A safety grade tells you how seriously a company takes AI safety research. It does not tell you whether you can deploy their model and defend it to an auditor. This tracks both, with a primary source and a verification date on every cell.
Vendors come in two kinds, and conflating them is the most common mistake in AI vendor selection. Model developers build the models and are graded by the Future of Life Institute.Deployment platforms host other companies' models under their own commercial and compliance terms, and FLI does not grade them at all.
The safety grade travels with the model. The compliance terms travel with the platform.
You can run a top-graded developer's model through a platform FLI never assessed, under that platform's BAA. Those are two different columns, and you need both.
Every cell carries the primary source it came from and the date we last read it. Where a vendor's wording is hedged or carries exclusions, we quote it rather than summarise it — the exclusions are usually the part that matters.
Three ways a cell can be empty
Not applicable
The question does not apply to this kind of vendor — a platform has no FLI grade.
Not publicly documented
We looked and could not find it published. That is a finding about the vendor.
Not yet verified
We have not checked yet. That is a finding about us, and we will not dress it up as anything else.
Compare vendors
Safety grades and compliance terms side by side. Every cell carries a primary source and the date it was last checked — select one to see them.
as of August 8, 2026
AI vendor assurance comparison. Vendors in columns, assurance criteria in rows. Select any cell for its source and verification date.
Criterion
AnthropicDeveloper
Azure OpenAI (Microsoft Foundry)Platform
OpenAIDeveloper
Google DeepMindDeveloper
MetaDeveloper
Mistral AIDeveloper
Amazon BedrockPlatform
FLI safety gradeSafety-research posture, per the Future of Life Institute
BAA availableWill they sign a business associate agreement for PHI
CertificationsIndependently audited attestations
Trains on your dataWhether your inputs and outputs feed model training
RetentionHow long your data is kept, and where
SubprocessorsWho else processes your data
EU AI ActObligations, and which transfer to you as deployer
Select any cell for the full value, its primary source, and when it was last checked.
No cell selected.
7 vendors — 5 model developers and 2 deployment platforms. Every one of the 49 cells carries a primary source and the date we last read it. 6 cells read “not publicly documented” — we looked and the vendor does not publish it.
What each criterion means
Seven questions that decide whether an AI deployment survives an audit, and what a strong answer to each one looks like.
FLI safety grade
The Future of Life Institute grades frontier model developers across 37 indicators in six domains — risk assessment, current harms, safety frameworks, existential safety, governance and accountability, and information sharing — with scoring reviewed by an independent expert panel.
Why it matters. It is the closest thing the industry has to an external, methodologically transparent assessment of how seriously a developer takes safety. It is also the single most misread number in AI procurement, because it says nothing about whether you can deploy that developer’s model under HIPAA and defend the decision.
What good looks like. Treat the grade as one input and read the domain breakdown rather than the headline. In the Summer 2026 edition no company scored above C+ overall, and the best existential-safety grade in the entire field was a D+ — so a high relative grade is not a passing absolute one.
BAA available
A Business Associate Agreement is the contract HIPAA requires before a vendor may process protected health information on your behalf. Without one, the vendor cannot lawfully touch PHI, regardless of how secure the platform is.
Why it matters. This is a yes-or-no gate on healthcare deployments, and vendor-level answers are routinely wrong because coverage is set per feature, not per company. A vendor can offer a BAA while excluding the exact surface you intended to use.
What good looks like. A written BAA naming the specific products and API surfaces in scope, plus an explicit list of what is excluded. Ask which features are carved out and whether beta functionality is covered — the exclusions are usually where the risk is.
Certifications
Third-party attestations that controls were assessed by an accredited auditor: SOC 2 Type II for operating effectiveness over time, ISO/IEC 27001 for information security management, ISO/IEC 42001 for AI management systems specifically, HITRUST CSF where healthcare is involved.
Why it matters. Certifications are the evidence an auditor will accept without re-performing the work themselves. They also differ sharply in what they prove: Type I is a point-in-time design assessment, Type II tests whether controls actually operated across a period.
What good looks like. SOC 2 Type II plus ISO/IEC 27001 as a baseline, with the report obtainable under NDA rather than merely referenced on a marketing page. ISO/IEC 42001 is still uncommon and is a meaningful signal that AI governance is managed as a system rather than improvised.
Trains on your data
Whether prompts, completions, embeddings and uploaded files are used to train or improve models — by default, on opt-in, or not at all — and whether that differs between consumer and commercial tiers.
Why it matters. If your inputs train a shared model, confidential material has left your control in a way no retention policy can undo. Consumer and commercial tiers of the same product frequently have opposite defaults, so the answer depends on which contract you are actually on.
What good looks like. A written default of no training on commercial data, with any exception requiring an affirmative act by you. Confirm whether submitting feedback counts as consent, and confirm the answer applies to the tier you are buying rather than the enterprise tier you were shown.
Retention
How long prompts, outputs and logs are stored, in which jurisdictions, under whose encryption keys, and whether abuse-monitoring copies are kept separately from the operational path.
Why it matters. Retention drives breach exposure, records obligations and cross-border transfer analysis all at once. It is also the answer most likely to have a second layer: many platforms retain a monitoring copy even when the primary path is zero-retention.
What good looks like. A stated period, a named geography, and a documented route to zero retention if you need it. Ask specifically whether abuse or safety monitoring retains data outside the main retention policy, and whether you can verify the setting rather than being told it.
Subprocessors
The published list of third parties that process customer data on the vendor’s behalf — hosting, inference, moderation, support tooling — and the notice you receive before that list changes.
Why it matters. Your obligations flow through to every subprocessor. Under GDPR you need a lawful basis for each, and under a BAA each must be bound by equivalent terms. A vendor that will not enumerate its subprocessors cannot be assessed, only trusted.
What good looks like. A public, versioned subprocessor list with advance notice of additions and a documented right to object. Silence here is a finding in itself, not a neutral absence.
EU AI Act
How the vendor classifies its models under the EU AI Act — notably general-purpose AI obligations — and which duties it considers yours as the deployer rather than its own as the provider.
Why it matters. The Act assigns obligations to deployers directly. Buying from an EU-based vendor does not transfer them to that vendor, and the top-scoring European company on the Summer 2026 safety index was in fact the lowest-graded company in the field — jurisdiction is not a proxy for posture.
What good looks like. A written statement of the vendor’s classification and the documentation it will supply to support your own conformity work, with the provider/deployer split made explicit rather than left to inference.
Every claim, in full
The complete record behind each cell — the vendor’s own wording where it is hedged or carries exclusions, its primary source, and the date we last read it. Verified August 8, 2026.
AnthropicModel developerFrontier model developer. Claude via first-party API, Enterprise plans, and Claude Code.
FLI safety grade
Highest overall grade in the Index, leading five of six domains. Its Existential Safety domain grade was D+, the highest any company received in that domain.Primary source · verified 2026-08-04
BAA available
Anthropic: "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." Coverage is narrower than that sentence suggests. The BAA "only covers the single organization that accepted it, and excludes features such as Workbench, Claude Console, Claude Cowork, or features currently in beta." Batch API, Files API, Computer Use, and Web Fetch are stated as not covered and not accessible to HIPAA-ready API users. Claude Code is covered only with Zero Data Retention enabled. Check feature-level coverage, not vendor-level.Primary source · verified 2026-08-04
Certifications
ISO/IEC 42001:2023 is the AI management system standard, still uncommon among frontier developers. Reports are available through the Anthropic Trust Portal.Primary source · verified 2026-08-04
Trains on your data
Anthropic: "By default, we will not use your inputs or outputs from our commercial products to train our models." Applies to commercial products; consumer tiers are governed separately.Primary source · verified 2026-08-04
Retention
This figure covers feedback data specifically. General API retention and Zero Data Retention terms are documented separately and are not yet verified here.Primary source · verified 2026-08-04
Subprocessors
The per-product scoping is the distinguishing feature: entries read "All Products except Claude for Government", "Claude Free/Pro/Max" or "Claude for Work" rather than applying blanket. Claude for Government is carved out of every user-support, analytics and fraud-detection sub-processor and runs on Palantir Federal Cloud Service instead. Infrastructure runs on all three major clouds — Google Cloud Platform, Amazon Web Services and Microsoft Azure, each Worldwide. No advance-notice period is published; the Trust Center offers a subscribe-to-updates control rather than a committed notice window, which puts Anthropic alongside OpenAI and Mistral and behind Microsoft and AWS.Primary source · verified 2026-08-08
EU AI Act
Read from the European Commission's own signatory list rather than from any vendor announcement. The Commission cautions that "Some signatories may not appear immediately, but we are making sure to continuously update the list as signatures are confirmed", so absence from the list is weaker evidence than presence on it.Primary source · verified 2026-08-07
Azure OpenAI (Microsoft Foundry)Deployment platformDeployment platform. Hosts OpenAI models in Microsoft's Azure environment under Microsoft's commercial terms — frequently the compliant route to a model whose direct API is not.
FLI safety gradeNot applicable
FLI grades model developers, not deployment platforms. The safety grade that bears on this row belongs to the model developer (OpenAI); the compliance terms below are Microsoft's. That split is the reason this tracker separates the two row kinds.Primary source · verified 2026-08-04
BAA available
Microsoft: the HIPAA BAA "is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." Azure and Azure Government are named in the in-scope services list. Microsoft also states plainly that a BAA does not by itself achieve HIPAA compliance for the customer.Primary source · verified 2026-08-04
Certifications
Microsoft: services covered under the BAA "undergo audits conducted by accredited independent auditors for the Microsoft ISO/IEC 27001 certification and the HITRUST Common Security Framework (CSF) certification." Audit reports are obtained through the Service Trust Portal.Primary source · verified 2026-08-04
Trains on your data
Microsoft states prompts, completions, embeddings and training data "are NOT available to OpenAI or other providers of Models sold by Azure", "are NOT used by providers... to improve their models or services", and "are NOT used to train any generative AI foundation models without your permission or instruction." Also: "The models are stateless: no prompts or completions are stored in the model."Primary source · verified 2026-08-04
Retention
Modified abuse monitoring must be applied for and approved. Once approved, "the data storage and human review process described above is not performed", though automated review may continue. Customers can verify the state via the ContentLogging attribute in the Azure portal or CLI, which appears as "false" only when storage is off. Data stored at rest sits in the customer's Azure tenant within their designated geography; Global and DataZone deployment types change where processing occurs.Primary source · verified 2026-08-04
Subprocessors
Microsoft: "Microsoft publishes the names of any new subprocessors for its online services at least six months in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data." The longest advance-notice commitment of any vendor tracked here. The list "is applicable for all Microsoft Online Services governed by the Microsoft Data Protection Addendum"; notification is via the Service Trust Portal’s My library rather than a separate subscription.Primary source · verified 2026-08-07
EU AI Act
The signatory here is Microsoft, the platform operator. OpenAI, whose models this platform hosts, is separately a signatory in its own right. Both rows carry the commitment independently, which is the distinction this tracker exists to keep visible.Primary source · verified 2026-08-07
OpenAIModel developerFrontier model developer. GPT models via the first-party API Platform, plus ChatGPT Business, Enterprise, Edu and Healthcare workspaces.
FLI safety grade
Second overall of the nine companies graded. Shared the highest Existential Safety grade awarded to anyone in the Index, a D+.Primary source · verified 2026-08-07
BAA available
OpenAI: "We are able to sign Business Associate Agreements (BAA) in support of customers’ compliance with the Health Insurance Portability and Accountability Act (HIPAA). Please reach out if you require a BAA." Phrased as a capability exercised on request rather than a standing term, and this page states no feature-level exclusions — unlike Anthropic, which enumerates them. Confirm scope in the executed agreement. ChatGPT for Healthcare is described separately as "a secure workspace designed to support HIPAA compliance".Primary source · verified 2026-08-05
Certifications
Taken from the Compliance section of OpenAI’s Trust Portal. Note a mismatch worth carrying into diligence: the portal’s prose says only that "Our products are also ISO 27001, 27017, 27018, and 27701 certified" — ISO/IEC 42001:2023, the AI management system standard, appears in the badge list but not in that sentence. The ISO 27001 certificate is scoped "for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services", so certification scope is narrower than the product surface.Primary source · verified 2026-08-07
Trains on your data
OpenAI: "By default, we do not use your business data for training our models. If you have explicitly opted in to share your data with us (for example, through our opt-in feedback mechanisms) to improve our services, then we may use the shared data to train our models." The exclusion is dated: it covers API Platform data "(after March 1, 2023)".Primary source · verified 2026-08-05
Retention
OpenAI: "Except for certain endpoints and features listed in our platform documentation, OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case." ZDR is conditional on both endpoint eligibility and a "qualifying use-case", so it is not a setting a customer can simply switch on. Fine-tuning data is retained "until the customer deletes the files".Primary source · verified 2026-08-05
Subprocessors
Last updated by OpenAI on June 2, 2026. Columns are Entity Name, OpenAI Product or Service, Location of Processing and Purpose of Processing, which is more granular than a bare name list. Notification is opt-in and un-timed: "Sign up to receive notification of new third party Subprocessors by filling out this form." No advance-notice period is committed to, in contrast to AWS (30 days) and Microsoft (six months).Primary source · verified 2026-07-08
EU AI Act
Read from the European Commission’s published signatory list rather than from OpenAI’s own announcement.Primary source · verified 2026-08-07
Google DeepMindModel developerFrontier model developer. This row describes the Gemini Developer API on its paid tier — the first-party route. Gemini bought through Vertex AI on Google Cloud is a different contractual product with a materially different compliance posture, and is not yet tracked here.
FLI safety grade
Third overall of the nine companies graded, and the only company other than Anthropic and OpenAI to clear an F in the Existential Safety domain, with a D.Primary source · verified 2026-08-07
BAA availableNot publicly documented
Google documents BAA scope as an explicit list of Covered Products and instructs customers to "Disable or otherwise ensure that you do not use Google Cloud Products that are not explicitly covered by the BAA (see Covered Products) when working with PHI." The Gemini Developer API and Google AI Studio do not appear on that list, which covers Google Cloud products such as Gemini Enterprise, Gemini Code Assist and Gemini in BigQuery. The list read on 2026-08-07 also contained no entry for Vertex AI itself, only "Vertex AI Workbench instances". A buyer with PHI should treat the developer API as out of scope and confirm the exact Google Cloud product against that list.Primary source · verified 2026-08-07
CertificationsNot publicly documented
No certification scope covering the Gemini Developer API specifically was found in the API additional terms, the API documentation, or Google Cloud’s compliance pages, which are scoped to Google Cloud products. Google holds an extensive certification portfolio, but it attaches to Google Cloud and Workspace rather than to this developer surface. This is a finding about where the certifications are scoped, not a claim that Google lacks them.Primary source · verified 2026-08-07
Trains on your data
The split is the whole story here. Paid: "Google doesn’t use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products." Unpaid: "Google uses the content you submit to the Services and any generated responses to provide, improve, and develop Google products and services", and "Human reviewers may read, annotate, and process your API input and output." An API key that has not been attached to billing carries the unpaid terms.Primary source · verified 2026-08-07
Retention
Google: "Google logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy… and any required legal or regulatory disclosures." The period is not quantified anywhere in the terms. Every other developer tracked here publishes a number or an explicit zero-retention path; this one does not, which is the material difference for a buyer who must document retention.Primary source · verified 2026-08-07
SubprocessorsNot publicly documented
Google publishes a detailed sub-processor list for Google Cloud, with advance notice governed by the Cloud Data Processing Addendum and notification sent to Essential Contacts without any need to subscribe. That page is scoped to Google Cloud. No equivalent disclosure scoped to the Gemini Developer API was located.Primary source · verified 2026-08-07
EU AI Act
The Commission lists the signatory as "Google". Read from the Commission’s published list rather than from a vendor announcement.Primary source · verified 2026-08-07
MetaModel developerFrontier model developer, and the only one here that also distributes open weights. This row describes the hosted Meta Model API on Standard Services — the tier where Meta acts as your processor. The cheaper Discounted Services tier trains on your content by default, and self-hosting the open weights moves every question below to whoever runs them.
FLI safety grade
Fourth overall of the nine companies graded, up from sixth in the Winter 2025 edition. Received an F in the Existential Safety domain, as did every company other than Anthropic, OpenAI and Google DeepMind.Primary source · verified 2026-08-07
BAA availableNot publicly documented
Neither the Meta Model API Terms of Service, Meta's general Terms of Service, nor Meta's Privacy Policy contains any occurrence of "HIPAA" or "Business Associate". The terms point the other way for the discounted tier: "You must not submit sensitive, confidential, or personal information to the Discounted Services. If you intend, or are required (including by contract), to keep information such as software code confidential, you must not submit that information to the Discounted Services."Primary source · verified 2026-08-08
CertificationsNot publicly documented
No SOC, ISO or equivalent attestation is named anywhere in the Meta Model API Terms of Service, Meta's general Terms of Service, or Meta's Privacy Policy. Section 14 delegates the whole subject to a separate document — "Meta shall treat your Content and Customer Data in accordance with the Data Security Terms" — which is incorporated by reference rather than published alongside the terms. Ask for that document, and for certificate scope, before relying on any assurance here.Primary source · verified 2026-08-08
Trains on your data
The tier split is the whole story. Standard: Meta acts as processor and "will not use Content from Standard Services to train Meta Models". Discounted: "You agree that Meta may use your Content to train, develop, evaluate, and improve Meta's artificial intelligence models, products, and services", and critically "the Discounted Services do not offer a mechanism to exclude specific traffic from training. If… you otherwise require that Content not be used for training, you must use the Standard Services for that traffic." Disassociation from your account is attempted but bounded: "Meta may use Content for evaluation, safety, abuse, quality, and policy review without first applying those steps", and models so trained "may produce outputs or take actions (including for third parties) that are similar or identical to your Content". Note also that on both tiers you instruct Meta to retain and process Content "to develop, evaluate, and improve systems for the safety and the security of Meta products and services" — not model training, but not nothing.Primary source · verified 2026-08-08
Retention
Meta: "Meta will retain your Content and Usage Data as needed: (i) to provide the Services under these Terms; (ii) to the extent necessary for compliance with applicable laws; (iii) in connection with the exercise of Meta's rights to use your Content and Usage Data under these Terms; (iv) when our systems flag data for a potential policy violation; and (v) for security, safety, abuse, and policy review and improvements." No duration, no deletion commitment and no zero-retention option appears anywhere in the terms. This is the weakest retention disclosure of any vendor tracked here — Google at least bounds it to "a limited period of time", and every other row publishes a number or a zero-retention path.Primary source · verified 2026-08-08
Subprocessors
Meta: "You authorize Meta to engage subprocessors included in the list located [here], as may be updated by Meta from time to time." The authorisation is blanket and prospective, and the terms attach no advance-notice period, no change log and no subscription. Compare Microsoft at six months and AWS at thirty days, both contractual. The list itself sits behind a link in the terms rather than on a public compliance page.Primary source · verified 2026-08-08
EU AI Act
Read from the European Commission’s published signatory list, on which Amazon, Anthropic, Google, Microsoft, Mistral AI and OpenAI all appear and Meta does not. Absence is weaker evidence than presence: the Commission states that "Some signatories may not appear immediately, but we are making sure to continuously update the list as signatures are confirmed." Non-signature is not non-compliance — the Code is one route to demonstrating compliance with the AI Act, and a provider may use alternative adequate means instead.Primary source · verified 2026-08-07
Read the full Meta record →What this combination means for a regulated buyer, and what to check before signing.
Mistral AIModel developerEuropean frontier model developer. This row describes the paid API on the Scale plan, the tier a regulated buyer would contract for; consumer and lower paid tiers carry materially weaker defaults.
FLI safety grade
Lowest of the nine companies graded. Worth holding against the assumption that regulatory jurisdiction predicts vendor safety posture: the EU has the world’s most developed AI safety regulation, and the leading European developer placed last in the Index. A failing safety grade is not a bar to compliant deployment, and this row’s other cells are largely independent of it.Primary source · verified 2026-08-07
BAA availableNot publicly documented
Mistral’s Data Processing Addendum, effective July 27 2026, contains no occurrence of "HIPAA" or "Business Associate" while addressing GDPR, Standard Contractual Clauses and sub-processors at length; the help centre has no HIPAA article. Meanwhile Mistral’s solutions page markets "our HIPAA-compliant solutions" to healthcare buyers. A marketing adjective is not a BAA. Ask for the agreement in writing before assuming one exists.Primary source · verified 2026-08-07
Certifications
Quoted in full: "Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks." The wording is "complies with … frameworks" rather than "is certified", and the article is answering a question that asked about certification. That distinction is load-bearing for an auditor. Reports are available on request through the Trust Center; obtain the certificate and its scope rather than relying on this sentence.Primary source · verified 2026-08-07
Trains on your data
Mistral: "Customers on a Scale plan are opted out of training by default" and "Users of Vibe Teams or Enterprise plan are opted out of training by default." The default is plan-dependent, which no other vendor tracked here is — everyone else excludes business data by default across their commercial surface. On a Pro or free tier the data is used for training until someone turns it off. Once opted out, "Mistral no longer uses your input or output data for the purpose of training its models." Le Chat has been renamed Vibe.Primary source · verified 2026-08-07
Retention
Mistral: "Zero Data Retention (ZDR) is available only for the Scale plan and only for stateless API calls", and "ZDR is not available for Vibe Work, Chat, libraries, agents, conversations, batch files, or other stateful products that must store data to work." Requesting it requires "sufficient detail of your legitimate reasons". The published retention schedule covers account and billing data — five years for identity data, one rolling year for technical data, ten years for invoices — not inference data, for which no default period is stated.Primary source · verified 2026-08-07
Subprocessors
Mistral: "The updated list of our subprocessors is available at all times on our Trust Center" and "You can subscribe by email to receive notifications when we add or remove a subprocessor from this list." Notification covers removals as well as additions, which is unusual and useful. No advance-notice period is committed to.Primary source · verified 2026-08-07
EU AI Act
Listed by the Commission as "Mistral AI". Read from the Commission’s published list rather than from a vendor announcement.Primary source · verified 2026-08-07
Amazon BedrockDeployment platformDeployment platform. Hosts third-party foundation models inside the customer’s AWS account and region under AWS commercial terms — frequently the compliant route to a model whose direct API is not.
FLI safety gradeNot applicable
FLI grades model developers, not deployment platforms. The safety grades that bear on this row belong to the developers whose models it hosts — Anthropic, Meta and Mistral are all tracked here separately, and their grades span C+ to F. The compliance terms below are Amazon’s and apply regardless of which of those models is selected.Primary source · verified 2026-08-07
BAA available
Listed among AWS HIPAA Eligible Services, but with a model-level carve-out recorded verbatim as "Amazon Bedrock [excluding Fable and Mythos models]"; Amazon Bedrock AgentCore is listed separately. AWS states that covered entities "agree not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information… without first entering into an AWS business associate agreement." Eligibility is per-service and here per-model — check the specific model, not the service.Primary source · verified 2026-08-07
Certifications
AWS: "Amazon Bedrock is one of the AWS services under ISO Compliance for the ISO 9001, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 22301, and ISO 20000 standards", and it "is included in the scope of the SOC 1, 2, 3 reports". The breadth is the widest of any row here, though note the absence of ISO/IEC 42001, the AI management system standard that Anthropic and OpenAI both list.Primary source · verified 2026-08-07
Trains on your data
Two AWS pages sit in tension and the narrower one governs. The FAQ states flatly that "your content is not used to improve the base models and is not shared with any model providers" and that AWS and third-party providers "will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models." The data retention documentation then carves out an exception: "Claude Fable 5 and Claude Mythos 5 require provider data sharing (allowed_modes: ['provider_data_share']). Customers must explicitly set their data retention mode to provider_data_share before they can invoke these models." Sharing is opt-in and the models are simply unavailable otherwise, so the default holds — but the blanket FAQ sentence is no longer true of every model on the platform. These are the same two models excluded from HIPAA eligibility above.Primary source · verified 2026-08-07
Retention
Modes are default, provider_data_share, none and inherit, resolved project → account → model default. Mode none is "Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider", and it can be enforced organisation-wide by Service Control Policy — the only vendor here where retention posture is machine-enforceable rather than a support request. Two caveats: for models requiring provider_data_share, "user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes"; and AWS warns that "Setting store=false does not guarantee zero data retention." ZDR on retention-requiring models is "evaluated on a per-account, per-model basis in coordination with the model provider."Primary source · verified 2026-08-07
Subprocessors
AWS: "AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates, AWS will notify you by email of changes to this page." Last updated July 28, 2026. Sub-processors are split into four types, with those for the AWS European Sovereign Cloud listed separately. Shorter notice than Microsoft’s six months, but unlike OpenAI and Mistral it is a committed period rather than best-effort notification.Primary source · verified 2026-08-07
EU AI Act
The signatory is Amazon, the platform operator, and the commitment does not travel to the third-party models hosted on the platform. Anthropic and Mistral are signatories in their own right; Meta, whose models are also hosted here, is not listed.Primary source · verified 2026-08-07
Safety grades come from theFuture of Life Institute AI Safety Index, Summer 2026. FLI grades nine frontier companies across 37 indicators in six domains, with scoring reviewed by an independent panel. We cite the grades we use and link to the source for everything else.
Grades are stored against the edition that produced them. FLI's methodology changes between editions, so an unlabelled grade becomes wrong rather than merely stale.
What the Index does not measure is whether you can deploy a given vendor under HIPAA, SOC 2, or the EU AI Act and defend that decision. That gap is why the rest of this table exists. We explain the Index in full — the six domains, the complete grade table for all nine graded companies, and what it deliberately leaves out — on our FLI AI Safety Index methodology page.
Compliance claims come from each vendor's own documentation, terms, or trust centre. Press coverage is treated as a lead, never a citation.
Selecting an AI vendor you will have to defend
We help regulated organisations build AI vendor diligence that holds up in an audit.