that line differently, as the table above shows.

Take a hypothetical health insurer that summarizes claim notes labelled ADL-3-IN, meaning sensitive data governed from India.

  1. Claim notes: labelled ADL-3-IN. Leads to OpenAI India region (fails), Your cloud account, Open-weight model.
  2. OpenAI India region: may process outside India.
  3. Your cloud account: Indian region, where offered. Leads to Choose the model.
  4. Open-weight model: on your own servers. Leads to Choose the model.
  5. Choose the model: from the routes that clear it.
OpenAI's India region stores data in India but does not process it there, so that endpoint does not meet the level. The insurer's own cloud account in an Indian region, or an open-weight model on its own servers, does.

The in-country rule comes from the framework, not from India's DPDP Act, whose Rules were notified on 14 November 2025 with an 18-month phased compliance timeline.

The route matters even for one model, because your own cloud account changes who sees the data. In Claude in Amazon Bedrock, AWS runs the inference infrastructure and Anthropic personnel have no access to it. In Claude Platform on AWS, Anthropic runs the service as the data processor, and the HIPAA-ready program is not available, so the two routes can sit at different levels.

A BAA covers features, not vendors

For patient data at ADL-4, HIPAA requires a business associate agreement, or BAA, with every vendor that creates, receives, maintains or transmits protected health information for a covered entity, such as a health plan or health care provider.

A signed BAA covers only the features it lists. Anthropic warns that "a feature can be available and still not be covered," and OpenAI points customers to its list of HIPAA-eligible products. OpenAI also says that accepting a BAA does not, by itself, make an application HIPAA compliant. Several Vertex AI products now carry Gemini Enterprise Agent Platform names, so check each feature against the current covered list, under its current name.

Self-hosting moves the work to you

Open-weight models, whose trained parameters you can download and run yourself on an open-source server such as vLLM, keep all data on your servers, and your team carries the operations.

We disagree with treating self-hosting as the safe default. It removes the model vendor from the data path, so it can carry ADL-3 and ADL-4 without zero-retention terms or a model vendor's BAA, and it is the plainest route to ADL-5.

But the controls a vendor ran are now yours: access control, patching, logging, and the evaluations that show the model still works. Servers in someone else's cloud put that provider in the data path, under its terms and agreements.

Sovereign clouds need a written assessment

A sovereign cloud is a cloud region or service that its provider says keeps data, operations and control inside one jurisdiction. These offerings target ADL-5. The dates and the sovereignty claims below are each provider's own.

Sovereign clouds, by date

  1. 2 Sep 2021OVHcloud's Hosted Private Cloud becomes available with SecNumCloud

    SecNumCloud is the trusted-cloud qualification from France's cybersecurity agency, ANSSI.

  2. 31 Jul 2023Oracle EU Sovereign Cloud opens in Frankfurt and Madrid

    The date comes from Oracle's release notes.

  3. 21 May 2025Google Cloud sets out Data Boundary, Dedicated and Air-Gapped

    Google says that PREMI3NS, the S3NS service in France built on Dedicated, holds SecNumCloud 3.2 qualification.

  4. 16 Jun 2025Microsoft announces Microsoft Sovereign Cloud

    Partner clouds are run by Bleu in France and Delos Cloud in Germany.

  5. 15 Jan 2026AWS launches its European Sovereign Cloud in Brandenburg, Germany

    AWS says only EU residents operate it.

  6. 24 Feb 2026Microsoft adds support for large AI models in fully disconnected environments

  7. 1 Sep 2026OVHcloud announces SecNumCloud for its SNC Cloud Platform

  8. 17 Sep 2026AWS offers open-weight Gemma 4 models on Amazon Bedrock in its European Sovereign Cloud

  9. 24 Oct 2026AWS says it will run the cloud without its global network backbone for several hours

We do not treat the word "sovereign" as settled. The US CLOUD Act of March 2018 covers data in a provider's "possession, custody, or control, regardless of whether" it is stored in the United States or abroad, and a provider subject to US law must meet its US obligations to preserve or disclose that data.

Whether a sovereign cloud owned by a US company is outside that reach is a legal judgment. ADL-5 therefore requires a written sovereignty assessment for every deployment, self-hosted ones included.

Choose the deployment, then the model

Name the data's level, list the deployments that clear it, then pick the best model they offer. Comparing models first can waste the comparison, because the winner may only be offered on a route the data cannot use.

We work across Claude, GPT, Gemini and open-weight models and keep client data in client accounts wherever possible, so for us the route is the decision that carries the risk.

Start with one check

  1. List every AI endpoint your systems call

  2. Write down four facts for each

    Its deployment kind, where it processes data, what it retains and which agreement covers it.

  3. Compare them with the level of the data it receives

    The levels are in Data licenses for AI.

  4. Fix any endpoint that falls short first

  5. Repeat the check on each label's review date

    Terms change.

For a second reviewer on your endpoint list, talk to us.

Sources

Companion post

  • extendfuture, Data licenses for AI, which defines the six AI Data Levels, ADL-0 to ADL-5, with the full table of rules for each level.

Vendor data terms, read on 10 October 2026

Sovereign clouds

Law and tools

· views
Amol PatilFounderFounded extendfuture in 2019. Has shipped computer vision, voice and agentic systems into production across ten industries. Amol Patil on LinkedIn

Working on something in this territory?

Tell us what you are trying to win. We answer within one business day, from the people who build.