Buying guides
What AI providers' data terms allow. Choose the deployment, then the model.
- Choose the deployment before the model. The same model can be safe for health records through one route and off-limits through another.
- Business terms stop training on your content, not logging. Sensitive data needs more: zero retention with in-region processing, your own cloud account, or your own servers.
- A region on a provider account may describe storage, not processing, and a BAA covers only the features it lists.
- Every route to the top level, self-hosting included, needs a written sovereignty assessment.
We think the first question about any AI service is which deployment you use, not which model, because the contract, the processing region and the operator change with the route.
We map seven kinds of deployment to the six AI Data Levels from our companion post, Data licenses for AI:
- ADL-0 is public data, and ADL-1 is internal data with no personal data.
- ADL-2 is ordinary personal data, and ADL-3 is sensitive data such as health records or ID numbers.
- ADL-4 is data a sector law ties to a signed agreement, such as patient data under HIPAA, the US health privacy law.
- ADL-5 is data that must stay under one jurisdiction's control.
We read the vendor terms below on 10 October 2026, and they change often. Nothing here is legal advice.
Seven deployments against the six levels
| ADL-0 public | ADL-1 internal | ADL-2 personal | ADL-3 sensitive | ADL-4 sector law | ADL-5 one jurisdiction | |
|---|---|---|---|---|---|---|
| Consumer app | None beyond the source license (yes) | no | no | no | no | no |
| Business API on standard terms | yes | yes | No training on your content, plus a DPA for personal data (yes) | no | no | no |
| Zero data retention | yes | yes | yes | Processing stays in the labelled region (yes) | no | no |
| Region-pinned endpoint | yes | yes | yes | Zero retention as well, or the model is called through your own cloud account (yes) | no | no |
| BAA-covered feature | yes | yes | yes | yes | Only the features the BAA lists (yes) | no |
| Self-hosted open-weight model | yes | yes | yes | yes | yes | Servers, keys, logs and admin access inside the jurisdiction, plus a sovereignty assessment (yes) |
| Sovereign cloud | yes | yes | yes | yes | yes | Inside the jurisdiction, with a written sovereignty assessment (yes) |
ADL-0 public
- Consumer app
- None beyond the source license (yes)
- Business API on standard terms
- yes
- Zero data retention
- yes
- Region-pinned endpoint
- yes
- BAA-covered feature
- yes
- Self-hosted open-weight model
- yes
- Sovereign cloud
- yes
ADL-1 internal
- Consumer app
- no
- Business API on standard terms
- yes
- Zero data retention
- yes
- Region-pinned endpoint
- yes
- BAA-covered feature
- yes
- Self-hosted open-weight model
- yes
- Sovereign cloud
- yes
ADL-2 personal
- Consumer app
- no
- Business API on standard terms
- No training on your content, plus a DPA for personal data (yes)
- Zero data retention
- yes
- Region-pinned endpoint
- yes
- BAA-covered feature
- yes
- Self-hosted open-weight model
- yes
- Sovereign cloud
- yes
ADL-3 sensitive
- Consumer app
- no
- Business API on standard terms
- no
- Zero data retention
- Processing stays in the labelled region (yes)
- Region-pinned endpoint
- Zero retention as well, or the model is called through your own cloud account (yes)
- BAA-covered feature
- yes
- Self-hosted open-weight model
- yes
- Sovereign cloud
- yes
ADL-4 sector law
- Consumer app
- no
- Business API on standard terms
- no
- Zero data retention
- no
- Region-pinned endpoint
- no
- BAA-covered feature
- Only the features the BAA lists (yes)
- Self-hosted open-weight model
- yes
- Sovereign cloud
- yes
ADL-5 one jurisdiction
- Consumer app
- no
- Business API on standard terms
- no
- Zero data retention
- no
- Region-pinned endpoint
- no
- BAA-covered feature
- no
- Self-hosted open-weight model
- Servers, keys, logs and admin access inside the jurisdiction, plus a sovereignty assessment (yes)
- Sovereign cloud
- Inside the jurisdiction, with a written sovereignty assessment (yes)
Each deployment clears every level up to its highest one, under the condition written beside that level.
Consumer apps take public data only
A consumer app is the wrong place for anything above ADL-0, even with training switched off, because the training choice belongs to each user, and a company cannot audit it. OpenAI says it may train on content from services such as ChatGPT unless the user opts out. Anthropic uses consumer chats to improve its models when the user allows it, and flagged chats to improve its safety systems.
Business APIs stop training, not logging
Business terms are the floor for company data, not a pass for sensitive data. They exclude customer content from training by default, which clears ADL-1.
What each provider's business terms say
| OpenAI | Anthropic | Google Cloud | Microsoft Azure | Amazon Bedrock | |
|---|---|---|---|---|---|
| Training on your content | Excluded by default | Excluded by default | Excluded by default | Excluded by default | Model providers have no access to the accounts that run their models, or to customer prompts |
| Where processing happens | Ten storage regions, but in-region processing only in the United States, Europe and the United Arab Emirates, not in India or the United Kingdom | Inference geo is US or global, and workspace geo is currently US only | Requests to global endpoints "may be processed in any Google Cloud location around the world" | Global deployments may process prompts in any geography where the model is deployed; DataZone deployments stay in the United States or the EU | Inference profiles keep inference inside a geography such as the EU; global profiles can use any commercial AWS Region |
| Business associate agreement | Offered for its API | Offered for its HIPAA-ready services | Lists generative AI on its Agent Platform as covered | Signed for its enterprise cloud services | On AWS's HIPAA eligible list |
OpenAI
- Training on your content
- Excluded by default
- Where processing happens
- Ten storage regions, but in-region processing only in the United States, Europe and the United Arab Emirates, not in India or the United Kingdom
- Business associate agreement
- Offered for its API
Anthropic
- Training on your content
- Excluded by default
- Where processing happens
- Inference geo is US or global, and workspace geo is currently US only
- Business associate agreement
- Offered for its HIPAA-ready services
Google Cloud
- Training on your content
- Excluded by default
- Where processing happens
- Requests to global endpoints "may be processed in any Google Cloud location around the world"
- Business associate agreement
- Lists generative AI on its Agent Platform as covered
Microsoft Azure
- Training on your content
- Excluded by default
- Where processing happens
- Global deployments may process prompts in any geography where the model is deployed; DataZone deployments stay in the United States or the EU
- Business associate agreement
- Signed for its enterprise cloud services
Amazon Bedrock
- Training on your content
- Model providers have no access to the accounts that run their models, or to customer prompts
- Where processing happens
- Inference profiles keep inference inside a geography such as the EU; global profiles can use any commercial AWS Region
- Business associate agreement
- On AWS's HIPAA eligible list
Inference is the step where a model processes a prompt and returns an answer. Vendor terms read on 10 October 2026.
Personal data at ADL-2 also needs a data processing agreement, or DPA, which GDPR requires with every vendor that processes personal data for you, plus a lawful transfer mechanism if the data leaves its home jurisdiction.
The same terms keep logs. OpenAI keeps abuse-monitoring logs for up to 30 days, and Anthropic deletes API data within 30 days by default, which suits support tickets at ADL-2 but not health records at ADL-3.
Zero data retention still has exceptions
Zero data retention, or ZDR, is the contract term under which the provider keeps no prompts or outputs, apart from listed exceptions. OpenAI and Anthropic grant ZDR by approval, and Google takes requests for an exception to its abuse-monitoring logs.
Anthropic keeps User Safety classifier results, and says certain Covered Models require 30-day retention and are not available with ZDR unless it authorizes an exception. OpenAI may make a model ineligible for ZDR when needed to investigate or prevent severe risk. Write the exceptions you accept into the label.
Regional storage is not regional processing
A region on a provider account can describe where data is stored, where it is processed, or both. From ADL-3 up, only in-region processing counts, and providers draw that line differently, as the table above shows.
Take a hypothetical health insurer that summarizes claim notes labelled ADL-3-IN, meaning sensitive data governed from India.
- Claim notes: labelled ADL-3-IN. Leads to OpenAI India region (fails), Your cloud account, Open-weight model.
- OpenAI India region: may process outside India.
- Your cloud account: Indian region, where offered. Leads to Choose the model.
- Open-weight model: on your own servers. Leads to Choose the model.
- Choose the model: from the routes that clear it.
The in-country rule comes from the framework, not from India's DPDP Act, whose Rules were notified on 14 November 2025 with an 18-month phased compliance timeline.
The route matters even for one model, because your own cloud account changes who sees the data. In Claude in Amazon Bedrock, AWS runs the inference infrastructure and Anthropic personnel have no access to it. In Claude Platform on AWS, Anthropic runs the service as the data processor, and the HIPAA-ready program is not available, so the two routes can sit at different levels.
A BAA covers features, not vendors
For patient data at ADL-4, HIPAA requires a business associate agreement, or BAA, with every vendor that creates, receives, maintains or transmits protected health information for a covered entity, such as a health plan or health care provider.
A signed BAA covers only the features it lists. Anthropic warns that "a feature can be available and still not be covered," and OpenAI points customers to its list of HIPAA-eligible products. OpenAI also says that accepting a BAA does not, by itself, make an application HIPAA compliant. Several Vertex AI products now carry Gemini Enterprise Agent Platform names, so check each feature against the current covered list, under its current name.
Self-hosting moves the work to you
Open-weight models, whose trained parameters you can download and run yourself on an open-source server such as vLLM, keep all data on your servers, and your team carries the operations.
We disagree with treating self-hosting as the safe default. It removes the model vendor from the data path, so it can carry ADL-3 and ADL-4 without zero-retention terms or a model vendor's BAA, and it is the plainest route to ADL-5.
But the controls a vendor ran are now yours: access control, patching, logging, and the evaluations that show the model still works. Servers in someone else's cloud put that provider in the data path, under its terms and agreements.
Sovereign clouds need a written assessment
A sovereign cloud is a cloud region or service that its provider says keeps data, operations and control inside one jurisdiction. These offerings target ADL-5. The dates and the sovereignty claims below are each provider's own.
Sovereign clouds, by date
2 Sep 2021OVHcloud's Hosted Private Cloud becomes available with SecNumCloud
SecNumCloud is the trusted-cloud qualification from France's cybersecurity agency, ANSSI.
31 Jul 2023Oracle EU Sovereign Cloud opens in Frankfurt and Madrid
The date comes from Oracle's release notes.
21 May 2025Google Cloud sets out Data Boundary, Dedicated and Air-Gapped
Google says that PREMI3NS, the S3NS service in France built on Dedicated, holds SecNumCloud 3.2 qualification.
16 Jun 2025Microsoft announces Microsoft Sovereign Cloud
Partner clouds are run by Bleu in France and Delos Cloud in Germany.
15 Jan 2026AWS launches its European Sovereign Cloud in Brandenburg, Germany
AWS says only EU residents operate it.
24 Feb 2026Microsoft adds support for large AI models in fully disconnected environments
1 Sep 2026OVHcloud announces SecNumCloud for its SNC Cloud Platform
17 Sep 2026AWS offers open-weight Gemma 4 models on Amazon Bedrock in its European Sovereign Cloud
24 Oct 2026AWS says it will run the cloud without its global network backbone for several hours
We do not treat the word "sovereign" as settled. The US CLOUD Act of March 2018 covers data in a provider's "possession, custody, or control, regardless of whether" it is stored in the United States or abroad, and a provider subject to US law must meet its US obligations to preserve or disclose that data.
Whether a sovereign cloud owned by a US company is outside that reach is a legal judgment. ADL-5 therefore requires a written sovereignty assessment for every deployment, self-hosted ones included.
Choose the deployment, then the model
Name the data's level, list the deployments that clear it, then pick the best model they offer. Comparing models first can waste the comparison, because the winner may only be offered on a route the data cannot use.
We work across Claude, GPT, Gemini and open-weight models and keep client data in client accounts wherever possible, so for us the route is the decision that carries the risk.
Start with one check
List every AI endpoint your systems call
Write down four facts for each
Its deployment kind, where it processes data, what it retains and which agreement covers it.
Compare them with the level of the data it receives
The levels are in Data licenses for AI.
Fix any endpoint that falls short first
Repeat the check on each label's review date
Terms change.
For a second reviewer on your endpoint list, talk to us.
Sources
Companion post
- extendfuture, Data licenses for AI, which defines the six AI Data Levels, ADL-0 to ADL-5, with the full table of rules for each level.
Vendor data terms, read on 10 October 2026
- OpenAI, Data controls in the OpenAI platform, Getting a Business Associate Agreement for the OpenAI API and How your data is used to improve model performance.
- Anthropic, How long do you store my organization's data?, Zero data retention, BAAs for commercial customers, commercial training policy, consumer training policy, Data residency, Claude in Amazon Bedrock and Claude Platform on AWS.
- Google Cloud, Zero data retention, Data residency, Name changes from Vertex AI and HIPAA compliance.
- Microsoft, Data, privacy and security for models sold by Azure in Foundry and HIPAA and the HITECH Act.
- AWS, Data protection in Amazon Bedrock, Cross-Region inference and HIPAA Eligible Services Reference, updated 3 September 2026.
Sovereign clouds
- OVHcloud, Hosted Private Cloud SecNumCloud availability, 2 September 2021, and SNC Cloud Platform qualification, 1 September 2026.
- Oracle, Oracle EU Sovereign Cloud is now available, release date 31 July 2023.
- Google Cloud, Google advances sovereignty, choice, and security in the cloud, 21 May 2025, and Delivering a secure, open, and sovereign digital world, February 2026.
- Microsoft, Announcing comprehensive sovereign solutions, 16 June 2025, and Microsoft Sovereign Cloud adds support for large AI models running disconnected, 24 February 2026.
- AWS, AWS launches AWS European Sovereign Cloud, 15 January 2026; Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud, 17 September 2026; Demonstrating an independent operation, 28 September 2026.
Law and tools
- EU, General Data Protection Regulation, Article 28 on processor contracts and Chapter V on transfers.
- US eCFR, 45 CFR 160.103, definitions including protected health information and covered entity, and 164.502, business associate agreements.
- Press Information Bureau, Government of India, Government notifies DPDP Rules, 14 November 2025.
- US Department of Justice, CLOUD Act Resources; Cornell Legal Information Institute, 18 U.S.C. 2713.
- vLLM, an open-source inference and serving engine for language models.